Category: HB Risk Notes
-
Francoise Gilbert on Colorado’s New Privacy Law: Are You Ready?

Effective Sept. 1, 2018, Colorado will require all entities that process or store certain personal information of Colorado residents, regardless of whether the entity is located within or outside of Colorado, to have formal data security and data disposal programs. This is the result of the adoption of Bill 18-1128 “Concerning Strengthening Provisions for Consumer Data Privacy,” signed into law at the end of May 2018, to amend and supplement existing law …. Previously, the definition of “personal identifying information” under the Colorado law was limited to a resident’s first name or initial and last name in combination with the individual’s Social Security, driver’s license, or identification card number, or a credit or debit card or bank account number, combined with a password or access code. The new definition includes additional forms of identification, such as student, military, passport, and health insurance identification number, as well as other types of information, such as medical information or biometric data. It also includes username or e-email address in combination with a password or security question answers that would permit access to an online account …. Organizations that collect personal identifying information of Colorado residents and that do not yet have the written programs necessary to formalize their data protection practices urgently need to focus on compliance. — Francoise Gilbert, Greenberg Traurig
Francoise Gilbert, a partner at Greenberg Traurig, is the author of the two volume treatise “Global Privacy and Security Law” (Wolters Kluwer Publishing), covering 68 countries. Her practice has focused on information privacy and security for more than 25 years. She advises clients on the entire spectrum of domestic and international privacy and cyber security issues legal issues, such as Internet of Things, smart cities, artificial intelligence, analytics, digital advertising and other cutting-edge developments that rely on the extensive use of personal data.She is one of the featured speakers at the Privacy+Security Forum which takes place Oct. 3-5, 2018, in Washington, DC.
-
A.I. Best Practices: Rules and Policies for Using Artificial Intelligence in Your Business
Explore how cybersecurity breaches impact insurance, risk management, and data privacy with evolving legal and compliance challenges.

[one-third-first]
DATE: Sept. 27, 2018
TIME: 2 p.m. EDT; 1 p.m. CDT; 12 p.m. MDT; 11 a.m. PDT
PLACE: Your computer or mobile device
PRICE: $197* per dial-in site
*Price is good through Aug. 16. After that it’s $247.GROUPS ARE GOOD: Registering qualifies you to multiple attendees at your location.
CLE: 1 credit
Please send CLE questions to
CLE@LitigationConferences.comSPEAKER:
John Frank Weaver
Attorney
McLane Middleton
Your registration includes:
• A site license to attend this webinar (invite as many people in one location as you can fit around your computer at no extra charge).
• Downloadable PowerPoint presentations from our speakers.
• The opportunity to connect directly with speakers during the audience Q&A session.
• At least one-hour of CLE credit.
Produced in collaboration with
and their new
Journal of Robotics, Artificial
Intelligence & Law[/one-third-first] [two-thirds]
Nearly every industry is adopting or preparing to adopt artificial intelligence applications into their business practices.
That’s exciting. However, there are almost no government regulations for their use and few resources providing best practices that anticipate ethical considerations and forthcoming legal requirements.
This lack of direction poses a serious problem as A.I. applications become more widespread. Businesses are creating their own ad hoc practices without considering the eventual government oversight and ethical consensus, which will result in costs and potential liability later when those companies have to change their practices.
This webinar looks at how your company should approach its A.I. rules and policies in order to minimize the impact of expected government action and cultural norms.
Register now and join our speaker as he explores existing laws addressing privacy and data security, pending A.I. legislation at the state and federal levels, and the recommendations of federal agencies that are most likely to be codified.
The webinar will provide practical guidance for attendees to use when developing internal rules, policies, practices, contracts, and public facing documents. The speaker will rely on relevant existing laws, proposed legislation, and reports from federal agencies that advocate certain public policies for the governance of AI.
What you will learn:
1. The requirements of privacy laws – including GDPR, Canada’s PIPEDA, and the new California privacy statute – that have special application to A.I.
2. Best practices for drafting a public facing privacy policy that addresses your use of A.I.
3. Best practices for preparing internal rules and policies governing your employees’ use of A.I.
4. Best practices for bots and other forms of A.I. that interact with consumers.
5. Best practices for A.I.-specific terms of use and consents.
6. Best practices for addressing A.I. in employee contracts and handbooks.
7. Best practices for addressing A.I. in vendor contracts, including assignment of liability and indemnification obligations.
And more!
Attendees will be able to go back to their companies and review their current A.I. practices, policies, and rules to determine how appropriate they are in light of expected regulations and expectations. The ultimate goal is to avoid costly revisions in response to evolving consumer expectations and government requirements. A little investment now could potentially save a lot of money in revisions changes, PR, and remediation later. — John Weaver, speaker
Speaker
The webinar speaker, John Frank Weaver, is an attorney with McClane Middleton whose practice focuses on A.I. and autonomous technology. He is the author of Robots Are People Too: How Siri, Google Car, and Artificial Intelligence Will Force Us to Change Our Laws, a contributing writer at Slate focusing on legal issues implicated by AI and autonomous devices, and a columnist for and member of the board of editors of The Journal of Robotics, Artificial Intelligence & Law.[/two-thirds]
-
McLoughlin on Artificial Intelligence in Banking

