Cybersecurity & Tech
The latest medical equipment suseptible to hackers are CT scans that would allow hackers access to alter images raising regulatory concerns about data security of medical equipment.
IN March 2019 hackers got into a small Colorado water utility.
Are there regualtory parallels that can be made to secure the water and waste water systems? Yes, Water utilities & power distributors share similar industrial control systems
Which states have taken water security measures forward? NJ, NY
Maryland HB 397 (2019 | MD) would increase telecom fees to harden the state 911 system.
Why the legislation? the Maryland 911 system has overloaded and resulted in death of injured residents
Why is data security an issue with 911?
Baltimore Sun | Modern 9-1-1 system will increase state and local fees
Facebook CEO is the latest tech CEO calling for adoption of GDPR standards.
The Coalition: Organizations representing accountants, techNet, AGC, engineers and technology professionals, + ALEC. Separate opposition stems from National Association of Chief Information Officers
The coalition opposes: state legislative efforts to require contracts install monitoring software
What sparked this? 30 states have a legislative push by TransparentBusiness that claims to ahve software that stops contractors from over-billing their clients
State Scoop | Industry groups urge state legislators to oppose tracking software bills
Nevada’s Uniform Regulation of Virtual-Currency Businesses Act SB 195 (2019 | NV) would require:
Are other states considering uniform bitcoin legislation? Yes, CA, HI and OK
D.C. Attorney General new proposal would add the following to the list of information that would trigger notification in a data breach:
Security Week | D.C. Attorney General Introduces New Data Security Bill
Know those calls to your mobile that look suspiciously like a number you know? Arkansas SB 514 (2019 |AR) would change the penalty for those calls.
The bill would increase the penalty for spoofing from a Class B misdemeanor to a Class D felony. That’s up to 6 years in prison & a fine up to $10,000.
Telecom companies would have to:
Debate over Michigan HB 4186 (2019 | MI) and HB 4187 (2019 | MI) focuses on the time period for notification.
The bills cut notification time in MI from 90 days to 45 days. Chamber of Commerce is as thrilled as a cat in the rain.
45 days is a standard adopted by 13 states.
An amendment proposal is for 75 days when the information is processed by a credit card processor.
Small Business Association of Michigan | New Data Breach Bill Moves Amid Latest Ransomware Attack
Marriott CEO testified before the Senate Committee on Homeland Security and Governmental Affairs Permanent Subcommittee on Investigations and said that the hotel chain would now use encryptiona nd toeknization (blockchain, distributed ledger) to safely store data.
Security Boulevard | Marriott Could Have Prevented Privacy Data Breach with Tokenization
New Jersey AB 3245 (2019 | NJ) will:
The Daily Swig | New Jersey to expand data breach notification law
Digitizing currency is moving tangible assets to the cloud and opening conversations on using crypto currency as collateral.
Bonjour new fintech, bitcoin and blockchain legislation.
Legaltech News | Crypto-Collateral? Securing Loans with Digital Currency
Facebook has admitted to storing 10s of MILLIONS of passwords in plain text. Security Expertts say 600 Million passwords were stored in plain text.
Tech Crunch | Facebook admits it stored ‘hundreds of millions’ of account passwords in plaintext
What data do scooter companies want to protect from local government?
Why do local governments want this data?
What enforcement actions have been taken?
What data concerns exist?
Mother Board | Scooter Companies Split on Giving Real-Time Location Data to Los Angeles
New data breach lingo: The Internet of Medical Things (IoMT)
Why does this matter? Health care data breaches are thepriciest at $08 per record
What’s the latest breach of medical devices? ultasound equipment that can be hacked and have images swppaed by hackers
Dark Reading | Ultrasound Machine Diagnosed with Major Security Gaps
Politico | Why 2020 contenders need to worry about hackers now
Vermont is subsidizing “last mile” for broadband access in rural areas that will:
US News and World Report | In Vermont, High-Speed Internet for All Gets More Likely
HB 4371 (2019 | TX) requires that digital currency (crypto currency)have a verified identity.
Texas would be the first state to prohibit anonymous cryptocurrency.
