Cybersecurity & Tech
The Democratic National Committee is claling on state party offices to srengthen cyber security.
Buzz Feed | DNC Warns State Parties On Cybersecurity: Be Better
Connecticut is creating the Connecticut Cyber Task Force.
The Connecticut Cyber Task Force will consist of:
2 Priorities of the tax force:
Business and Commerce Committee Study access issues regarding digital assets of decedents. Study social media privacy laws and whether job applicants and students’ privacy is jeopardized under current law.
A bipartisan bill in Congress seeks to require social media companies to disclose the same campaign related information that is required of radio and tv.
Which social media companies would be affected? websites, apps, search engines, social media and ad networks with over 50 million unique visitors
What would be trigger amount for dislcosures? if a person or entity spends at least $500 on political ads a year
What disclosures would be required?
S 1989 (2017) by Kolbuchar, McCain and Warner
The Hill | Bill to halt election meddling on social media introduced
House Committee on Appropriations
#5 Trends in data security & cost savings Monitor the ongoing implementation of Article IX, Sec. 9.13 of the General Appropriations Act and determine if state agencies are realizing cost savings and/or security enhancements in state operations related to cybersecurity, information technology, and cloud computing. Study trends in cloud computing and IT delivery services, and identify whether additional cost efficiencies, economies of scale, or IT modernization could be achieved.
House Committee on Business & Industry
#3 Data gathering by employers & businesses. Review the increased use of third party data gathering, particularly individual background information and history, by Texas employers and businesses. Examine the standards for accessing, providing, and updating accurate background information used for employment purposes.
#4 Data breaches & securing sensitive data. Study the impact of data breaches or theft on Texas consumers and businesses. In particular, study the consequences of recent data breaches and subsequent mitigation efforts. Review the existing standards of risk as well as the current best practices in securing sensitive and personal information held or used by private industries. Determine if existing rules and regulations offer adequate consumer protection while allowing continued economic success for businesses in the state.
House Committee on Elections
#1 Harvey & Election Security. Study the potential impact of disaster events on election administration and security. Specifically, examine any effects or vulnerabilities identified during Hurricane Harvey and the subsequent recovery period.
#2 Election Security. Study the efficiency and security of the state’s existing election protocols and systems, including but not limited to registration and early voting procedures, ballot styles, and the rules regarding time and location of polls. Identify available processes and options which could lead to increased voter participation and election integrity.
House Committee on Government Transparency & Operation
#1 Harvey & Data. Public/Private Partnership. Examine the role of technology in disaster preparedness and the response to Hurricane Harvey and future natural disasters. Review and make recommendations to drive innovation and efficiency and evaluate whether there are any regulatory impediments to collaboration between the public and private sectors.
#2 Statewide Technology Centers. Evaluate whether qualifying state agencies are appropriately utilizing available state disaster recovery services, including the statewide technology centers. Consider the costs and benefits of allowing other states to participate in Texas’ statewide technology centers under Subchapter L, Chapter 2054, Texas Government Code for disaster recovery purposes.
#5 Interagency data sharing. Study how state agencies can share knowledge and practices, reduce duplicative data gathering, and conduct business in a more efficient manner through interagency data sharing. Review best practices to provide the public with more transparency and access to government information.
House Committee on Investments & Financial Services
#2 Security Breaches. Study the impact and risks that a large-scale security breach of a credit bureau has on Texans. Identify opportunities to protect Texas consumers and to mitigate the impact of such a breach.
#4 Fin tech. Study policy challenges in the area of financial technology. Evaluate the concept of a “sandbox” as a regulatory approach for enabling innovation and the feasibility of implementing such in Texas. If appropriate, make recommendations for possible legislative action to foster innovation in the finance industry.
House Committee on Transportation
#6 Smart Roads. Intelligent Transportation Systems. Study emerging issues in transportation related to technology and evaluate the state’s preparedness for addressing challenges and opportunities posed by technological advances. Review the implementation of state and federal programs and legislation related to intelligent transportation systems, autonomous vehicles, unmanned aircraft systems (i.e. drones), and other technological changes.
