Skip to main content

Is your Board addressing these two issues?

Is your Board addressing these two issues?

We’ve been talking about how your Board and shareholders have a vested interest in understanding and overseeing how yourcompany will defend itself against the effects of cybercrime. Here are two more areas where you will need to have plansand your board should be focussed on how they will be handled

Data Loss

Unless their goal is pure mischief, most cyber thieves are seeking data that can be monetized in some fashion. Customerdata is a rich trove of data, providing thieves with the information to steal identities or hack bank accounts andcredit cards. Only, they don’t just want your customers' data. Your business has its own proprietary and financialinformation. You have company credit cards and bank accounts.

Legal

Should you suffer a significant loss of customer data, you may be subject to legal regulations. At the very least, youare likely required to notify the victims and the state or legal entity that regulates data loss in your jurisdiction orindustry sector. For example, HIPAA has reporting requirements. Beyond reporting requirements, there may be financialpenalties that can be imposed for significant data loss, especially if it could have been avoided via more strictinternal controls. Again, HIPAA is an excellent example. California now has data regulations and the European Unionimposes severe penalties for data loss that impacts any resident of the EU, even if the violator is not located withinits geographic boundaries.

Your entire c-suite should be focussed on these issues and working with the Board to get the support and investment toprotect the organization.

Comments

Popular posts from this blog

Ransomware vs other malware attacks

Ransomware vs. other malware attacks There is no end to the volume and type of malware out there in cyberspace. For a very long time, organizations were aware that viruses could attack their data, render it corrupted and unusable. They were also aware that malware was used to steal data and use it for–primarily–monetary gain. Sell off banks of credit card numbers, steal identities, re-sell Social Security numbers, etc. Phishing, as we talked about in an earlier blog, is a set of tricks to get access to personal information and probably even to your IT network by stealing access credentials, but that’s not the only way. Cybercriminals also deploy various malware such as viruses, worms and trojan horses to attack IT networks. These malware usually gain entry into the system disguised as genuine email attachments, links to file downloads, etc. and then corrupt the data. If it is a case of a virus whose sole intent is criminal mischief, your surest protection are consistent and frequen...

Everyone wants to go phishing

Everyone wants to go phishing. You are very much aware that your company or organization is at risk, every minute of the day, from cyberattacks, malware, ransomware, and even benign errors that can put your data at risk. Even a failed backup procedure could mean a loss of critical company and customer data. In today’s blog we’re just going to review one of the most common methods that bad actors use to try to gain access to your data. Phishing. Phishing isn’t a particular type of malware or virus that attacks your data. Instead, it refers to the tools cyber criminals use to get access to your data. Phishing refers generally to the bag of tricks they use to break into your house. In phishing attacks, cybercriminals generally send a web link that is disguised to look genuine, and prompt the receiver to share information that will then be misused. For example, an email may be sent to you that looks as though it came from your bank or the IRS announcing a tax refund that your business ...

Your business runs on data, but so do the cyber criminals

Your business runs on data, but so do the cyber criminals who want to steal yours One very painful truth about running a business is that you possess data that is attractive to criminals. There is no avoiding that reality. You have data. They want data. It is an ongoing challenge to maintain data security as cyber criminals' efforts evolve and change on a daily basis. The wall that kept you safe last week may have holes in them today. Keeping up with the latest threats is a specialized field that in-house IT support likely doesn't have. An MSP can provide the support you need in the face of ransomware threats and other malware. Also, an MSP can provide 24/7 monitoring. Speaking of data security, brand damage isn't the only issue with data security breaches. In many cases, there are data protection laws that regulate how you secure personal information. In specific industries there are federal, state, and even overseas regulations that set standards for data protectio...