Posted inData Privacy

Anthem Discloses Huge Data Breach

Health insurer Anthem said hackers gained unauthorized access to its IT systems and stole personal information relating to tens of millions of current and former members and employees. Calling it a “very sophisticated external cyber-attack,” Anthem CEO Joseph Swedish said the breach does not appear to have compromised credit card or medical information, but it did sweep up addresses, income estimates, Social Security numbers, and more. Details inside.

Posted inData Privacy

SEC, FINRA Dropping Hints on Risk

Compliance officers looking to read some tea leaves about what worries the Securities and Exchange Commission these days might want to skim the 2015 exam priorities that the SEC and FINRA have posted. That guidance applies foremost to financial firms, but “it’s only a matter of time before they require more organizations to have these safeguards in place,” says Ken Fleming of Xerox Litigation Services.

Posted inData Privacy

AvePoint Compliance Guardian SP 3 Helps With Data Loss Prevention

AvePoint, a provider of enterprise-class Big Data management, governance, and compliance software solutions for next-generation social collaboration platforms, has announced the general availability of AvePoint Compliance Guardian Service Pack (SP) 3. Compliance Guardian mitigates privacy, information security, and compliance risks across your information gateways with a comprehensive risk management process allowing organizations to document their policies, implement and measure them, and demonstrate conformance.

Posted inData Privacy

Latest PCI Standard Pushes Toward Risk Management

Image: Version 3.0 of the PCI Data Security Standard goes into effect this month—and maybe, just possibly, it will strengthen companies’ discipline against credit card data theft. The new standard prods companies to approach security as a continuous risk monitoring duty. “You can’t have smooth implementation until you start to think about this more broadly, like you would any other business problem,” says Christopher Avery of the law firm Davis Wright Tremaine.

Posted inData Privacy

ECI Launches New Data Security Solution, PayArmor

Electronic Commerce International, a payment processing solutions provider, today announced the  launch of PayArmor, a new way for companies to protect customer data from cyber criminals. PayArmor is a multi-layered suite of security and compliance services built to safeguard businesses against fraud, credit card data security breaches and to assist with PCI compliance. Details inside.

Posted inData Privacy

Another Step Forward in Tackling Cyber-Security Risk

Image: Dec. 31—COSO’s Internal Control — Integrated Framework talks a good game about being useful beyond financial reporting risks, but Compliance Week Editor Matt Kelly has always wondered how that works in practice. Then came a nifty piece of guidance: a taxonomy of operational risks in cyber-security, published by the Software Engineering Institute, a division of CERT at Carnegie Mellon University. Combine that tool for risk assessment and COSO’s approach for risk management, he says, and cyber-risks get a little less scary. Details inside.

Posted inData Privacy

Podcast: Navigating the Pitfalls of Geolocation Data

Uber, Snapchat, and Golden Technologies are the latest companies to come under fire for how they use the geolocation data they colect from their customers. In this week’s podcast, we talk to Fernando Bohorquez, a partner at the law firm BakerHostetler who specializes in privacy and data security issues, about how companies can navigate the inherent risks of this increasingly valuable data, incorporate the FTC’s “privacy-by-design” standard, and stay out of trouble with regulators and privacy advocates alike.

Posted inData Privacy

Sony, Lesson 1: Communication Breakdown

Image: The lessons from Sony’s surrender to North Korean hackers last week are too many to count right now, so let’s start with an immediate one: understand the risks your company creates with its communication habits, and enforce smarter business practices to change them. Easy enough to say, Compliance Week editor Matt Kelly writes. As always, forcing cultural change like that is much harder. More of his thoughts inside.

Posted inData Privacy

TD Bank to Pay $625K for Data Breach

TD Bank this week reached a $625,000 settlement with the Massachusetts Attorney General’s Office after losing unencrypted back-up tapes containing personal information of more than 260,000 consumers nationwide, and delaying notice of the incident. The final settlement amounted to $825,000, but the AG’s Office credited the bank $200,000 to reflect security measures and upgrades it has already taken following the incident. Details inside.

Verify your email

We'll send a verification code to .

Gift this article