Data Privacy


  • Street view of the Securities and Exchange Commission, SEC, Building in Washington DC.
    Image attribution tooltip
    qingwa via Getty Images
    Image attribution tooltip

    SEC settles charges with 4 firms it says downplayed SolarWinds hack exposure

    The agency alleged Unisys, Avaya, Check Point Software and Mimecast misled investors about the extent of their respective cyber risks.

    By David Jones • Oct. 22, 2024
  • Empty interior of modern security system control room with workstations with multiple displays and big screens mounted on the wall.
    Image attribution tooltip
    .shock via Getty Images
    Image attribution tooltip

    Where organizations invest after a data breach

    Asking customers to foot the bill for data breach remediation will not prevent future data breaches or address the issues that cause costs to increase.

    By Sue Poremba • Oct. 22, 2024
  • SEC seal outside Washington D.C. building
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    Majority of global CISOs want to split roles as regulatory burdens grow

    Trellix research shows rising cybersecurity demands from the SEC and other government bodies are pushing CISOs even closer to the edge.

    By David Jones • Oct. 15, 2024
  • cybersecurity hackers cyberattacks IT
    Image attribution tooltip
    Olemedia via Getty Images
    Image attribution tooltip

    Cybersecurity risk called a human issue, not a technical problem

    Ransomware and phishing attacks are evolving and an effective cybersecurity approach requires employees to be educated about risks, a panel of experts says. 

    By Oct. 2, 2024
  • T-Mobile storefront in San Francisco.
    Image attribution tooltip
    Justin Sullivan/Getty Images via Getty Images
    Image attribution tooltip

    FCC reaches $31.5M settlement with T-Mobile over rash of data breaches

    The company agreed to a major change in board-level governance and will make a series of upgrades to boost its cyber resilience.

    By David Jones • Oct. 1, 2024
  • A man walks with an umbrella in front of AT&T logo.
    Image attribution tooltip
    Ronald Martinez via Getty Images
    Image attribution tooltip

    AT&T settles a 2023 data breach for $13M. Recent incidents are much worse.

    Telecom cybersecurity remains a challenge with widespread impacts. AT&T is not alone in experiencing a pattern of extensive breaches exposing customer data.

    By Matt Kapko • Sept. 18, 2024
  • Computer keyboard with key marked "insurance."
    Image attribution tooltip
    sodafish via Getty Images
    Image attribution tooltip

    Companies lean on AI in push to curb cyber insurance costs

    Half of business leaders responding to a Delinea survey said their organization was able to negotiate a lower cyber insurance rate after using AI.

    By Alexei Alexis • Sept. 10, 2024
  • Pumpjack (oil derrick) and refinery plant in West Texas.
    Image attribution tooltip
    dszc via Getty Images
    Image attribution tooltip

    Halliburton confirms data stolen in August cyberattack

    The company continues to incur expenses related to the attack, but does not expect a material impact. 

    By David Jones • Sept. 3, 2024
  • algorithmic pricing
    Image attribution tooltip
    Anya Berkut via Getty Images
    Image attribution tooltip

    RealPage lawsuit opens a new antitrust front for pricing algorithms

    The rise of Big Data across the economy raises antitrust concerns, especially where companies are sharing sensitive proprietary data, legal experts say.

    By Aug. 28, 2024
  • General Motors
    Image attribution tooltip
    Brandon Bell via Getty Images
    Image attribution tooltip

    Texas sues GM for selling customer driving data

    The automaker failed to tell buyers it was selling their driving data to help insurers analyze driving behavior, according to a Texas AG lawsuit.

    By Aug. 14, 2024
  • DOJ TikTok COPPA lawsuit for children privacy violations
    Image attribution tooltip
    Michael M. Santiago via Getty Images
    Image attribution tooltip

    Message alleges TikTok had actual knowledge it was violating child privacy law

    The company wouldn't delete children's accounts unless parents submitted a form with information that was already in its possession, a federal lawsuit alleges.

    By Aug. 5, 2024
  • Ransomware spelled out in a creative depiction.
    Image attribution tooltip
    Just_Super via Getty Images
    Image attribution tooltip

    Some companies pay ransomware attackers multiple times, survey finds

    Robust cybersecurity risk management begins in the boardroom given the costs of disruption and tighter regulatory oversight.

    By July 30, 2024
  • Securities and Exchange Commission, SEC, Building in Washington DC
    Image attribution tooltip
    qingwa via Getty Images
    Image attribution tooltip

    Judge deals major blow to SEC’s cybersecurity enforcement stance

    “The decision substantially limits the SEC’s authority to challenge a company’s cybersecurity program,” attorney Mark Schonfeld said.