Senate Select Committee on Election Security
In light of recent election irregularities in Texas, review voting security protocols as well as the responsibilities and duties of members of the Electoral
College. Specifically, examine the use of electronic voting machines and paper ballots, voting fraud and disenfranchisement occurring inside nursing homes and assisted living facilities, outside interference and manipulation of elections, and the voting requirements of presidential electors. Make recommendations to safeguard the integrity of elections, ensure the confidentiality and security of voting records, and ensure the will of the people is reflected through their ballot and carried out through their presidential electors.
85th Texas Legislature Interim Charges | Texas House | Texas Senate
Federal:
States:
Congressman Tom Graves H.R. 4036:
Tom Graves | Rep. Tom Graves Formally Introduces Active Cyber Defense Bill
There are also new federal guidelines for election machines.
New York Times | Wary of Hackers, States Move to Upgrade Voting Systems
The State: Kentucky
The proposed legislation would require companies responsible for a data breach to provide impacted Kentuckians:
How was the bill proposal announced? The State Attorney General Andy Beshear and the bill’s author, State Senator McGarvey, at AARP Kentucky’s Louisville headquarters
California regulations on ride share require annual data reports. The data required to be sent to the state includes:
What data do the cities want?
The data’s big bad issue: Privacy concerns about rider personal information
The Recorder | Uber and Lyft Resist Regulators’ Appeal for Data Sharing
October is National Cyber Security Awareness Month. Here’s exampkes of what governments and businesses have done to engage:
We Live Security | Five cool things happening for National Cyber Security Awareness Month
Thus far in 2017, the number of education data breaches:
Campus Technology | Education Data Breaches Double in First Half of 2017
Resiliance is the name of the game. R Street is calling for “resiliance” and not “remediation” in legislative solutions to data breaches.
If bills shouldn’t require that consumers receive free credit report monitoring and cyber security standards and breach notification requirements for entities that maintain consumer data, what should bills do?
R Street | Remediation won’t cut it – we need cyber resilience
Recode | Equifax rival TransUnion has hired cybersecurity lobbyists in Washington, D.C.
The Hill | Reddit hires first lobbyists
Texas State Representatives Minajarez, Pickett, Dale, Oliverson & Goldman requested the following interim charge:
The Minajarez, Pickett, Dale, Oliverson & Goldman letter to Speaker Straus dated 10.2.2017
During the Congressional hearings on the Equifax breach, Republicans bandied about the idea of requiring credit reporting businesses, that have exposed consumer information, to pay affected consumers “a couple thousand bucks each [consumer]”
The rational: An incentive to keep business data security up to snuff
The Republican: Congressman Joe Barton (R-TX), a founder of the bipartisan Congressional Privacy Caucus
The Hill | GOP rep pitches fines for hacked credit-monitoring firms
Data Security makes Governing’s Top 5 Government Trends to Watch.
Why is data security such a big deal?
A House Companion to the Senate’s, Securing Energy Infrastructure Act of 2017 by Senator Angus King (I-ME) and Senator James E. Risch (R-ID), has been filed by Congressman C.A. Dutch Ruppersberger (MD-02) and Congressman John R. Carter (TX-31). The legislation will:
According to the association representing tech giants, cryber crime will have a $6 trillion impact on the U.S.
Politico | Morning Cyber Security | Cybercrime will cost up to $6 trillion by 2021
The State: New York
The regulator: New York’s Department of Financial Services
The Subpoena: Seeks more information about Equifax’s data breach, including:
More regulatory enforcement in the works? Yes, New York also wants to impose the financial data security rules it finalized this year to apply to credit reporting agencies like Equifax.
What does this mean for other states? Colorado followed in New York’s footsteps to become the 2nd state to impose specific data security requirement son the financial industry. Look for a specific application to credit reporting agencies forthwith
Reuters | New York regulator subpoenas Equifax over massive data breach: Report
New York Law Journal | NY Issues Subpoena to Equifax Over Breach, Vullo Confirms
Kentucky Attorney General proposes revisions to the state’s data breach notification statute to require:
WCPO | Kentucky’s attorney general proposes new data breach protections after Equifax incident
New York General Assembly measure A08679 would allow New Yorkers to check their credit reports as often as they wanted for free.
