This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookie Settings
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Strictly Necessary: Used for the proper function of the website
Performance/Analytics: Used for monitoring website traffic and interactions
On May 19, 2024, Minnesota officially joined the ranks of states enacting robust dataprivacy protections for consumers. The Minnesota Consumer DataPrivacy Act (HF 4757 / SF 4782) was approved by the state legislature and is headed to the governor's desk for expected signature into law.
CSO's ultimate guide to security and privacy laws, regulations, and compliance Security and privacy laws, regulations, and compliance: The complete guide This directory includes laws, regulations and industry guidelines with significant security and privacy impact and requirements. Massachusetts Bill H.4806
The European Parliament’s Committee on Civil Liberties, Justice and Home Affairs has recommended that the European Commission reject the proposed EU-US DataPrivacy Framework, which would govern the way in which the personal information of EU citizens is handled by US companies.
We're hiding data even from ourselves," says the biotech and genetic testing company's head of security. How serious is the company about safeguarding its customers and their genetic information?
Dataprivacy automation company LightBeam.ai has launched a new AI-powered dataprivacy automation platform designed to help organizations streamline compliance.
Employment screening company DISA says data of 3.3 million people was exposed in a data breach lasts year, prompting AppOmni CSO Cory Michal to say that data collection companies like DISA and National Public Data need more oversight, regulations, and penalties.
Having CISOs participating in the discussions on what data is necessary for an app to function is table stakes. They should have a say in how that data is parsed to determine how it must be protected to remain in compliance with privacy laws.
As part of the country's growing scrutiny over the tech sector, China enacted on August 21 a sprawling and comprehensive dataprivacy law, the Personal Information Protection Law (PIPL), which goes into effect on November 1, 2021.
In-app browsers can pose significant security risks to businesses, with their tendency to track data a primary concern. This was highlighted in recent research which examined how browsers within apps like Facebook, Instagram and TikTok can be a dataprivacy risk for iOS users.
Private risk consultancy firm Concentric has announced the launch of Eclipse, a new “turnkey solution” designed to provide enhanced cybersecurity and digital privacy to users.
With many jurisdictions embracing EU-style privacy rules in line with the European Union’s GDPR , such as mandatory data-protection impact assessments, dataprivacy officers, and notification to individuals and regulators in the event of a data security breach, compliance is increasingly complex and an increasing burden for organizations.
On January 1, 2023, 20, the California Privacy Rights Act (CPRA) will go into effect. Approved by ballot measure as Proposition 24 in November 2020, it created a new consumer dataprivacy agency and put California another step ahead of other states in terms of privacy productions for consumers—and data security requirements for enterprises.
Prior to launching CyberSaint, Wrenn was CSO of Schneider Electric, a supplier of technologies used in industrial control systems. The CSF’s core principles have been incorporated into Europe’s GDPR , NYDFS’s cybersecurity requirement s, California’s Consumer Privacy Act and Ohio’s Data Protection Act.
Those stats come from ISACAs Tech Workplace and Culture 2025 report, which is based on a survey of about 7,700 of its members who work in IT areas such as information security, governance, assurance, dataprivacy and risk management.
On March 2, Virginia's Democratic Governor Ralph Northam signed into law the nation's second major piece of state legislation that governs consumer dataprivacy and protection. Virginia's Consumer Data Protection Act (CDPA) follows the California Consumer Privacy Act (CCPA) , which went into effect on January 1, 2020.
At that time generative AI was not a major consideration and novel privacy-preserving techniques (PPT) were not featured heavily on a CSO 5yr budgetary plan. The responsible use of GenAI, and adoption of PPT play a crucial role in aligning with DORA legislation while safeguarding sensitive data. The world has changed.
Organizations that want to prove to others – and to themselves – that they have a solid cybersecurity and dataprivacy program will undergo a SOC 2 audit. As such, a SOC 2 audit is a big deal, and it’s demanding, and it requires some serious preparation.
The Indian federal government on Friday published a new draft of dataprivacy laws that would allow personal data transfer to other nations under certain conditions, and impose fines for breaches of data-transfer and data-collection regulations. The proposed legislation has been in the works for about four years.
The Certified DataPrivacy Solutions Engineer (CDPSE) certification focuses on the implementation of privacy solutions, from both a technical and governance perspective. What is the CDPSE certification?
In November of 2020, California voters approved an amendment to the CCPA which increased consumer dataprivacy protections. Even more critically, the CCPA grants consumers the right to opt out of the selling and sharing of their personal information. These protections only recently went into effect in January of 2023.
(TechTarget) Buffer Overflow Attacks Explained (Tech Sky) 2 - Europol to banks: Prepare for quantum computing threat Financial institutions in Europe must get ready to face the cyberthreat that quantum computers will pose to data security and dataprivacy when these powerful systems become widely available.
Achieve Compliance and DataPrivacy Regulation Standardization at the Federal Level. James Carder, CSO, LogRhythm. In March 2021, President Biden signed the $1.9 In order to stay ahead of the curve, they should keep a close eye on the renewed legislative discussions and high-profile breaches.
