Cybersecurity & Tech
The U.S. Cybersecurity Solarium Commission is taking inspiration from the 1950s era commission that studying nuclear strategy.
The 14 member Cybersecurity Solarium Commission will be comprised of:
Strategies to develop:
AXIOS | New cybersecurity task force draws inspiration from ’50s
Tech Target | Women in cybersecurity work to grow voice in US lawmaking
What additional information is protected:
Can notice be given to a consumer electronically? Yes, unless it was the account that was breached
The bill: A-3245 (2019 | NJ)
National Law Review | New Jersey’s Data Breach Notification Amendment Signed into Law
Inside NJ | Caputo & Murphy Bill Requiring Disclosure of Online Security Breaches Signed into Law
The legislation: HB 904 (2019 | NC)
How does it impact businesses: Creates a duty on businesses to maintain reasonable security procedures and practices
Notification time frame: 15 days
Free credit freezes, thaws and monitoring? yes, yes and yes
Consent: Requires consent to access a consumers credit report
Where: San Francisco
What else does the ban on facial recognition tech by municipal entities and local law enforcement do ?
What are supporters saying?
2 More cities set to consider the ban:
Governing | San Francisco the First U.S. City to Ban Facial Recognition Technology
KQED | San Francisco Bans Police, Municipal Use of Facial Recognition Technology
What do they say to legislators? Trust US
What do they say to consumers? We won’t misues your data, AKA trust us
What are they saying to investors? There won’t be any regulations, trust us, returns will be great still
Bonjour to Kentucky Secretary of State Candidate Stephen Knipper. It’s an elected office in Kentucky.
The Knipper wants to improve data security and clean voter rolls of persons not eligible to vote.
Courier Journal | Stephen Knipper: As secretary of state, I would clean up voter rolls
Where is this proposal progressing? California
What is the proposed fee/tax? Data Dividend to be paid by businesses that hold.sell,track, sell data
The messaging: “We trade it away for so much of our experience on the internet. Money from a data tax could begin to counter this trade imbalance.”
Wired | TECH LOBBYISTS PUSH TO DEFANG CALIFORNIA’S LANDMARK PRIVACY LAW
Texas HB 2689 (2019 | TX) would set a standard that all public schools should have a liaison that can communicate data security/cyber security issues with their local communities.
State : New York
Legislation: AB 6787 (2019 | NY)
What does this bill do?
Lockport Union Sun Journal | Bill calls for study of facial recognition systems in schools
What type of healthcare data breach? electronic health information was exposed online
How did it happen? a misconfigured web setting
What went wrong with notification that caught the Michigan Attorney General’s attention? Patients were receiving notifications addressed to other patients and contacted the Attorney General
Health IT Security | Michigan Attorney General Looking into Inmediata Breach, Mailing Error
Where: Maine
The legislation: LD 946 (2019 | ME)
What would this bill do? Require Internet Service Provers to get Customers to OPT IN to sell cusotmer data
Government Technology | Maine Bill Would Force ISPs to Ask to Sell Customer Data
State: Washington
The bills that succeeded: HB 1071 (2019 | WA)
What does the data breach bill do?
SC Magazine | Washington state legislature passes data breach law, but punts on privacy law
Washington State Legislature did not enact SB 5376, a GDPR like data privacy bill, here are some reasons why:
SC Magazine | Washington state legislature passes data breach law, but punts on privacy law
Tech Target | State data privacy laws, regulations changing CISO priorities
Who: Defending Digital Campaigns, the nonprofit spinoff of a Harvard cybersecurity project
What: FEC is considering allow campigns to get free cybersecurity help
Why? Elizabeth Warren, Kamala Harris are disclosing funds spent on cybersecurity and the retention of cybersecurity experts
The catch: the nonprofit is founded by Hillary Clinton’s campaign manager
Slate | This Nonprofit Wants to Offer Political Campaigns Free Help With Cybersecurity
State: Massachusetts
Legislation: H 4806 (2018 |MA)
What did Massachusetts enact?
Leominster Champion | Governor Signs Bill to Enhance Credit Data Security
What? SB 2373 (2019 | TX)
What legal challenges would be allowed? Deceptive Trade Practices Act challenges
What does this mean? Know those press releases from the Attorney General Office about how much its collected in fines (hint: it is A LOT). Yes, it means business fines.
