Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
As If Bank Failures Arent Enough  Hackers Are Exploiting the Chaos to Breach Security
Blog May 08, 2023
The Massachusetts State Police Commonwealth Fusion Center (CFC) believes that cyber actors may use the current bank failures for future phishing and business email compromise (BEC) attacks. Cyber actors often use current events to mask their phishing campaigns to seem more believable and relevant.  As everyone now knows, Silicon Valley Bank (SVB) became one of the largest banks to fail since the 2008 financial crisis. More recently, First Republic Bank also failed…
Requiring Robust Security for Financial Institutions, FTC Finalizes Amendments to Safeguards Rules
Blog November 19, 2021
The Federal Trade Commission has finalized amendments to the Standards for Safeguarding Customer Information (“Safeguards Rule”), specific to defined financial institutions, designed to strengthen security for consumer financial information following a recent uptick in data breaches. The amendments contain four main modifications to the existing Rule that outline additional protections financial institutions must implement when handling sensitive consumer data. First, the amendments……
InfoTrax Systems Settles FTC Allegations It Failed to Safeguard Consumer Data
Blog November 30, 2019
InfoTrax Systems, a Utah-based technology company, has agreed to implement a comprehensive data security program to settle Federal Trade Commission allegations that the company failed to put in place reasonable security safeguards, which allowed a hacker to access the personal information of a million consumers.  InfoTrax Systems, L.C., provides back-end operation services to multi-level marketers. This includes such services as compensation, inventory, orders, accounting, training…
Watch: Cybersecurity Regulation and Enforcement
Blog October 11, 2019
As data breaches are seemingly reported on a daily basis, cybersecurity has emerged as a top enforcement priority for federal and state regulators and a key concern for companies of all sizes in a diverse range of industries. For example, compliance with federal cybersecurity regulations is required by nearly every government contract and the New York Division of Financial Services adopted a vast set of regulations that is applicable to all entities operating under NYDFS licensure…
Minimizing Litigation Risk: What Cybersecurity Auditors Can Learn From Their Financial Statement Auditor Analogues
Blog January 15, 2019
Data breaches – always critically important to those with responsibility for storing, transporting and protecting electronic information – have become an all-consuming topic of late. Stories about data theft dominate political headlines, boardroom discussions, and family meetings around the dinner table.  They, of course, have also been the subject of government investigations and private litigation. The current environment is not unlike other moments in our recent past that seemed to have……
Massachusetts Amends Its Data Breach Response Law
Blog January 12, 2019
On January 10, 2019, Massachusetts Governor Charlie Baker signed a new law that amends its data breach reporting law, and requires credit reporting agencies such as Equifax to provide a free credit freeze to consumers.  The new law, An Act Relative to Consumer Protection from Security Breaches, also requires companies to offer up to three years of free credit monitoring to victims of a security breach…
Senator Warner's White Paper Gives Congress Options for Regulating Social Media and Technology Companies
Blog October 09, 2018
Senator Mark Warner of Virginia has released a white paper outlining policy proposals for regulating social media and technology companies. The paper has gained significance in recent weeks as pressure builds on Congress to pass federal data privacy legislation. In the wake of Europe's GDPR and California's Consumer Privacy Act, industry groups, tech companies, and privacy activists alike have urged Congress to act…
Massachusetts Securities Division Files First Complaint Related to Initial Coin Offering
Blog January 19, 2018
On January 17, 2018, the Massachusetts Securities Division Enforcement Section filed a complaint against the company Caviar and its founder Kirill Bensonoff for violations of the Massachusetts Uniform Securities Act in connection with an ongoing initial coin offering (ICO). This is Secretary of the Commonwealth William F. Galvin's first enforcement action related to an ICO. Last month, Secretary Galvin announced that the Massachusetts Securities Division would conduct a sweep of……
Cybersecurity 2018 – The Year in Preview: Financial Institutions and the SEC
Blog December 20, 2017
Editors' Note:  This is the eighth in a multi-part end-of-year series examining important trends in data privacy and cybersecurity during the coming year.  Previous installments include analyses of HIPAA compliance, emerging security threats, federal enforcement trends, state enforcement trends…
1 of 9

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors