Tag: Data Privacy
-
National Geographic Disclosed Customer Info, Class Action Says — Top Class Actions Blog
[one-half-first]
[/one-half-first] [one-half]“The National Geographic class action states that prior to and at the time that he subscribed to the magazine, the company did not notify him that it discloses the personal reading information of its customers.
“Markham also claims that he wasn’t provided with any written notice that National Geographic makes a practice of renting, exchanging, or otherwise disclosing personal reading information to third parties, and provides no means of opting out.
“However, the National Geographic information disclosure class action lawsuit says that since subscribing to National Geographic and between Mach 26, 2016 andJuly 30, 2016, National Geographic disclosed Markham’s personal reading information to data aggregators, data appenders, and/or data cooperatives.”
Read the complete post by Top Class Actions Editor Emily Sortor here.
[/one-half]
-
Million-Dollar Settlement in Employee Background Check Case, Top Class Actions Reports
“Job applicants have secured a $1.2 million settlement ending allegations that Maxim Healthcare did not properly inform potential employees that they would have a consumer report pulled as part of the application process. Class Members include those who applied and got a job with the healthcare services company between May 5, 2009 and Aug. 27, 2012, who were also subject to a consumer report check by Maxim. The Maxim Healthcare class action lawsuit claimed that Maxim violated federal consumer privacy protections when procuring employee background checks.”

-
South Korea, EU Having ‘Adequacy’ Discussions
Because of its robust network connectedness, its advanced use of mobile devices and its rich collection of intellectual property, South Korea is a leading target for hackers.
Discussions are under way between the EU and South Korea to determine, as a non-EU country, whether its data protections are adequate. Also, South Korea has joined the APEC Cross-Border Privacy Rules system. Significant caselaw is developing regarding this country’s 2011 data protection statute as well as its sector-specific laws.
Daniel Solove and Paul Schwartz have selected Professor Haksoo Ko from the Law School at Seoul National University to speak at the International #PrivacySecurity Forum April 3-5, 2019. Ko will co-present to provide an up-to-date account of developments in South Korea and analyze the most important compliance hurdles.
Learn more: http://bit.ly/IPSF-2019
-
Financial Institutions Struggle to Keep Up with ‘Changing Business Needs’ Such as Social Mobile Apps, and Getting Risk Data Quickly, Deloitte Report Suggests
Deloitte’s report is based on a survey of 94 financial institutions around the world that operate in a range of financial sectors and with aggregate assets of $29.1 trillion.
Deloitte’s Edward Hida — financial risk community of practice global leader and a partner in Deloitte Risk and Financial Advisory — posted his executive summary the latest Global Risk Management Survey which is the organization’s eleventh. The report is a detailed one and Deloitte draws quite a few conclusions around the continued focus on cyber security, engagement of boards of directors, increase attention to non-financial risks, the potential of digital risk management, enterprise risk management, the proliferation of Chief Risk Officers, an increased reliance on stress testing and more.
A couple figures jumped out at me which show at least two challenges to financial institutions.
Hear this Deloitte professional at ICRMC in Toronto April 15-16!
Respondents are finding “extremely challenging” the need to keep up with changing business operational needs, such as deployment of social mobile applications, data analytics and cloud-based risks. Also in the “extremely challenging” category, not surprisingly, are threats from “sophisticated actors,” like foreign governments and crackerjack hacktivists.
Other issues categorized as “extremely high priority “revolve around getting quality risk data quickly. Given the average length of time other studies show that a hacker can poke around in your network before you realize it — and how much damage they can do when they have all that time — it’s easy to see why this is a major concern for financial institutions.
You can read the rest of his executive summary here. You can also download the full report as well as all of Deloitte’s past editions.
Two of Edward Hida’s Deloitte colleagues — Beth Dewitt and Adel Melek — are speaking at the International Cyber Risk Management Conference April 15-16, 2019, in Toronto. They are addressing the global regulatory landscape.