Crypto Globe | Texas Lawmaker Proposes Banning Anonymous Cryptocurrency Transactions
Where: Pennsylvania
The legislation: HB 225 (2019 | PA)
The Cybersecurity Innovation Commission must:
New Castle News | Under the Radar: Bill would aim to beef up state’s cybersecurity
Bipartisan S592 (2018-2019| Congress) would require businesses to disclose:
California’s SB 561 (CA | 2019) would allow individuals to bring suit against a company for a data breach that includes their personal information.
The caveat: companies would have to have failed to provide reasonable security precautions.
Insurance Journal | California Bills Would Add More Punch to Consumer Data Protection Law
Nevada is considering Senate Bill 69 (NV | 2019) which will:
3News | Cybersecurity, human trafficking among issues before Legislature this week
Georgia’s House Bill 197 (GA | 2019) would create:
Rome News Tribune | Legislation creating Georgia Data Analytics Center clears Crossover Day hurdle
California’s AB 953 (CA | 2019) would permit legal cannabis businesses to pay state taxes using cryptocurrency
What legislative provisions are getting push back from state data officials? require government contractors to install monitoring software
Is there a national group pushing back on this lobbying effort? National Association of State Chief Information Officers issued a statement opposing the bills
What is the opposition? It puts citizen information at risk
How many states have seen this language? 23
State Scoop | Nationwide lobbying push for contractor monitoring software alarms state CIOs
California is revising its first in the nation data protection bill by:
Tech Crunch | California to close data breach notification loopholes under new law
City: San Francisco
The proposed ordinance would:
State Tech | San Francisco Considers Banning Facial Recognition Tech
Oregon’s Senate Bill 703 will:
Health Tech | What Oregon’s Move to Redefine Data Privacy Means for PHI
A 2018 Brookings study categorizes state blockchain legislation and regulation.
States Recognizing Innovation Potential:
States Actively Engaged:
States that are orgnaized:
States that are appreciative:
States that are reactionary:
States that are unaware:
Consensys | Meet the American Legislators Bullish on Blockchain
Hawaii’s Public Land Trust Information System allows for searchable information such as:
tenants on state lands and in state buildings
rent paid for state land and buildings
fees for encroaching on public property
revenue from camping and wedding or event rentals
Government Technology | Hawaii Launches State Land Use Database
Hawaii joins the ranks of states implmenting a statewide Data Officer position to oversee data security.
SF 0125 (WY | 2019) will allow crypto currency to have property rights outside third party storage.
What does this mean?
Bitcoinist | WYOMING BECOMES FIRST STATE TO GIVE BITCOIN OWNERS FULL PROPERTY RIGHTS
Smartereum | Wyoming Just Passed a Bill That Gives Full Property Rights to Digital Currency Holders
Georgia uses exclusively paperless ballots. The November 2018 election produced high numbers of people not voting for Lt. Governor.
A lawsuit seeks to invalidate that race due to the low voting numbers in that specific race and calling for forensic examination of the electronic voting machines.
Cisco is asking governmetns around the world to make data privacy a fundamental right.
The talking points:
New Zealand Reseller News | Cisco calls on governments to make privacy a ‘fundamental human right’
WHAT: Cyber Security Exchange Act,”
Bipartisan? Yes, Senators Thune (R) & Klobuchar (D)
How does the Cyber security Exchange work?
The Hill | Bipartisan bill would create public-private cyber workforce exchange
After passing firs tin the nationa data privacy protection, to a GDPR level, here’s a roadmap of the supporters and opponents :
Why does this matter? Other states are following suit- New Mexico, Massachusetts
MERCURY NEWS | Inside the lobbying war over California’s landmark privacy law
Jail time is being added to the list of potential penalties in data breaches. Under the proposal the FTC could impose fines on companies and could also impose criminal penalties on executives.
The impetus for this bill? Facebook
Government Technology | Oregon’s Wyden Pitches Jail Time for Breaches
Utah’s HB 57 (UT | 2019) would require a warrant before police can access data shared with an app or third party, like cloud storage.
Supporters say:
Washington State is considering SB 5376 and HB 1854 (WA | 2019) will:
The bills build on parts of the California data privacy law, builds on lessons learned from California, and uses from GDPR standards.
New York Department of Education is proposing new rules that will:
How can governments use data from self driving cars?
phys.org | self-driving cars and geospatial data: Who holds the keys?
