Blog

  • Financial Services Cyber Risk Information Sharing

    Why We Need to be More Like Apes, Less Like Seagulls

    By Tom Hagy

    Featuring Craigg Ballance, Director of Canadian Member Services, FS-ISAC

    Even before we can walk we are encouraged to share. We’re told to share our things even when we barely have any. Even some wild animals share food and resources – even when those resources are scarce. Some creatures are better at it than others, of course. Apes and lions? Absolutely. Seagulls? All you have to do next time you’re on the beach is toss what’s left of your ham sandwich into the air and see how generous gulls are.

    People fall into sharing — and not-fond-of-sharing — groups, too. Sharing is particularly critical in the financial sector where, while privacy and security regulations command a tight lid on data, global financial institutions are successfully sharing data about cyber risk, says Craigg Ballance, Director of Canadian Member Services for FS-ISAC in Toronto. But, he says, sharing has to take place across a broad landscape.

    “Information analysis sharing has to cut across the various subsets of the financial sector,” says Ballance. “While banks share local data, they are trying more and more to share globally, but,” he says, “banks need to share with other institutions, like insurers, investment funds, pension funds, and other types of financial institutions, for this cooperation to have the greatest and most effective impact on security.”

    While some IT professionals may tend to want to play things close to the vest, when it comes to cybersecurity teams it is the IT professional who works openly with others who is an invaluable player.

    The Danger of Over-Confidence

    Some blamed over-confident IT professionals for the massive cyber attack that temporarily crippled shipping giant Maersk in June 2017. At the same time, as reported by Reuters on June 27, 2017, Ukrainian commercial banks also sustained a cyber attacks.

    “There are a lot of smart people out there actively trying to figure out ways to mess us up,” Ballance says, whether it’s through new denial of service attacks, or cyberware and ransomware, or the creatively diabolical phishing attacks. “When one entity is falls prey to one of these schemes we’re suddenly all at greater risk,” Ballance says. “There is a limited volume of resources and talent to combat cyber-attacks, so pooling resources, information and skill sets is critical.”

    Ballance emphasizes the importance of having a playbook so when a crisis occurs people know who is supposed to do what and when. “In the midst of an attack people tend to lose their minds and not necessarily act logically,” he says. “So having a prepared methodology to get your organization out of a pickle is a piece of work we strongly advocate, as well as sharing that methodology across industries. This way, as examples, banks and insurance companies and investors can enrich each other with new insights and skills.”

    He also advocates simulated attacks and table-top exercises so people can engage as if they are dealing with a real disaster, like those conducted by FS-ISAC. Conducting post-event analysis to improve response and sharing those findings is also important.

    Experience tells us that when it comes to global cybersecurity we need to be more like gorillas and big cats than selfish seagulls down by the sea shore.


    Craigg Ballance will share insights like these and more at the International Cyber Risk Management Conference Dec. 6-7, 2018 in Bermuda. He will be joined by Nick Galletto, Global Cyber Risk Services Leader at Deloitte in a session titled, “Strength Through Information Sharing Within the Global Financial Services Arena.”

    Over the past three-plus decades, Ballance has led and managed advanced technology-enabled business initiatives across a wide range of competitive sectors, countries and areas of innovation. These build on his experience in leading electronic commerce development in one of the world’s path-setting banks in the field and on his extensive work in finance, logistics, international business and government. He is the author/co-author of three books on leveraging technology for business innovation.

    Tom Hagy is a Philadelphia-based writer and entrepreneur, Founder and Managing Director of HB Litigation Conferences LLC and Custom Legal Content LLC, former Editor and Publisher of Mealey’s Litigation Reports, and a former Vice President at LexisNexis®.

  • Cognitive Shortcuts: Assessing Case Value & Litigation Risk with Homer Simpson and Spock

    By Jeff Trueman, Esq.
    Mediator

    The central question on the minds of counsel, their clients, and insurance professionals in civil litigation is, of course, “What’s the case worth?” Although lead paint litigation may be going through some changes, it remains a mature tort where enough historical settlement and verdict data exist for counsel to argue why a particular case should or should not fit within a certain settlement range. In the midst of these discussions, the human brain plays tricks on us. For example, litigators sometimes assume that their trial experience can determine how jurors will negotiate with one another and resolve factual discrepancies after closing arguments. This assumption is a “heuristic” – a cognitive shortcut called attributional error or illusion of control.

