Category: Corporate Compliance

  • Two Judges Find Florida Medical Marijuana Law Unconstitutional

    The Program is ‘Absolutely Broken’ — Now What?

    Edited by Tom Hagy

    Florida Circuit Judge Karen Gievers just held that the Florida medical marijuana law is unconstitutional. Reporting on the judge’s Trulieve decision for the Florida Politics news service, journalist Jim Rosica called it “a rebuke to lawmakers and the Rick Scott Administration” that was “stunning even for” Judge Gievers. “In the spirit of boxing legend Muhammad Ali, known for his pre-fight rhymes, Gievers opined that in Florida ‘the medical marijuana system was broken. Now, in the Constitution, the people have spoken.’”

    Rosica reported that while Gov. Scott is appealing the major marijuana decisions against the state Department of Health, the transition team of Republican Governor-elect Ron DeSantis, including Lt. Gov.-elect  Jeanette Nuñez, has suggested that he will not continue to defend the law in court.

    Rosica continued: “Gievers, who retires in April, said her decision striking down the law ‘includ(ed), but (is) not limited to, replacement of the voter-selected registry plan with an arbitrary, inconsistent licensing scheme … throttling access of qualifying patients to … safe use of medical marijuana from (providers that) the Department has a clear, undisputed duty to register.’ In fact, just passing the law was itself unconstitutional, Gievers suggested: ‘Voters made clear in 2016 that the Legislature was to have no role in implementing access to and availability of medical marijuana.’” Read Rosica’s full article.

    ‘It is incumbent on the Legislature to fix this’

    Today I spoke with attorney Jonathan Robbins, who is actively litigating the matter on behalf of Tampa-based Florigrown. Robbins, chair of the cannabis practice at Akerman LLP , pointed to a similar holding in the Florigrown case, commenting that, yes, “yet another judge has found that the statute implementing the amendment is unconstitutional because of the arbitrary cap on the number of dispensaries that would qualify for licensing.”

    “This further illustrates,” Robbins told me, “that the Florida medical marijuana program is absolutely broken and needs to be fixed. But rather than the courts repairing it piecemeal, the Legislature needs to get something done. It is incumbent on the Legislature to fix this.”

    In the Florigrown case, Leon County Circuit Judge Charles Dodson granted an injunction and ordered DOH to issue licenses. Once DOH appealed that triggered an automatic stay. “We went back to Judge Dodson to lift the stay because people need their meds,” Robbins said. “The judge lifted the stay, but the DOH appealed to the 1st District to reimpose the stay, which the court did.” Briefing is under way.

    “Our client wants to operate but is restricted because the statute unconstitutionally creates special classes of companies entitled to licensing. Not only does it arbitrarily cap the number of licenses, it requires that licensees must be fully vertically integrated, meaning companies must cultivate, process and sell medical marijuana. This is inconsistent with what the citizens voted for,” Robbins said. He said this prohibits a company from merely dispensing the product, for example, effectively and unfairly shutting out many businesses.

    “The Legislature was charged with providing safe and affordable medical marijuana to patients who need it. All of this was to be in place in 2017. Here we are in 2019 and we still don’t have it,” Robbins said.

    While there are 14 companies operating and people can get marijuana, many more potential competitors are blocked from operating.

    Clearly, implementation of the law, overwhelmingly approved by Florida voters, has been less than smooth and requires quite a bit more ironing out. The lack of competition hurts businesses and patients alike, critics say. In the meantime there is plenty of confusion for companies ready to provide medical marijuana services in Florida.


    Join our webinar on Jan. 25,  when attorneys in the thick of the issue –  Akerman LLP  partners Jonathan S. Robbins  and  Ari H. Gerstin  — will share background, insights and practical guidance.

