Showing posts with label cyber negligence. Show all posts
Showing posts with label cyber negligence. Show all posts

Thursday, 6 October 2016

Yahoo: Directors liability for cyber breach : IP protection in the Digital Age

With only 20 months until the implementation of the GDPR large organisations such as Barclays have already put big teams and resources in place to meet the new requirements. With breach fines up to 4% of turnover and the requirements to maintain a personal data inventory and report breaches within 72 hours this will be a big challenge for the SME and Mid Size community. The requirements of explicit consent for processing sensitive personal data (likely to include video and voice) and a linked right to be forgotten will require significant resource commitment and expertise.

TalkTalk were fined a record £400,000 yesterday by the ICO for a very poor level of cyber security which is close to the maximum under current UK legislation. This is a wake up call for businesses handling personal data in the UK as fines will be much higher under the new regime. Dido Harding may be regretting that she did not obtain an independent view of her cyber safety levels and allowed her IT team to mark their own homework.

The Yahoo hack has made the news but most of the focus has been around its scale in terms of numbers of email addresses. The class action suit available HERE  alleges under Count V Negligence. The specific wording is "Defendant owed a duty to Plaintiffs and the other class members to exercise reasonable care in safeguarding and protecting their PI and financial information in its possession from being compromised, lost, stolen, misused, and/or disclosed to unauthorised parties".

Further in the suit it is suggested that that the identity thieves may wait for years to use the information gained and that therefore class members will need to be vigilant for years or decades to come.

The combination of negligence and the potential for decades of required monitoring points to a potentially huge damages number. This could be the end of the road for Yahoo and open the way for personal negligence claims against Directors in this area.


Taken together the regulatory regime in terms of personal data is significantly tightening up and the associated risk level is beginning to become clear. 

Thursday, 18 August 2016

Stormy weather for healthcare providers (and others) not protecting personal data - $5.55 million fine

The recent fine of $5.55 million dollars levied on Advocate Health Care Networks (AHCN) starts to sketch out liability levels for failing to protect sensitive personal information. This will be of great interest to insurance companies looking to calculate risk premiums and to IT providers looking to limit liability.

AHCN is the largest health care provider in the Chicago area and between July and November 2013 they suffered 3 data breaches. 4 million records went missing but there has been no indication that these records have been used or published. So no loss to date for the victims.

2 of the 3 breaches were straighforward theft of hardware (4 desktops / 1 laptop) rather than the more exotic type of cyber attack.

The areas of failure were identified as follows;

failure to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to all of its ePHI;

failure to implement policies and procedures and facility access controls to limit physical access to the electronic information systems housed within a large data support center;

failure to obtain satisfactory assurances in the form of a written business associate contract that its business associate would appropriately safeguard all ePHI in its possession; and

failure to reasonably safeguard an unencrypted laptop when left in an unlocked vehicle overnight.

No doubt AHCN will have attempted to present itself as the victim of crime, which it was, but was fined nevertheless even though the data does not appear to have been misused.

How many handlers of personal data would currently pass the tests above ?

Tuesday, 16 August 2016

Sage hacked : insider threat and third party liability

Recent news that Sage (the accounting software provider) has been hacked and that staff details of around 300 UK businesses have been accessed (names, addresses, bank details etc) should alarm many SME's who rely on third party technology providers without question.

According to reports internal login details were used so this was less of a high tech hack and more of a walking in through an unlocked door - a disgruntled insider probably.

The Information Commissioners Office are having a look at this and this breach is potentially more serious than TalkTalk as the type of data access looks to be more valuable and personal. But when the fire has been put out who will pick up the tab and compensate the individuals whose data has been taken ?

Sage will no doubt be going through the terms and conditions of standard contracts to determine if they can wriggle out of any liability to their impacted customers. In any event what direct loss does a customer suffer if name, address, bank details etc are published on the open internet ? If a customer is later the victim of internet fraud will it be possible to create a causal link between the breach and the loss ?

Might Sage be insured for cyber breach ? If so does this cover insider threat which might well be viewed as negligent ? Will the insurance extend to pay customers of Sage compensation ?

Given the above complexity it is understandable that Sage should seek to keep as low a profile as possible on this matter but if you are using a Sage solution right now how secure do you feel ?

Anybody can be hacked but the question of who picks up the tab when it happens is far from settled.