SEC Recommendations to Protect Against Cybersecurity Threats
March 09, 2020 —
Shaia Araghi and Jeffrey Dennis – Newmeyer DillionWhat Happened?
The Securities and Exchange Commission's Office of Compliance Inspections and Examinations ("OCIE") issued a detailed
report on January 27, 2020 regarding various ways for organizations to safeguard data and protect against security and data breaches. Cyber threat actors are now invading data in a more sophisticated manner than ever before, and implementation of the SEC's recommended practices are essential in order to protect from outside vulnerabilities.
What is at Risk?
If market participants fail to implement these recommended policies, they will become more vulnerable to external attacks and data breaches. This can weaken an organization or firm if all employees are not properly trained and informed of the increasing dangers of cybersecurity breaches.
What Can You Do to Protect Yourself from a Cybersecurity Threat?
1.
Governance and Risk Management. Senior leaders should make efforts to improve the cyber safety at their organization. Some of these efforts may include:
- Devote attention to overseeing the organization's cybersecurity and resilience programs;
- Develop a risk assessment process to identify and mitigate cybersecurity risks to the organization;
- Adopt and implement policies and procedures regarding these risks;
- Promptly respond and adapt to changes by updating policies and procedures when necessary; and
- Establish communication policies and procedures to provide timely information to customers, employees, and others when needed.
2.
Access Rights and Controls. Implement updated controls to determine appropriate users for organization systems, limit access as appropriate to authorized users (including the set-up of multi-factor authentication) and monitor user access.
3.
Data Loss Prevention. OCIE has recommended various important data loss prevention measures for organizations:
- Establish a vulnerability management program;
- Implement capabilities that can monitor network traffic and detect threats on endpoints;
- Establish a patch management program covering all software and hardware;
- Maintain an inventory of hardware and software assets;
- Encrypt data and implement network segmentation;
- Create an insider threat program to monitor any suspicious behaviors; and
- Secure legacy systems and equipment through disposal of sensitive information from hardware and software and by reassessing vulnerability and risk assessments.
4.
Mobile Security. Establish policies and procedures for mobile device use, manage use of mobile devices through a mobile device management application, implement security measures for internal and external users, and train employees on mobile device policies and effective practices.
5.
Incident Response and Resiliency. Detect and disclose material information regarding incidents in a timely manner and assess appropriateness of corrective actions taken in response to incidents. Organizations should develop a plan if an incident occurs, address applicable reporting requirements, assign staff to execute specific areas of the plan, and test and assess the plan. In the event that a data breach occurs, an organization should improve its resiliency by maintaining an inventory of core business services and prioritizing business operations based on an assessment of risks.
6.
Vendor Management. Establish a vendor management program to ensure that vendors meet your organization's security requirements. Organizations should aim to understand all contract terms with vendors to ensure that all parties are in agreement regarding risk and security. Organizations should also monitor third-party vendors and ensure that the vendor continues to meet the organization's security requirements.
7.
Training and Awareness. Train staff to implement cybersecurity policies of the organization. Organizations should provide cybersecurity and resiliency training and re-evaluate the effectiveness of training procedures.
A Final Reminder for Organizations
Organizations should strive to implement as many of the SEC's recommended protection measures as possible. Ensuring that senior members of an organization are leading the initiative in increased awareness about cybersecurity threats through training of employees will lead to greater cyber safety for the overall organization. Although prevention of all breaches cannot be guaranteed, developing data loss prevention plans to keep the organization and its core businesses safe from attack will benefit the entire organization.
How We Can Help
If you feel that your business falls below the SEC's recommended security measures, our firm can assist with compliance. Contact us for a free initial consultation to determine a reasonable and practical way for your business to become compliant with these guidelines.
Shaia Araghi is an associate in the firm's Privacy & Data Security, and supports the team in advising clients on cyber-related matters, including compliance and prevention that can protect their day-to-day operations. For more information on how Shaia can help, contact her at shaia.araghi@ndlf.com.
Jeff Dennis (CIPP/US) is the Head of the firm's Privacy & Data Security practice. Jeff works with the firm's clients on cyber-related issues, including contractual and insurance opportunities to lessen their risk. For more information on how Jeff can help, contact him at jeff.dennis@ndlf.com.