Where: Georgia
The legislation: HB 392 (2019 | GA)
What would this bill require:
Atlanta Journal Constitution | New safeguards for Georgia election security await Kemp’s signature
The city: San Francisco
The proposal:
How many other cities have done this? none
Opponents: law enforcement
The policy goal: ““The propensity for facial recognition technology to endanger civil rights and civil liberties substantially outweighs its purported benefits,”
Government Technology | Will San Francisco Ban Facial Recognition Technology?
State: Nevada
The legislation: SB 195 (2019 | NV)
Why did SB 195 die a legislative death?
Read an opposition letter from the cryptocurrency industry.
CoinGeek | Nevada lawmakers scrap controversial Bitcoin bill
State: Oregon
The legislation: House Bill 2395 (2019 |OR)
What would HB 2395 require?
Why? So that a hacker could access only 1 device in 1 hack.
Oregonian | Oregon House passes bill requiring security for online devices
What do I need to know about data minimization? It means that companies shouldn’t collect personal data “beyond what is adequate, relevant and necessary” for the product or service.
What’s an example? Your takeaway driver doesn’t need access to your photo library to scan your credit card
NextGov | Inside One Lawmaker’s Proposal for a Privacy Bill of Rights
North Carolina: the 1st State to pass the model legislation imposed the 72-hour notice requirement in the model.
Michigan: opted for a 10 day notice requirement
Ohio: allows licensees that have certain cybersecurity programs to use an affirmative defense against tort claims
Bloomberg | States Imposing New Cybersecurity Requirements on Insurers
Where: Missoula County, Montana
The County adopted rules for crypto miners that:
Michigans HB 4103 (2019 | MI) would:
The definition of cryptocurrency used in Michigan: “digital currency in which encryption techniques are used to regulate the generation of units of currency and verify the transfer of funds, and that operates independently of a central bank.”
Detroit News | Bitcoin, blockchain crime bills clear Michigan House
Where: Australia
What group is recommending a Biometric Security Oversight Commission? The Parliamentary Joint Committee on Law Enforcement
In its report the joint committee found that:
Biometric Update | Committee recommends Australia set up biometric data security oversight body
IOT legislation is the hot topic for 2019. Also known as how to keep your thermostat from being the way hackers hack your personal information.
So, what is the next hacker target? Indoor Garden sellers that offer a light source and temperature control gardening.
Tech Crunch | AeroGarden maker says hackers stole months of credit card data
Who: Facebook
What does Facebook want? It wants to know the rules of the game for political speech and the Constitution
Why? The government rather than a private comapny, like facebook shuld detemrine constitutional limitations
Variety | Facebook’s Mark Zuckerberg Says ‘We Need New Rules’ Regulating Political Speech
West Virigina HB 2452 (2019 |WV) created the a new Cybersecurity Office within the Office of Technology.
Goals of the a new Cybersecurity Office:
Stems from WV’s 2018 particiaption in the National Governors Association (NGA) cybersecurity policy academy.
Government Technology | W.Va. to Open Cybersecurity Office, Launch Unification Plan
The latest medical equipment suseptible to hackers are CT scans that would allow hackers access to alter images raising regulatory concerns about data security of medical equipment.
IN March 2019 hackers got into a small Colorado water utility.
Are there regualtory parallels that can be made to secure the water and waste water systems? Yes, Water utilities & power distributors share similar industrial control systems
Which states have taken water security measures forward? NJ, NY
Maryland HB 397 (2019 | MD) would increase telecom fees to harden the state 911 system.
Why the legislation? the Maryland 911 system has overloaded and resulted in death of injured residents
Why is data security an issue with 911?
Baltimore Sun | Modern 9-1-1 system will increase state and local fees
Facebook CEO is the latest tech CEO calling for adoption of GDPR standards.
The Coalition: Organizations representing accountants, techNet, AGC, engineers and technology professionals, + ALEC. Separate opposition stems from National Association of Chief Information Officers
The coalition opposes: state legislative efforts to require contracts install monitoring software
What sparked this? 30 states have a legislative push by TransparentBusiness that claims to ahve software that stops contractors from over-billing their clients
State Scoop | Industry groups urge state legislators to oppose tracking software bills
Nevada’s Uniform Regulation of Virtual-Currency Businesses Act SB 195 (2019 | NV) would require:
Are other states considering uniform bitcoin legislation? Yes, CA, HI and OK
D.C. Attorney General new proposal would add the following to the list of information that would trigger notification in a data breach:
Security Week | D.C. Attorney General Introduces New Data Security Bill
Know those calls to your mobile that look suspiciously like a number you know? Arkansas SB 514 (2019 |AR) would change the penalty for those calls.
