Showing posts with label ashley madison. Show all posts
Showing posts with label ashley madison. Show all posts

Wednesday, July 29, 2015

Jason Atchley : Data Security : New Standards Coming, Time for a Data Security Check

jason atchley

New Standards Coming, Time for a Data Security Check

, Corporate Counsel
    | 1 Comments

It appears that hackers don’t take the summer off. From the U.S. Office of Personnel Management to online dating site Ashley Madison, cybercriminals have been proving that they will go after just about any sort of target that holds people’s personal data.
At the same time, regulators have been trying to fight back—particularly in the European Union, where new rules on data protection are emerging that may be finalized as early as the end of this year. Although these regulations are European, many U.S. companies that do business in the EU and work with customers and employees there will still have to worry about complying.
Given the one-two punch of increasing cyberattacks and impending regulatory changes, now might be a good time for companies to take a hard look at the way they process and protect their data. “Most companies nowadays are going above and beyond anything that’s out there right now and looking forward to the future,” Kristoph Gustovich, director of hosting and security at Mitratech, told CorpCounsel.com. “They’re always looking to meet what’s going to be the next stage of regulations.”
To help direct companies’ energies and attention toward the cybersecurity issues that matter, Mitratech has released a white paper titled A 6-Step Health Check for your Organization’s Data Privacy Program.
One major action that companies should be taking in anticipation of regulatory changes from Europe, according to the white paper, is ensuring that they’ve taken account of how new rules will redefine their roles in data protection activities. Many companies that managed to avoid a certain amount of responsibility for their customer data by being labeled “data processors” will have the same amount of responsibility as “data controllers” under new regulations. This leveling means that some companies will have to toughen their security stance when it comes to dealing with customers’ personal data.
It’s not just the roles of some companies that are changing, however. Roles of individuals within the companies also have to evolve to meet heightened legal and security needs. The new EU regulations, for example, may require companies with a certain number of employees and a certain amount of data to appoint a data protection officer from either inside or outside the company. This person will be responsible for making sure the company complies with privacy requirements.
General counsel are also seeing their roles evolve as breach risks rise and regulatory risks grow. "The laws are always going to change, and unless you have a general counsel involved to understand that, to present that to the technologist in a way that they can understand, there’s no way the technologist will be able to understand all the nuance,” said Gustovich. He also warned of putting cybersecurity responsibilities in silos—whether they are IT’s or legal’s. In his experience, he noted, that approach is doomed to fail.
One of the most important jobs in-house counsel have for cybersecurity is ensuring that the company’s contracts are compliant with data security laws. The white paper identifies use of contract language as an area where companies covered by new European regulations will probably have to make substantial changes.
The new rules will likely require that companies tell users and customers, in the company’s contracts, what data of theirs the firm will use and how it will use the information. Then, they must get the users to “opt in.” In contrast, a good number of U.S. companies have customers opt in to data collection by default, and insist that they explicitly “opt out.”
Another contractual issue the white paper addresses is the need for very specific language in user contracts. It explains that blanket contract terms will no longer cut it, in terms of compliance with emerging data security laws. And if a company intends to conduct data mining, this has to be made contractually clear to customers and users.
For companies, it’s essential to stay ahead of the curve on the increasingly difficult security environment and on the new European regulations, which may very well set the pace for other future data privacy rules in the U.S. and abroad, said Gustovich. He pointed out that when budgets and contracts need to be adjusted, companies shouldn’t wait to get started—even if the EU gives the two-year lead time between finalization and implementation that it has indicated it will give. Adjusting to serious regulatory changes takes time and planning. “It will come up much faster than people expect,” Gustovich warned.


Read more: http://www.corpcounsel.com/id=1202732943057/New-Standards-Coming-Time-for-a-Data-Security-Check#ixzz3hI0IPaS1


Monday, July 20, 2015

Jason Atchley : Data Security : Hackers Gain Access to Extramarital Dating Databases

jason atchley

Hackers Gain Access to Extramarital Dating Databases

, Legaltech News
    | 0 Comments

Few things in life are as private as our romantic entanglements. So with hackers announcing they’ve made off with as many as 37 million records from the parent company of extramarital dating site AshleyMadison.com, you can be sure there are plenty of people sweating over the potential fallout.
The group, which calls itself “The Impact Team,” released a statement on July 20 saying that it has gained access to the databases of Canada-based Avid Life Media, which runs Ashley Madison and other dating sites.  The hackers said that if ALM does not comply with its demand to shut down services, it will release private information on its clientele. In addition to the notification, the group has also released a small portion of the data stolen as a demonstration of its intent.
In an interview with cybersecurity blogger Brian Krebs, Avid Life Media CEO Noel Bidderman, said that the company is investigating the breach, which he called “criminal” in nature. “We’re on the doorstep of [confirming] who we believe is the culprit, and unfortunately that may have triggered this mass publication,” Biderman said. “I’ve got their profile right in front of me, all their work credentials. It was definitely a person here that was not an employee but certainly had touched our technical services.”
Avid Life Media’s services differ from traditional dating sites in that they target subsets of dating culture. Ashley Madison bills itself as a dating site for married people, using the tagline “Life is Short. Have an Affair,” to illustrate that point. The site EstablishedMen.com offers affluent males dating connections to younger women, but hackers charge that it is also used to facilitate prostitution and human trafficking.
Avid Life Media offers a “full delete” option designed to help users cover their tracks, a service they charge $19.99 for. However, the hacking group said that the service did little to protect information collected from users.
Impact Team wrote in the statement: “Full Delete netted Avid Life Media $1.7 [million] in revenue in 2014. It’s also a complete lie. Users almost always pay with credit card; their purchase details are not removed as promised, and include real name and address, which is of course the most important information the users want removed.” 
While Avid Life Media has not announced how it intends to react to the request, it is unlikely that they will shutter site operations. If hackers are successful in leaking Avid Life Media user information, legal action stemming from the breach is inevitable. That’s likely to include not only the standard class action against the breach victims, but probably an uptick in divorce filins as well.


Read more: http://www.legaltechnews.com/id=1202732567355/Hackers-Gain-Access-to-Extramarital-Dating-Databases#ixzz3gT58JOxB