Tag: Data Breach
-
Artificial Intelligence: DeepMind on Debugging Learned Predictive Models
DeepMind, an artificial intelligence research company, in a recent blog post discusses three ways to eliminate bugs in learned predictive models. The company was founded in London in 2010. Google acquired it in 2014. In addition to London they have research centers in Edmonton and Montreal, Canada, and a DeepMind Applied team in Mountain View, California.
“Bugs and software have gone hand in hand since the beginning of computer programming,” the post reads. “Over time, software developers have established a set of best practices for testing and debugging before deployment, but these practices are not suited for modern deep learning systems. Today, the prevailing practice in machine learning is to train a system on a training data set, and then test it on another set. While this reveals the average-case performance of models, it is also crucial to ensure robustness, or acceptably high performance even in the worst case. In this article, we describe three approaches for rigorously identifying and eliminating bugs in learned predictive models: adversarial testing, robust learning, and formal verification.”Read the complete post here!
-
Moving Your Corporate Data to the Cloud: Top 13 Things to Think About as you Review Your Hosting Agreement — Judy Selby Consulting
Some data migration risks can be mitigated at the cloud contract stage, Allison Bird, Judy Selby’s partner at Clearview Privacy Consulting LLC, explains.
Regarding indemnification, Bird says, “If data is lost or exposed by the hosting company, your company as well as any affiliates who use the services will be subject to suits from clients and individuals whose data was impacted. You may also be subject to regulatory scrutiny which could result in legal costs and regulatory penalties. To the extent possible, negotiate a full indemnification of third party claims arising out of the hosting services.”She says the limitation of liability section of your hosting agreement “may be the single most important” part. “Your hosting company may make a lot of promises in the agreement. However, if their liability under the agreement is significantly capped, you won’t receive the monetary compensation necessary to make up for hosting company’s acts and omissions that damage the company. Negotiations for a higher cap will translate into real dollars in the event of a security incident.”
Of course, insurance is always a good solution if done right. “You can negotiate the perfect contract but unless your hosting company has a deep pocket, it may not have sufficient capital to make good on contractual obligations in the event of a breach or data loss situation, especially one affecting many of its customers,” Bird says. “Consider adding language into the agreement which requires your hosting company to maintain insurance (with your company as a named insured) covering data breach and inability to access data.”
Read the complete post by Allison Bird on Judy Selby Consulting’s blog.
-
The Cloud: Selected Benefits, Risks, and Insurance Coverage Issues (Part 1) — Barnes & Thornburg
Cloud Risk: Do You Transfer Liability Along with Data?
Many of us were using data clouds before we even knew what they were. Now, while most of us are comfortable with the concept, we may not be comfortable knowing who is liable when data is lost, damaged or breached. It’s not a given that your cloud provider absorbs any liabilities, and it’s not a given they can even afford the liability should it arise. Below are quotes from an article by Scott Godes, Kara Cleary, and Heidi Fessler of Barnes & Thornburg LLP on the subject, and a link to their complete article.
Godes, Cleary, and Fessler list several cloud-related risks: data breaches, data loss, interruption of access, compromised credentials and broken authentication, and denial of service. But two other categories for concern are: #1. BYOC, or Bring Your Own Cloud. Employees may be innocently using productivity applications that store work data on non-company clouds, in effect, “bringing their own clouds” to the workplace.
#2. Multi-Tenancy. This involves risks posed when unrelated cloud users are sharing the same computing resources.
“Both the cloud provider and the user must be aware of system and data security to prevent a breach in the security. In addition, when a risk is realized, it may not always be clear who is at fault for the system or security failure.
“There are a lot of misconceptions around the cloud and liability,” the Barnes & Thornburg attorneys write.
