Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, May 29, 2014

Jason Atchley : Data Security : Law Firms Fail to Protect Data When File Sharing

jason atchley

Law Firms Fail to Protect Data When File Sharing

LexisNexis survey shows disconnect between security concerns and steps taken to protect data.
, Law Technology News
    |3 Comments

U.S. law firms may be worried about the security risks of sharing confidential information online, but a new survey by LexisNexis' legal and professional division reveals that they are not doing much about it.
Unencrypted email remains by far the most prominent way that law firms share privileged communications with their clients, with 89 percent of respondents reporting that it is the firm's primary method of distributing information. 
In March, the company canvassed about 300 legal professionals in 40 states across 15 different practice areas. Results show that although respondents were aware of the risks, and wary of them, the most common method of securing documents and protecting privilege was the use of a confidentiality statement at the bottom of an email, with 77 percent of firms reporting this was their primary line of defense.
“There’s clearly a disconnect between expressed security concerns and measures law firms employ to protect their clients and themselves,” said Christopher Anderson, a senior product manager at LexisNexis, in a statement. “Relying on a mere statement of confidentiality when sharing privileged communications by email is a weak measure—and further it might protect the law firm but affords very little protection for the client,” he said.
A minority of law firms go a step further to protect their information, with 22 percent saying they use email encryption,14 percent using a password to protect documents and 13 percent employing a secure file-sharing site. At the reverse end of the spectrum, 4 percent of respondents said they take no measures at all to protect private information. “Law firms need to perform their due diligence, stay abreast of technology and ultimately protect their clients’ interest online just as they do in providing legal counsel,” said Anderson.
Attorney Marlisse Silver Sweeney is a freelance writer based in Vancouver. Twitter: @MarlisseSS.


Read more: http://www.lawtechnologynews.com/id=1401279925290/Law-Firms-Fail-to-Protect-Data-When-File-Sharing#ixzz338kEgR00



Thursday, May 15, 2014

Jason Atchley : Data Security : Coping With Evolving U.S., State Cyber-security Rules

