Showing posts with label privacy breach. Show all posts
Showing posts with label privacy breach. Show all posts

Thursday, February 7, 2019

Is your business PCI compliant? Avoid fines for breaches!

Major breaches like TJMaxx and Target have been widely publicized in the past, but breaches at smaller businesses have received very little attention. This is mainly because information about these smaller occurrences have been very hard to come by due to two reasons.

First, not all states have disclosure laws requiring merchants to disclose breaches and secondly, card associations are not required to disclose individual cases.

According to a Wall Street Journal article, most breaches come from small businesses who are not up to date with technology or compliance laws. Here are some of the article highlights:
  • More than 80% of the credit card breaches have occurred at small businesses.
  • Visa levied $3.3 million in fines for non compliance against small businesses in just one year.
  • MasterCard did not disclose their fines.
  • Any business that accepts credit cards must agree to be PCI complaint.
Take for example the case study of Lodi Beer, a microbrewery and restaurant in California who unknowingly stored 11,728 credit card records in their point of sale system. (Track data from the credit card's magnetic strip cannot be stored according to PCI standards). When that data was breached, Visa and MasterCard fined Abanco, the restaurant's merchant account provider, $27,000. Abanco then in turn passed that fine onto the restaurant. In addition to the fines, this merchant has spent over $50,000 in remediation costs, legal fees, upgrades, etc. That is a huge amount of money for a small business. Had they been up to date with their technology, this situation could have been avoided.

Here are some interesting facts that you should know about PCI compliance standards:
  • Visa, MasterCard and the other card brands have put the responsibility  of maintaining compliance status on the processor or merchant account provider. They've successfully done this with a policy of making them responsible for paying fines when breaches occur.
  • While these processors are responsible for fines, they will almost always pass whatever they're fined onto the merchant.
  • If merchants are ultimately responsible for the fines, it is their responsibility to maintain PCI standards and stay up to date with their technology.

IES would love to help you become compliant. Give us a call at 781-816-9437 or check us out online at iesAdvisors.com.

Monday, March 24, 2014

Microsoft will break into your Outlook, Hotmail, and instant messenger accounts if it deems necessary.

The company's ability (and willingness) to take such an approach became apparent this week. Microsoft admitted in federal court documents that it forced its way into a blogger's Hotmail account to track down and stop a potentially catastrophic leak of sensitive software. The company says its decision is justified.

From the company's point of view, desperate times call for desperate measures.

"In this case, we took extraordinary actions based on the specific circumstances," said John Frank, one of the company's top lawyers, in a blog post Thursday night.

According to an FBI complaint, Microsoft in 2012 discovered that an ex-employee had leaked proprietary software to an anonymous blogger. Fearing that could empower hackers, Microsoft's lawyers approved emergency "content pulls" of the blogger's accounts to track it down. Company investigators entered the blogger's Hotmail account, then pored over emails and instant messages on Windows Live. The internal investigation led to the arrest on Wednesday of Alex Kibkalo, a former Microsoft employee based in Lebanon.

Although the move could be perceived as a breach of trust, Microsoft says it's allowed to make such unilateral decisions. It pointed to its terms of service: When you use Microsoft communication products, (Outlook, Hotmail, Windows Live) you agree to "this type of review ... in the most exceptional circumstances," Frank wrote.

Microsoft's legal team thought there was enough evidence suggesting the blogger would try selling the illegally obtained intellectual property. In such instances, law enforcement agents would typically seek a warrant, but Microsoft said it didn't need one. The servers storing the information are on its own property.

Ginger McCall, a director at the Electronic Privacy Information Center, said those actions are deeply troubling, because they show "Microsoft clearly believes that the users' personal data belongs to Microsoft, not the users themselves."

"This is part of the broader problem with privacy policies," she said. "There are hidden terms that the users don't actually know are there. If the terms were out in the open, people would be horrified by them."

Microsoft recognizes that it's a sensitive topic, especially as the nation grapples with revelations about the extent of warrantless surveillance on Americans by their own government -- spying that Microsoft and other major tech companies have loudly criticized.

That's why Microsoft is instituting a new policy: In the future, it'll loop in an outside lawyer who's a former federal judge and seek his or her approval.

In a move that might be deemed ironic, Microsoft will now add its own internal searches to its biannual transparency reports on government surveillance.

Source: CNN