The bill would increase the penalty for spoofing from a Class B misdemeanor to a Class D felony. That’s up to 6 years in prison & a fine up to $10,000.
Telecom companies would have to:
Debate over Michigan HB 4186 (2019 | MI) and HB 4187 (2019 | MI) focuses on the time period for notification.
The bills cut notification time in MI from 90 days to 45 days. Chamber of Commerce is as thrilled as a cat in the rain.
45 days is a standard adopted by 13 states.
An amendment proposal is for 75 days when the information is processed by a credit card processor.
Small Business Association of Michigan | New Data Breach Bill Moves Amid Latest Ransomware Attack
Marriott CEO testified before the Senate Committee on Homeland Security and Governmental Affairs Permanent Subcommittee on Investigations and said that the hotel chain would now use encryptiona nd toeknization (blockchain, distributed ledger) to safely store data.
Security Boulevard | Marriott Could Have Prevented Privacy Data Breach with Tokenization
New Jersey AB 3245 (2019 | NJ) will:
The Daily Swig | New Jersey to expand data breach notification law
Digitizing currency is moving tangible assets to the cloud and opening conversations on using crypto currency as collateral.
Bonjour new fintech, bitcoin and blockchain legislation.
Legaltech News | Crypto-Collateral? Securing Loans with Digital Currency
Facebook has admitted to storing 10s of MILLIONS of passwords in plain text. Security Expertts say 600 Million passwords were stored in plain text.
Tech Crunch | Facebook admits it stored ‘hundreds of millions’ of account passwords in plaintext
What data do scooter companies want to protect from local government?
Why do local governments want this data?
What enforcement actions have been taken?
What data concerns exist?
Mother Board | Scooter Companies Split on Giving Real-Time Location Data to Los Angeles
New data breach lingo: The Internet of Medical Things (IoMT)
Why does this matter? Health care data breaches are thepriciest at $08 per record
What’s the latest breach of medical devices? ultasound equipment that can be hacked and have images swppaed by hackers
Dark Reading | Ultrasound Machine Diagnosed with Major Security Gaps
Politico | Why 2020 contenders need to worry about hackers now
Vermont is subsidizing “last mile” for broadband access in rural areas that will:
US News and World Report | In Vermont, High-Speed Internet for All Gets More Likely
HB 4371 (2019 | TX) requires that digital currency (crypto currency)have a verified identity.
Texas would be the first state to prohibit anonymous cryptocurrency.
Crypto Globe | Texas Lawmaker Proposes Banning Anonymous Cryptocurrency Transactions
Where: Pennsylvania
The legislation: HB 225 (2019 | PA)
The Cybersecurity Innovation Commission must:
New Castle News | Under the Radar: Bill would aim to beef up state’s cybersecurity
Bipartisan S592 (2018-2019| Congress) would require businesses to disclose:
California’s SB 561 (CA | 2019) would allow individuals to bring suit against a company for a data breach that includes their personal information.
The caveat: companies would have to have failed to provide reasonable security precautions.
Insurance Journal | California Bills Would Add More Punch to Consumer Data Protection Law
Nevada is considering Senate Bill 69 (NV | 2019) which will:
3News | Cybersecurity, human trafficking among issues before Legislature this week
Georgia’s House Bill 197 (GA | 2019) would create:
Rome News Tribune | Legislation creating Georgia Data Analytics Center clears Crossover Day hurdle
California’s AB 953 (CA | 2019) would permit legal cannabis businesses to pay state taxes using cryptocurrency
What legislative provisions are getting push back from state data officials? require government contractors to install monitoring software
Is there a national group pushing back on this lobbying effort? National Association of State Chief Information Officers issued a statement opposing the bills
What is the opposition? It puts citizen information at risk
How many states have seen this language? 23
State Scoop | Nationwide lobbying push for contractor monitoring software alarms state CIOs
California is revising its first in the nation data protection bill by:
Tech Crunch | California to close data breach notification loopholes under new law
City: San Francisco
The proposed ordinance would:
State Tech | San Francisco Considers Banning Facial Recognition Tech
Oregon’s Senate Bill 703 will:
Health Tech | What Oregon’s Move to Redefine Data Privacy Means for PHI
A 2018 Brookings study categorizes state blockchain legislation and regulation.
States Recognizing Innovation Potential:
States Actively Engaged:
States that are orgnaized:
States that are appreciative:
States that are reactionary:
States that are unaware:
Consensys | Meet the American Legislators Bullish on Blockchain
Hawaii’s Public Land Trust Information System allows for searchable information such as:
tenants on state lands and in state buildings
rent paid for state land and buildings
fees for encroaching on public property
revenue from camping and wedding or event rentals
Government Technology | Hawaii Launches State Land Use Database
Hawaii joins the ranks of states implmenting a statewide Data Officer position to oversee data security.