What entity is ranking states on student data protection? Parent Coalition for Student Privacy
Best State for student Data Protection? Colorado with a B
Worst states for student data protection? 11 way tie with Fs for Alabama, Alaska, Massachusetts, Minnesota, Montana, Mississippi, New Jersey, New Mexico, South Carolina, Vermont, Wisconsin
The populous states?
Lingering Education Data Security Issue for all states: Teacher Data Protections
EdScoop | Controversial report shows many states fail on student data privacy
Blue Ribbon Commission on Pennsylvania Election Security (January 2019)
Let’s take a peak at what the National Assocaition fo Realtors spent on cyber security lobbying in 20198?
Politico | Morning Cyber Security
Pennsylvania Supreme Court rules that all employers must exercise reasonable care to protect worker data.
How did they get there? A health care provider employee data breach led to a lawsuit. Lower courts sided with the employer that there was no data security requirements for employee records. The PA Supreme Court disagreed.
Pittsburg Post Gazette | PA Supreme Court rules UPMC — and all employers — must protect workers’ data. Doing so is harder
Why is procurement key?
Procurement contracts can set the tone for state data security standards
Telecom infratructure is key to data security
States should offensively say what the data standards are, rather than what cannot be done
Private-public cooperation is the key for leading global solutions
Strengthen cyber security workforces
Contracted cloud solutions can fill in when funding does not exist for state data security experts
The Kosciuszko Institute| CYBERSEC 2018 RECOMMENDATIONS AND KEY TAKEAWAYS
State: Minnesota
Bill: SF 17 (MN | 2019)
What does it do?
Tim Cook (Apple) is recommending a Data Broker Registry.
What’s a data broker? they buy and sell data from third parties
So how would it work?
Why does this sound familiar? Because in 2018 informed:intel told you about the first in the nation data broker state law in VT, and we gave you the bill text to create one in your state
Wired | How Tim Cook’s Data Broker Registry Might Actually Work
The Hill | Four cybersecurity priorities for Congress to confront active threats
Who is backing this bill: North Carolina State Attorney General
What impact does this have to businesses?
Have other states shortened notification timelines? Yes, in 2018 Colorado also went to 30 days. Iowa went to 45 days.
Health IT Security | North Carolina Reintroduces Strict Data Breach Notification Law
What are states doing to train their employees to protect data?
GCN | As states lag on cyber training, agencies are fertile phishing grounds
SB273 (OH |2018) does the following:
Cybersecurity experts favor: hand-marked paper records processed by optical scanners
What did Georgia’s voting security commission recommend? paper records but not hand marked and processed by optical scanners
Paper products rejoice! South Carolina legislature will consider requiring paper ballots. S374 (2019 |SC)
Politico | Two states are placing election security on their agenda this week.
Anatomy of a white hacker on construction equipment:
The solution: Move equipment away from “esoteric custom protocols” and to “modern, standardized tech” that can be easily upgraded for security
Forbes | Exclusive: Hackers Take Control Of Giant Construction Cranes
What is special about Rhode Island’s newly implemented risk limiting audits?
Rhode Island Assembly | General Assembly passes Sheehan, Ajello bill that would establish a post-election audit program | (2017-S 0413A, 2017-H 5704A)
StateTech | How States Benefit from Appointing a Chief Data Officer
Why is statutorily protecting business email correspondence increasingly important to law makers?
Data.
What does the FBI data say about business email hacking?
Are there other terms I need to watch for in legislation/from clients?
National Law Review | Privacy and Cybersecurity Issues to Watch in 2019
IN 2018, Vermont became the first state to regulate data brokers.
What is a data broker?
What business guidance did the Vermont Attorney General offer?
Los Angeles City Attorney filed suit against the Weather Channel App for not properly disclosing that the app retains user location data.