Here is the session description:
“Large-scale data breaches are increasingly in the public eye; consumer trust in brands is faltering, creating a surge in data and privacy protection discussions from the Boardroom to the front lines. While the European Union’s General Data Protection Regulation (GDPR) has occupied much of the spotlight since coming into effect in May, globally there has been a barrage of privacy laws like the California Consumer Privacy Act that was passed in June and the breach-reporting amendments to PIPEDA came into force on November 1st. What do these and the plethora of other privacy regulations mean for your organization when it comes to protecting an individual’s personal data?”
-
Mitigating Operational Cyber Risk: As Business Technology Changes, So Does Your Risk Profile
By Tom Hagy
The various risks of doing business in our digitally connected world continue to evolve. So must the approach organizations take in confronting those risks, for failing to do so in the current risk landscape can be far more dangerous than in prior years.
I spoke with Nick Galletto, Global Cyber Risk Leader at Deloitte, who traced the evolution of the dangers of doing business in a digitally connected world. Early on, our focus in the cyber risk management space was on how to protect websites from being defaced, he explained. Organizations had to make sure websites were functioning properly, that data was secure, and the integrity was maintained.
Galletto went on to say that we’ve moved from an era of compliance and risk management to an era of complexity. From an organization’s perspective, their focus was on making sure the company was compliant with new and evolving regulations, and risk management meant having policies, procedures and effective controls in place.“While compliance is a necessity, it is not the silver bullet that’s going to protect us from any potential breaches,” Galletto said. “So organizations must look at conducting their business in this connected world not merely from a compliance perspective but from a risk perspective. A clear example of this is the number of PCI-compliant companies that were still getting breached.”
“Now as organizations move into an era of complexity, they need to be proactive in detecting anomalies and suspicious behavior and be prepared so their teams have a playbook that allows for seamless response. Effective organizations will play back possible breach scenarios – whether they involved data breaches or denial of service — to prevent and prepare for similar attacks. They also focus on understanding what their crown jewels are and where they reside and how to best protect them. Much of this also has to do with data,” Galletto said.
“Organizations are increasingly reliant on the cloud and they must understand the associated risks and the individuals responsible for managing those risks,” he said. “They need to be sure they have the right coverage as well.”
“This era of complexity – automation, machine learning, artificial intelligence and the internet of things, along with the tremendous advantages, like the cloud – also bring new risks,” Galletto continued. “As consumers we see use of these technologies more and more in our daily lives. But organizations are increasingly integrating them into their operations. When something goes wrong here there can be actual safety implications, such as with autonomous vehicles or industrial controls in the mining and manufacturing sectors, as examples. In the financial sector these technologies bring great advantages to customers in terms of accessing their information more efficiently or providing better customer support. But as machine learning and AI become more prevalent in the world of FinTech, decisions are being made without human cognitive capabilities to know right from wrong. These new technologies bring more complexity.”
“As organizations take advantage of these innovative new technologies, they also have to know that their risk profile is changing right along with them. Smart companies will be proactive in understanding the risks associated with cyber everywhere, understanding where their cyber posture is and make adjustments along the way to better manage complexity.”
Galletto is one of the speakers at this week’s International Cyber Risk Management Conference in Bermuda, which just kicked off this afternoon with more than 200 professionals in this center of global cyber risk.
-
Aon SVP Belfiore on Corporate Cyber Risk
Cyber Risk of Paramount Concern to Corporate Boards
Lack of History Remains a Challenge
“Cyber security is the most polarizing issue on the corporate board agenda these days,” says Anthony Belfiore, SVP and Chief Information Security Officer at Aon. “It has the most potential impact and the most regulatory pressure among all risks companies face. Nothing is more top of mind right now.”
“You just have to look at the amount of media coverage and the actual realized impacts companies are experiencing. Hundreds of thousands of businesses from big to small are being affected. The entire healthcare system in the UK went down. The impact is tangible. It’s affecting day-to-day operations,” he says. “And no one is immune. Board members come from a diverse set of industries, and all are impacted.”Why is cyber risk such a hot button for companies versus other types of risks?
“The risk has become more urgent as it has shifted to actual business interruption,” Belfiore says. “Historically companies were concerned with data leakage and loss, or regulatory fines, but now the actual operation itself can come to a halt. When a company goes down for three days that hits the media. Analysts notice. You can trace a specific event to a drop in stock values.”
Aren’t fines still a concern?