Federal law requires an annuak free credit report check be available.
New York State Assembly measure SO 6886 would require a breached entity to provide 5 years of free credit freezes.
In the Cybersecurity Act of 2015, Congress created the Health Care Industry Cybersecurity Task Force.
6 “critical” recommendations were offered:
Define and streamline leadership, governance, and expectations for health care industry cybersecurity.
Increase the security and resilience of medical devices and health IT.
Develop the health care workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities.
Increase health care industry readiness through improved cybersecurity awareness and education.
Identify mechanisms to protect research and development efforts and intellectual property from attacks or exposure.
Improve information sharing of industry threats, weaknesses, and mitigations.
The local government: Montgomery Co. Maryland
The hackers demanded: 9 bitcoins, valued at between $40,000 and $50,000
Other local governmetns have been able to retrieve data from back up and not pay the ransom, was that tried? Yes, but for reasons unrelated to the hack the backup was not a viable option
What was the value of the data to the county? $5 million
Montgomery Advertiser | Montgomery County pays ransom, gets data back
Wisconsin’s election officials have created a state elections security team, and here’s what you need to know:
Wisconsin Law Journal | State creating elections security team, plan
Politico | How to erect an economic powerhouse using cybersecurity
Cybersecurity as an Engine for Growth Authors: Natasha Cohen, Rachel Hulvey, Jittip Mongkolnchaiarunya, Anne Novak, Robert Morgus and Adam Segal
A new report, Cybersecurity as an Engine for Growth, looked at Beersheba, Israel; Malvern, United Kingdom; and San Antonio, United States to find 3 ways cyber security can lead to economic growth:
Politico Morning Cyber Security | How to erect an economic powerhouse using cybersecurity
How does the spy network analogy play out for data?
Say your a city controller making payments to a contractor. The payment can be processed instaneously without being hacked because the information is broken down into packets, encrypted and each packet is sent a different path & then reassembled so that the city knows the funds have been withdrawn and the contract recipient has funds deposited.
New York State Assembly is pursuing SB06880 to require a consumer to be notified of a breach within 15 days of discovering the breach.New York SB 06880 (2017)
Supporting changes to New York’s Data Security and Notification Act, the state Attorney General states:
New York Daily News |Op-Ed by New York A.G. Eric Schneiderman | Raising our guard vs. mega-breaches
Long Island Business News | AG calls for tighter regs after Equifax breach
Convenience and Fuel retailers and a coalition of that includes the American Hotel & Lodging Association, International Franchise Association, National Association of Realtors, National Association of Truck Stop Operators, National Council of Chain Restaurants, National Grocers Association, National Retail Federation, Society of Independent Gasoline Marketers of America, and the U.S. Travel Association support 4 principles of data security legislation:
Illinois is proposing to eliminate fees that credit-reporting companies are allowed to charge for imposing or lifting a credit security freeze.
2 Attorneys General (MA and NY) are suing, or my soon sue, Equifax for violating state consumer laws.
This sparked legislation to require credit reporting agencies to have the same scrutiny as banks, hospitals and others that handle confidential consumer data.
WGBH | Mass. AG Maura Healey Will Sue Equifax Over Data Breach
Nebraska State Sen. Adam Morfeld is proposing a bill to require a credit reporting agency that has a breach to offer lifetime credit monitoring for free.
Morfeld’s reasoning? Equifax response to its hack was not enough
Virginia de-certified touch screen voting machines that do not leave a paper trail after voting machines were hacked within seconds at a tech conference earlier this year.
A vote by the State Election Department triggered the removal of the voting machines.
Tech Crunch | Virginia just decertified its most hackable voting machines
What is a data trespass law? While it sounds like data security, these laws create a crime against physically entering land to acquire data like pollution or animal cruetly.
Are data trespass laws constititional? Maybe not. A Federal Appeals court has found a Wyoming law likely violates the 1st Amendment.
Who is for these laws? Land owners, members of the Farm Bureau
Who is against these laws? People for the Ethical Treatment of Animals, Center for Food Safety, National Press Photographers Association
Casper Star Tribune | Denver court rules against Wyoming data trespass law
Recent cyber security philanthropic gifts:
Inside Philanthropy | Are Gifts for Cybersecurity the Next Gold Rush for Campus Fundraisers?