About Newmeyer Dillion
For 35 years, Newmeyer Dillion has delivered creative and outstanding legal solutions and trial results that achieve client objectives in diverse industries. With over 70 attorneys working as a cohesive team to represent clients in all aspects of business, employment, real estate, environmental/land use, privacy & data security and insurance law, Newmeyer Dillion delivers holistic and integrated legal services tailored to propel each client's success and bottom line. Headquartered in Newport Beach, California, with offices in Walnut Creek, California and Las Vegas, Nevada, Newmeyer Dillion attorneys are recognized by The Best Lawyers in America©, and Super Lawyers as top tier and some of the best lawyers in California and Nevada, and have been given Martindale-Hubbell Peer Review's AV Preeminent® highest rating. For additional information, call 949.854.7000 or visit www.newmeyerdillion.com.
Read the court decisionRead the full story...Reprinted courtesy of
Japan Quake Triggers Landslides, Knocks Power Plant Offline
September 10, 2018 —
Jeff Rubenstone - Engineering News-RecordA magnitude 6.7 earthquake occurred on the northern Japanese island of Hokkaido on Sept. 6, leaving at least seven dead and damaging buildings and structures in the region, including a 1,650MW coal-fired thermal power plant that was taken offline.
Read the court decisionRead the full story...Reprinted courtesy of
Jeff Rubenstone, ENRMr. Rubenstone may be contacted at
rubenstonej@enr.com
Are We Having Fun Yet? Construction In a Post-COVID World (Law Note)
June 20, 2022 —
Melissa Dewey Brumback - Construction Law in North CarolinaRemember how I said to never assume? Yeah, about that…… even when you plan for failures, mistakes, and other problems, sometimes things get so outside the realm of what you considered that it can leave your construction project spinning. Take, as a random example, a world-wide pandemic that shuts down supply chains, shuts down job sites, and limits the labor pool. Just as an example.
What does construction law say about pandemics? They fall under an “Act of God” that you may have read about in your contracts, or in the contracts of the contractors working your projects. An “Act of God” is an event that is not foreseeable, and as such not something the parties could have anticipated when they drafted the contract. Acts of God generally excuse a party’s failure– for example, a contractor’s failure to complete the project on time can be excused when an “act of God” has occurred.
By now, you’ve dealt with the practical fall out, one way or another. Many projects no longer made financial sense for your clients. Others may have been modified, reduced in scope, or had substitute materials put in place.
Read the court decisionRead the full story...Reprinted courtesy of
Melissa Dewey Brumback, Ragsdale LiggettMs. Brumback may be contacted at
mbrumback@rl-law.com
Specified Or Designated Operations Endorsement – Limitation of Insurance Coverage
July 15, 2024 —
David Adelstein - Florida Construction Legal UpdatesYour commercial general liability (CGL) policy may contain a specified or designated operations endorsement. This does not operate as an exclusion but as a LIMITATION of coverage. The endorsement may provide that bodily injury or property damage ONLY applies to the operations or business described therein. Similarly, there may be a limitation of coverage for designated classifications or codes which has the same effect—limiting coverage to the classifications/codes listed therein. This is an important consideration, and you need to understand and watch out for such limitations of coverage. (These aren’t the only ones, but it’s important to appreciate that limitations of coverage operate to limit the coverage to which the CGL policy applies.)
The Eleventh Circuit Court of Appeal dealt with this exact issue under Alabama law (although the same analysis would apply in numerous jurisdictions). In this case, a landscaper (the insured) had a CGL policy with a specified operations endorsement that limited coverage to landscaping operations. The landscaper was hired to install an in-ground trampoline in addition to site and landscaping operations at a house. A person got hurt using the trampoline and the landscaper was sued. The CGL insurer denied coverage outright (and, thus, any duty to defend) because the complaint asserted that the injury occurred from the landscaper’s assembly and installation of the trampoline, which was not a landscaping operation. Furthermore, the Eleventh Circuit noted that the landscaper’s insurance application specified that the landscaper did not perform any recreational or playground equipment erection or construction, and the installation and assembly of a trampoline would constitute recreational or playground equipment.
Read the court decisionRead the full story...Reprinted courtesy of
David Adelstein, Kirwin Norris, P.A.Mr. Adelstein may be contacted at
dma@kirwinnorris.com
Will Claims By Contractors on Big Design-Build Projects Ever End?