    Underneath the games of litigation “chicken” that are the hallmark of settlement negotiation, heuristics lead to erroneous valuations and assessments of risk.

    Although more than one hundred heuristics exist, approximately 15-20 occur commonly in the context of settlement negotiations. It is easy for potential clients to employ a heuristic similar to the illusion of control by imagining a connection between something they desire, such as a favorable case outcome, and the past successes of their prospective lawyer. Representative and confirmation biases influence how we connect “model” to “outcome.” When differences over case value intensify, litigators return to threats of relinquishing control: “Maybe we have to try this case;” or “We feel good about our chances in front of a jury.” Underneath the games of litigation “chicken” that are the hallmark of settlement negotiation, heuristics lead to erroneous valuations and assessments of risk.

    Borrowing from Daniel Kahneman’s book, “Thinking Fast and Slow,” cognitive shortcuts live in our “System One” brain where we react to circumstances intuitively without giving much thought about the way in which we perceive problems or how to calculate probabilities and manage risk. “System Two” thinking is slower, more deliberate, logical, and usually more accurate. Think of the difference between Homer Simpson and Star Trek’s Spock and you get the picture.

    Although we like to think that we are System Two negotiators who act analytically and rationally, we usually operate within System One. We negotiate emotionally. For example, in terms of perceiving and managing financial risk, we prefer to avoid loss rather than experience an equivalent gain. It feels better not to lose five dollars rather than find five dollars. Whether we consider something a loss or a gain depends on a reference point (our expectations, for example) which is usually based on perceived surroundings, desires, or what we think happened to others. Loss and fear of loss carry significant psychological power when we think about the future.

    Many lawyers default to their role as advocates for legal rights without considering the quality of counsel they give to clients regarding risk management. This plays right into the endowment bias that potential clients carry, valuing property or experiences merely because they have them. When thinking about future risk, many lawyers exhibit an overconfidence and self-serving bias in favor of past success. Unfortunately, competitive bargainers are disinclined to compromise even when it would benefit their bottom lines. Of course, it goes without saying that clients are often better served by lawyers who have some experience in a courtroom. But prior success does not guarantee future results.

    Granted, it’s hard to know whether a particular settlement number is “good” since it’s impossible to compare trial verdicts to settlement results in the same case. Although most law suits settle on terms that are good enough, practically speaking, lawyers will emphasize trial advocacy and “justice” over risk management. Few potential clients want to hear about “cognitive heuristics” and risk management when they seek a fighter for a “just” cause. Even so, litigants who are aware of the well-worn chutes and ladders of emotion that commandeer their thinking can tune out Homer Simpson in favor of Spock to make better decisions about valuation and risk.


    Jeff Trueman, Esq., ADR Services, Sole Practitioner, Baltimore, MD. Private mediator of litigated civil disputes, including personal injury, premises liability, toxic and environmental torts, wrongful death, professional malpractice, partnership dissolution, employment, domestic, and guardianship petitions. Public speaker and presenter of mediation and negotiation-related dynamics at law schools, law firms, and litigation conferences. Author of ADR column that appears semi-regularly in the Maryland Daily Record.


    Jeff is one of the featured presenters at this year’s National Lead Litigation + Emerging Toxic Torts Conference, Oct. 15 in New York.

    The event is being held at the same time and in the same location as our Drug & Defense Forum.

  • Complex Post-Settlement Liens | CLE Course | Recorded July 26, 2018


    [two-fifths-first]

    Two ways to access this session.

    Get it direct from HB for just $197 for the video — audio synced with slides.

    Or, it’s included in your West LegalEdcenter (Thomson Reuters) subscription.

    ____________________


    Speakers

    Franklin Solomon
    Solomon Law Firm

    Brett Newman
    Lien Resolution Group

    [/two-fifths-first] [three-fifths]

    Complex Post-Settlement Liens:

    Beyond Traditional Medicare and Medicaid Issues

    Take this highly practical course with two deeply experienced practitioners who share insights on issues that impact the cases on your desk today.

    Learn about the newest case law, agency positions and litigation tactics affecting health and disability plan reimbursement claims, including how to protect your clients and your practice in this rapidly developing area.