Hurricane Harvey exposed the need for energy security legislation by:
Oracle repoprtedly broke with other tech companies, to openly back a federal human trafficking bill.
The legislation:Stop Enabling Sex Traffickers Act, sponsored by Senator Richard Blumenthal (D-CT) and Senator Robert Portman (R-OH)
What this bill would do: Amend protections for social networking sites & online platforms such as Google and Facebook from being held legally liable for content shared by those on the site.
What do tech opponents say? These amendments will create endless lawsuits and stifle digital innovation.
Tech Crunch | Oracle breaks with tech industry in backing human trafficking bill
A review of grid security by Symatec reveals that since 2015 hackers have been trying to gain access to the energy sector. Here’s what you need to know:
The Hill | Sophisticated hacking campaign has targeted energy sector since 2015
National Association of Insurance Commissioner’s approved Insurance Data Security Model Law to improve cyber risk management in the U.S. insurance market.
What does the model law do?
8 States have a plan to replace their voting machines: MN, MI, NV, NM, CO, AR, MD, RI
Politico | Cash-strapped states brace for Russian hacking fight
Governing | State Election Officials Need Money to Boost Cybersecurity, But Where Will They Get It?
Experts say self driving cars are better protected from hackers; making human driven cars more likely to face a hacker.
Why are non-selfing driving cars easier to hack? Because the cars send signals via sensors to themselves about distances and the like over low-level system that hackers have been penetrating for years.
The fusion of these sensors in self-driving cars creates a ecueity protection as each sensor doesn’t trust the others data and the system as a hwole can override a command.
Guardian News | Assume self-driving cars are a hacker’s dream? Think again
Hurricane Harvey marks the 1st wide scale commerical use of drones after a disaster.
In addition to news crews utilizing drone footage, drones have been deployed by :
465,000 pacemakers are under voluntary recall for security issues that could allow a cybersecurity breach that would allow a 3rd party to :
No known cybersecurity issues with the pacemakers are known.
Regulatory Affairs Professionals Society | Abbott Recalls 465,000 Pacemakers for Cybersecurity Patch
In 2013 North Carolina created the 1st Innovation Center (iCenter) in the U.S.
Since 2013, the iCenter has become focused on changing the culture of state government by:
What does this mean? State innovation centers are a way to introduce new technology to all levels of government within a state.
Data Centers are chosing to set up shop in Iowa. Corn fields and data servers go together like Bluebell Ice cream and Texas.
The latest data center by Apple Inc. includes an economic incentive package that includes:
What does the Hawkeye State have to offer?
AP | Apple gets $208 million in tax breaks to build Iowa data center
Nevada is streamlining its state email servers, for all its state employees, to a single provider contract.
Government Technology | Nevada CIO: State’s Major IT Initiatives Are Moving Forward
Cinncinati is using predictive modeling to determine which properties might fall into disrepair to thwart blight before it occurs.
The Business: Integrated Roadways
What are integrated roadways? Roads with sensors, phone, and internet connectivity, telecommunications, fiber-optic cable, and high-speed Internet, as well as other hardware, inside road surfaces.
Would these integrated roads collect data for the benefit of the city? Yes.
What type of dats would roadways collect? data on vehicle counts, speeds, and weights to give cities access to information
Virginia has a new state level program to train veterans to fill cybersecurity jobs.
Virginia’s vetrans training program :VetSuccess Immersion Academies via SANS CyberTalent Solutions
The veterans can take up to 3 courses and receive certification when they qualify.
The State: Virginia
The goal of the public-private partnership: “optimizing opportunities for innovative collaboration and investment in Virginia’s transportation system”
The data shared with the private sector: 22 different data sets, with initial data sets including traffic volumes, speed limits, travel advisories, lane closures, crashes, truck restrictions, traffic sensors, incidents, sign messages and locations, paving schedules, short- and long-term weather events, the Six-Year Improvement Plan, major road construction and Signal Phase and Timing data.
Equipment World | Virginia DOT launches SmarterRoads data portal for transportation app development
Gartner Inc. estimates that cybersecurity spending will increase in 2017:
Spending will be focused on:
By 2020, bundled cybersecurity contracts will account for 40% of all managed security service contracts and will include:
Maryland is offering its Medicaid patients a Telehealth App with these policy goals:
State Government Tech | Maryland Offers Medicaid Users Free Telemedicine App
These 30 Governors, Republican and Democrat, signed onto ther National Governor’s Association Confront the Cyber Threat Initiative: AL, AK, AZ, AR, CA, CO, CT, DE, Guam, HI, ID, IN, IA, KY, LA, MA, MD,MI, MN, MO, MT, NV, NH, NJ, NC, ND, OK, OR, PA, Puerto Rico, RI, UT, VT, Virgin Islands, WA, WV, WI, WY.
The Compact calls for 3 major strides:
The Federal Trade Commission settled a data privacy investigation by Uber agreeing to 20 years of privacy audits.
The FTC says the company “failed consumers”
CNBC | Uber agrees to 20 years of privacy audits after FTC says it ‘failed consumers’
First comes banning investments in the country du jour, now comes stopping outsourcing funds or policy initiatives related to cybersecurity to Russia.
Amendments bandied about D.C. by Senators Durbin, Warren and Whitehouse prohibit the use of federal funds to establish or support a “joint cybersecurity initiative” with Russia.
This trend is heading toward statehouses near you.
Politico | Morning Cybersecurity | Amendments to the policy roadmap
North Carolina’s electronic voting system in 2016 was hacked. The way hackers got in was through the company that provided the poll book- the electronic data that allows voting personnel to verify voters.
What changes we will we see to election procurement:
NPR | Russian Cyberattack Targeted Elections Vendor Tied To Voting Day Disruptions
71 % of health care organizations budget for cyber security
The majority say cybersecurity is more than 3% of their budget
A majority have hired a chief information security officer or other executive level cybersecurity position
75% do regular cybersecurity testing
80% of US healthcare orgnaizations will increase cybersecurity spending in 2017
Healthcare Dive | HIMSS survey: Hospitals ramping up cybersecurity efforts
Michigan created a volunteer public private task force to step in at a moment’s notice to resolve a cyber attack on state systems.
What is the group called? Michigan Cyber Civilian Corps, MiC3
Has Michigan Cyber Civilian Corps, MiC3 been deployed? No
How does it function? Like a volunteer fire department
Who has volunteered? cybersecurity experts from government, education and private industry
Has any other state done this? No.
Governing | Michigan’s Volunteer-Based Cybersecurity Strategy Catches On
GCN | Why state and local government still struggle with cybersecurity
Missouri tests its state employees with its own phishing scams to keep state employees laser focused on cybersecurity.
Government Technology | In Illinois, Cybersecurity Training for State Employees Now Required by Law
Illinois HB 2371 requires every state employee to complete annual cybersecurity training. The Department of Information resources may offer a video in lieu of training.
By every employee, the Legislature managed to exclude these employees:
Government Technology | In Illinois, Cybersecurity Training for State Employees Now Required by Law
Johnson Co. Kansas relies on big data to address public safety and mental health concerns. The use of bug data has saved the local government:
How did Johnson Co. do it? By cross referencing 2 databases- county wide criminal jsutice database and a health and human services database that notes mental health issues.
State Tech | Johnson County (Kan.) Calls On Big Data to Link Public Safety and Mental Health
As schools place a greater concern on ensuring parents that student data is protected, schools are asking their edcation vendors more about data security.
Ed Tech | 3 Tips to Keep Parents Assured that Student Data Is Protected
A tech researcher visiting DefCon Voting Village in Las Vegas, hacked a U.S. styled voting machine within 2 minutes.
Companies are finding cybersecuity weaknesses in employees by sending faux phishing emails and seeing which employees bite.
Corporate test data shows cyber literacy training reduces the number of employees who fall for phishing scams.
How many years until there are cyber literacy requirements in public education? in state contracts?
SC Media | Diagnosing employee phishing weaknesses key to improving email security
Taxpayers for Common Sense is ahead of the curve by creating a database to track federal cybersecurity spending.
The cybersecurity spending database is organized by agency and tracks spending for last 10 years.
