Cyber-Security


Hackers

SEC fines broker-dealer $1.5M for SARs filing failures

2021-05-12T18:01:00+01:00By

GWFS Equities will pay $1.5 million as part of a settlement with the SEC for lapses in the filing of suspicious activity reports related to the threat of cyber-breaches.

Comey CW2021 blog

James Comey: Lessons from Enron era will ‘become real again’

2021-05-11T20:17:00+01:00By

Former FBI Director James Comey kicked off Compliance Week’s 16th annual National Conference on Tuesday by speaking candidly about a variety of risk and compliance matters, including the importance of a strong ethical culture in the coming post-pandemic “boom times.”

AI

What you need to know about proposed EU rules for trustworthy AI

2021-04-29T18:27:00+01:00By

With various levels of defined risk and the potential for steep fines for offenders, the European Commission’s recent proposal to ensure trust in the use of artificial intelligence should receive urgent attention from industries beyond Big Tech.

Coronavirus office

Six best practices for managing cyber-security upon return to office

2021-04-23T13:18:00+01:00By Marc Gilman, CW guest columnist

The hybrid work environment many organizations are expected to utilize as part of the gradual return to the workplace presents numerous cyber-security risks that require proactive attention.

Data money

Fines key attention to data privacy from boards, says ICO head

2021-04-21T15:04:00+01:00By

The threat of fines has done more to focus boardroom attention on data privacy and effective cyber-security than any other measure, U.K. Information Commissioner Elizabeth Denham believes.

columnist icons - kyle

New chief compliance officer, same Facebook

2021-04-16T14:29:00+01:00By

It isn’t surprising to see Facebook think it doesn’t have an ethical obligation to alert users to its latest data leak, writes Kyle Brasseur, but it is disappointing knowing the company now has a chief compliance officer in place.

Russia_United States

U.S. sanctions Russia over SolarWinds hack

2021-04-15T19:52:00+01:00By

The Treasury Department announced sanctions against Russia implemented under an executive order from President Joe Biden in response to the SolarWinds hack and alleged election interference by the country.

Nailedit1200x800

Video: Kudos to whistleblower chief Jane Norberg on successful SEC tenure

2021-04-15T18:03:00+01:00By Compliance Week

Aaron Nicodemus applauds outgoing SEC whistleblower chief Jane Norberg for “revolutionizing” the program and the agency, while Kyle Brasseur laments Facebook’s ethical bungling of its recent data leak.

Facebook

Facebook facing 10th GDPR probe over data leak

2021-04-14T17:10:00+01:00By

The Irish Data Protection Commission has launched an inquiry into Facebook over concerns the social media giant may not have properly disclosed the full extent of its recent data leak.

Facebook privacy

Facebook’s new leak: Assessing its liability under the GDPR

2021-04-08T20:19:00+01:00By

Old personal data of more than 533 million Facebook users was recently made publicly available on a hacker forum. Could the social media giant face a new investigation under the GDPR in response?

Facebook

​Irish DPC seeking answers on Facebook breach

2021-04-07T19:37:00+01:00By

The Irish Data Protection Commission has reached out to Facebook seeking to determine whether the social media giant’s weekend data breach should receive scrutiny under the General Data Protection Regulation.

breach

Data breach disclosures drop in 2020, report says

2021-04-07T18:44:00+01:00By

Cyber-breach disclosures in 2020 were down 19 percent from 2019—the first drop in the statistic in five years, according to a new report from Audit Analytics.

Booking

Booking.com fined $557K under GDPR for reporting data breach late

2021-04-01T20:55:00+01:00By

Online reservation Website Booking.com has been fined €475,000 (U.S. $557,000) by the Dutch Data Protection Authority for reporting a data breach 22 days later than the 72 hours required under the GDPR.

Nailedit1200x800

Video: More scrutiny coming to data breach disclosures?

2021-04-01T19:50:00+01:00By Compliance Week

Aly McDevitt assesses controversial data breach disclosures from U.K. retailer FatFace and technology vendor Ubiquiti in light of a report Congress is considering stricter requirements for reporting data breaches.

James Comey

James Comey: Buckle up for dangerous post-pandemic risk landscape

2021-03-30T17:41:00+01:00By

Former FBI Director James Comey predicted a “time of extraordinary change” is ahead for the compliance profession in the post-pandemic world during a prerecorded video message at Compliance Week’s Financial Crimes virtual event.

Cyber-security

Internal audit’s role in cyber-security testing: Where to start

2021-03-22T18:00:00+00:00By

Nathan Anderson, senior director of internal audit at McDonald’s, discusses ways internal audit can better answer management questions about cyber-risks and become a more independent cyber-security testing function overall.

Roberts Ask a CCO

Ask a CCO: Are you in favor of federal data privacy legislation?

2021-03-09T21:30:00+00:00By Compliance Week

It’s a clean sweep: All five CCOs we spoke with are in favor of U.S. federal data privacy legislation. Read on for the reasoning behind their answers.