    Our speakers discuss:

    Medicare Advantage Plans

    Federal Employees Health Benefits Act (FEHBA) Plans

    Employee Retirement Income Security Act (ERISA) Claims

    Medicare set-asides

    TRICARE

    Veterans Administration Claims


    Speaker Bios

    Franklin P. Solomon | Solomon Law Firm

    Franklin Solomon has a nationwide practice focused on evaluation, litigation and resolution of healthcare lien/reimbursement claims. He represents personal injury victims and their attorneys in defending against claims by health plans and government benefits programs seeking payment out of tort recoveries. Most recently, he was plaintiffs’ counsel in two federal appellate court cases decided last summer: Wurtz v. The Rawlings Company, ___ F.3d ___, (2d Cir. 2014), a class action challenging New York insurers’ reimbursement claims against their insureds, and Taransky v. Sec. U.S. Dept. of Health & Human Svcs., ___ F.3d ___ (3d Cir. 2014), a class action challenging Medicare’s claims for reimbursement out of New Jersey tort recoveries.

    Brett Newman | The Lien Resolution Group

    Brett Newman is known nationally by plaintiff attorneys for his expertise on claims avoidance and reduction. Recognizing the ever-growing nature of lien resolution and the ever-increasing associated liability, Brett established The Lien Resolution Group and The Newman Structured Settlement Group to assist both individual claimants of personal injury lawsuits and mass tort claimants in the protection of their proceeds and government benefits.

    [/three-fifths]

  • Alliance of Women Trial Lawyers | First Fall Conference 2018 | Oct. 27-29, 2018 | New Orleans


    [one-third-first]

    Contact
    Nancy Holston
    Founder
    Alliance of Women Trial Lawyers
    nancy@awtriallawyers.com


    DETAILS

    When
    Oct. 27-29, 2018

    Meeting Venue
    Ritz-Carlton
    New Orleans

    LEARN MORE

    REGISTER

    Prices

    The Alliance is all about women helping women so they’re offering discounts to anyone who brings a law student, clerk, or first year associate to the conference with them.

    • 1st and 2nd Attendee: $895/Attendee

    • 3 or more Attendees from same firm: $795 each

    • 1 Attendee with Guest (Law Student, Clerk or 1st Year Associate): $1,295 for Attendee and Guest

    • More than 5 Attendees please fill out their Contact form or call Nancy Holston at 850-304-9674 for more information

    To Register by Check: Click here for Payment by Mail Registration Form.

    [/one-third-first] [two-thirds]

    New Alliance of Women Trial Lawyers Announces First Event in New Orleans

    Congratulations to Nancy Holston on the formation of the Alliance of Women Trial Lawyers. HB is proud to support this group and a mission that is dear to our hearts — promoting the careers of women professionals.

    Nancy has been successful at building events for plaintiff attorneys — some you may have probably attended! — and it’s great to see her strike out on her own to develop something she believes in.

    Take a minute to learn more about the AWTL, and see who is speaking at their first event.

    AWTL Vision

    To create a community that inspires and empowers women trial lawyers, the Alliance is passionately committed to the purpose of the family of women lawyers. We support women who take responsibility for successful relationships with other professionals. The Alliance of Women Trial Lawyers advances the influence and impact of women in the legal community.

    We aim to represent the intelligence, creativity, complexity and diversity of women lawyers’ experience — across nation, ethnicity, race, religion, sexual orientation and economic background.

    The Alliance will provide an environment for women lawyers to lead, inspire, and mentor other women lawyers. We hope to help women litigators to embrace their power, purpose, and value, and to take responsibility for their relationships.

    Check out the complete agenda and faculty!

    [/two-thirds]

  • HB Announces Alliance with Alliance of Women Trial Lawyers

    We are proud to announce our latest alliance with a new trial attorneys group just for women on the plaintiff side of tort litigation.

    Founded by plaintiff law conference veteran Nancy Holston, the Alliance of Women Trial Lawyers is committed to empowering these professionals, helping them to overcome “systematic obstacles and to realize greater self-sufficiency and wholeness through support, acknowledgement and utilization of dormant, yet innate strengths.” Before founding the Alliance in July 2018, Nancy was a principal at 360 Advocacy and before that the first Executive Director of Mass Torts Made Perfect.  Nancy is well-connected in the plaintiff bar and is excited by the initial reaction to her new venture.

    Nancy is equally inspired by the feedback she is getting for the Alliance’s first national conference which will be held from Saturday, Oct. 27th through Monday, Oct. 29 at the Ritz-Carlton in New Orleans. The program features many of the leading women trial attorneys in the country and a range of topics on practice development, litigation strategy, preparing witnesses, jury selection, deposition skills, direct examination, opening arguments and ethical issues involved in settlements. 