The Consumer Tech Association filing with the Commerce Department recommends government action on cybersecurity/datasecurity policies for education because there are so many differnt players in education.
The recommendations that we may soon see in Education Procurement Contracts:
Your Roomba is mapping your house and collecting data. Let’s repeat, your Roomba is colelcting data about how to get around your house and what is in your house.
Better yet, the company hasn’t asked you whether they can keep the data, store the data or sell the data. What retailer wouldn’t want to buy data that says you have no loveseat? or only 1 sad and lonely dining chair?
This type of private property data is screaming for legislation. Legislation about disclosure of the data, sale of the data, consent to store the data, and how protected is the Roomba from hackers?
USA Today | Your Roomba already maps your home. Now the CEO plans to sell that map.
Congress’ H.R. 3170 tackles cyber security in small businesses by requiring cyber security training for small business devleopment centers.
In 2016, California created the State Innovation Lab.
California maintains an Office of Digital Innovation.
The policy goal in California is to “create novel, deployable technologies that address needs identified by state entity partners — with a particular focus on open-sourced technology.”
State Tech | How Innovative States Stay Ahead of the Tech Curve
Body cameras- love them, hate them- they collect data and a lot of data.
Lots of people support body cameras:
Body cameras are everywhere in law enforcement, so how are counties handling all that data?
State Tech | How Counties Manage the Body-Worn-Camera Video Data Boom
2017 Q2 reflects record spedning by tech giants.
The 10 top issues tech wants elected officials and policymakers to know:
Data Center Dynamics | Tech, data center firms increase US lobbying spend
Arkansas Workforce Services experienced a data breach that exposed the personally identifable details of 600,000 residents and 19,000 employment applications.
The state is seeking new database services.
U.S. News and World Report | Data Breach Has Arkansas Seeking New Vendor
Yes, the California Supreme Court held that the California Medical Board can access private patient records in the state prescription database because the state interest in regulating potent prescription drugs and protecting patients from negligent doctors.
Access to patient records + Texas Medical Board Sunset Review = Patient Privacy vs. State Interest Amendments
Law 360 | Calif. Justices OK Medical Board’s Access To Rx Database
The 2016-2017 Chair of the National Governor Association, Virginia Governor Terry McAuliffe, explains that cyber security directly impacts these policy areas and businesses:
National Governors Association is pushing for state reform of cyber security laws because:
The National Governor’s Association initiative, Meet the Threat, calls for:
Lloyds of London estimates a global cyber attack will result in damages similar to hurricane Sandy, or $53 billion in economic losses from a global hacking of cloud services.
How do the $53 Billion oin costs break down?
Average economic losses $4.6 billion to $53 billion
Actual losses could be as high as $121 billion
$45 billion of that sum may not be covered by cyber policies, because
companies are underinsuring
If operating systems are hacked, average losses range from $9.7 billion to $28.7 billion.
How is Texas regulating the cyberinsurance market?
Washington State University kept sensitive personal information on a backup disk locked in a $159 safe in a small safe in a storage unit.
The WSU storage unit was burlagized, and was the only unit burgalarized.
The takeaway for policy makers: Do not allow state institutions to store personal data in storage units.
Common sense governing. Better late than never.
A poll by Carbon Black reveals the concern level of voters for election integrity.
SC Media | Cybersecurity concerns may stop 59 million Americans from voting in 2018
In August 2016, Maryland officials notices hackers were trying to get to voter information, that set off a flurry of legislator and regulator activity. Here’s where they ended up almost a year later:
Wall Street Journal | How Maryland Contended With Attempted Hack Of Its Voter-Registration System
To avoid the use of stolen personally identifiable information, the uK is seeing a rise in the use of biometric identifiers.
SC Media | Rise in use of biometrics products for cyber-security, report predicts
Oregon’s Senate Bill 90 creates a new position of Chief Information Officer who is responsible for:
Why are Frederick County Public Schools (Maryland) adopting new data security rules? The School experiences a data breach.
5 Elements from the new data breach policy:
Also requires a 3rd party contractor to test the schools’ data security regularly.