    What we will cover:

    • Background: Federal vs. State Law Conflict
    • History of Medical Marijuana in Florida
    • The 2016 Amendment to the Florida Constitution
    • Implementation of the State Medical Marijuana Program
    • Litigation Over the Constitutionality of the Implementation
    • Practical Considerations When Operating in This Industry
    • Banking and Insurance Issues
    • Ethical Considerations for Attorneys

    What you will get:

    • Up-to-the-minute insights from attorneys active in the litigation.
    • Thorough course materials for later reference.
    • Real-time answers to your questions via our moderated chat.
    • The ability to send questions in advance.
    • Continuing legal education credit (CLE)
    • Access for your entire team with a feed into your conference room.
    • No scheduling risk: Suddenly can’t make it? We will send you the recording.

    Register by Jan. 18 and save $50. 

  • Mitigating Operational Cyber Risk: As Business Technology Changes, So Does Your Risk Profile

    By Tom Hagy

    The various risks of doing business in our digitally connected world continue to evolve.  So must the approach organizations take in confronting those risks, for failing to do so in the current risk landscape can be far more dangerous than in prior years.

    I spoke with Nick Galletto, Global Cyber Risk Leader at Deloitte, who traced the evolution of the dangers of doing business in a digitally connected world. Early on, our focus in the cyber risk management space was on how to protect websites from being defaced, he explained. Organizations had to make sure websites were functioning properly, that data was secure, and the integrity was maintained.

    Galletto went on to say that we’ve moved from an era of compliance and risk management to an era of complexity.  From an organization’s perspective, their focus was on making sure the company was compliant with new and evolving regulations, and risk management meant having policies, procedures and effective controls in place.

    “While compliance is a necessity, it is not the silver bullet that’s going to protect us from any potential breaches,” Galletto said. “So organizations must look at conducting their business in this connected world not merely from a compliance perspective but from a risk perspective. A clear example of this is the number of PCI-compliant companies that were still getting breached.”

    “Now as organizations move into an era of complexity, they need to be proactive in detecting anomalies and suspicious behavior and be prepared so their teams have a playbook that allows for seamless response. Effective organizations will play back possible breach scenarios – whether they involved data breaches or denial of service — to  prevent and prepare for similar attacks. They also focus on understanding what their crown jewels are and where they reside and how to best protect them.  Much of this also has to do with data,” Galletto said.

    “Organizations are increasingly reliant on the cloud and they must understand the associated risks and the individuals responsible for managing those risks,” he said. “They need to be sure they have the right coverage as well.”

    “This era of complexity – automation, machine learning, artificial intelligence and the internet of things, along with the tremendous advantages, like the cloud – also bring new risks,” Galletto continued. “As consumers we see use of these technologies more and more in our daily lives. But organizations are increasingly integrating them into their operations. When something goes wrong here there can be actual safety implications, such as with autonomous vehicles or industrial controls in the mining and manufacturing sectors, as examples. In the financial sector these technologies bring great advantages to customers in terms of accessing their information more efficiently or providing better customer support. But as machine learning and AI become more prevalent in the world of FinTech, decisions are being made without human cognitive capabilities to know right from wrong. These new technologies bring more complexity.”

    “As organizations take advantage of these innovative new technologies, they also have to know that their risk profile is changing right along with them. Smart companies will be proactive in understanding the risks associated with cyber everywhere, understanding where their cyber posture is and make adjustments along the way to better manage complexity.”

    Galletto is one of the speakers at this week’s International Cyber Risk Management Conference in Bermuda, which just kicked off this afternoon with more than 200 professionals in this center of global cyber risk.  

  • Kenneth Jones of Tanenbaum Keale on Law Firm Tech Development Capabilities

    Should Law Firms Should be Able to Develop Custom Technologies?

    Here is #10 of Jones’ Top-10 List.

