Prepared for distribution at the CYBERSECURITY 2015: MANAGING THE RISK Program September 25, 2015



Similar documents
How Cybersecurity Initiatives May Impact Operators. Ross A. Buntrock, Partner

The Matrix Reloaded: Cybersecurity and Data Protection for Employers. Jodi D. Taylor

Cyber Risks in the Boardroom

Presidential Summit Reveals Cybersecurity Concerns, Trends

Introduction to Data Security Breach Preparedness with Model Data Security Breach Preparedness Guide

Data Security: Risks, Compliance and How to be Prepared for a Breach

Trends in Data Breach and CybersecurityRegulation, Legislation and Litigation. Part I

Cybersecurity. Shamoil T. Shipchandler Partner, Bracewell & Giuliani LLP

Moderated by: Paul M. Schwartz Berkeley Law School Fourth Annual BCLT Privacy Forum March 13, Data Security Issues

The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide

CYBERSECURITY RISK MANAGEMENT

Cybersecurity Information Sharing Legislation Protecting Cyber Networks Act (PCNA) National Cybersecurity Protection Advancement (NCPA) Act

Cybersecurity and Data Breach: Mitigating Risk and How Government Policymakers Approach These Critical Issues

12/4/2013. Regulatory Updates. Eric M. Wright, CPA, CITP. Schneider Downs & Co., Inc. December 5, 2013

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

The Legal Pitfalls of Failing to Develop Secure Cloud Services

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF NEW JERSEY

Law Firm Cyber Security & Compliance Risks

Cyber Warfare. Global Economic Crime Survey. Causes of Cyber Attacks. David Childers, CEO Compli Vivek Krishnamurthy, Foley Hoag LLP. Why Cybercrime?

Special Report The HITECH Act

Mastering Data Privacy, Protection, & Forensics Law

The Problems With SEC s Cybersecurity Approach

114 th Congress March, Cybersecurity Legislation and Executive Branch Activity I. ADMINSTRATION S CYBERSECURITY PROPOSALS

Surviving Contact with Reality Crisis exercises as a key element of cyber incident and crisis management response.

HEALTH CARE AND CYBER SECURITY:

3/4/2015. Scope of Problem. Data Breaches A Daily Phenomenon. Cybersecurity: Minimizing Risk & Responding to Breaches. Anthem.

CLIENT UPDATE CRITICAL INFRASTRUCTURE CYBERSECURITY: U.S. GOVERNMENT RESPONSE AND IMPLICATIONS

Cyber-insurance: Understanding Your Risks

HIPAA Cyber Security: Your Vendor is a Back Door to Your Server

Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission. June 25, 2015

Cybersecurity and Insurance Companies

When Can We Expect a Federal Data Breach Notification Law?

Testimony of PETER J. BESHAR. Executive Vice President and General Counsel. Marsh & McLennan Companies

What s trending on NP Privacy Partner

Mastering Data Privacy, Social Media, & Cyber Law

Cybersecurity Issues for Community Banks

Defense of State Employees: LIABILITY AND LAWSUITS. UNCW Office of General Counsel January 2010

Recent Developments in Privacy/Security Litigation

Data Breach and Senior Living Communities May 29, 2015

Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation

Perspectives on Cybersecurity and Its Legal Implications

The data breach lifecycle: From prevention to response IAPP global privacy summit March 6, 2014 (4:30-5:30) Draft v

Perspectives on Cyber Security & Digital Issues

What Data? I m A Trucking Company!

Data Breach Response Planning: Laying the Right Foundation

Cyber Security for the Private Sector: What Companies and Their Lawyers Need to Know

How To Protect Your Computer From Attack

Cybersecurity For Brokers: 'Only The Paranoid Survive'

Transcription:

Prepared for distribution at the CYBERSECURITY 2015: MANAGING THE RISK Program September 25, 2015 CONTENTS: PROGRAM SCHEDULE... 11 FACULTY BIOS... 19 1. Big Picture Cyber: Threats, Vulnerabilities and Cyber Space... 33 Austin P. Berglas K2 Intelligence 2. M-Trends 2015: A View from the Front Lines (Threat Report)... 57 Josh Goldfarb 3. Hacking the Street? Fin4 Likely Playing the Market (Special Report)... 89 Barry Vengerik Kristen Dennesen Jordan Berry Jonathan Wrolstad Josh Goldfarb 4. USA, The International Comparative Legal Guide to: Data Protection 2015 (2 nd ed.)... 109 Aaron P. Simpson Chris Hydak 5