jason atchley

Coping With Evolving U.S., State Cybersecurity Rules

, Corporate Counsel
    |0 Comments

Cybersecurity and data protection, more than ever, are priority items for the government and private sector. The government’s interest is to protect the country from a cyberattack that will cripple the economy or critical infrastructure. The private sector’s interest is to protect its products as well as the safety of its customers’ financial and private data. Recent high-profile data breaches exposed vulnerabilities in the safety of our country’s consumer data, which is the bedrock of the rebounding economy, resulting in millions of dollars in damages.
The government has reacted by proposing legislative “fixes” that would require organizations to satisfy basic levels of cybersecurity protection and disclose breaches or face fines. Whether a mandatory compliance model for cybersecurity will be effective given the rapid pace by which technology advances is unclear. It may be unrealistic to expect the government’s legislative pace to keep up with hackers.
Another complication that affects the efficiency of solutions is the question of who should regulate and enforce cyber law. To date, federal and state governments have been able to share jurisdiction over cybersecurity and data protection without much controversy, albeit with some inefficiency. However, this shared jurisdiction may be getting more complicated as federal agencies, such as the Federal Trade Commission (FTC), try to take a bigger role.
Regardless of whether cybersecurity laws are enforced on a federal or state level, or both, corporate counsel, who are on the front lines of data security compliance, should be aware of their legal obligations in order to mitigate risk for the organization and its customers. The primary jurisdicational questions that should be on corporate counsel’s radar during this time of change in cybersecurity law are: 1) What is the federal government’s role in cybersecurity compliance, and will it change in the near future? 2) Will a federal disclosure law increase a corporation’s obligations or streamline them?
The Federal Government’s Role
At present, there are more than 50 federal laws that govern some aspect of cybersecurity law. In addition, many federal agencies have jurisdiction to enforce these laws in sectors such as finance, energy and health care. Recent attempts at passing comprehensive legislation have failed, resulting in a piecemeal approach. This began with the 2013 Cybersecurity Executive Order, which created a voluntary best practices model for organizations of all sizes, with a focus on organizations considered “critical infrastructure.” The National Institute of Standards and Technology and the Department of Homeland Security, which have led this initiative, plan to continue implementation efforts in coming years to incentivize organizations to improve their cybersecurity on a voluntary basis led by the private sector.
At the same time, mandatory statutory measures are being formulated. The FTC has been actively advocating for Congress to pass legislation that would increase its enforcement authority and ability to fine organizations that do not adequately protect their data. Congress has drafted bills that would create such a compliance model, but, to date, no consensus has been reached and no new laws passed. Notwithstanding the absence of new legislation, the FTC’s authority to enforce data privacy standards for consumers was affirmed by the judicial branch in a decision in April. A federal district court in New Jersey denied Wyndham Worldwide Corporation’s motion to dismiss an FTC complaint alleging that Wyndham engaged in unfair and deceptive data security practices by failing to maintain “reasonable and appropriate data security” for its customers. In doing so, the court affirmed that the FTC’s authority to redress “unfair” or “deceptive” trade practices extends to data security
The practical reach of the Wyndham decision is unsettled because the court expressly recognized limits to the FTC’s authority in future cases. The court stated that the FTC does not have “a blank check to sustain a lawsuit against every business that has been hacked.” That said, Wyndham involves claims of deceptive practices relating to online privacy policies. In the short term, corporations should take from the court’s holding that accurate descriptions of their online privacy policies (and their effectiveness) must be a priority in order to minimize legal vulnerabilities, such as a possible lawsuit from the FTC. Corporations should also understand that the FTC’s jurisdictional reach and enforcement in the area of cybersecurity will likely continue to expand given the growing support for such jurisdiction in the courts and in Congress.
With increasing FTC authority, it is unclear what will happen to state cybersecurity laws. For example, California and Massachusetts have implemented robust cybersecurity enforcement initiatives. Whether these state initiatives will be curtailed in light of increased federal authority will likely be answered in coming years. For now, corporations should be prepared to comply with both federal and state initiatives until compliance models are finalized.
The Effect of a Disclosure Law
Most states require organizations to disclose breaches of their citizens’ data. Kentucky is the most recent state to enact a disclosure law. The problem for disclosing entities is that state laws have different requirements and thus lack uniformity. In response, one of the proposed federal bills establishes a federal data breach disclosure law. The purpose is to clarify and simplify the onerous requirements of inconsistent state laws. A federal law would also aim to resolve potential jurisdictional obstacles in state court actions where a state is trying to enforce its disclosure statute on an out-of-state organization.
In reality, it is unlikely that states will take a “back seat” to the federal government on data breach issues, particularly because of the state’s interest in protecting the personal and financial data of its citizens. While it is possible that a federal-state cybersecurity disclosure model may evolve similar to that which is in place under existing laws (like the Health Insurance Portability and Accountability Act), a federal disclosure law would likely not supplant state efforts, especially given the limited enforcement capabilities and budget of both.


Read more: http://www.corpcounsel.com/id=1202654946074/Coping-With-Evolving-U.S.%2C-State-Cybersecurity-Rules#ixzz31mz8NZZE




Monday, February 24, 2014

Jason Atchley : eDiscovery : EDM Updates Privacy, Security Risk Reduction Model

jason atchley

EDRM Updates Privacy, Security Risk Reduction Model

The new model incorporates real-world experiences and industry feedback.
, Law Technology News
    |0 Comments













EDRM, an electronic discovery and information governance company, has announced the reintroduction and refinement of its Privacy & Security Risk Reduction Model, in a recent statement. This model was originally introduced last September and provides a process for reducing the volume of private, protected and risky data by using a series of steps applied in sequence as part of the information management, identification, preservation and collection phases within e-discovery.
According to the company, the model has been revised to address issues of exposure in an organized and systematic manner, since high-risk data can cause significant trouble for companies.  This was made all too clear in the Target and Neiman Marcus data breaches.  EDRM says they have revised the model to include industry feedback and real-world experiences into the data remediation and e-discovery projects.
The updated model provides a framework for ongoing iterative risk reduction and a step-by-step guide to addressing highly sensitive data, including personally identifiable information, proprietary data and privileged communications.
Attorney Marlisse Silver Sweeney is a freelance writer based in Vancouver.MarlisseSilverSweeney@gmail.com. Twitter: @MarlisseSS. LTN: @lawtechnews.


Read more: http://www.lawtechnologynews.com/id=1392982595237/EDRM-Updates-Privacy%2C-Security-Risk-Reduction-Model#ixzz2uG8zeWeh