    #10. Security. The cloud is great, and generally speaking, companies in this space operate systems in a highly professional manner. However, occasionally one encounters special business needs which call for extensive “above and beyond” levels of security. This could be times a firm is storing financial information, medical records, or other data they wish to absolutely, positively protect. In these situations — under the theory that “no one does things better than I do” —it’s nice to have the option to build super-secure systems with features such as encrypted data within database tables, and to manage the systems with a very small number of highly trusted professionals specifically known by the law firm. Read more of the article posted by Thomson Reuters.


    Kenneth Jones oversees various aspects of technology at Tanenbaum Keale LLP in the role of Chief Technologist. He leads efforts to support TK’s computing environment and infrastructure, one that features a strategy of professionally protecting and processing client data in the cloud with highly skilled and respected leading-edge business partners in the technology space. Ken also helps lead and support various TK programs in the areas of security, compliance, business continuity and firm administration. Learn more. 

  • Blockchain: Power to the People

    Dan Solove, co-founder of the Privacy+Security Forum and professor at GW Law School, just posted an interview with Steve Shillingford, Founder and CEO of Anonyome Labs, a consumer privacy software company. Below is part of just one exchange in the interview. 

    SOLOVE: The Internet has made so many things possible that we couldn’t do in an analog world. Yet, in some ways, the online world seems to lack the capabilities of the offline world. In the offline world, it is much easier to have anonymous transactions. This becomes much more challenging online. How can the online world be made more like the offline world in this regard?

    SHILLINGFORD: Blockchain technology shifts the balance of power back to people—to individuals—and away from tech giants, governments and data miners. It allows you to transact on your terms, just as you do offline. And it’s not just limited to financial transactions. Put anything on the blockchain you want. The blockchain gives a person the ability to publish only the information THEY decide to divulge. Nothing more, nothing less. And no more hidden agendas, no selling personal data without your consent, no worries about privacy. Just like the analogue world, you decide the context, the content, and duration of the information you provide…not the big guys. It can really be that easy.

    Read the complete interview. 

    See the latest faculty and agenda updates for the Privacy+Security Forum 2018 | Oct. 3-5, 2018 | Washington, D.C.

  • Courtney Klein on Social Media & Security

    A Restructured Paradigm for Corporate Teamwork

    By Courtney Klein of Soteria Risk Consultants

    Social media has become an integral part of everyday life. It’s how some of us get our news, research our opinions, learn about local events, and connect with friends. For the modern western business, it is also immensely important for staying in touch with customers, advertising, and overall visibility. For this reason, many companies employ veritable armies of “Social Media Specialists” that do everything from designing graphics to writing tweets to replying to customer questions and complaints. Some companies interact with each other (such as the hilarious and long-standing Twitter Battle between Wendy’s and McDonald’s), and some use it as their primary form of communication.

    Customers, too, know that social media is a way to get in touch with a company – for good reasons and for bad – and while many companies are aware that they will and do receive threats on social media, very few of them have any kind of protocol in place for how to deal with them – and even fewer still encourage their social media teams to pass this information on to or (better yet) work together with their security team. This sort of blasé attitude to threats – either because “it’s not my job” or “they can’t be serious” – leads to real-world ramifications. Incidents such as the April 4th Youtube Shootings (which, we acknowledge, was a failure of many different departments, companies, and law enforcement operations) are a reminder of just how social media “banter” can turn into a real-world nightmare.

    Now, in defense of essentially any company guilty of this, Social Media is a new beast that even the best are still trying to get their arms wrapped around. Not only is social media relatively new to the game, but it’s dynamic and ever-changing. What was relevant yesterday no longer will be tomorrow. Updates add new features and kill our favorites, terms of service changes impact business, trends are fleeting but ever so important for a business to understand, customer service issues must be dealt with in a timely fashion. Take all of this and add security concerns on top of the social media specialist’s plate and you’re only going to run into failure. That’s why we at Soteria are such strong believers in having social media and security teams work together every step of the way.