“Capital adequacy requirements are not the only kind of regulation that AI is helping banks to meet. An even bigger area is monitoring of trading activities for misconduct and abuse. The Bank of England estimates that misconduct by traders has cost banks a global cumulative of $320 billion to date. For this very large reason, banks are aggressively deploying machine learning to monitor the behavior of their traders and detect unusual behavior.”
Read Michael McLoughlin’s post on LinkedIn.
Michael McLoughlin is Global Digital Transformation Partner & Advocate with Microsoft.
-
Joshua Gold on Cyber Crime and Insurance

With the amount of trickery going into thefts and embezzlements these days, crime insurance companies too often use the many steps involved in a fraudulent scheme to argue that losses are indirect and otherwise uncovered.
The recent decisions of the Second Circuit and Sixth Circuit on the “direct loss” argument and the scope of computer fraud coverage are important victories for policyholders generally, making clear that where the predominant step in the chain is some type of covered fraudulent misconduct involving a computer, a court is not going to entertain a direct loss defense to excuse the insurance company from paying.
As such, policyholders should be familiar with their crime coverage and promptly notify all potentially implicated lines of insurance coverage when a cybercriminal is afoot. — Joshua Gold, Anderson Kill
Read Josh’s complete article.
Joshua Gold is Chair of Anderson Kill’s Cyber Insurance Recovery Practice and was amicus counsel for United Policyholders in the Medidata Solutions, Inc. v. Federal Insurance Company case before the Second Circuit.
-
Halligan, Weyland on Cybersecurity, Trade Secret Asset Management and the Defend Trade Secret Act of 2016

“Cybersecurity protection against outsider theft has largely succeeded, if competently crafted business methods are strictly followed. The more intractable problem of insider theft is now the major concern, and traditional cybersecurity methods are unavailing. The ever-higher digital barriers placed around the corporation and its sensitive data are no defense against data theft by people allowed inside the digital walls in the normal course of business.”
Read their complete post on LinkedIn.
R. Mark Halligan is a Partner and Trial Lawyer at FisherBroyles, LLP. Mr. Halligan has taught Advanced Trade Secrets Law in the John Marshall Law School LLM program for 24 years.
Richard F. Weyand is the President of the Trade Secret Office, Inc. www.thetso.com
See R. Mark Halligan and Richard F. Weyand Trade Secret Asset Management 2018: A Guide to Information and Asset Management Including RICO and Blockchainavailable on Amazon. https://www.amazon.com/dp/0997070986
-
Willis Towers Watson: Cyber Risk Top D&O Concern

Based on their survey, Willis Towers Watson says cyber risk continues to top the list of concerns for directors and officers (right up there with employee claims). As for coverage, while they care about price, things like their relationship with the carriers and how well they handle claims are critical elements.
And, maybe one key reason cyber events keep happening: “Only 13% of board members feel that their organizations learn from past cyber mistakes.”
Read the results of the Willis Towers Watson survey.
-
RSA’s Zulfikar Ramzan on Blockchain
Is blockchain as impenetrable as people think? Or as necessary?
It’s not predicated on the same type of cryptographic security that we’ve seen historically, but if someone has enough money and enough motivation — like a nation state — couldn’t they severely compromise a system? Is blockchain the only way transactional protections can become so secure, or could traditional technologies be employed and with less effort?
RSA Security’s Chief Technology Officer Zulfikar Ramzan, Ph.D., spoke at our Cyber Sector Risk: Blockchain Security in April 2018 in New York. Hear what he had to say about this much-heralded technology.
Related content
https://hb.worryfreeweb.com/www-litigationconferences-comprivacysecurity-forum-2018-2/
International Cyber Risk Management Conference | Dec. 6-7, 2018 | Bermuda
The Urgency of Cyber Threats to U.S. and Global Critical Infrastructures | Video Session
-
Judy Selby on Improving Cyber and Privacy Board Reporting

“While general awareness of cyber risks among corporate boards is increasing, even the most motivated and knowledgeable directors cannot effectively fulfill their duties without receiving appropriate data about the organization’s risk profile. Unfortunately, however, there appears to be a disconnect between management and boards when it comes to cyber risk reporting . . . In order for directors to effectively discharge their duty of active, informed, and engaged oversight, the information they receive must be relevant, understandable, reliable, and objective.”
Judy Selby, JD
Judy Selby Consulting
Read the full article and Judy’s tips for improving board reporting.
Judy Selby of Judy Selby Consulting