    By Alexei Alexis • July 23, 2024
  • limitations of liability clauses
    Image attribution tooltip
    peepo via Getty Images
    Image attribution tooltip

    Companies turn to AI contract tools to reduce external risks

    Executives often overlook the importance of shrewd third-party contracting when managing their risk profiles, according to a legal tech panel.

    By July 18, 2024
  • SolarWinds
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Legal Dive; photograph by ismagilov via Getty Images
    Image attribution tooltip

    Majority of SEC civil fraud case against SolarWinds dismissed, but core remains

    The court ruling related to claims leading up to and immediately following the 2020 Sunburst supply chain hack.

    By David Jones • July 18, 2024
  • Matrix background of blurred programming code.
    Image attribution tooltip
    Getty Plus via Getty Images
    Image attribution tooltip

    Ransomware leak site posts jumped 20% in Q2

    Threat groups claimed attacks on 1,237 organizations during the quarter, marking an increase from Q1. U.S.-based businesses accounted for more than half of all victims, Reliaquest found.

    By Matt Kapko • July 16, 2024
  • Outside shot of Citigroup HQ with a sign with the Citi logo in the shot
    Image attribution tooltip
    Mario Tama via Getty Images
    Image attribution tooltip

    Citi to pay $135.6M in new penalties over 2020 orders

    The bank has made insufficient progress toward resolving nagging data quality, risk management and internal control issues, the OCC and Federal Reserve said.

    By Dan Ennis • July 11, 2024
  • The letters AI on a digital block
    Image attribution tooltip
    BlackJack3D via Getty Images
    Image attribution tooltip

    AI policy, compliance leave lawyers more skeptical than executives: survey

    North America has so far adopted an “innovation-friendly” approach to AI regulations compared to countries in Europe and Asia, a report finds.

    By July 10, 2024
  • Computer keyboard with key marked "insurance."
    Image attribution tooltip
    sodafish via Getty Images
    Image attribution tooltip

    Cyber insurance prices fall amid rising competition: report

    The pricing relief comes even as cyberattacks are escalating and businesses are paying more to recover from them.

    By Alexei Alexis • July 2, 2024
  • voluntary self disclosure
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    SEC’s $2.1M fine on RR Donnelly over hack response slammed as overreach

    The agency’s assertion that a cybersecurity failure can be punished as an “internal accounting controls” violation is raising eyebrows.

    By Alexei Alexis • June 25, 2024
  • Cyberhackers-Ransomware
    Image attribution tooltip
    (Gorodenkoff) via Getty Images
    Image attribution tooltip

    Ransomware victims becoming less likely to pay cyberhackers

    Demands jumped in 2023 even as more companies plot better defenses against attacks that can incur deep business interruption costs, a report says. 

    By June 17, 2024
  • Rohit Chopra, Director of the Consumer Financial Protection Bureau, giving a speech in an auditorium.
    Image attribution tooltip
    Anna Moneymaker via Getty Images
    Image attribution tooltip

    Chopra raises alarm on ‘financial surveillance’ at Senate hearing

    “These plans to monetize sensitive financial transaction data are a reminder that the United States is slowly lurching toward more financial surveillance and even financial censorship,” CFPB Director Rohit Chopra said.

    By Rajashree Chakravarty • June 13, 2024
  • American Privacy Rights Act
    Image attribution tooltip
    Kevin Dietsch / Staff via Getty Images
    Image attribution tooltip

    Solution to patchwork of state data-privacy laws shows promise

    By mostly preempting state laws, the American Privacy Rights Act would give companies a much-needed roadmap for compliance, privacy specialists say.

    By Jessica Mach • April 12, 2024
  • A general view inside the European Parliament.
    Image attribution tooltip
    Christopher Furlong via Getty Images
    Image attribution tooltip

    EU lawmakers pass sweeping AI rules with global reach, stiff penalties

    Penalties include up to €35 million or 7% of a company’s total worldwide annual turnover — whichever is higher — for violations of a ban on “emotion recognition” in the workplace.

    By Alexei Alexis • March 13, 2024
  • Ryan McInerney with arms folded
    Image attribution tooltip
    Permission granted by Andy Gerit
    Image attribution tooltip

    Visa spends ‘billions’ battling cybersecurity threats

    The company is using generative artificial intelligence to thwart account-to-account fraud by way of Visa services.

    By Lynne Marek • March 11, 2024