“Yes. We are operating in a regulatory environment which can have a significant downside,” Belfiore says. “This is especially true if you are a multi-national firm with considerable operating and capital expenses. You can sustain significant and unforeseen punitive fines which can be imposed anywhere around the globe, for example, if you’re found non-compliant with GDPR.”
What about directors themselves?
“Potential for board liability for failing to protect shareholders is a hot-button issue right now. D&O liability and coverage is evolving,” says Belfiore. “There is uncertainty as to who is protected.”
The digitization of so many aspects of conducting business has been around for a while now. So why does cyber risk continue to present challenges for the insurance industry?
“Historical data is a challenge for insurers because there is very little relative to other risks like those posed by fire or storms for which we have decades of statistics. This makes it difficult to qualify and quantify the risk. Models are used to gauge the potential for losses but, still,” he says, “there isn’t a lot of history to go on.”
Aren’t companies and boards okay as long as they have insurance?
“Organizations who think they are covered may come to a different conclusion when they read the fine print. That’s why it’s imperative to work with an experienced broker to navigate the various coverages and nuances in policy language,” Belfiore says.
At a high-level, what should security leaders at companies do to reduce risk and anxiety around potential cyber losses?
Belfiore urges companies to “set up effective governance and establish an effective governance committee. Examine how you run your operation day-to-day, consider how to best manage the expectations of the C-suite and the board. Get the most out of governance committee discussions, ensure you have alignment up and down the stack, and make sure you have installed effective risk management and risk protocols.”
Belfiore is on “The CISO Perspective” panel at the International Cyber Risk Management Conference (ICRMC) on Dec. 6-7, 2018 in Bermuda, along with Tim Dawson, Cybersecurity Chief Technology Officer at HSBC; Tom Pageler, Chief Security Officer at BitGo, Inc.; and Derek Vadala, Chief Information Security Officer at Moody’s Corporation.
You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda.

This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.
-
Protecting Intangible Assets: Risk Transfer Market Yet to Catch Up
Intrinsically Intangible.
by Giles Harlow, Senior Vice President, Aon (Bermuda) Ltd.
In the early 1980’s, tangible assets made up around 80% of the value of the S&P 500. Fast forward to today and nearly 85% of the value of the S&P 500 is attributable to intangible assets.However, the risk transfer market has not caught up. According to the Aon/Ponemon report of last year, whilst around 60% of tangible assets (property, plant and equipment) are currently being insured, only 12% of informational assets are.
So what gives?
If the vast majority of companies’ values in 2018 are attributable to intangibles, why are they not transferring those risks? Is it a lack of education on the client side? A lack of innovation in the brokerage community? A lack of understanding or willingness to accept these new risks on the carrier end? Or is it that whilst the marine and property markets have had centuries to evolve, the newer intangible insurance markets are just gearing up to size as they collate the data they need to properly price and model these risks?
Likely, it is some combination of all of these factors. We have seen great strides in the cyber market, with double-digit premium growth over the last four-to-five years. The market has evolved from being focused on large data holders, to providing products which contemplate the cyber perils affecting manufacturers, the transportation industry and other non-data holders. “Business interruption” has quickly morphed into “system failure coverage.” “Contingent business interruption” now looks more akin to full supply chain risk, not just for IT service providers but now contemplating all vendors. “Bodily injury” and “property damage” stemming from non-physical threats complete the circle back into tangible loss being covered under cyber policies.
Intellectual property — hands down — makes up the largest dollar percentage of the intangible asset value of the S&P 500. This has long been a conundrum for the industry as a whole – both in terms of how to value the asset and, more so, how to value the loss. Again, we have seen great momentum here with much larger limits than were historically available now obtainable from the markets both as a theft product as well as being offered for IP infringement. Even now carriers are contemplating supporting the multi-trillion dollar asset class of intellectual property when used as collateral. This could dramatically impact both the equity financing model and asset backed lending world we know today.
Clearly the will to innovate is alive and well within the industry. It is tough to price emerging risk when the models that our industry are built on rely on historical data, data that is often out of date or irrelevant in these rapidly evolving intangible classes of business. New ways to price and structure these insurance purchases have to be found in order to maintain the industry’s relevance in today’s world.