“Many companies assume that along with the transfer of their data, they have also transferred their risk to the cloud provider,” they say. “Absent a clear agreement that shifts liability to the cloud provider, the practical reality is that in most cases, there’s very little protection in terms of liability with cloud providers, unless parties are willing to engage in protracted litigation to determine otherwise. The shifting of liability is not nearly as easy as the transfer of data and often it may be the case that the responsibility for a data breach rests with the party that collected and maintained the data originally. Perhaps the most notable exception has been in the healthcare industry, where companies providing support often are classified as ‘business associates’ under HIPAA and might be subject to the same obligations for protecting data as the entity with the original patient relationship. Even here, one could argue that liability transfer does not occur, but rather a liability expansion that includes the cloud provider.”
Read the complete article, the first in a series, on the Barnes & Thornburg blog.
-
Anderson Kill’s 5th Annual Cyber Insurance Recovery Conference
[one-half-first]
[/one-half-first] [one-half]
Recent news of “Collection 1”, a cache of sensitive data now appearing for sale on the dark web and comprised of an astonishing 773 million records, is a grim reminder of the scope of cyber perils for most. Last year’s staggering tally of serious data breaches and theft coupled with a spate of new legislation for companies gathering, hosting and selling consumer data means policyholders must rise to the challenge. New state legislation compounds an already daunting federal and international regulatory landscape, and regulatory compliance will be a must to deal with the attendant fines, penalties and consumer claims that non-compliance can trigger. New technology also continues to drive the evolving conversation about the legal relationships between parties transacting business electronically. Risks range from anonymity that raises jurisdictional and collection issues to “immutable” record keeping that creates a permanent, public record of transactions. –Anderson Kill [/one-half]Find out more about this complimentary seminar from Anderson Kill here!
-
South Korea, EU Having ‘Adequacy’ Discussions
Because of its robust network connectedness, its advanced use of mobile devices and its rich collection of intellectual property, South Korea is a leading target for hackers.
Discussions are under way between the EU and South Korea to determine, as a non-EU country, whether its data protections are adequate. Also, South Korea has joined the APEC Cross-Border Privacy Rules system. Significant caselaw is developing regarding this country’s 2011 data protection statute as well as its sector-specific laws.
Daniel Solove and Paul Schwartz have selected Professor Haksoo Ko from the Law School at Seoul National University to speak at the International #PrivacySecurity Forum April 3-5, 2019. Ko will co-present to provide an up-to-date account of developments in South Korea and analyze the most important compliance hurdles.
Learn more: http://bit.ly/IPSF-2019
-
Financial Institutions Struggle to Keep Up with ‘Changing Business Needs’ Such as Social Mobile Apps, and Getting Risk Data Quickly, Deloitte Report Suggests
Deloitte’s report is based on a survey of 94 financial institutions around the world that operate in a range of financial sectors and with aggregate assets of $29.1 trillion.
Deloitte’s Edward Hida — financial risk community of practice global leader and a partner in Deloitte Risk and Financial Advisory — posted his executive summary the latest Global Risk Management Survey which is the organization’s eleventh. The report is a detailed one and Deloitte draws quite a few conclusions around the continued focus on cyber security, engagement of boards of directors, increase attention to non-financial risks, the potential of digital risk management, enterprise risk management, the proliferation of Chief Risk Officers, an increased reliance on stress testing and more.
A couple figures jumped out at me which show at least two challenges to financial institutions.
Hear this Deloitte professional at ICRMC in Toronto April 15-16!
Respondents are finding “extremely challenging” the need to keep up with changing business operational needs, such as deployment of social mobile applications, data analytics and cloud-based risks. Also in the “extremely challenging” category, not surprisingly, are threats from “sophisticated actors,” like foreign governments and crackerjack hacktivists.
Other issues categorized as “extremely high priority “revolve around getting quality risk data quickly. Given the average length of time other studies show that a hacker can poke around in your network before you realize it — and how much damage they can do when they have all that time — it’s easy to see why this is a major concern for financial institutions.
You can read the rest of his executive summary here. You can also download the full report as well as all of Deloitte’s past editions.