New York cyber-security

NYDFS fines mortgage banker $1.5M for cyber-security violations

2021-03-05T13:34:00+00:00By

The New York State Department of Financial Services fined Residential Mortgage Services $1.5 million for violating New York’s cyber-security regulation.

Ask a CCO image

Ask a CCO: What’s your strategy for preventing and detecting data breaches?

2021-03-04T13:40:00+00:00By Compliance Week

Five senior compliance practitioners outline their strategies for protecting their firms from data breaches.

ask cco 3x2 roberts

Ask a CCO: How is your company reacting to cyber-risks introduced by COVID-19?

2021-03-03T12:56:00+00:00By Compliance Week

Five senior compliance practitioners tell Compliance Week how their organizations are reacting to new cyber-threats introduced by the pandemic.

kortney quote

Ask a CCO: What’s your role in creating/implementing cyber-security policies?

2021-03-02T18:16:00+00:00By Compliance Week

Five senior compliance practitioners share insights on their roles in implementing and overseeing cyber-security policies and procedures.

LifePoint

Special report: Compliance, infosec & battling cyber-threats

2021-03-02T16:54:00+00:00By

LifePoint Health’s VP for Compliance Program Operations/Chief Privacy Officer Ellen Hunt and VP/CISO Andy Heins share how they work ”hand in glove” to protect their company’s data from bad actors.

intsights 300x200

CPE Webcast: How modern cyber-threat intelligence can enrich system security

2021-02-23T14:00:00+00:00Provided by

Threat Intelligence is normally used to enrich the process of security assessment, providing proof on the enforcement of security controls required to be secure and compliant.

cyber insurance

Cyber-insurance: Why you need it and how to choose the right plan

2021-02-22T20:49:00+00:00By

As cyber-attacks surge, the need for cyber-insurance is growing more urgent. But it’s critical for companies to first familiarize themselves with how to navigate the labyrinth of cyber-insurance products on the market so that they are properly covered.

Kroger

Kroger joins victims of Accellion data breach

2021-02-22T19:58:00+00:00By

Two months after cloud service vendor Accellion first identified one of its legacy products was targeted by a sophisticated cyber-attack, users of the product continue to feel the impact, with grocery chain Kroger the latest to reveal its exposure.

Cyber-guard

Survey: Firms enhanced cyber-security in 2020, but not enough

2021-02-17T14:26:00+00:00By

Companies forced to pivot to remote work in a global health crisis spent the bulk of 2020 grappling with heightened cyber-security risks. A year later, compliance practitioners say their companies’ cyber-security postures are better for it—even in the wake of the stunning SolarWinds hack.

exterro300x200

CPE Webcast: Vital framework to defensible data incident and breach response

2021-02-16T14:00:00+00:00Provided by

Today’s breach landscape is unprecedented and complex. Every organization is facing potential enforcement of many interconnected and overlapping laws in multiple jurisdictions.

Risk

FINRA report: Top risk areas for AML, cyber-security

2021-02-05T20:31:00+00:00By

The Financial Industry Regulatory Authority has published a new report designed to help inform member firms’ compliance programs by providing annual insights from its examinations and risk monitoring programs.

2021

Survey: Pandemic pervades executives’ top 10 risks for 2021

2021-02-05T17:39:00+00:00By

The aftermath of the coronavirus pandemic dominates the top risks that will keep boards of directors and executive management teams on their toes in 2021, a new survey by Protiviti and NC State’s ERM Initiative finds.

cybergrx digital transformation

White paper: Digital Transformation & Cyber Risk: What You Need to Know to Stay Safe

2021-02-03T06:07:00+00:00Provided by

CyberGRX and Ponemon Institute surveyed 581 IT security and 302 C-suite executives to determine what impact digital transformation is having on cybersecurity and how prepared organizations are to deal with that impact.

SolarWinds

SolarWinds hack turning into Pandora’s box of cyber-risk

2021-02-02T20:47:00+00:00By

The more we learn about the SolarWinds hack, the more troubled compliance officers should be by the scope and breadth of the risks their companies might have incurred.

Maria Vullo

NYDFS regulation a best-practices model for cyber-security training

2021-02-01T17:05:00+00:00By

Companies must make cyber-security a continuous priority as threats evolve, often more quickly than the technology and regulations to counter them. That’s why the New York Department of Financial Services, under Maria Vullo, developed a policy that should act as a model for organizations.

cybergrx fs infosheet coverimg

White paper: Reducing Cyber Risk for the Financial Service Industry

2021-01-26T07:29:00+00:00Provided by

The financial services industry is a leading target for cyber criminals because there’s more than one way one way to profit from an attack.

Cyber-risk panelists

Cyber-Risk Summit: Compliance should view cyber-security through prism of risk

2021-01-21T21:39:00+00:00By

What’s most important for compliance officers is to understand the risks breaches and hacks pose to their organizations, not the technical manner of how those breaches occur, according to an expert panel at CW’s virtual Cyber-Risk & Data Privacy Summit.

