Showing posts with label Data security. Show all posts
Showing posts with label Data security. Show all posts

Tuesday, April 27, 2021

Data Security Oversight - Corporate Boards

 

Corporate boards: Don’t underestimate your role in data security oversight

 

Federal Trade Commission

For businesses in the middle of a global pandemic, there’s no such thing as “business as usual.” The percentage of Americans working remotely has grown substantially, now reportedly up to 33% of the U.S. workforce. Accompanying that seismic shift have been increased security threats to data, with one analysis reporting that over 36 billion online records were exposed in the first half of 2020 alone. Consumers whose lives have been upended by identity theft are paying close attention to how corporations are responding. But is the typical corporate Board of Directors giving data security the attention it deserves?

 

In addition to the significant costs to consumers, data breaches, network intrusions, and looming cyber threats can open up a firm to substantial financial costs, reputational hits, and legal liability. The FTC has continued to challenge allegedly deceptive or unfair conduct related to companies’ data security practices. A few recent examples include settlements with SkyMed International, Tapplock, and Zoom. We’re also in the process of reviewing some data security rules for industry, including the Health Breach Notification Rule and the Gramm-Leach-Bliley Safeguards Rule.

 

Against that backdrop, it’s essential for corporate boards to do what they can to ensure that consumer and employee data is protected. The good news is that according to a recent study, 60% of directors surveyed said they plan to improve their cybersecurity oversight role over the next year. What would that look like for a typical corporation? FTC staff has five common-sense recommendations for conscientious directors.

 

MAKE DATA SECURITY A PRIORITY.

Contrary to popular belief, data security begins with the Board of Directors, not the IT Department. A corporate board that prioritizes data security can set the tone throughout an organization by instilling a culture of security, establishing strong security expectations, and breaking down internal silos to facilitate technical and strategic collaboration. While there’s no one-size-fits-all formula, here are strategies some companies have implemented to make security a priority.

  • Build a team of stakeholders from across your organization. Despite a 2018 study that found that 89% of CEOs treat cybersecurity as an IT function, experience suggests that cyber risk management is a “whole business” issue. A sound data security program should incorporate stakeholders from business, legal, and technology departments across the company – both high-level executives and operational experts. Of course, many committees include the Chief Information Officers and the Chief Information Security Officer, but other companies promote practical synergies by also including executives who bring a different perspective to the issues – for example, the CEO, CFO, or General Counsel. A broad and diverse range of voices can provide the board with cross-cutting information about cyber risks and solutions.
  • Establish board-level oversight. Some corporate boards delegate their cyber risk oversight duties to an audit committee. Others have a stand-alone cybersecurity committee at the board level. Irrespective of how an organization structures its cyber risk oversight duties, the key takeaway is that cyber risks should be a priority within the board room. Board-level oversight helps to ensure that cybersecurity threats, defenses, and responses have the attention of those at upper echelons and get the resources needed to do the job right.
  • Hold regular security briefings. When it comes to security, board members need to be in the know, but research suggests many of them are out of the loop. A 2012 survey found that fewer than 40% of corporate boards regularly received reports about privacy and security risks and 26% rarely or never got that information. According to another study, only 12% of boards frequently received cyber threat briefings. A survey of public companies conducted six years later in 2018 didn’t suggest much progress. Only 37% of board members said they felt “confident” or “very confident” that their company was properly secured against cyberattack. Of course, cybersecurity isn’t a one-and-done proposition. It’s a dynamic process that requires board members to be informed, engaged, and updated. Regular briefings prepare boards to carry out their oversight responsibility, navigate the security landscape, and prioritize threats to the company.

 

UNDERSTAND THE CYBERSECURITY RISKS AND CHALLENGES YOUR COMPANY FACES.

A strong data security program starts at the top. While it might not be the board’s role to manage day-to-day security operations, it is their job to set priorities and allocate the resources necessary to ensure effective security. Board members need to talk the talk and walk the walk. They should demonstrate a sophisticated grasp of the data security challenges their company faces and act in a way that sets the tone for the entire organization.