    “I admire anyone who takes a risk to do something they believe in, and Nancy has demonstrated both enthusiasm and commitment to improving the professional lives — and personal lives, for that matter — of women who represent plaintiffs in mass torts,” said Tom Hagy of HB Litigation Conferences. “It’s an important mission and we’re excited to lend our support.”

    “We look forward to working together to grow our respective portfolios and educate attorneys on important and emerging legal issues. There is an outside chance we will also have some fun along the way,” Tom added.

    Click here for more information about the AWTL’s 2018 Fall Conference. 

  • Blockchain: Power to the People

    Dan Solove, co-founder of the Privacy+Security Forum and professor at GW Law School, just posted an interview with Steve Shillingford, Founder and CEO of Anonyome Labs, a consumer privacy software company. Below is part of just one exchange in the interview. 

    SOLOVE: The Internet has made so many things possible that we couldn’t do in an analog world. Yet, in some ways, the online world seems to lack the capabilities of the offline world. In the offline world, it is much easier to have anonymous transactions. This becomes much more challenging online. How can the online world be made more like the offline world in this regard?

    SHILLINGFORD: Blockchain technology shifts the balance of power back to people—to individuals—and away from tech giants, governments and data miners. It allows you to transact on your terms, just as you do offline. And it’s not just limited to financial transactions. Put anything on the blockchain you want. The blockchain gives a person the ability to publish only the information THEY decide to divulge. Nothing more, nothing less. And no more hidden agendas, no selling personal data without your consent, no worries about privacy. Just like the analogue world, you decide the context, the content, and duration of the information you provide…not the big guys. It can really be that easy.

    Read the complete interview. 

    See the latest faculty and agenda updates for the Privacy+Security Forum 2018 | Oct. 3-5, 2018 | Washington, D.C.

  • Oracle Health Sciences on Pharmacovigilance and Artificial Intelligence

    “The potential to use artificial intelligence methods increasingly for the analysis of the increasing amounts of pharmacovigilance data is well understood and many companies are moving (or planning to move) there, and we can predict that routine tasks in pharmacovigilance will in the future be increasingly automated. It will be crucial, however, for regulatory authorities to very clearly provide a position about the use of AI as well as the acceptable level of quality from AI applications. But in parallel with the shaping of those definitions, given the massive increase in their AE case workloads that most companies are currently experiencing, the industry will out of necessity proceed swiftly with the adoption of AI and cloud technologies to reduce their costs and increase their efficiencies.

    “Like other industries, the pharmaceutical business and in particular the pharmacovigilance field will see a massive change in their processes in the near future, away from tedious, repetitive manual tasks towards a better utilization of scarce resources, in particular medical and scientific knowledge, for value-adding tasks. It is imperative for all stakeholders – industry, service providers and regulators – to provide an environment in which such a transformation can take place without ever compromising public health or the safety of the individual patient, and ideally providing additional benefit for patients.”

    A quote from
    Addressing the Data Challenges of Pharmacovigilance

    Download the paper from Oracle Health Sciences


    We are covering this subject at:

    Drug & Device Defense Forum | Oct. 15, 2018 | New York

  • Artificial Intelligence in the Drug and Device Industries

    Are Data Divers and Miners Going to Lead Innovation?

    The big tech companies are into it. Apple, IBM and Google. Roche is into it. Medtronic, as well. Artificial intelligence has been a big part of innovation in the healthcare space for several years, and its impact is only going to get bigger.

    “Artificial intelligence-based healthcare technologies have contributed to improved drug discoveries, tumor identification, diagnosis, risk assessments, electronic health records (EHR), and mental health tools, among others,” writes Blank Rome attorney Brian Higgins in his Artificial Intelligence and the Law Blog (it’s excellent, by the way).  [1]

    Daniel Faggella of TechEmergence.com writes that machine learning healthcare applications are getting a lot of attention in the press and from the investment community. He adds to the list of machine learning’s impact things like treatment queries and suggestions, and even robotic surgery.