Cyber-risk panel

Cyber-Risk Summit: 7 best practices for protecting employee health data

2021-01-21T21:19:00+00:00By

Experts at CW’s virtual Cyber-Risk and Data Privacy Summit explain the importance for companies to review and enhance their current data security compliance policies and procedures.

Health records

Excellus Health Plan fined $5.1M for 2015 data breach

2021-01-20T16:21:00+00:00By

The U.S. Department of Health and Human Services’ Office for Civil Rights fined Excellus Health Plan $5.1 million for failures relating to a 2015 data breach that exposed the personal information of 9.3 million individuals.

British Airways

British Airways breach could cost billions in landmark class-action push

2021-01-15T15:12:00+00:00By

British Airways faces the largest group claim ever made in U.K. legal history over a 2018 data breach that exposed the financial and personal details of more than 400,000 of its customers.

Cyber locks

Biden names NSA cyber head to White House position

2021-01-07T19:41:00+00:00By

Anne Neuberger, currently the cyber-security director at the National Security Agency, has been appointed to fill a newly created cyber-security position on President-elect Joe Biden’s National Security Council.

Cloud supply chain

Learning from SolarWinds: Five steps to fortify your cloud supply chain

2020-12-30T20:24:00+00:00By

For most companies, supply chain risk management traditionally focuses on managing physical third-party risks. But what the SolarWinds cyber-attack revealed is the catastrophic havoc fourth and fifth parties can also wreak in the often-ignored cloud supply chain.

Coronavirus fails

Assessing 2020: Lessons learned for the financial crime landscape

2020-12-29T21:49:00+00:00By James Thomas, International Compliance Association

This year has been one most of us would like to forget. As we look toward 2021, nevertheless, it is worth considering lessons learned over the last 12 months and (where possible) drawing on any positives that have come to light regarding the financial crime landscape.

SolarWinds

Cyber-security lessons from the SolarWinds hack

2020-12-18T15:44:00+00:00By

The lessons from the massive SolarWinds hack on where vulnerabilities still lurk in the third-party vendor supply chain cannot be grasped soon enough.

Twitter

Twitter’s tiny $547K GDPR fine leaves many scratching their heads

2020-12-15T20:19:00+00:00By

Ireland’s first major decision against a Big Tech company under the GDPR has stirred controversy as the country’s data regulator hit Twitter with an underwhelming €450,000 (U.S. $547,000) fine for a 2018 data breach.

Europe

Five challenges for European CCOs heading into 2021

2020-12-10T21:13:00+00:00By

Many of the problems European compliance officers faced in 2020 will remain in place going into the new year, but new risks and new regulations will also present new challenges.

Cyber-security

Preparation, monitoring key to combating third-party cyber-security risk

2020-12-07T17:49:00+00:00By

A spate of recent cyber-security breaches occurring via third parties is a reminder of the importance for companies to stay on top of risk management. Regulators have shown to not take kindly to finger-pointing.

Crypto

Cryptocurrency’s future: What compliance needs to know

2020-11-17T19:15:00+00:00By David Povey, International Compliance Association

Cryptocurrency is complicated, but it’s not going away anytime soon. David Povey of the ICA takes a look at what regulators are trying to do and offers tips on where compliance officers can go to study this complex topic further.

Ticketmaster

Ticketmaster UK fined $1.6M under GDPR for 2018 data breach

2020-11-13T18:18:00+00:00By

The U.K. Information Commissioner’s Office fined Ticketmaster £1.25 million (U.S. $1.6 million) for its failures relating to a 2018 data breach by a third party.

Coronavirus fails

OCC report: Banks sound, but compliance risks elevated amid pandemic

2020-11-11T19:10:00+00:00By

The U.S. banking industry is stable nearly nine months into the coronavirus pandemic, but the OCC warns of increased risks for banks seeking to comply with the Bank Secrecy Act and consumer protection and fair lending requirements.

Cyber risk

Audit committee best practices for understanding and acting on cyber-threats

2020-11-05T20:44:00+00:00By

Cyber-security risk oversight is the area with the greatest increase in audit committee disclosures in proxy statements, so you better make sure you’ve got a handle on understanding your responsibilities.

Coronavirus look ahead

New bank resiliency guidance tackles cyber-risk, pandemic planning

2020-11-02T17:45:00+00:00By

Federal banking regulators have released new operational resiliency guidance aimed to strengthen risk management around technology-based failures, cyber-incidents, pandemic outbreaks, natural disasters, and more.

Marriott

In second drastic reduction, ICO fines Marriott $23.8M

2020-10-30T19:44:00+00:00By

The Marriott GDPR fine handed down by the U.K. Information Commissioner’s Office is less than 20 percent of the original number the regulator proposed, the second time this month such a drastic reduction has taken place.