Thursday, April 15, 2010
Brokerage firm victim of elaborate extortion scheme - but also gets hit with a fine
The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.
The Financial Industry Regulatory Authority, which announced the fine agreement on Monday, said although the attack activity was reflected in the brokerage’s server logs, administrators failed to examine those logs. The intruders obtained data on about 192,000 customers, according to the press release announcing the fine. (Previous reports indicated that more than 300,000 customer files were stolen). The data included customer account numbers, Social Security numbers, names, addresses, dates of birth and other private information.
The company discovered the breach only after receiving an extortion e-mail from one of the hackers on Jan. 16, 2008, which contained an attachment with the records of 20,000 customers as proof of the intrusion. DA Davidson contacted the Secret Service, and the subsequent investigation led to four suspects, three of whom are Latvian nationals, who were extradited from the Netherlands to face charges in Montana. In a statement released yesterday by the U.S. Attorney for Montana, the three Latvians pleaded guilty to receipt of extortion proceeds.
More: Wired Magazine
Three Plead Guilty in Plot to Extort DA Davidson - Financial Planning
The United States Department of Justice - United States Attorney's Office
Thursday, March 4, 2010
Major "goof" at Citibank
Check this out at WalletPop
Monday, March 1, 2010
Today is the day......
Discussion continues and questions abound. Will this set the bar nationwide as the articulation of what constitutes "reasonable security" for personal information? How should companies handle the varying risk of harm standards when dealing with state laws and federal law, such as the HITECH Act?
Friday, February 26, 2010
Top 3 questions relating to compliance with 201 CMR 17.00
16 Days to March 1..... and Countdown to compliance with 201 CMR 17.00.....11 days). Here are some questions that have been reoccurring over the last few weeks:
1) What should I be doing about the requirement relating to third party service providers and how does my company get "assurances" that those service providers (like payroll and benefits) are in compliance?
The answer to this will depend upon the kind of access and extent of information that the vendors have. Some companies have created extensive 3rd party/ vendor PI due diligence forms and processes. In the end, all your vendors should provide their own attestation that they are capable of meeting the requirements of 201 CMR 17.00 as part of the vendor review process, and it should be part of the contract. Depending on the situation, targeted risk assessments of vendors may be appropriate, as well as detailed security exhibits attached to contractual agreements. With existing service providers, if the contract is in place by Monday, you will have two years to amend it....but you should be addressing the security safeguard issues now.
2) What about faxes? How can I encrypt those, and is that required under 201 CMR 17,04?
A rather complex answer, but if the fax machine is using the Plain Old Telephone System (POTS to telecom engineers) this is not a "Public Transport" as used in 17.04(3). POTS is a private, switched, 2 party connection. The fax transmission in this case is simply not traveling over a public connection....and does not need to be encrypted nor would the fax machine require an encryption key technology. There are many other concerns with the "process" of sending and receiving faxes, most of these fall under logical or physical access controls, that are required elsewhere in 201 CMR 17.00. One thought of caution, is that there are many FAX systems that are NOT, 100% based on POTS or based on private switched network technology. If your business uses eFax or some other Internet-based form of transmission, that may be going to a traditional fax machine -- it’s POTS to me, but an email to you that is traveling over the public network. If you have a concern about the security of PI in a process, then you most likely have something which needs to be locked down and controlled.
3) We have a good handle on the computer system security requirements and the technical issues, including the whole portable device issue, but what about all that paper?