    Folding security into the fray … will make a world of difference

    With few exceptions, social media teams plan their calendar very carefully. Words must be scripted, graphics must be designed, legal must be consulted; it’s not often that there’s a “last minute tweet that just has to go out right here right now.” With everything else that goes into these seemingly benign releases, folding security into the fray is, ultimately, a minor change, but one that will make a world of difference. Giving the security team insight into what will be posted provides a number of benefits.

    The security team will be able to assess what posts may aggravate any known or active threats. In general, security teams like to keep information about who wants to do harm to a company under relative secrecy so as to not unnecessarily alarm staff. As a dedicated intelligence analyst (working for a company with an incredible need to integrate a security function into social media) I personally witnessed a number of occasions where I’d read a post – a perfectly fine, professional post that a normal person wouldn’t bat an eye at – and thought “Oh heck, John Doe isn’t going to be happy about this one,” and upon further investigation discovered that, as suspected, Doe was all sorts of worked up over 260 characters and was heading down to the local office to cause a ruckus. With a little bit of notice, my team could have prepared our local staff for the event and given them adequate time to get ready rather than going into overdrive mode.

    It can help reduce the stress that the social media team feels during the normal course of their duties. Most people know that it’s possible to directly message a company’s customer service group via social media, but often times it’s actually the social media team that is in charge of screening and fielding these messages. On the occasion when a hateful comment or threat comes through, the social media specialist on the receiving end – who likely and rightly doesn’t have a lot of experience with such things – may react in any number of ways, from panic to disbelief. Whatever the response is, the likelihood that they’ll consider sending it to security for analysis without some previous instruction to do so is slim to none. At the very least, giving these staff this simple instruction can mitigate some of the basic issues. At best, it can begin to smooth the path for future growth into a more robust Social Media-Security partnership.

    Even security teams with dedicated social media analysts are still constrained by the limits of being human. While your company may have a well staffed social media threat team there is only so much a person can handle at any given time. In reality, though, it’s more likely that whoever is watching social media for threats is also juggling a multitude of different security tasks as well. By working or liaising with your organization’s social media team, you’ll have extra eyes on all the time. Many times, when a person is threatening an organization online they are not directing this information to the company’s inbox or direct messaging their team. Sometimes it’s as simple (and clear) as someone saying “I’m going to go shoot up XYZ Company tomorrow” without any connection to official accounts. Most social media groups monitor for any mention of their company’s name as part of a marketing strategy and to ensure only legitimate accounts are using the company branding. Clearly, this threat is not something that they should be dealing with – but it is certainly the job of corporate security. Even a tenuous partnership between the teams could result in threats like this being effectively handled.

    Just as your average security specialist wouldn’t know how to effectively announce a major company event on Twitter, neither will your typical social media analyst have the tools and skills necessary to investigate threats and persons.

    Security teams, by the nature of our work, are often able to access information that is not available to social media teams. Tools like Nexis and TLO aren’t given to groups without a legitimate use case, but these tools are often necessary in order to identify a threat actor. Depending on the severity of a threat, this information is often incredibly useful when providing information to the police. They are generally so overworked, underfunded, and understaffed, that having so much information handed to them, especially with an honest, well-documented case file that explains the methodology of your investigation, is a relief, and will help jumpstart an investigation.

    Social media teams know who is a regular issue. They know that John Doe sends rude comments to the Instagram inbox every time something is posted. They also know that they have a lot more to their job description than just reading mean comments. The regulars are remembered because of their consistency, but there are other threats who may not come up often enough to remember, and these may be the most dangerous. Likewise, if John Doe suddenly stops sending his vitriol, a social media specialist is likely to feel relief, whereas an intelligence analyst or other security professional might feel apprehension. What’s changed? Where did he go? Was he arrested? Did he find a new target? Or is he planning something that’s taking all of his time? For five years Jarrod Ramos threatened the staff at the Capital Gazette through social media, phone calls, emails, and any means he could find. It was normal for them, though the staff never ignored his threats. But in 2016 he went quiet. The small newspaper had neither the staff nor the resources to figure out why, and it would have been impossible for them to guess that in June of 2018 Ramos would be responsible for the vicious murder of five of their colleagues, but that’s exactly what happened. Likewise, in the reverse, should a case of minor, random harassment become more regular it’s possible an overworked social media specialist might be so harried they just wouldn’t notice. Paying attention to and noticing such trends is well within the wheelhouse of Corporate Security, but our ability to do this work is dependent on good, effective, two-way communication with the people on the receiving end (including and beyond social media).