Frederick News Post | New FCPS data security policy takes measures to protect student information
How to pass electric grid cybersecurity standards in 2 steps of legislstive logic:
Natural Gas Intel | Senate Energy Policy Reform Bill Revived, Fast-Tracked
A bipartisan, and awkwardly named piece of legislation, the Promoting Good Cyber Hygiene Act, calls for:
1/2 of health care organizations say they are prepared for a data breach.
The American Medical Association proposes these data security incentives:
Health IT Security | Incentivize Cybersecurity Best Practices for Data Security
Automakers say they need flexibility to adapt technology of self driving cars.
What’s known for flexibility? the sarcastic answer: enacted statutes and their ability to keep up with technology
What’s the solution for cybersecurity for self driving cars? According to the American Center for Mobility self imposed rules by industry are the best option.
Automotive News | Cybersecurity push may tie up autonomous-car legislation
Department of Defense is adding cybersecurity standards to its procurement process.
Requirements in the new contracting rules that take effect this fall are:
FedScoop | Pentagon will soon hold contractors to elevated cyber standards
Data Breach at HHSC? No, a box of client records was left in a box unattended by a dumpster in Houston.
The personal information exposed included:
The HHSC response:
SC Media | 2,000 Texas HHSC clients health data compromised
HHSC | HIPAA Notice: Houston-area Accidental Loss of Client Information
Vermont’s Governor signed S135 that will expand economic opportunity for financial technology industries.
Arizona’s Governor signed HB2417 that recognizes blockchain signatures and smart contracts
Buckley Sandler | Vermont Governor Enacts Law Including Blockchain Application
GOP Data Firm, Deep Root Analytics, stored personal details of roughly 198 million citizens unprotected and publicly assessible.
A cybersecurity firm says potentially all of America’s 200 million registered voters were exposed, including names, dates of birth, home addresses, phone numbers, and voter registration details.
The complaint: McAleer v. Deep Root
SC Media | No recourse, perhaps, for 200M affected in breach of RNC database, attorney says
21 States responded to President Trump’s repeal of Obama era internet privacy regulations, by offering state regulations for internet privacy. Let’s take a peak.
In California, one internet service providfer, AT&T, has spent $2.71M in the last year.
Federal preemption isn’t a concern because the FCC laws and rules share duties with the states and there is no explicit preemption.
NCSL | PRIVACY LEGISLATION RELATED TO INTERNET SERVICE PROVIDERS
The Recorder | Calif. Pushes Internet Privacy Rules That Trump Repealed
21 States responded to President Trump’s repeal of Obama era internet privacy regulations, by offering state regulations for internet privacy. Let’s take a peak.
In California, Assembly Bill 375, will:
Federal preemption isn’t a concern because the FCC laws and rules share duties with the states and there is no explicit preemption.
NCSL | PRIVACY LEGISLATION RELATED TO INTERNET SERVICE PROVIDERS
The Recorder | Calif. Pushes Internet Privacy Rules That Trump Repealed
Some say hospitals that get hit by a ransomware attack need not disclose the ransomware data breach.
The question- If data is held hostage/accessed but is not taken must that be disclosed?
The supporters for disclosure say: More mandatory reporting.This regulatory gap limits the health-care system’s ability to fight cybercriminals.
Who is counted among supporters of disclosure? Congressman Ted Lieu, a California Democrat who along with Congressmen Will Hurd, a Texas Republican
What do hospital lawyers say? Hospitals have financial and competitive incentives to avoid all but required reporting
WallStreet Journal | Why Some of the Worst Cyberattacks in Health Care Go Unreported
Cyber security is becoming an element in analysis for bond markets.
Is this shift a result of a catalyst? Yes, the use of malware toward local governmental entities
Does this follow inthe footsteps of other entities disclosing cyber protections to investors? Yes, utilities and hospitals are starting to disclose any information to potential investors in bond documents about cyber risks or defenses
Reuters | U.S. muni market slowly starts paying heed to cyber risks
State: Illinois
Illinois’ Solutions to prevent election hacking in the 2018 mid term elections:
Politico | LAND OF LINCOLN PREPS FOR 2018
WGN | Illinois among 8 states investigating Russian hacking of its elections
Thank you for subscribing to our newsletter.
Great things are just around the corner!