As regulators and legislators consider new approaches to addressing consumer privacy, CISO s and colleagues in technology and consumer products companies that use personal data should reconsider how they’re balancing their management of dataprivacy risks and the need for speed.
The protocol was developed so that recipients of threat data could assess its sensitivity and determine how to share it with others, without giving any aid to the bad actors, revealing personal data, or running afoul of dataprivacy regulations. To read this article in full, please click here
Allowing the states to regulate dataprivacy could cost businesses more than $1 trillion in the next 10 years, according to a new study by the Information Technology & Innovation Foundation.
Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk Episode 256: Recursive Pollution? Data Feudalism? The post Security Teams Lean Into AI As Cyber Worker Shortage Persists appeared first on The Security Ledger with Paul F. Related Stories China Calls Out U.S. For Hacking. Gary McGraw On LLM Insecurity
Related Stories Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt Spotlight Podcast: CSO Chris Walcutt on Managing 3rd Party OT Risk China Calls Out U.S. The post At Nebraska Event, FBI Calls Out Cyber Threats To Agriculture appeared first on The Security Ledger with Paul F. For Hacking.
The technology sector's vulnerability to the vagaries of geopolitics and the macroeconomy became clearer than ever in 2022, as IT giants laid off workers en masse, regulators cracked down on tech rule-breakers, nations negotiated dataprivacy, the EU-China chip war widened, and the Ukraine war disrupted business as usual.
Related Stories Spotlight: Traceable CSO Richard Bird on Securing the API Economy Episode 249: Intel Federal CTO Steve Orrin on the CHIPS Act and Supply Chain Security Forget the IoT. The post Episode 250: Window Snyder of Thistle on. Read the whole entry. » » Click the icon below to listen.
Faulkner was joined by Sarah Buerger, BISO, The Kraft Heinz Company; Mike Zachman, VP & CSO, Zebra Technologies; and Lynn Dohm, Executive Director, Women in CyberSecurity (WiCyS), who artfully moderated the panel discussion.
Former Uber CSO Joe Sullivan was found guilty of obstructing a federal investigation in connection with the attempted cover-up of a 2016 hack at Uber, NIST and Microsoft say that mandatory password expiration is no longer needed but many organizations are still doing it, and how fake executive profiles are becoming a huge problem for […].
Microsoft on Thursday said it will begin rolling out the first phase of its European Union data boundary plan from January 1, 2023 that’ll allow customers to store and process their customer data within the EU. Microsoft has included Azure, Power BI, Dynamics 365 and Office 365 under the first phase.
You can enable root access, but you have to jump through a lot of security hoops just to activate it,” noted Terry Dunlap, CSO and co-founder at ReFirm Labs. All sensitive data should only be stored for the amount of time required and in accordance with any dataprivacy policies,” said Smith.
When talking about risk in the IT world, we mainly talk about data, with terms like dataprivacy, data leakage and data loss. But there is more to cybersecurity risk than just protecting data. Individuals and organizations often think about risk in terms of what they’re trying to protect.
Click the icon below to listen. Related Stories Episode 250: Window Snyder of Thistle on Making IoT Security Easy Forget the IoT. Video Podcast ] | [ MP3 ] | [ Transcript ] The Internet of Things is growing – and fast.
.” Also read: Network Protection: How to Secure a Network National DataPrivacy Law Still Needed Traceable AI CSO Richard Bird said the new rules are an insufficient response to a much larger problem. “But breach notices are not security – and never will be.”
states have enacted strict privacy laws, the United States still lacks a comprehensive federal privacy statute, a vacuum that has fueled what many observers argue is a culture of “surveillance capitalism.” Although a handful of U.S.
and the European Union (EU) have a preliminary agreement over the storing of European data on U.S. If successful, the data agreement would resolve a significant point of contention in U.S.-EU EU relations since a previous deal regulating trans-Atlantic data flows – Privacy Shield – was deemed illegal by the EU’s top court in 2020.
The future of the American Privacy Rights Act (APRA), proposed as a federal framework to unify dataprivacy standards, is now uncertain. States like New Jersey, Tennessee, and Minnesota are developing comprehensive dataprivacy laws that emphasise data transparency, risk assessments, and consumer protection.
The European Commission announced Tuesday that is has officially begun the process of approving the EU-US DataPrivacy Framework—hammered together to allow the flow of data between the US and the European Union—after concluding that the framework provides privacy safeguards comparable to those of the EU.
He joined TikTok, the world’s most popular app with some 1 billion downloads annually, when the company came under scrutiny i n the United States over security and dataprivacy issues that emerged with the discovery of vulnerabilities within the app, as well as concerns about ties between Chinese parent ByteDance and the Chinese government.
We organize all of the trending information in your field so you don't have to. Join 28,000+ users and stay up to date on the latest articles your peers are reading.
You know about us, now we want to get to know you!
Let's personalize your content
Let's get even more personalized
We recognize your account from another site in our network, please click 'Send Email' below to continue with verifying your account and setting a password.
Let's personalize your content