    But optimism for AI’s application to drug discovery seems greater than that inspired by other healthcare sectors. One reason for that, Faggella writes, is that compared to other segments where various laws and stakeholder incentives may not align, “drug discovery stands out as a relatively straightforward economic value for machine learning healthcare application creators.” He adds that this application also involves “one relatively clear customer who happens to generally have deep pockets: drug companies.” [2]

    Also writing for TechEmergence.com, Kumba Sennaa says doctors may feel threatened at the idea of competing with artificial intelligence tools. Not so in the case of drug makers.  “Unlike doctors, pharma companies have every reason in the world to adopt the most cutting-edge technologies in the expensive and lengthy process of drug discovery,” Sennaa writes. “Unlike other applications within healthcare facilities, drug discovery seems to have a clearer path to adoption.” [3]

    AI-fueled innovation is, in turn, fueled by data. Lots and lots of data. “And there is no better place to find big data sets than in the healthcare sector,” Higgins says. “According to an article last year in the New England Journal of Medicine, by 2012 as much as 30% of the world’s stored data was being generated in the healthcare industry.”

    “Thanks in large part to AI and the availability of health-related data,” Higgins says, “health tech is one of the fastest growing segments of healthcare and one of the reasons why the sector ranks highest on many lists.”

    “To be successful,” Higgins predicts, “tomorrow’s healthcare leaders may be those who have access to data that drives innovation in the health tech segment. This may explain why, according to a recent survey, healthcare CIOs whose companies plan spending increases in 2018 indicated that their investments will likely be directed first toward AI and related technologies.”


    Related

    Given the investment and tremendous opportunity AI provides for the drug and device industries, the chairs of our Fifth Annual Drug & Device Forum are developing a session on the subject. Join us for this and discussion of other important topics on Oct. 15, 2018 in New York.

    If you have ideas please reach out to one of our chairs directly or via Ideas@LitigationConferences.com. They are Megan Grossman of Segal McCambridge Singer & Mahoney, Michelle Hart Yeary of Dechert, and Jim Frederick of Goodell DeVries Leech & Dann. Learn more. 

    Also, on Sept. 27 we are co-producing a webinar titled A.I. Best Practices: Rules and Policies for Using Artificial Intelligence in Your Business. The webinar features John Weaver of the McClane Middleton law firm and contributing author to the Journal of Robotics, Artificial Intelligence & Law. We are producing this in collaboration with growing legal research company Fastcase. Learn more.


    Links to the articles cited in this post:

    #1. http://aitechnologylaw.com/2018/03/data-driven-health-tech-innovation/

    #2.  https://www.techemergence.com/machine-learning-healthcare-applications/

    #3. https://www.techemergence.com/ai-in-pharma-and-biomedicine/

  • Courtney Klein on Social Media & Security

    A Restructured Paradigm for Corporate Teamwork

    By Courtney Klein of Soteria Risk Consultants

    Social media has become an integral part of everyday life. It’s how some of us get our news, research our opinions, learn about local events, and connect with friends. For the modern western business, it is also immensely important for staying in touch with customers, advertising, and overall visibility. For this reason, many companies employ veritable armies of “Social Media Specialists” that do everything from designing graphics to writing tweets to replying to customer questions and complaints. Some companies interact with each other (such as the hilarious and long-standing Twitter Battle between Wendy’s and McDonald’s), and some use it as their primary form of communication.

    Customers, too, know that social media is a way to get in touch with a company – for good reasons and for bad – and while many companies are aware that they will and do receive threats on social media, very few of them have any kind of protocol in place for how to deal with them – and even fewer still encourage their social media teams to pass this information on to or (better yet) work together with their security team. This sort of blasé attitude to threats – either because “it’s not my job” or “they can’t be serious” – leads to real-world ramifications. Incidents such as the April 4th Youtube Shootings (which, we acknowledge, was a failure of many different departments, companies, and law enforcement operations) are a reminder of just how social media “banter” can turn into a real-world nightmare.

    Now, in defense of essentially any company guilty of this, Social Media is a new beast that even the best are still trying to get their arms wrapped around. Not only is social media relatively new to the game, but it’s dynamic and ever-changing. What was relevant yesterday no longer will be tomorrow. Updates add new features and kill our favorites, terms of service changes impact business, trends are fleeting but ever so important for a business to understand, customer service issues must be dealt with in a timely fashion. Take all of this and add security concerns on top of the social media specialist’s plate and you’re only going to run into failure. That’s why we at Soteria are such strong believers in having social media and security teams work together every step of the way.