Where would I see this in legislation? in fraud, deceptive trade practices, competititve practices, cybersecurity bills that protect geolocation
Engadget | LA sues Weather Channel app owner over ‘fraudulent’ data use
Senate Bill 2110 (2019 | ND) would give a North Dakota state agency, Information Technology Department, the power to:
What’s the state argument for a unified cybersecurity approach? the local govenrments and entities are connected at some point to a state network
Local government support? Yes, the North Dakota League of Cities supports the initiative because of (1) ransomware threats and (2) small cities with part time auditors
Grand Forks Herald | Bill looks to standardize North Dakota cybersecurity for public entities
Ohio was the first state to create a safe harbor for business in its 2018 cybersecurity legislation. SB220 (OH | 2018)
How did Ohio craft its liability protection for businesses? A business has to do 1 of these:
(1) Create, maintain, and comply with a written cybersecurity program that contains administrative, technical, and physical safeguards for the protection of personal information and that reasonably conforms to an industry recognized cybersecurity framework, as described in section 1354.03 of the Revised Code; or
(2) Create, maintain, and comply with a written
cybersecurity program that contains administrative, technical,
and physical safeguards for the protection of both personal
information and restricted information and that reasonably
conforms to an industry recognized cybersecurity framework, as
described in section 1354.03 of the Revised Code.
(B) A covered entity's cybersecurity program shall be
designed to do all of the following with respect to the
information described in division (A)(1) or (2) of this section,
as applicable:
(1) Protect the security and confidentiality of the
information;
(2) Protect against any anticipated threats or hazards to
the security or integrity of the information;
(3) Protect against unauthorized access to and acquisition
of the information that is likely to result in a material risk
of identity theft or other fraud to the individual to whom the
information relates.
(C) The scale and scope of a covered entity's
cybersecurity program under division (A)(1) or (2) of this
section, as applicable, is appropriate if it is based on all of
the following factors:
(1) The size and complexity of the covered entity;
(2) The nature and scope of the activities of the covered entity;
(3) The sensitivity of the information to be protected;
(4) The cost and availability of tools to improve
information security and reduce vulnerabilities;
(5) The resources available to the covered entity.
1st state to adopt model insurance data security law: South Carolina
2nd state: Ohio legislation with 8 modifications SB 273 (OH | 2018)
The model law: NAIC
In 2018, Vermont passed a data breach notification bill to address the Equifax data breach.
Vermont’s Attorney General is Recommending the following additional legislative fixes:
VT Digger | AG says Vermont should take more steps to protect data privacy
New Jersey is looking to save costs by moving to exclusively digital records, making the state government paperless.
The caveat: data security risks
What was the legislative plan to get to a paperless NJ state government?
Government Technology | New Jersey Bill Would Push State Government to Go Paperless
According to lawyers wirting in the Harvard Business Review, a data security regulatory system should:
Harvard Business Review | Stopping Data Breaches Will Require Help from Governments
Harvard Business Review | Stopping Data Breaches Will Require Help from Governments
Stanford researchers and other professors looking at this federal definition of cybersecurity:
Prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation
think that the definition is outdated and needs to reflect the use of disinformation.
The list of cybersecurity legislative changes that are being bandied about:
The New Jersey Senate passed a Block Chain Task Force bill S2297 (NJ |2018) that will determine whether:
Touted benefits of blockchain/distributed ledger storage? could also help safeguard government systems from cyber-security attacks
What did the Michigan Chamber of Commerce tout as reasons to support a Data Security bill, HB 6405 (MI | 2018) that required businesses to do certain new tasks concerning data breaches:
S3288 (115th Congress) creates an offense of Aggravated damage to a critical infrastructure computer & allows for forfeiture of assets related to bots.
Morning Cybersecurity | Sen. Sheldon Whitehouse, meanwhile, complained that the Trump administration hasn’t collaborated with him on bipartisan legislation (S. 3288) to take down botnets.
EdScoop | Five reasons schools need to address cybersecurity now
The allegations of fake constitutent support:
The investigations:
Targets of the subpoenas:
Baltimore Post Examiner | Why is State Cybersecurity better than Federal Cybersecurity?
HR7283 (115th Congress) requires devices purchased by the federal government to be:
Text of HR7283 (115th Congress)
NextGov | Upcoming Bill Would Lock Down Agencies’ Internet-Connected Devices
Is this bipartisan? Yes, Sen. Rob Portman, R-Ohio, and Maggie Hassan, D-N.H.