Start with the basics - do you really need to have the PI in paper format, and do you need as much as you have? If you don't have it, you can't lose it. Keep track of what is in the file, so missing items will be noticed, and to enable you to comply with data breach notification obligations if the worst happens. Simple things like: use color-coding and labels to indicate the sensitivity of the file; consider whether the original or a copy can be taken, if a copy, track the number of copies and stamp them; physically attaching documents to a folder makes copying/losing items more difficult. Use log-in/out records for the files. Remind employees to keep the records in sight or in a safe location when out of sight - use a briefcase lock if there is one, keep files in the trunk of the car and not on the car seat. The most important step is to make sure the plan is followed and to TRAIN EMPLOYEES. Companies can craft great policies and procedures to handle PI and comply with 201 CMR 17.00. But if employees and third parties are not educated and trained in these policies then compliance with the law is highly unlikely! Training, training, training. Security awareness is a big key to avoiding the unfortunate data breach.
And, it's Friday, February 26th......
Monday, February 22, 2010
T Minus 10,080 Minutes and Counting.....
- Have you done your risk assessment? Looked at what you collect and how you collect and how it is transmitted through and outside your organization?
- Have you reached out to service providers that may have access to PI of your employees/customers?
- Is your written information security plan in place, or at least have you started pulling together the various policies and processes ("P&P") that would make up a "written information security plan"? Is the plan tailored to your actual P&P and, thus an accurate representation of what your business really does (and not a template with [insert company name here])?
- Have you thought about employee security awareness training?
Monday, February 1, 2010
27 days and counting...
If you are one of the procrastinators (and, you are not alone), the basic information and the regulations can be found at the Office of Consumer and Business Affairs Regulation website. If you are larger than a mom-and-pop shop, however, you rely on the template information security plan at some considerable risk.
Over the next week or so, we will be blogging with preparedness tips, so come back often.
Thursday, January 28, 2010
Data Privacy Day -- Tip #4 -- Transactional Best Practices for Lawyers
Even though lawyers working on both sides of an M&A transaction during the due diligence phase might immerse themselves in a “confidentiality bubble”, they still must be careful not to disclose or access confidential employee information in the course of that transaction. Attorneys evaluating potential transactions might be tempted to access information regarding target employees, such as personnel files, compensation information, and information concerning performance evaluation and other historical employment information. Transactional attorneys are often surprised to learn that dissemination of some of this information, even among those subject to a confidentiality agreement, may violate an employee’s privacy rights and even violate the law.
Some states preclude employers from disclosing employee personnel information or from revealing information regarding employee compensation altogether while other states require a waiver from the employee as a condition to dissemination to any third parties. Federal and many states laws make it illegal for companies to disclose employee medical records without authorization, and this is particularly a concern where those records include personal health information and may implicate newly-expanded HIPAA regulations. Personnel files of employees that are Massachusetts residents will contain "personal information" that can only be transmitted in compliance with the Massachusetts regulations. In the cross-border M&A context, "personal data" of employees can only be transferred to the U.S. (or to U.S. persons) in compliance with applicable data protection laws in their country of residence/employment -- and in most cases can only be with the employee's consent. Even documents in a digital "data room" that can be accessed from the U.S. may fall afoul of data protection laws in other countries.
Companies must ensure that they have the proper mechanisms in place to minimize the exposure of personnel information during a contemplated transaction, including having a good understanding as to what legally may and may not be provided to potential acquirers, and securing any necessary waivers from employees prior to turning that information over in the due diligence process.
And finally, storage and disposal of due diligence files containing personal information or protected health information must be handled in accordance with applicable state and federal laws. If you don't keep it, you can't lose it!
Tuesday, December 22, 2009
Data Security Roundtable
http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&newsId=20091222005345&newsLang=en
Some very interesting discussions with folks who are on the cutting edge of data security. I'll post the other segments as they are released.
Thursday, September 10, 2009
Some "light reading" for privacy geeks...
It's a must-read for thought leadership in this space.
Friday, August 14, 2009
To Encrypt or Not To Encrypt…….An Incentive Rather than a Mandate From Michigan
The Information Security Program Standards Act introduced last week differs a bit from Massachusetts and Nevada (and other pending legislation) in that it would not require the implementation of detailed security measures --- the Michigan act provides a carrot to those who do: Breach liability immunity.