5. SEC Cybersecurity Investigations: A How-to Guide, Westlaw Journal: Securities, Litigation, & Regulation, Volume 21, Issue 3 (June 11, 2015)... 125 Lisa J. Sotto Scott H. Kimpel Matthew P. Bosher 6. Privacy & Information Security Law Blog... 135 Update: Cybersecurity Justice Department Releases Guidance on Best Practices for Cyber Incident Preparedness, May 5, 2015... 137 House of Representatives Passes Two Cybersecurity Bills, April 23, 2015... 139 President Obama Issues Executive Order Enabling Treasury to Impose Sanctions on Cyber-Enabled Activities, April 1, 2015... 141 IPTF Issues Request for Public Comment Regarding Cybersecurity Issues Affecting the Digital Economy, March 20, 2015... 141 President Obama Signs Executive Order on Cybersecurity Information Sharing, February 17, 2015... 143 President Obama Announces a National Data Breach Notification Standard and Other Cybersecurity Legislative Proposals and Efforts, January 14, 2015... 145 In a Surprising Move, Congress Passes Four Cybersecurity Bills, December 12, 2014... 147 NIST Releases Update on Implementation of Cybersecurity Framework, December 9, 2014... 148 Update: Data Breach New Dutch Law Introduces General Data Breach Notification Obligation and Higher Sanctions, June 2, 2015... 149 Washington State Senate Approves Amendment to Data Breach Notification Law, April 15, 2015... 151 6

AT&T Enters into Largest Data Breach Settlement with FCC to Date, April 8, 2015... 151 Third Circuit Hears Oral Arguments in FTC v. Wyndham, March 5, 2015... 153 Two Wyoming Bills Amending the State s Breach Notification Statute Are Headed to the Governor, February 27, 2015... 153 Proposed Indiana Law Would Raise Bar for Security and Privacy Requirements, January 20, 2015... 154 California Lawmakers Pass Bill to Amend State s Breach Notification Law, August 28, 2014... 155 Lisa J. Sotto 7. Surviving Contact with Reality: Crisis Exercises as a Key Element of Cyber Incident and Crisis Management Response... 157 8. Litigation Roundup... 167 Vermont Gets Tough On Data Breach Notification Issues (May 28, 2015)... 169 Plaintiff Lacks Standing in ebay Data Breach Suit (May 5, 2015)... 171 Obama Orders Hackers Hit Where It Hurts (April 6, 2015)... 173 Another Setback for LabMD in Its Challenge to FTC (January 23, 2015)... 175 Zappos Buys State AGs $100k in New Shoes (January 9, 2015)... 177 FCC Will Continue Punishing Data Security Violations (January 2, 2015)... 179 Court Permits Banks Negligence Claims Against Target for Data Breach (December 19, 2014)... 181 TD Bank Settles for $625,000 in Massachusetts Data Breach Suit (December 16, 2014)... 183 7

Alaska Health Company Settles HIPAA Investigation (December 12, 2014)... 185 New York Financial Regulator Subjects Banks to New Cybersecurity Review (December 11, 2014)... 187 Boston Hospital Settles Data Breach Suit Over Unencrypted Laptop (December 4, 2014)... 189 Wyndham Directors Found Not Liable for Data Breach (November 17, 2014)... 191 FCC Joins the Alphabet Soup of Data Security Regulators (November 11, 2014)... 193 New York Financial Regulator Calls for Stricter Scrutiny of Bank Vendors Cybersecurity Standards (October 30, 2014)... 195 TD Bank Pays State AGs $850,000 to Resolve Breach Investigation (October 16, 2014)... 197 LinkedIn Agrees to Settle Data Breach Suit For $1.25 Million (August 21, 2014)... 199 Michael A. Vatis Steptoe & Johnson LLP 9. Managing Cyber Risks in an Interconnected World: Key Findings from The Global State of Information Security Survey 2015 (September 30, 2014)... 201 10. Cybercrime & Data Breach: Experience and Innovation Across the Globe... 247 11. Current Issues in Digital Management for Corporate General Counsel (April 2014)... 253 8

12. 2015 US CEO Survey: Leading in Extraordinary Times... 269 13. In Confronting Cyberattacks, Preparation Is Key (March 2015)... 277 Aaron P. Simpson Chris Hydak INDEX... 283 Program Attorney: Tamara C. Kiwi 9