SEC Recommendations to Protect Against Cybersecurity Threats
March 09, 2020 —
Shaia Araghi and Jeffrey Dennis – Newmeyer DillionWhat Happened?
The Securities and Exchange Commission's Office of Compliance Inspections and Examinations ("OCIE") issued a detailed
report on January 27, 2020 regarding various ways for organizations to safeguard data and protect against security and data breaches. Cyber threat actors are now invading data in a more sophisticated manner than ever before, and implementation of the SEC's recommended practices are essential in order to protect from outside vulnerabilities.
What is at Risk?
If market participants fail to implement these recommended policies, they will become more vulnerable to external attacks and data breaches. This can weaken an organization or firm if all employees are not properly trained and informed of the increasing dangers of cybersecurity breaches.
What Can You Do to Protect Yourself from a Cybersecurity Threat?
1.
Governance and Risk Management. Senior leaders should make efforts to improve the cyber safety at their organization. Some of these efforts may include:
- Devote attention to overseeing the organization's cybersecurity and resilience programs;
- Develop a risk assessment process to identify and mitigate cybersecurity risks to the organization;
- Adopt and implement policies and procedures regarding these risks;
- Promptly respond and adapt to changes by updating policies and procedures when necessary; and
- Establish communication policies and procedures to provide timely information to customers, employees, and others when needed.
2.
Access Rights and Controls. Implement updated controls to determine appropriate users for organization systems, limit access as appropriate to authorized users (including the set-up of multi-factor authentication) and monitor user access.
3.
Data Loss Prevention. OCIE has recommended various important data loss prevention measures for organizations:
- Establish a vulnerability management program;
- Implement capabilities that can monitor network traffic and detect threats on endpoints;
- Establish a patch management program covering all software and hardware;
- Maintain an inventory of hardware and software assets;
- Encrypt data and implement network segmentation;
- Create an insider threat program to monitor any suspicious behaviors; and
- Secure legacy systems and equipment through disposal of sensitive information from hardware and software and by reassessing vulnerability and risk assessments.
4.
Mobile Security. Establish policies and procedures for mobile device use, manage use of mobile devices through a mobile device management application, implement security measures for internal and external users, and train employees on mobile device policies and effective practices.
5.
Incident Response and Resiliency. Detect and disclose material information regarding incidents in a timely manner and assess appropriateness of corrective actions taken in response to incidents. Organizations should develop a plan if an incident occurs, address applicable reporting requirements, assign staff to execute specific areas of the plan, and test and assess the plan. In the event that a data breach occurs, an organization should improve its resiliency by maintaining an inventory of core business services and prioritizing business operations based on an assessment of risks.
6.
Vendor Management. Establish a vendor management program to ensure that vendors meet your organization's security requirements. Organizations should aim to understand all contract terms with vendors to ensure that all parties are in agreement regarding risk and security. Organizations should also monitor third-party vendors and ensure that the vendor continues to meet the organization's security requirements.
7.
Training and Awareness. Train staff to implement cybersecurity policies of the organization. Organizations should provide cybersecurity and resiliency training and re-evaluate the effectiveness of training procedures.
A Final Reminder for Organizations
Organizations should strive to implement as many of the SEC's recommended protection measures as possible. Ensuring that senior members of an organization are leading the initiative in increased awareness about cybersecurity threats through training of employees will lead to greater cyber safety for the overall organization. Although prevention of all breaches cannot be guaranteed, developing data loss prevention plans to keep the organization and its core businesses safe from attack will benefit the entire organization.
How We Can Help
If you feel that your business falls below the SEC's recommended security measures, our firm can assist with compliance. Contact us for a free initial consultation to determine a reasonable and practical way for your business to become compliant with these guidelines.
Shaia Araghi is an associate in the firm's Privacy & Data Security, and supports the team in advising clients on cyber-related matters, including compliance and prevention that can protect their day-to-day operations. For more information on how Shaia can help, contact her at shaia.araghi@ndlf.com.