Two of Edward Hida’s Deloitte colleagues — Beth Dewitt and Adel Melek — are speaking at the International Cyber Risk Management Conference April 15-16, 2019, in Toronto. They are addressing the global regulatory landscape.
Here is the session description:
“Large-scale data breaches are increasingly in the public eye; consumer trust in brands is faltering, creating a surge in data and privacy protection discussions from the Boardroom to the front lines. While the European Union’s General Data Protection Regulation (GDPR) has occupied much of the spotlight since coming into effect in May, globally there has been a barrage of privacy laws like the California Consumer Privacy Act that was passed in June and the breach-reporting amendments to PIPEDA came into force on November 1st. What do these and the plethora of other privacy regulations mean for your organization when it comes to protecting an individual’s personal data?”
-
Mitigating Operational Cyber Risk: As Business Technology Changes, So Does Your Risk Profile
By Tom Hagy
The various risks of doing business in our digitally connected world continue to evolve. So must the approach organizations take in confronting those risks, for failing to do so in the current risk landscape can be far more dangerous than in prior years.
I spoke with Nick Galletto, Global Cyber Risk Leader at Deloitte, who traced the evolution of the dangers of doing business in a digitally connected world. Early on, our focus in the cyber risk management space was on how to protect websites from being defaced, he explained. Organizations had to make sure websites were functioning properly, that data was secure, and the integrity was maintained.
Galletto went on to say that we’ve moved from an era of compliance and risk management to an era of complexity. From an organization’s perspective, their focus was on making sure the company was compliant with new and evolving regulations, and risk management meant having policies, procedures and effective controls in place.“While compliance is a necessity, it is not the silver bullet that’s going to protect us from any potential breaches,” Galletto said. “So organizations must look at conducting their business in this connected world not merely from a compliance perspective but from a risk perspective. A clear example of this is the number of PCI-compliant companies that were still getting breached.”
“Now as organizations move into an era of complexity, they need to be proactive in detecting anomalies and suspicious behavior and be prepared so their teams have a playbook that allows for seamless response. Effective organizations will play back possible breach scenarios – whether they involved data breaches or denial of service — to prevent and prepare for similar attacks. They also focus on understanding what their crown jewels are and where they reside and how to best protect them. Much of this also has to do with data,” Galletto said.
“Organizations are increasingly reliant on the cloud and they must understand the associated risks and the individuals responsible for managing those risks,” he said. “They need to be sure they have the right coverage as well.”
“This era of complexity – automation, machine learning, artificial intelligence and the internet of things, along with the tremendous advantages, like the cloud – also bring new risks,” Galletto continued. “As consumers we see use of these technologies more and more in our daily lives. But organizations are increasingly integrating them into their operations. When something goes wrong here there can be actual safety implications, such as with autonomous vehicles or industrial controls in the mining and manufacturing sectors, as examples. In the financial sector these technologies bring great advantages to customers in terms of accessing their information more efficiently or providing better customer support. But as machine learning and AI become more prevalent in the world of FinTech, decisions are being made without human cognitive capabilities to know right from wrong. These new technologies bring more complexity.”
“As organizations take advantage of these innovative new technologies, they also have to know that their risk profile is changing right along with them. Smart companies will be proactive in understanding the risks associated with cyber everywhere, understanding where their cyber posture is and make adjustments along the way to better manage complexity.”
Galletto is one of the speakers at this week’s International Cyber Risk Management Conference in Bermuda, which just kicked off this afternoon with more than 200 professionals in this center of global cyber risk.
-
Aon SVP Belfiore on Corporate Cyber Risk
Cyber Risk of Paramount Concern to Corporate Boards
Lack of History Remains a Challenge
“Cyber security is the most polarizing issue on the corporate board agenda these days,” says Anthony Belfiore, SVP and Chief Information Security Officer at Aon. “It has the most potential impact and the most regulatory pressure among all risks companies face. Nothing is more top of mind right now.”