    Folding security into the fray … will make a world of difference

    With few exceptions, social media teams plan their calendar very carefully. Words must be scripted, graphics must be designed, legal must be consulted; it’s not often that there’s a “last minute tweet that just has to go out right here right now.” With everything else that goes into these seemingly benign releases, folding security into the fray is, ultimately, a minor change, but one that will make a world of difference. Giving the security team insight into what will be posted provides a number of benefits.

    The security team will be able to assess what posts may aggravate any known or active threats. In general, security teams like to keep information about who wants to do harm to a company under relative secrecy so as to not unnecessarily alarm staff. As a dedicated intelligence analyst (working for a company with an incredible need to integrate a security function into social media) I personally witnessed a number of occasions where I’d read a post – a perfectly fine, professional post that a normal person wouldn’t bat an eye at – and thought “Oh heck, John Doe isn’t going to be happy about this one,” and upon further investigation discovered that, as suspected, Doe was all sorts of worked up over 260 characters and was heading down to the local office to cause a ruckus. With a little bit of notice, my team could have prepared our local staff for the event and given them adequate time to get ready rather than going into overdrive mode.

    It can help reduce the stress that the social media team feels during the normal course of their duties. Most people know that it’s possible to directly message a company’s customer service group via social media, but often times it’s actually the social media team that is in charge of screening and fielding these messages. On the occasion when a hateful comment or threat comes through, the social media specialist on the receiving end – who likely and rightly doesn’t have a lot of experience with such things – may react in any number of ways, from panic to disbelief. Whatever the response is, the likelihood that they’ll consider sending it to security for analysis without some previous instruction to do so is slim to none. At the very least, giving these staff this simple instruction can mitigate some of the basic issues. At best, it can begin to smooth the path for future growth into a more robust Social Media-Security partnership.

    Even security teams with dedicated social media analysts are still constrained by the limits of being human. While your company may have a well staffed social media threat team there is only so much a person can handle at any given time. In reality, though, it’s more likely that whoever is watching social media for threats is also juggling a multitude of different security tasks as well. By working or liaising with your organization’s social media team, you’ll have extra eyes on all the time. Many times, when a person is threatening an organization online they are not directing this information to the company’s inbox or direct messaging their team. Sometimes it’s as simple (and clear) as someone saying “I’m going to go shoot up XYZ Company tomorrow” without any connection to official accounts. Most social media groups monitor for any mention of their company’s name as part of a marketing strategy and to ensure only legitimate accounts are using the company branding. Clearly, this threat is not something that they should be dealing with – but it is certainly the job of corporate security. Even a tenuous partnership between the teams could result in threats like this being effectively handled.

    Just as your average security specialist wouldn’t know how to effectively announce a major company event on Twitter, neither will your typical social media analyst have the tools and skills necessary to investigate threats and persons.

    Security teams, by the nature of our work, are often able to access information that is not available to social media teams. Tools like Nexis and TLO aren’t given to groups without a legitimate use case, but these tools are often necessary in order to identify a threat actor. Depending on the severity of a threat, this information is often incredibly useful when providing information to the police. They are generally so overworked, underfunded, and understaffed, that having so much information handed to them, especially with an honest, well-documented case file that explains the methodology of your investigation, is a relief, and will help jumpstart an investigation.

    Social media teams know who is a regular issue. They know that John Doe sends rude comments to the Instagram inbox every time something is posted. They also know that they have a lot more to their job description than just reading mean comments. The regulars are remembered because of their consistency, but there are other threats who may not come up often enough to remember, and these may be the most dangerous. Likewise, if John Doe suddenly stops sending his vitriol, a social media specialist is likely to feel relief, whereas an intelligence analyst or other security professional might feel apprehension. What’s changed? Where did he go? Was he arrested? Did he find a new target? Or is he planning something that’s taking all of his time? For five years Jarrod Ramos threatened the staff at the Capital Gazette through social media, phone calls, emails, and any means he could find. It was normal for them, though the staff never ignored his threats. But in 2016 he went quiet. The small newspaper had neither the staff nor the resources to figure out why, and it would have been impossible for them to guess that in June of 2018 Ramos would be responsible for the vicious murder of five of their colleagues, but that’s exactly what happened. Likewise, in the reverse, should a case of minor, random harassment become more regular it’s possible an overworked social media specialist might be so harried they just wouldn’t notice. Paying attention to and noticing such trends is well within the wheelhouse of Corporate Security, but our ability to do this work is dependent on good, effective, two-way communication with the people on the receiving end (including and beyond social media).