SF 0125 (WY | 2019) will allow crypto currency to have property rights outside third party storage.
What does this mean?
Bitcoinist | WYOMING BECOMES FIRST STATE TO GIVE BITCOIN OWNERS FULL PROPERTY RIGHTS
Smartereum | Wyoming Just Passed a Bill That Gives Full Property Rights to Digital Currency Holders
Georgia uses exclusively paperless ballots. The November 2018 election produced high numbers of people not voting for Lt. Governor.
A lawsuit seeks to invalidate that race due to the low voting numbers in that specific race and calling for forensic examination of the electronic voting machines.
Cisco is asking governmetns around the world to make data privacy a fundamental right.
The talking points:
New Zealand Reseller News | Cisco calls on governments to make privacy a ‘fundamental human right’
WHAT: Cyber Security Exchange Act,”
Bipartisan? Yes, Senators Thune (R) & Klobuchar (D)
How does the Cyber security Exchange work?
The Hill | Bipartisan bill would create public-private cyber workforce exchange
After passing firs tin the nationa data privacy protection, to a GDPR level, here’s a roadmap of the supporters and opponents :
Why does this matter? Other states are following suit- New Mexico, Massachusetts
MERCURY NEWS | Inside the lobbying war over California’s landmark privacy law
Jail time is being added to the list of potential penalties in data breaches. Under the proposal the FTC could impose fines on companies and could also impose criminal penalties on executives.
The impetus for this bill? Facebook
Government Technology | Oregon’s Wyden Pitches Jail Time for Breaches
Utah’s HB 57 (UT | 2019) would require a warrant before police can access data shared with an app or third party, like cloud storage.
Supporters say:
Washington State is considering SB 5376 and HB 1854 (WA | 2019) will:
The bills build on parts of the California data privacy law, builds on lessons learned from California, and uses from GDPR standards.
New York Department of Education is proposing new rules that will:
How can governments use data from self driving cars?
phys.org | self-driving cars and geospatial data: Who holds the keys?
What entity is ranking states on student data protection? Parent Coalition for Student Privacy
Best State for student Data Protection? Colorado with a B
Worst states for student data protection? 11 way tie with Fs for Alabama, Alaska, Massachusetts, Minnesota, Montana, Mississippi, New Jersey, New Mexico, South Carolina, Vermont, Wisconsin
The populous states?
Lingering Education Data Security Issue for all states: Teacher Data Protections
EdScoop | Controversial report shows many states fail on student data privacy
Blue Ribbon Commission on Pennsylvania Election Security (January 2019)
Let’s take a peak at what the National Assocaition fo Realtors spent on cyber security lobbying in 20198?
Politico | Morning Cyber Security
Pennsylvania Supreme Court rules that all employers must exercise reasonable care to protect worker data.
How did they get there? A health care provider employee data breach led to a lawsuit. Lower courts sided with the employer that there was no data security requirements for employee records. The PA Supreme Court disagreed.
Pittsburg Post Gazette | PA Supreme Court rules UPMC — and all employers — must protect workers’ data. Doing so is harder
Why is procurement key?
Procurement contracts can set the tone for state data security standards
Telecom infratructure is key to data security
States should offensively say what the data standards are, rather than what cannot be done
Private-public cooperation is the key for leading global solutions
Strengthen cyber security workforces
Contracted cloud solutions can fill in when funding does not exist for state data security experts
The Kosciuszko Institute| CYBERSEC 2018 RECOMMENDATIONS AND KEY TAKEAWAYS
State: Minnesota
Bill: SF 17 (MN | 2019)
What does it do?
Tim Cook (Apple) is recommending a Data Broker Registry.
What’s a data broker? they buy and sell data from third parties
So how would it work?
Why does this sound familiar? Because in 2018 informed:intel told you about the first in the nation data broker state law in VT, and we gave you the bill text to create one in your state
Wired | How Tim Cook’s Data Broker Registry Might Actually Work
The Hill | Four cybersecurity priorities for Congress to confront active threats
Who is backing this bill: North Carolina State Attorney General
What impact does this have to businesses?
Have other states shortened notification timelines? Yes, in 2018 Colorado also went to 30 days. Iowa went to 45 days.
Health IT Security | North Carolina Reintroduces Strict Data Breach Notification Law
What are states doing to train their employees to protect data?