“You just have to look at the amount of media coverage and the actual realized impacts companies are experiencing. Hundreds of thousands of businesses from big to small are being affected. The entire healthcare system in the UK went down. The impact is tangible. It’s affecting day-to-day operations,” he says. “And no one is immune. Board members come from a diverse set of industries, and all are impacted.”Why is cyber risk such a hot button for companies versus other types of risks?
“The risk has become more urgent as it has shifted to actual business interruption,” Belfiore says. “Historically companies were concerned with data leakage and loss, or regulatory fines, but now the actual operation itself can come to a halt. When a company goes down for three days that hits the media. Analysts notice. You can trace a specific event to a drop in stock values.”
Aren’t fines still a concern?
“Yes. We are operating in a regulatory environment which can have a significant downside,” Belfiore says. “This is especially true if you are a multi-national firm with considerable operating and capital expenses. You can sustain significant and unforeseen punitive fines which can be imposed anywhere around the globe, for example, if you’re found non-compliant with GDPR.”
What about directors themselves?
“Potential for board liability for failing to protect shareholders is a hot-button issue right now. D&O liability and coverage is evolving,” says Belfiore. “There is uncertainty as to who is protected.”
The digitization of so many aspects of conducting business has been around for a while now. So why does cyber risk continue to present challenges for the insurance industry?
“Historical data is a challenge for insurers because there is very little relative to other risks like those posed by fire or storms for which we have decades of statistics. This makes it difficult to qualify and quantify the risk. Models are used to gauge the potential for losses but, still,” he says, “there isn’t a lot of history to go on.”
Aren’t companies and boards okay as long as they have insurance?
“Organizations who think they are covered may come to a different conclusion when they read the fine print. That’s why it’s imperative to work with an experienced broker to navigate the various coverages and nuances in policy language,” Belfiore says.
At a high-level, what should security leaders at companies do to reduce risk and anxiety around potential cyber losses?
Belfiore urges companies to “set up effective governance and establish an effective governance committee. Examine how you run your operation day-to-day, consider how to best manage the expectations of the C-suite and the board. Get the most out of governance committee discussions, ensure you have alignment up and down the stack, and make sure you have installed effective risk management and risk protocols.”
Belfiore is on “The CISO Perspective” panel at the International Cyber Risk Management Conference (ICRMC) on Dec. 6-7, 2018 in Bermuda, along with Tim Dawson, Cybersecurity Chief Technology Officer at HSBC; Tom Pageler, Chief Security Officer at BitGo, Inc.; and Derek Vadala, Chief Information Security Officer at Moody’s Corporation.
You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda.

This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.
-
Cyber Risks Enter a New and Increasingly Vicious Phase
For anyone plotting the evolution of cyber risks, the last phase of cyber-attacks was dominated by breaches that resulted in lost or stolen personal or financial data that could then be monetized.
The current phase is different.
“We have observed a significant increase in the number of disruptive breaches that our clients are dealing with,” says Charles Carmakal, Vice President at Mandiant/FireEye. “These involve destruction, extortion, or public shaming.”
How are organizations dealing with this shift?

“It’s catching many organizations off guard. Most don’t have a playbook for dealing with extortion,” Carmakal says. “While they may have thought about a ransomware situation, that’s different from the more common type of extortion we are seeing these days, where a threat actor threatens C-level executives or corporate board members with the release of sensitive information.”
“Many organizations assume the default is they wouldn’t give into the demands, but when in the middle of a crisis too often the decision is made to pay the threat actors,” he says.
“So it’s important to consider what your organization will do in this situation. For example, who will be involved in the decision-making process? Organizations should play out an extortion scenario so they have a plan when faced with real demands.”
How can organizations better test the efficacy of their security capabilities?
Many organizations conduct penetration testing or red-teaming exercises, but they often undermine their own efforts.