Jeff Dennis (CIPP/US) is the Head of the firm's Privacy & Data Security practice. Jeff works with the firm's clients on cyber-related issues, including contractual and insurance opportunities to lessen their risk. For more information on how Jeff can help, contact him at jeff.dennis@ndlf.com.
About Newmeyer Dillion
For 35 years, Newmeyer Dillion has delivered creative and outstanding legal solutions and trial results that achieve client objectives in diverse industries. With over 70 attorneys working as a cohesive team to represent clients in all aspects of business, employment, real estate, environmental/land use, privacy & data security and insurance law, Newmeyer Dillion delivers holistic and integrated legal services tailored to propel each client's success and bottom line. Headquartered in Newport Beach, California, with offices in Walnut Creek, California and Las Vegas, Nevada, Newmeyer Dillion attorneys are recognized by The Best Lawyers in America©, and Super Lawyers as top tier and some of the best lawyers in California and Nevada, and have been given Martindale-Hubbell Peer Review's AV Preeminent® highest rating. For additional information, call 949.854.7000 or visit www.newmeyerdillion.com.
Read the court decisionRead the full story...Reprinted courtesy of
Traub Lieberman Attorneys Lisa Rolle and Christopher Acosta Win Motion to Dismiss in Bronx County Trip and Fall
May 22, 2023 —
Lisa M. Rolle & Christopher D. Acosta - Traub LiebermanTraub Lieberman Partner Lisa Rolle and Associate Christopher Acosta won a motion to dismiss in a trip and fall accident complaint and cross-claim brought before the New York Supreme Court, Bronx County. The underlying accident allegedly occurred on the sidewalk abutting the subject premises, which is owned by the Property Owner and was leased to a Pest Control Company. The Property Owner brought a cross-claim against the Pest Control Company as a result of the initial complaint.
Reprinted courtesy of
Lisa M. Rolle, Traub Lieberman and
Christopher D. Acosta, Traub Lieberman
Ms. Rolle may be contacted at lrolle@tlsslaw.com
Mr. Acosta may be contacted at cacosta@tlsslaw.com
Read the full story... Read the court decisionRead the full story...Reprinted courtesy of
Flooded Courtroom May be Due to Construction Defect
September 01, 2011 —
CDJ STAFFThe General Services Administration wouldn’t pin it on a construction defect, but a spokesperson said that a pipe that was misaligned during installation was the likely cause of a flood in the Thomas F. Eagleton US Courthouse on August 23. According to the St. Louis Dispatch, the burst pipe caused a 17-story waterfall in the courthouse, soaking ceilings and floors, and drenching the building’s contents.
The building was dedicated eleven years ago. During the nearly ten years before the building was complete, there were construction disputes and soil contamination issues.
Read the full story…
Read the court decisionRead the full story...Reprinted courtesy of
Developer Transition - Maryland Condominiums
June 21, 2017 —
Nicholas D. Cowie - Maryland Condo Construction Defect Law BlogINTRODUCTION
“Developer transition” is the process by which the governance of a condominium association is transferred from developer to unit owner control. This article provides a brief overview of the legal requirements that govern the developer transition process for Maryland condominiums. This article also as well as a “transition checklist” for transitioning unit owner-controlled boards of directors.
PERIOD OF DEVELOPER CONTROL
A developer initially controls an association because it owns all unsold units in the newly created condominium community. As such, the developer has the controlling votes associated with majority ownership and can appoint its own employees as the initial members of the board of directors and thereby control how the condominium association conducts its affairs. This is referred to as the “period of developer control,” during which the developer makes all decisions on behalf of the association.
The developer also creates an association’s governing documents, allowing it to dictate, subject to applicable law, the procedures and time periods under which control over the association’s board of directors will eventually be transferred to the homeowners.
Read the court decisionRead the full story...Reprinted courtesy of
Nicholas D. Cowie, Cowie & Mott, P.A.Mr. Cowie may be contacted at
ndc@cowiemott.com
Unlicensed Contractor Shoots for the Stars . . . Sputters on Takeoff
September 20, 2017 —
Garret Murai - California Construction Law BlogElon Musk . . .