Bermuda is at the forefront of many of these initiatives and its underwriters and brokers are constantly seeking to raise the bar to address evolving client need. The panel titled “Evolution of Product and Buyer” will be tackling these and more topics in detail at the Dec. 6-7, 2018, International Cyber Risk Management Conference, or ICRMC, in Bermuda from the perspective of brokers, underwriters and insurance purchasers.
Get 10% off the registration fee with promotion code HB2018.
http://www.aon.com/risk-services/cyber.jsp
http://www.aon.com/risk-services/amats/intellectual-property-solutions.jsp
-
Financial Services Cyber Risk Information Sharing
Why We Need to be More Like Apes, Less Like Seagulls
By Tom Hagy
Featuring Craigg Ballance, Director of Canadian Member Services, FS-ISAC
Even before we can walk we are encouraged to share. We’re told to share our things even when we barely have any. Even some wild animals share food and resources – even when those resources are scarce. Some creatures are better at it than others, of course. Apes and lions? Absolutely. Seagulls? All you have to do next time you’re on the beach is toss what’s left of your ham sandwich into the air and see how generous gulls are.
People fall into sharing — and not-fond-of-sharing — groups, too. Sharing is particularly critical in the financial sector where, while privacy and security regulations command a tight lid on data, global financial institutions are successfully sharing data about cyber risk, says Craigg Ballance, Director of Canadian Member Services for FS-ISAC in Toronto. But, he says, sharing has to take place across a broad landscape.
“Information analysis sharing has to cut across the various subsets of the financial sector,” says Ballance. “While banks share local data, they are trying more and more to share globally, but,” he says, “banks need to share with other institutions, like insurers, investment funds, pension funds, and other types of financial institutions, for this cooperation to have the greatest and most effective impact on security.”
While some IT professionals may tend to want to play things close to the vest, when it comes to cybersecurity teams it is the IT professional who works openly with others who is an invaluable player.
The Danger of Over-Confidence
Some blamed over-confident IT professionals for the massive cyber attack that temporarily crippled shipping giant Maersk in June 2017. At the same time, as reported by Reuters on June 27, 2017, Ukrainian commercial banks also sustained a cyber attacks.
“There are a lot of smart people out there actively trying to figure out ways to mess us up,” Ballance says, whether it’s through new denial of service attacks, or cyberware and ransomware, or the creatively diabolical phishing attacks. “When one entity is falls prey to one of these schemes we’re suddenly all at greater risk,” Ballance says. “There is a limited volume of resources and talent to combat cyber-attacks, so pooling resources, information and skill sets is critical.”
Ballance emphasizes the importance of having a playbook so when a crisis occurs people know who is supposed to do what and when. “In the midst of an attack people tend to lose their minds and not necessarily act logically,” he says. “So having a prepared methodology to get your organization out of a pickle is a piece of work we strongly advocate, as well as sharing that methodology across industries. This way, as examples, banks and insurance companies and investors can enrich each other with new insights and skills.”
He also advocates simulated attacks and table-top exercises so people can engage as if they are dealing with a real disaster, like those conducted by FS-ISAC. Conducting post-event analysis to improve response and sharing those findings is also important.
Experience tells us that when it comes to global cybersecurity we need to be more like gorillas and big cats than selfish seagulls down by the sea shore.
Craigg Ballance will share insights like these and more at the International Cyber Risk Management Conference Dec. 6-7, 2018 in Bermuda. He will be joined by Nick Galletto, Global Cyber Risk Services Leader at Deloitte in a session titled, “Strength Through Information Sharing Within the Global Financial Services Arena.”Over the past three-plus decades, Ballance has led and managed advanced technology-enabled business initiatives across a wide range of competitive sectors, countries and areas of innovation. These build on his experience in leading electronic commerce development in one of the world’s path-setting banks in the field and on his extensive work in finance, logistics, international business and government. He is the author/co-author of three books on leveraging technology for business innovation.
Tom Hagy is a Philadelphia-based writer and entrepreneur, Founder and Managing Director of HB Litigation Conferences LLC and Custom Legal Content LLC, former Editor and Publisher of Mealey’s Litigation Reports, and a former Vice President at LexisNexis®.