“A problem arises when an organization contracts a third-party to test their capabilities, but puts a lot of restrictions on those who are doing the testing,” Carmakal says. “For example, they will tell the testing team or red team to identify vulnerabilities, but not to exploit them, or they can exploit a vulnerability but stop there and not dig any further. The penetration testers might be allowed to test only during a certain day of the week or certain time of day. Or they might be allowed to sample only a fraction of the organization’s IP addresses and ignore everything else.”
“What happens is the penetration testers are not permitted access to the crown jewels,” Carmakal warns. “They can’t demonstrate business impact to the organization. This creates a false sense of security because the organization can say they had a team of qualified people try and fail to break into the network, but in reality they were unable to break through because of all the unrealistic restrictions imposed on that team.”
This false sense of security travels to the top. “Testing results are shared with the board and the board believes that because a really good third-party was not able to get to the crown jewels that they have a much safer environment than they really do. That’s a very common theme we see across the industry,” Carmakal says.
How do penetration testers deal with unrealistic testing parameters?
“It’s part of the education process,” he says. “When a company wants us to do a very limited test, and we believe our reports will be shared with the leadership team or the board, then we just won’t take the engagement. We try to make it clear that this is not an exercise to make anyone look bad, but a way to leverage the lessons from all the bad guys who are breaking into organizations so you can strengthen your security.”In the end, he says, “It’s better we identify the vulnerabilities than have the bad guys do it.”
What the geopolitical trends you are seeing?
Iran – “They used to be unorganized. They even clumsily posted social media profiles of themselves,” Carmakal says. “But they have become much more organized, more structured, more technologically adept, and have affiliated with government entities.”
“In 2017 we saw more intrusions from Iran than we had ever seen before. There was a noticeable spike in offensive intrusions coming from them. For some reason, in 2018 we really haven’t seen Iran targeting organizations in the United States. They’ve scaled back significantly in the US, but are still active in other parts of the world.”
“What makes security professionals nervous about Iran,” Carmakal says, “is that they are a wildcard. You don’t know what they are going to do. You don’t understand the rationale behind their activity. But what we do see is a capability and a willingness to be incredibly destructive – taking down businesses and publicly shaming organizations. The fact that they’ve slowed down their attacks on U.S. organizations is interesting, but we expect that to change.”
Russia – “Russia is not hacking the U.S. midterm elections like they were with the presidential election in 2016, but they are conducting some significant offensive operations around the world. They are very capable. They are also very good at disinformation and throwing false flags, so when you investigate them it’s difficult to tell who they really are. Russia is one of the few countries that demonstrates the willingness and capabilities to cause kinetic consequences through cyber-attacks, such as when they turned off the lights in Ukraine.”
In March 2018 The New York Times wrote, “The Trump administration accused Russia … of engineering a series of cyber-attacks that targeted American and European nuclear power plants and water and electric systems, and could have sabotaged or shut power plants off at will.”
When asked about this and the reporting that surrounded it, Carmakal said the story was a bit “sensationalized” and not 100% accurate. “While the intrusion was serious, we didn’t see the Russian actors getting anywhere near being able to shut off the lights,” he said, adding that they “certainly have the capability” in other parts of the world.
China – There has been a “notable decrease” in cyber intrusions from China since the 2015 bi-lateral cyber agreement was reached between President Obama and China’s President Xi, Carmakal says. While narrow in scope, addressing economic espionage — China’s state-sponsored theft of private U.S. intellectual property and then turning it over to state-owned and private companies in China — the agreement does appear have helped, reports suggest. “They are still hacking organizations and are following a defined playbook. We’re keeping a close eye on them to see how their offensive operations evolve,” Carmakal says.
North Korea – Except for the highly publicized attack against a major U.S.-based entertainment company, “North Korea rarely goes after Western organizations.” Given the country’s need for cash, “their focus has been more on robbing digital currency exchanges and stealing from banks digitally,” Carmakal says, adding that they, like Iran, are a bit of a “wild card.” North Korea actors have stolen more than $100 million from victims, Carmakal says.
You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda when Carmakal and his fellow panelists discuss important trends in global cyber risks.

This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.