Eccentric engineer.
Technology billionaire.
And, now, litigation bad ass.
Frequent readers of the California Construction Law Blog know that we’ve talked about the importance of being properly licensed when doing construction work and the risks to you if you don’t.
One California contractor recently found this out the hard way.
In Phoenix Mechanical Pipeline, Inc. v. Space Exploration Technologies Corp., California Court of Appeals for the Second District, Case No. B269186 (June 13, 2017), contractor Phoenix Mechanical Pipeline, Inc. (Phoenix) lost its boosters . . . err britches . . when it sued Elon Musk’s Space Exploration Technologies Corp. (Space X) due to its failure to have a California contractor’s license.
Read the court decisionRead the full story...Reprinted courtesy of
Garret Murai, Wendel Rosen Black & Dean LLPMr. Murai may be contacted at
gmurai@wendel.com
There's No Place Like Home
March 02, 2020 —
Brian Brenner - Engineering News-RecordTwo things that generally do not go well together, bridges and tornadoes, collided with unfortunate results on July 21, 2003. On that date, a tornado struck the Kinzua viaduct in northwestern Pennsylvania. The old bridge structure already had deteriorated foundation supports, which were then under repair. The tornado lifted parts of the bridge off its foundation, and more than half of the structure collapsed.
Brian Brenner, Engineering News-Record
ENR may be contacted at ENR.com@bnpmedia.com
Read the full story... Read the court decisionRead the full story...Reprinted courtesy of
Compliance with Contractual and Jurisdictional Pre-Suit Requirements is Essential to Maximizing Recovery
November 27, 2023 —
Michael S. Levine, Geoffrey B. Fehling & Charlotte Leszinske - Hunton Insurance Recovery BlogTimely notice is an important first step in a successful insurance recovery. But insurance policies are not always straightforward in identifying how, when, and to whom notice must be provided. Some states may also impose additional procedural hurdles, including requiring policyholders to contact their insurers before filing suit (the idea behind this requirement is that it may avoid litigation). Failing to comply with pre-suit requirements can hurt the policyholder’s recovery, as illustrated in a recent decision from the Northern District of Texas.
In NewcrestImage Holdings, LLC v. The Travelers Lloyds Insurance Company, No. 2:23-cv-039-BR (N.D. Tex. Oct. 17, 2023), the court considered whether NewcrestImage had forfeited its right to recover attorneys’ fees by failing to give Travelers pre-suit notice. NewcrestImage had filed suit against Travelers to obtain coverage for damage to its hotel property arising out of Winter Storm Uri. In its answer, Travelers asserted that NewcrestImage failed to provide the insurer with pre-suit notice as required under the Texas Insurance Code, and that if NewcrestImage successfully proved it was entitled to coverage, NewcrestImage’s failure to provide pre-suit notice precluded it from recovering attorneys’ fees. Travelers later moved to strike the claim for attorneys’ fees on that basis.
Reprinted courtesy of
Michael S. Levine, Hunton Andrews Kurth,
Geoffrey B. Fehling, Hunton Andrews Kurth and
Charlotte Leszinske, Hunton Andrews Kurth
Mr. Levine may be contacted at mlevine@HuntonAK.com
Mr. Fehling may be contacted at gfehling@HuntonAK.com
Ms. Leszinske may be contacted at cleszinske@HuntonAK.com
Read the court decisionRead the full story...Reprinted courtesy of
KB to Spend $43.2 Million on Florida Construction Defects
August 27, 2013 —
CDJ STAFFIn their second quarter filing with the SEC, KB Homes estimates that repairing damage caused by defects in framing, stucco, roofs, and sealant will cost it $43.2 million. That estimate includes homes that are yet to be identified. KB had estimated lower costs earlier, but subsequently determined it was necessary to increase the funds by $15.9. As a result, the firm showed a loss in the second quarter. The company hopes to recover some funds in insurance settlements.
Read the court decisionRead the full story...Reprinted courtesy of