 

DON’T CONFUSE LEGAL COMPLIANCE WITH SECURITY.

In 2019, the FTC held a series of hearings on consumer protection and technology in the 21st century. One common theme was that compliance doesn’t necessarily translate into good security. Cybersecurity threats are constantly and rapidly evolving. A strong data security program should never be reduced to a “check the box” approach geared toward meeting compliance obligations and requirements. Instead, boards should ensure that their security programs are tailored to their companies’ unique needs, priorities, technology, and data. Boards should ask tough questions about whether their policies and procedures effectively address their company’s security risks and whether actual security practices effectively address the threats they face. That no-holds-barred conversation might include fundamental questions like:

  • What kind of data are we keeping and why? And where are we keeping it?
  • Are our policies and procedures adequate to protect our data?
  • Are our actual security practices in line with our policies and our public-facing statements?
  • Are our security investments and expenditures in line with our security risks and threats?

 

IT’S MORE THAN JUST PREVENTION.

A strong data security program ensures that a company is undertaking reasonable precautions to protect its network and consumers’ personal information from intruders. However, no data security program is perfect and no program can guarantee that a company will be protected from attack or a data breach. If nothing else, recent breaches have demonstrated the importance of both a strong data security program and a robust incident response plan. In responding to a security incident, time is often of the essence. Every minute that employees spend attempting to flag down key executives and focus their attention on what’s happened is time taken away from the critical tasks of stanching the damage to data and implementing an appropriate response. In contrast, an effective security program ensures that when it’s appropriate, a security incident can be swiftly elevated to the appropriate level. In addition, building organizational resilience into your security program can help your company sustain operations while responding to a security incident.

 

LEARN FROM MISTAKES.

If your company has had the misfortune of experiencing a data breach, take the opportunity to learn from the incident and improve your program. Companies often require periodic independent third-party assessments to establish a baseline against which future progress can be measured and – in the event of a security incident – to determine how a breach occurred. Of course, learning from other companies’ mistakes can be just as valuable (and substantially less painful). There are certainly no shortage of data breaches and many likely involve competitors or other parties in similar lines of business. Boards should take the opportunity to understand the cybersecurity risks related to their industry and learn from their company’s own mistakes as well as the mistakes of others.

The FTC Business Center has data security resources for companies of any size and in any sector.

 

Thursday, October 25, 2018

FTC, In the Matter of Uber Technologies, Inc., Decision and Order, Docket No. C-4662


Consumer Protection
Consumer Privacy
Data Security
Unfair Practices affecting Commerce
FTC
In the Matter of Uber Technologies, Inc.


Allegations that Uber deceived consumers about its privacy and data security practices. Federal Trade Commission gives final approval to this settlement with Uber.
As a result of its failure to take reasonable measures to secure both rider and driver data, said company suffered two breaches (May 2014 and Oct.-Nov. 2016).
Following the second data breach, the FTC negotiated this final settlement with Uber, under which:
Covered incident reports (Provision 4): Uber could be subject to civil penalties if it fails to notify the FTC of certain future incidents involving unauthorized access to consumer information, which includes both driver and rider information.
Prohibition against misrepresentations (Provision 1): The company is also prohibited from misrepresenting how it monitors internal access to consumers’ personal information and the extent to which it protects the privacy, confidentiality, security, and integrity of personal information.
Mandated privacy program (Provision 2), and privacy assessments by a third party (Provision 3): Uber must implement a comprehensive privacy program and for 20 years obtain biennial independent, third-party assessments, which it must submit to the Commission, certifying that it has a privacy program in place that meets or exceeds the requirements of the FTC order.
Compliance report and notices (Provision 6), and recordkeeping requirements (Provision 7).