    Finally, and very importantly, it is imperative for any security team to work with the people in their organization if for no other reason than to build relationships. Security is, if we’re being frank, a pain for everyone. While, yes, our goal is to keep people alive and well, completing this task also means we have to be an impediment. The same perimeter security measures that keep out a bad actor also slow down the company’s employee during a torrential downpour. The same check-in procedures that ensure only authorized persons and wanted guests get past the lobby also make the new guy late right before a big meeting when he’s left his badge at home. The same systems that only grant entry to someone with a need-to-access also ruins the forgetful employee’s day when she hears the door click shut behind her just as she notices she left her access card on her desk. Security costs money but doesn’t make it. Security gets in the way of art and gardens and aesthetics. Security is necessary, but it’s also difficult for everyone. By working amicably with as many people as possible throughout an organization and making sure they understand that you’re there to help them get their job done, you are building bridges to better relationships. You’re recruiting ambassadors that can help explain to others why piggybacking is such an issue. You’re educating additional bodies who can come to your team when they notice that outside door isn’t locking when it shuts. You’re expanding the pool of people who will quickly let you know when something doesn’t seem right, rather than just telling you after the fact. And, unlike many teams within many organizations, the social media team is often overwhelmingly comprised of young employees who will be more vocal about their support for you and may even come up with interesting, innovative ways to spread the security word that we may not think of.

    The long and short of it is that the world is always changing and evolving and in a field as vast and dynamic as security, we will always be met with new challenges. The most effective way to deal with such hurdles, at least on the front end, may very well be referring to the expertise of other professionals. By working with them instead of against them, we’ll be more able to understand the threats posed to our organizations and communities, and better ensure the continued safety of those who depend on us.

    Editor’s note: This article was re-published with the generous permission of the author. She is not the poor soul depicted in the photo above, however, who, for my money, is being a bit dramatic. –Tom Hagy


    COURTNEY KLEIN, PSP
    Courtney got her start in security while pursuing her master’s degree in criminal justice. Since then, she has served in a consulting capacity for educational institutions, major law firms, local and federal law enforcement, religious organizations, internationally celebrated entertainers, a number of non-profit organizations, a preeminent entertainment company, and state task forces grappling with innovative standards designs.

    Much of Courtney’s experience also rests in serving on dedicated corporate security teams, focused on everything from basic CPTED design and access control to international travel security and internal fraud investigations. Currently, Courtney proudly serves as the Senior Intelligence Analyst for a major international non-profit, where she uses her experience to identify and monitor individuals who pose a physical or intellectual threat to the organization’s employees, clients, assets and mission.

    Read more about Soteria Risk Consultants.

  • Francoise Gilbert on Colorado’s New Privacy Law: Are You Ready?


    Effective Sept. 1, 2018, Colorado will require all entities that process or store certain personal information of Colorado residents, regardless of whether the entity is located within or outside of Colorado, to have formal data security and data disposal programs. This is the result of the adoption of Bill 18-1128 “Concerning Strengthening Provisions for Consumer Data Privacy,”  signed into law at the end of May 2018, to amend and supplement existing law ….  Previously, the definition of “personal identifying information” under the Colorado law was limited to a resident’s first name or initial and last name in combination with the individual’s Social Security, driver’s license, or identification card number, or a credit or debit card or bank account number, combined with a password or access code. The new definition includes additional forms of identification, such as student, military, passport, and health insurance identification number, as well as other types of information, such as medical information or biometric data. It also includes username or e-email address in combination with a password or security question answers that would permit access to an online account …. Organizations that collect personal identifying information of Colorado residents and that do not yet have the written programs necessary to formalize their data protection practices urgently need to focus on compliance. — Francoise Gilbert, Greenberg Traurig