GCN | As states lag on cyber training, agencies are fertile phishing grounds
SB273 (OH |2018) does the following:
Cybersecurity experts favor: hand-marked paper records processed by optical scanners
What did Georgia’s voting security commission recommend? paper records but not hand marked and processed by optical scanners
Paper products rejoice! South Carolina legislature will consider requiring paper ballots. S374 (2019 |SC)
Politico | Two states are placing election security on their agenda this week.
Anatomy of a white hacker on construction equipment:
The solution: Move equipment away from “esoteric custom protocols” and to “modern, standardized tech” that can be easily upgraded for security
Forbes | Exclusive: Hackers Take Control Of Giant Construction Cranes
What is special about Rhode Island’s newly implemented risk limiting audits?
Rhode Island Assembly | General Assembly passes Sheehan, Ajello bill that would establish a post-election audit program | (2017-S 0413A, 2017-H 5704A)
StateTech | How States Benefit from Appointing a Chief Data Officer
Why is statutorily protecting business email correspondence increasingly important to law makers?
Data.
What does the FBI data say about business email hacking?
Are there other terms I need to watch for in legislation/from clients?
National Law Review | Privacy and Cybersecurity Issues to Watch in 2019
IN 2018, Vermont became the first state to regulate data brokers.
What is a data broker?
What business guidance did the Vermont Attorney General offer?
Los Angeles City Attorney filed suit against the Weather Channel App for not properly disclosing that the app retains user location data.
Where would I see this in legislation? in fraud, deceptive trade practices, competititve practices, cybersecurity bills that protect geolocation
Engadget | LA sues Weather Channel app owner over ‘fraudulent’ data use
Senate Bill 2110 (2019 | ND) would give a North Dakota state agency, Information Technology Department, the power to:
What’s the state argument for a unified cybersecurity approach? the local govenrments and entities are connected at some point to a state network
Local government support? Yes, the North Dakota League of Cities supports the initiative because of (1) ransomware threats and (2) small cities with part time auditors
Grand Forks Herald | Bill looks to standardize North Dakota cybersecurity for public entities
Ohio was the first state to create a safe harbor for business in its 2018 cybersecurity legislation. SB220 (OH | 2018)
How did Ohio craft its liability protection for businesses? A business has to do 1 of these:
(1) Create, maintain, and comply with a written cybersecurity program that contains administrative, technical, and physical safeguards for the protection of personal information and that reasonably conforms to an industry recognized cybersecurity framework, as described in section 1354.03 of the Revised Code; or
(2) Create, maintain, and comply with a written
cybersecurity program that contains administrative, technical,
and physical safeguards for the protection of both personal
information and restricted information and that reasonably
conforms to an industry recognized cybersecurity framework, as
described in section 1354.03 of the Revised Code.
(B) A covered entity's cybersecurity program shall be
designed to do all of the following with respect to the
information described in division (A)(1) or (2) of this section,
as applicable:
(1) Protect the security and confidentiality of the
information;
(2) Protect against any anticipated threats or hazards to
the security or integrity of the information;
(3) Protect against unauthorized access to and acquisition
of the information that is likely to result in a material risk
of identity theft or other fraud to the individual to whom the
information relates.
(C) The scale and scope of a covered entity's
cybersecurity program under division (A)(1) or (2) of this
section, as applicable, is appropriate if it is based on all of
the following factors:
(1) The size and complexity of the covered entity;
(2) The nature and scope of the activities of the covered entity;
(3) The sensitivity of the information to be protected;
(4) The cost and availability of tools to improve
information security and reduce vulnerabilities;
(5) The resources available to the covered entity.
1st state to adopt model insurance data security law: South Carolina
2nd state: Ohio legislation with 8 modifications SB 273 (OH | 2018)
The model law: NAIC
In 2018, Vermont passed a data breach notification bill to address the Equifax data breach.
Vermont’s Attorney General is Recommending the following additional legislative fixes:
VT Digger | AG says Vermont should take more steps to protect data privacy
New Jersey is looking to save costs by moving to exclusively digital records, making the state government paperless.
The caveat: data security risks
What was the legislative plan to get to a paperless NJ state government?
Government Technology | New Jersey Bill Would Push State Government to Go Paperless
According to lawyers wirting in the Harvard Business Review, a data security regulatory system should:
Harvard Business Review | Stopping Data Breaches Will Require Help from Governments
Harvard Business Review | Stopping Data Breaches Will Require Help from Governments
Thank you for subscribing to our newsletter.
Great things are just around the corner!