This Order will terminate on October 25, 2038, or 20 years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying settlement) in federal court alleging any violation of this Order, whichever comes later.

(The Oct. 25, 2018 complaint states that the acts and practices of respondent alleged in the complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act, and that the acts and practices of respondent as alleged in the complaint constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act, 15 U.S.C. § 45(a)).

(FTC, In the Matter of Uber Technologies, Inc., Oct. 25, 2018, Decision and Order, Docket No. C-4662)

Monday, January 8, 2018

Children's Online Privacy


Children's Online Privacy: Privacy: Data security: Competition: Internet: Safe WEB Act.

FTC, Bureau of Consumer Protection, Jan. 8, 2018.



Electronic toy manufacturer VTech Electronics Limited and its U.S. subsidiary have agreed to settle charges by the Federal Trade Commission that the company violated a U.S. children’s privacy law by collecting personal information from children without providing direct notice and obtaining their parent’s consent, and failing to take reasonable steps to secure the data it collected. VTech will pay $650,000 as part of the settlement with the FTC.

In a complaint filed by the Department of Justice on behalf of the FTC, the Commission alleges that the Kid Connect app used with some of VTech’s electronic toys collected the personal information of hundreds of thousands of children, and that the company failed to provide direct notice to parents or obtain verifiable consent from parents concerning its information collection practices, as required under the Children’s Online Privacy Protection Act (COPPA). In its first children’s privacy case involving Internet-connected toys, the FTC also alleges that VTech failed to use reasonable and appropriate data security measures to protect personal information it collected.

COPPA requires that companies collecting personal information from children under 13 online follow steps to ensure that children’s information is protected, including clearly disclosing to parents the information it collects, how the information will be used, and seeking verifiable parental consent. Companies also must take reasonable measures to protect the confidentiality, security and integrity of the personal information they collect about children.

According to the complaint against VTech, the company collected personal information from parents on its Learning Lodge Navigator online platform, where the Kid Connect app was available for download, and also through a now-defunct web-based gaming and chat platform called Planet VTech. Before using Kid Connect or Planet VTech, parents were required to register and provide personal information including their name, email address as well as their children’s name, date of birth and gender. VTech also collected personal information from children when they used the Kid Connect app.

With respect to Kid Connect, VTech failed to provide direct notice of its information collection and use practices to parents and did not link to its privacy policy in each area where personal information was collected from children.

At the same time, the complaint alleges that the company did not take reasonable steps to protect the information it collected through Kid Connect, such as implementing adequate safeguards and security measures to protect transmitted and stored information and implementing an intrusion prevention or detection system to alert the company of an unauthorized intrusion of its network. In November 2015, VTech was informed by a journalist that a hacker accessed its computer network and personal information about consumers including children who used its Kid Connect app.

The FTC also alleges that VTech violated the FTC Act by falsely stating in its privacy policy that most personal information submitted by users through the Learning Lodge and Planet VTech would be encrypted. The company, however, did not encrypt any of this information.

In addition to the monetary settlement, VTech is permanently prohibited from violating COPPA in the future and from misrepresenting its security and privacy practices as part of the proposed settlement. It also is required to implement a comprehensive data security program, which will be subject to independent audits for 20 years.

The FTC collaborated with the Office of the Privacy Commissioner of Canada, which is releasing its own Report of Findings. To facilitate cooperation with its Canadian partner, the FTC relied on key provisions of the U.S. SAFE WEB Act, which allows the FTC to share information with foreign counterparts to combat deceptive and unfair practices that cross national borders.

The Commission vote authorizing the staff to file the complaint and stipulated final order was 2-0. The complaint and stipulated final order was filed in the U.S. District Court for the Northern District of Illinois.

NOTE: The Commission files a complaint when it has “reason to believe” that the law has been or is being violated and it appears to the Commission that a proceeding is in the public interest. Stipulated final orders have the force of law when approved and signed by the District Court judge.

Related Case


For Consumers


For Businesses