    Francoise Gilbert, a partner at Greenberg Traurig, is the author of the two volume treatise “Global Privacy and Security Law” (Wolters Kluwer Publishing), covering 68 countries. Her practice has focused on information privacy and security for more than 25 years. She advises clients on the entire spectrum of domestic and international privacy and cyber security issues legal issues, such as Internet of Things, smart cities, artificial intelligence, analytics, digital advertising and other cutting-edge developments that rely on the extensive use of personal data.

    She is one of the featured speakers at the Privacy+Security Forum which takes place Oct. 3-5, 2018, in Washington, DC.


  • McLoughlin on Artificial Intelligence in Banking

    “Capital adequacy requirements are not the only kind of regulation that AI is helping banks to meet. An even bigger area is monitoring of trading activities for misconduct and abuse. The Bank of England estimates that misconduct by traders has cost banks a global cumulative of $320 billion to date. For this very large reason, banks are aggressively deploying machine learning to monitor the behavior of their traders and detect unusual behavior.”

    Read Michael McLoughlin’s post on LinkedIn.

    Michael McLoughlin is Global Digital Transformation Partner & Advocate with Microsoft.

  • Halligan, Weyland on Cybersecurity, Trade Secret Asset Management and the Defend Trade Secret Act of 2016

    “Cybersecurity protection against outsider theft has largely succeeded, if competently crafted business methods are strictly followed. The more intractable problem of insider theft is now the major concern, and traditional cybersecurity methods are unavailing. The ever-higher digital barriers placed around the corporation and its sensitive data are no defense against data theft by people allowed inside the digital walls in the normal course of business.”

    Read their complete post on LinkedIn.

    R. Mark Halligan is a Partner and Trial Lawyer at FisherBroyles, LLP. Mr. Halligan has taught Advanced Trade Secrets Law in the John Marshall Law School LLM program for 24 years.

    Richard F. Weyand is the President of the Trade Secret Office, Inc. www.thetso.com

    See R. Mark Halligan and Richard F. Weyand Trade Secret Asset Management 2018: A Guide to Information and Asset Management Including RICO and Blockchainavailable on Amazon. https://www.amazon.com/dp/0997070986

  • Willis Towers Watson: Cyber Risk Top D&O Concern

    Based on their survey, Willis Towers Watson says cyber risk continues to top the list of concerns for directors and officers (right up there with employee claims). As for coverage, while they care about price, things like their relationship with the carriers and how well they handle claims are critical elements.

    And, maybe one key reason cyber events keep happening: “Only 13% of board members feel that their organizations learn from past cyber mistakes.”

    Read the results of the Willis Towers Watson survey. 

  • RSA’s Zulfikar Ramzan on Blockchain

    Is blockchain as impenetrable as people think? Or as necessary?

    It’s not predicated on the same type of cryptographic security that we’ve seen historically, but if someone has enough money and enough motivation — like a nation state — couldn’t they severely compromise a system? Is blockchain the only way transactional protections can become so secure, or could traditional technologies be employed and with less effort?

    RSA Security’s Chief Technology Officer Zulfikar Ramzan, Ph.D., spoke at our Cyber Sector Risk: Blockchain Security in April 2018 in New York. Hear what he had to say about this much-heralded technology.


    Related content

    https://hb.worryfreeweb.com/www-litigationconferences-comprivacysecurity-forum-2018-2/

    International Cyber Risk Management Conference | Dec. 6-7, 2018 | Bermuda

    The Urgency of Cyber Threats to U.S. and Global Critical Infrastructures | Video Session