February 27, 2023 —
Richard Korman - Engineering News-RecordIn the annals of construction disputes, it is a blip, not a blast.
After a Flatiron Construction-Zachry Group joint venture struck out on most of its arbitrated claims against engineering firm partners on the I-85/385 design-build interchange project in Greenville, S.C., and had others dismissed in court, the contractors had one more source from which to try to cover unexpected project costs: a contractor protective professional policy. Flatiron-Zachry filed a lawsuit last October in San Antonio federal court to try to force payment from Steadfast, a subsidiary of Zurich American Insurance Co.
Reprinted courtesy of
Richard Korman, Engineering News-Record
Mr. Korman may be contacted at kormanr@enr.com
Read the full story... Read the court decisionRead the full story...Reprinted courtesy of
The Importance of a Notice of Completion to Contractors, Subcontractors and Suppliers
August 12, 2024 —
William L. Porter - Porter Law GroupThe recording of a valid “Notice of Completion” with the County Recorder is an event of significance to owners, contractors, subcontractors and suppliers alike. The recording of a Notice of Completion is one of several methods used to trigger the time period for the recording of mechanics liens and service of stop payment notices. Although the recording of a Notice of Completion is not absolutely required on any given project, all those working in the construction industry should understand its significance.
When a valid Notice of Completion has not been recorded in relation to a construction project, a contractor, subcontractor, or supplier might from ninety to one hundred fifty days after completion of the project to record a mechanics lien or serve a stop payment notice to secure payment for their services on the project, depending on the facts. However, if a valid Notice of Completion is recorded, then the deadline under most circumstances accelerates and subcontractors and suppliers must record a mechanics lien or serve a stop payment notice within only thirty days thereafter. Under the same circumstances, a prime contractor has only sixty days after the recording of a valid Notice of Completion to record a mechanics’ lien. Failure to meet these deadlines often results in loss of the right to a mechanics lien or stop payment notice. There are limited exceptions to these general deadlines, depending on the facts. If you believe you may have missed an important deadline to seek collection of a construction debt, you should consult with a construction attorney immediately to secure your avenues of collection, including the mechanics lien and stop payment notice remedies, if still available.
Read the court decisionRead the full story...Reprinted courtesy of
William L. Porter, Porter Law GroupMr. Porter may be contacted at
bporter@porterlaw.com
Construction Defects Checklist
July 18, 2018 —
Bremer Whyte Brown & O’MearaConstruction defects have existed since humans first began building structures, and will continue to be an occurrence into the future. For builder developers, contractors, and subcontractors, the specter of construction defects is a constant worry. Construction defect litigation is commonplace and can occur years after the construction project has been completed. This opens up an ongoing channel of risk and liability for construction contractors and project managers that are at risk of litigation far after they have completed a project. In this article, we’ll provide a helpful construction defects checklist that outlines the key avenues of risk and areas where construction defects litigation is most often focused. This checklist can help project managers, contractors, and subcontractors anticipate areas of their projects that may need extra attention or focus in order to ensure that they adhere to relevant local and state construction ordinances.
Gaining a greater understanding of what construction defects are can provide insight into how construction litigation can prove beneficial for structure owners or contractors who received substandard work. Many clients may not understand that they have an avenue to seek redress in cases where faulty workmanship may have resulted in economic damages or safety concerns in their home, building, or another construction project. Understanding the scope of what a construction defect is, and the areas that are most commonly litigated is helpful to understand when construction defect litigation is a viable option to pursue redress.
Read the court decisionRead the full story...Reprinted courtesy of
Bremer Whyte Brown & O’Meara
Virginia Chinese Drywall and pollution exclusion
May 27, 2011 —
CDCoverage.comIn Nationwide Mut. Ins. Co. v. The Overlook, LLC, No. 4:10cv69 (E.D. Va. May 13, 2011), homeowner Edmonds sued insured developer/general contractor Overlook seeking damages resulting from defective Chinese drywall installed in Edmonds’ home. Overlook’s CGL insurer Nationwide defended Overlook under a reservation of rights and filed a declaratory judgment action. The federal district trial court granted Nationwide’s motion for summary judgment.
Read the full story…
Reprinted courtesy of CDCoverage.com
Read the court decisionRead the full story...Reprinted courtesy of