    Finally, and very importantly, it is imperative for any security team to work with the people in their organization if for no other reason than to build relationships. Security is, if we’re being frank, a pain for everyone. While, yes, our goal is to keep people alive and well, completing this task also means we have to be an impediment. The same perimeter security measures that keep out a bad actor also slow down the company’s employee during a torrential downpour. The same check-in procedures that ensure only authorized persons and wanted guests get past the lobby also make the new guy late right before a big meeting when he’s left his badge at home. The same systems that only grant entry to someone with a need-to-access also ruins the forgetful employee’s day when she hears the door click shut behind her just as she notices she left her access card on her desk. Security costs money but doesn’t make it. Security gets in the way of art and gardens and aesthetics. Security is necessary, but it’s also difficult for everyone. By working amicably with as many people as possible throughout an organization and making sure they understand that you’re there to help them get their job done, you are building bridges to better relationships. You’re recruiting ambassadors that can help explain to others why piggybacking is such an issue. You’re educating additional bodies who can come to your team when they notice that outside door isn’t locking when it shuts. You’re expanding the pool of people who will quickly let you know when something doesn’t seem right, rather than just telling you after the fact. And, unlike many teams within many organizations, the social media team is often overwhelmingly comprised of young employees who will be more vocal about their support for you and may even come up with interesting, innovative ways to spread the security word that we may not think of.

    The long and short of it is that the world is always changing and evolving and in a field as vast and dynamic as security, we will always be met with new challenges. The most effective way to deal with such hurdles, at least on the front end, may very well be referring to the expertise of other professionals. By working with them instead of against them, we’ll be more able to understand the threats posed to our organizations and communities, and better ensure the continued safety of those who depend on us.

    Editor’s note: This article was re-published with the generous permission of the author. She is not the poor soul depicted in the photo above, however, who, for my money, is being a bit dramatic. –Tom Hagy


    COURTNEY KLEIN, PSP
    Courtney got her start in security while pursuing her master’s degree in criminal justice. Since then, she has served in a consulting capacity for educational institutions, major law firms, local and federal law enforcement, religious organizations, internationally celebrated entertainers, a number of non-profit organizations, a preeminent entertainment company, and state task forces grappling with innovative standards designs.

    Much of Courtney’s experience also rests in serving on dedicated corporate security teams, focused on everything from basic CPTED design and access control to international travel security and internal fraud investigations. Currently, Courtney proudly serves as the Senior Intelligence Analyst for a major international non-profit, where she uses her experience to identify and monitor individuals who pose a physical or intellectual threat to the organization’s employees, clients, assets and mission.

    Read more about Soteria Risk Consultants.

  • Francoise Gilbert on Colorado’s New Privacy Law: Are You Ready?


    Effective Sept. 1, 2018, Colorado will require all entities that process or store certain personal information of Colorado residents, regardless of whether the entity is located within or outside of Colorado, to have formal data security and data disposal programs. This is the result of the adoption of Bill 18-1128 “Concerning Strengthening Provisions for Consumer Data Privacy,”  signed into law at the end of May 2018, to amend and supplement existing law ….  Previously, the definition of “personal identifying information” under the Colorado law was limited to a resident’s first name or initial and last name in combination with the individual’s Social Security, driver’s license, or identification card number, or a credit or debit card or bank account number, combined with a password or access code. The new definition includes additional forms of identification, such as student, military, passport, and health insurance identification number, as well as other types of information, such as medical information or biometric data. It also includes username or e-email address in combination with a password or security question answers that would permit access to an online account …. Organizations that collect personal identifying information of Colorado residents and that do not yet have the written programs necessary to formalize their data protection practices urgently need to focus on compliance. — Francoise Gilbert, Greenberg Traurig


    Francoise Gilbert, a partner at Greenberg Traurig, is the author of the two volume treatise “Global Privacy and Security Law” (Wolters Kluwer Publishing), covering 68 countries. Her practice has focused on information privacy and security for more than 25 years. She advises clients on the entire spectrum of domestic and international privacy and cyber security issues legal issues, such as Internet of Things, smart cities, artificial intelligence, analytics, digital advertising and other cutting-edge developments that rely on the extensive use of personal data.

    She is one of the featured speakers at the Privacy+Security Forum which takes place Oct. 3-5, 2018, in Washington, DC.