What’s the bill called? The Public-Private Cybersecurity Cooperation Act
What would it do? Creates a vulnerability disclosure program, crafted by the Department of Homeland Securty, to allow hackers to report problems to the proper authorities without being prosecuted
NextGov | Senators Introduce Bill to Let Hackers Reports Bugs to DHS
Nextgov | Is this about grabbing some of the sizzle that comes with all things blockchain and crypto
New Jersey legislature is moving A3245 (2018 |NJ) which is in repsonse to the Marriott data breach and will:
HB 747 (2018 | OH) will estalish the Ohio Cyber Reserve to protect Ohioans from cyber terrorists.
Authors tout that the Reserve will also help cities with cyber inititatives.
How many aspects of cybersecurity will the reserve have its fingers in?
Like the national guard, the reserve will act by Governor action.
Fox 8 | Ohio House passes bill to establish cybersecurity team
Government Technology | Ohio House Passes Cybersecurity Team Bill
The Pennsylvania Supreme Court has ruled that employers have a duty to protect employees from cyberattacks by setting:
Dittman v. UPMC, 2018 Pa. LEXIS 6051 (Pa. Nov. 21, 2018)
Norway is changing the way it taxes bitcoin miners.
The current tax structure for cryptocurrency miners:
The new rate tax structure for bitcoin in Norway:
CryptoCurrency 365 | Norway Decided to Impose Normal Electricity Tax on Miners
The Nevada Legislature will consider SB69 (2019 | NV) which is:
Crypto Currency News | Ohio Accepts Bitcoin for Tax Payments: A Much-Needed Silver Lining.
States have taken different approaches to how to regulate hacking by research, or white hat hackers, who identify and report data security vulnerabilities.
An example of this is a researcher who discovered in 2017 that USPS had left open all user information of the usps.gov website. There was no response from USPS, and the breach was disclosed this week.
Tech Crunch | U.S. Postal Service Data Breach Exposes Data of 60M Customers
Jared Schroeder | Assistant professor of journalism, Southern Methodist University | Trib Talk | Texas needs legislation to combat bots — yesterday
Intel has drafted model data privacy bill that includes these 6 points:
New Hampshire voters approved a state constititional amendment to protect from government intrusion personal and private information.
The constitutional language: An individual’s right to live free from governmental intrusion in private or personal information is natural, essential, and inherent.
The passage rate: 80% of votgers supported it
Reason | N.H. Constitution Now Protects “Right to Live Free from Governmental Intrusion in Private or Personal Information”
How do consumers hold manufacturers of internet of things products, like a connected refrigerator, liable for a data theft or property damage from a hack?
That is part of what California’s SB 327 (2018 | CA) seeks to clarify to protect consumers.
CNN Wire | WE NEED STRONGER CYBERSECURITY LAWS FOR THE INTERNET OF THINGS
South Carolina Department of Revenue had a data breach impacting tax payers in 2012.
Then-Governor Nikki Haley promised those impacted life time credit mornitoring.
The Legislature de-funded the program effective OCtober 31, 2018.
Government Technology | South Carolina Lawmakers Vote to End Post-Hack Credit Protections
Vermont Digger | Christopher Minott: Protect small businesses from overly aggressive tech policy
Where: New Jersey
Who: New Jersey Attorney General Gurbir Grewal
What: In a settlement of a data breach of medical records, New Jersey Office of Attorney General banned those responsoible for the breech from owning or operating a business in New Jersey.
NY Attorney General | Virtual Markets Integrity Investigation
Ohio’s SB 220 (2018 | OH), signed by the Governor, will establish these blockchain standards:
SB 220 would apply to state contracting and state procurement.
Ohio’s SB 220 (2018 | OH)
If a business’ cybersecurity procedures reasonably conform to any of these:
(a) The security requirements of the “Health Insurance Portability and Accountability Act of 1996,” as set forth in 45 CFR Part 164 Subpart C;
(b) Title V of the “Gramm-Leach-Bliley Act of 1999,” Public Law 106-102, as amended;
(c) The “Federal Information Security Modernization Act of 2014,” Public Law 113-283;
(d) The “Health Information Technology for Economic and Clinical Health Act,” as set forth in 45 CFR part 162.
Then the business has a legal defnse to lawsuits challening the data security practices of the business.
Columbus Business First | Kasich signs bill protecting business that invest in data security
Huntington News | Bill Launched by Attorney General’s CyberOhio Initiative Signed into Law
Thank you for subscribing to our newsletter.
Great things are just around the corner!