To many, the new SEC rules that require public companies to disclose “material” cybersecurity incidents within four days of determining their materiality may seem like a challenging, if not unreasonable, demand. Companies should put a priority on preparing incident response plans that will help them meet compliance.
SEC's new rule for public companies to report data breaches within four days is a significant step towards transparency, cybersecurity preparedness, and standardizing reporting practices. Since news of the law broke, many security professionals have however expressed conflicting opinions.
CISA's new security-by-design and security-by-default guidance was released in collaboration with multiple other security agencies in the US as well as ones in Australia, Canada, New Zealand, the UK, Germany, and the Netherlands, formalizing the principles at an international level for the first time.
New report detailed a wide variety of IoT security and privacy flaws in common smart devices bought off-the-shelf from major retailers. Some of which are sending personal information to third party companies in China.
Wall Street is now demanding evidence of product uptake and pathways to profitability—and Microsoft is stumbling. The company’s latest earnings report led to a large drop in share prices, as investors and analysts raised concerns about its massive spending on AI infrastructure without the kinds of tangible returns that a really valuable product should demonstrate.
Behavioral targeting relies on a host of third parties in a highly complex, dynamic environment. Is your digital marketing ready for compliance with GDPR?
With the growth in BYOD, mobile messaging and a mobile workforce, companies should make it a priority to provide secure communications for data security and compliance.
This article is based on a presentation made during the Data Privacy Asia 2016 conference held on 9-11 November 2016. Author Karen Ngan is a commercial law partner at Simpson Grierson (New Zealand) . She co–heads the firm's information and communications technology group and its data protection and privacy group. In this article she discusses some of the challenges with dealing with 21st century privacy issues under a Privacy Act that is over 20 years old. She also covers some of the measures or practices that have been taken to address some of these challenges.
Researchers recently uncovered an IoT botnet that has infected more than 1M organizations. Can we survive the next DDoS attack and avoid a botnet apocalypse?
Covid highlighted the need for organizations to fully understand the world of their information and to mature their information governance program. While we are still reevaluating where we work, it is the perfect time to also reevaluate how we work.










