DocuCrunch.com » Feds put IT in the hot seat for security breaches

Feds put IT in the hot seat for security breaches

November 3, 2009 by Sam Narisi
Posted in: Regulations & Compliance, Security, Special Report

security-breach

The legal liability for getting hacked is getting real, as a few recent news stories demonstrate — and Congress is working on even tougher rules.

That puts a bigger security burden than ever on your company. Just promising to do better next time may not cut it.

Take these recent news stories:

  1. The Federal Trade Commission (FTC) recently made the biggest fine ever on a company whose records were stolen by a hacker. Data broker ChoicePoint was fined $275,000 for allowing two major data attacks, affecting more than 160,000 U.S. consumers. The attacks included the theft of social security numbers and other personal information.
  2. A federal judge shot down a recent offer by stockbroker TDAmritrade to settle claims based on a 2007 data breach that compromised names, addresses, phone numbers and trading information of potentially all of its more than 6 million retail and institutional customers. The solution that the company had worked out (which involved having a third-party analytics firm discover if any identity theft had happened, plus an offer of free security software for customers) was rejected as “very temporary fixes.” The company will have to do far better, according to the judge.
  3. In Maine, a decision is pending from the state Supreme Court on whether companies can be charged by consumers and banks for the time and money involved in resolving problems and reissuing cards compromised by stolen data. Regional supermarket chain Hannaford Brothers (no relation) had data about 4.2 million debit and credit card customers stolen.

As a Computerworld article dealing with the Maine case states:

“In most cases, courts have held that since consumers are compensated for any loss by the card-issuing bank they have little reason to seek other damages from the breached entity. They have also tended to reject the idea that consumers must be compensated for damages that they could suffer in the future as a result of a data breach.”

But that may be changing — whichever decision Maine’s high court makes is expected to influence judges in other jurisdictions. And, meanwhile, Congress is poised to pass Personal Data Privacy and Security Act, which would require notification of victims and hold companies liable for breaches (mirroring several state laws already on the books). The cost of inadequate data security may be about to get a lot higher.

  • Share/Bookmark

Tags: , , ,


Leave a Reply


advertisement






Here is a sample of the newest office productivity machines that have earned the Better Buys for Business Editor's Choice Award.

Sharp's Frontier series

Letter/legal copier-multifunctionals with high-end software features

Panasonic KV-S7075C

- one of the fastest flatbed scanners in the industry

Lexmark C734/C736

- Feature-laden color printers, for small-to-midsize workgroups.




The Archives


  • March 2010 (16)
  • February 2010 (27)
  • January 2010 (39)
  • December 2009 (39)
  • November 2009 (34)
  • October 2009 (30)
  • September 2009 (33)
  • August 2009 (29)
  • July 2009 (30)
  • June 2009 (31)
  • May 2009 (26)
  • April 2009 (20)
  • March 2009 (9)


  • Whitepapers