Cyber-Security


Microsoft

Microsoft data leak points to expansive industry-wide security vulnerabilities

2020-01-24T15:41:00+00:00By

Microsoft made headlines this week when it was discovered that nearly 250 million customer service and support records were exposed on the Web through several unsecured cloud servers. But that’s only a glimpse into wider cloud-security weaknesses throughout the industry.

Cyber locks

Proposed bill seeks to help non-federal entities improve cyber-security

2020-01-21T21:48:00+00:00By

A new bill proposed by Congress would install a federal “cyber-security state coordinator” in each state to facilitate non-federal entities’ access to technical know-how, training, communications, and other resources for improved cyber-security.

Data money

Lawmakers push for FTC probe into Envestnet data sales

2020-01-21T20:47:00+00:00By

Democratic Sens. Ron Wyden and Sherrod Brown and Rep. Anna Eshoo sent a letter to the Federal Trade Commission urging the agency to investigate Envestnet’s selling practices regarding consumer financial data.

Equifax

Equifax must spend ‘a minimum of $1B’ for data security

2020-01-21T19:40:00+00:00By

A massive data breach that was “entirely preventable” will cost credit-reporting agency Equifax another $1 billion to beef up its cyber-security efforts.

Risk

Cyber-threats, regulatory change highlight top-10 risks study

2020-01-14T20:24:00+00:00By

Cyber-incidents, business interruption, and changes in legislation and regulation are the three biggest risks to companies globally, according to research by German insurer Allianz.

FTC

FTC strengthens orders in data security cases

2020-01-08T19:50:00+00:00By

Chief compliance officers seeking more guidance from the Federal Trade Commission on how the agency has improved its orders in data security cases will find helpful a recent blog post by Andrew Smith, director of the Bureau of Consumer Protection.

Cyber

U.S. government warns: Be prepared for Iran cyber war

2020-01-06T20:06:00+00:00By

The killing of Iranian general Qassem Soleimani in a U.S. airstrike may bring about cyber warfare, the U.S. government has warned in a security bulletin.

Wawa

Wawa data breach part of ‘concerning’ industry trend?

2020-01-03T16:58:00+00:00By

While Wawa continues to investigate the source of a widespread data breach that put thousands of customers at risk, its connection to a recent Visa alert suggests other retailers should be on the lookout for similar threats to their cyber-security infrastructure.

riskalert

New COSO guidance addresses cyber-risk management

2019-12-30T17:59:00+00:00By

Boards of directors, audit committee members, and executive management teams interested in learning how to apply COSO’s Enterprise Risk Management framework to protect against cyber-attacks now have new guidance available.

Data transfers

Top EU advisor: Clauses used for EU-U.S. data transfers ‘valid’

2019-12-23T15:18:00+00:00By

Big Tech can breathe a sigh of a relief that the mechanisms it uses to transfer data outside of the European Union to “third countries” provide sufficient privacy protection, according to a key advisor to the EU’s top court.

Credit breach

Widespread Wawa data breach puts thousands at risk

2019-12-20T14:04:00+00:00By

Convenience store chain Wawa announced it has suffered a massive data breach that has affected “potentially all” of its store locations, compromising the debit and credit card information of thousands of customers.

SEC

SEC names new cyber chief

2019-12-03T17:31:00+00:00By

The Securities and Exchange Commission announced the appointment of Kristina Littman as chief of the Division of Enforcement’s Cyber Unit.

Excellence in Compliance Awards

Introducing ‘The Excellence in Compliance Awards’

2019-12-02T22:03:00+00:00By

Compliance Week is making some changes to its annual awards for 2020, evolving the “Top Minds” recognition into a full-blown, specifically targeted awards program dubbed “The Excellence in Compliance Awards.”

DIgitalUnease

U.S. consumers express unease over personal data collection

2019-11-20T14:57:00+00:00By

A recent survey says a majority of Americans don’t trust data privacy policies and procedures, even while U.S. companies are hastening to enhance them in advance of the California Consumer Privacy Act’s implementation.

CCPAUpdate

10 things you need to know about CCPA compliance

2019-11-19T21:37:00+00:00By

It’s go-time for compliance as the clock ticks toward the Jan. 1 effective date of the California Consumer Privacy Act.

Audit committee

Report: Investor confidence in audit committees high; more transparency needed

2019-11-19T21:13:00+00:00By

The 2019 Audit Committee Transparency Barometer indicated investor confidence in audit committee effectiveness was strong (81 percent) and had increased 10 percentage points since the first report was issued in 2014.

ThumbsUp

Data-driven compliance can create business success

2019-11-18T21:41:00+00:00By

Smart uses of data analytics show companies can not only improve their compliance programs with technology, but actually create bottom-line results for their companies as well.

SoftwareChoice

Best practices for choosing the right data privacy software

2019-11-18T21:41:00+00:00By

Don’t expect a plug-and-play technology solution to this complex new problem.

Cyber locks

Proactive approach needed in today’s cyber-crime environment

2019-11-18T15:23:00+00:00By

An expert sheds light on behavioral science-driven solutions that help businesses prepare for a breach before it happens.

Cyber

Cyber-security glossary

2019-11-18T15:21:00+00:00By

For those unfamiliar with the vernacular involved with cyber-security and the methods by which bad actors attempt to access restricted data, we present this glossary of common terms.

Payment card security

Verizon finds payment security declines for 2nd consecutive year

2019-11-14T20:36:00+00:00By

Although the Payment Card Industry Data Security Standard (PCI DSS) launched back in 2004, 15 years later, most organizations still struggle to adhere to it.

ItalyDataBreach

Data protection compliance lessons from UniCredit breach

2019-10-29T19:03:00+00:00By

UniCredit announced its cyber-security team has identified a data breach that compromised the personal records of approximately three million clients in Italy, highlighting critical compliance lessons for those in the financial services industry.

Cloud

Big Tech, banking policymakers clash over cloud computing

2019-10-18T20:47:00+01:00By

The “move fast and break things” mantra of the tech world rubs up against a more rigid banking industry as the two find their way in the cloud—but is more legislation really necessary?

DataBridge

NIST provides guidance on how to bridge privacy, cyber-security processes

2019-10-18T16:11:00+01:00By

NIST’s new draft Privacy Framework offers much-needed guidance to help companies align their data privacy and cyber-security risk management practices.

Food delivery

DoorDash data mishap showcases hazards of third-party vendors

2019-09-27T20:59:00+01:00By

DoorDash announced an incident of unauthorized third-party access to user data—a reminder companies need to mind the cyber-security of vendors in addition to their own.

Juniper

Juniper settles FCPA case with SEC for $11.7M

2019-08-30T14:34:00+01:00By

Juniper Networks has reached an $11.7 million settlement with the SEC for violations of the Foreign Corrupt Practices Act concerning its sales practices in Russia and China.

Mastercard

Mastercard reveals data breaches in third-party loyalty program

2019-08-27T18:16:00+01:00By

Mastercard is investigating two data breaches relating to a loyalty program it ran in Germany following a leak of personal information that saw customers’ names, addresses, and credit card numbers circulating on the internet.

European Central Bank

European Central Bank announces data breach

2019-08-16T17:35:00+01:00By

The European Central Bank announced unauthorized parties breached the security measures protecting its Banks’ Integrated Reporting Dictionary (BIRD) Website, which is hosted by an external provider.

CapitaoOneStory

Capital One hacker may have targeted dozens more

2019-08-16T16:50:00+01:00By

It appears Capital One may be just one in a long list of companies and organizations to be victimized by what now appears to be the inner workings of a serial hacker, in what the Department of Justice is calling one of “the largest cyber intrusions and data thefts in ...

Facial recognition

Facebook loses appeal, faces costly privacy class action

2019-08-12T16:34:00+01:00By

The ruling of a federal appeals court has Facebook once again at risk of facing fines north of $1 billion for alleged misuse of users’ biometric data.

Cisco

Cisco’s $8.6M settlement for security flaws has broader ramifications

2019-08-02T17:15:00+01:00By

Cisco has reached an $8.6 million settlement for knowingly selling video surveillance software with critical security vulnerabilities. It’s believed to be the first cyber-security whistleblower case of its kind successfully litigated under the False Claims Act.

CapitaoOneStory

Capital One announces massive data breach

2019-07-30T13:38:00+01:00By

Capital One Financial announced a hacker obtained the personal information of approximately 100 million individuals in the United States and approximately six million individuals in Canada.