Lessons Learned (or Not) From the Target Breach

My shopping list was eclectic: a birthday toy for my nephew, shampoo, dog food, and some holiday themed hand towels.  I needed to make the most of my time and budget during this particularly hurried time of the year.  The most logical answer?  Yes, you guessed it.  Target.   As  much as I wanted ...

“Their Office Is Down the Hall”

A number of years ago, I sat in a conference room, slacked jawed, at a response given by a senior manager from an Information Technology team to a federal examiner.  The examiner, in an ad-hoc discussion about organizational structure and process, simply queried about the risk management processe...

Know who is calling

Thanksgiving has always been a good time to catch up with family and friends. One of the themes at our Thanksgiving table this year quickly became privacy.

Four takeaways from the Greater Miami Chamber of Commerce panel

I was honored to be part of the Greater Miami Chamber of Commerce hosted a panel discussion entitled The Convergence of Technology & Banking: Security & Compliance. The panel consisted of Andrew Obuchowski, Jr. of McGladrey LLP, Patrick Whelan of All Covered, Tom Neclerio of SilverSk...

Giving Privacy a Hand

Or just your finger in this case. Today for lunch, I went to Wendy’s.  I strolled up to the counter and, when the cashier took my order, I noticed something awesome.  The person running the register had to use their thumb to access the terminal.  This is sheer genius, I had to know...

Change is Good, but Change is Difficult

One of the most important aspects of a privacy program is making sure that your customers and other stakeholders understand any changes that are made to your privacy policy and notice.  If they know what you are doing, and you are transparent about it, generally you will be able to have positive ...

Breached: a round up of data breaches

Kmart, Goodwill, Home Depot, JP Morgan Chase, PF Chang’s, ACME Financial, Cedars Sinai, Supervalu (twice), Jimmy John’s, Dairy Queen and American Family Care are all included in the list of recently reported data breaches. These events should bring several questions to the mind of any...

A First Timer’s Privacy Academy

Six months ago, I attended my first IAPP Summit in Washington D.C.  In September, I went to the 2014 IAPP Privacy Academy in San Jose; I have to say that I got a lot more out of this event.  This had very little to do with the actual content and people there, and more to […]

Is your organization prepared for a data breach?

Most companies have a crisis communication plan stashed somewhere. Whether it’s policies and procedures reviewed monthly or updated on a yearly basis, companies must prepare for worst-case scenarios. But has your company prepared for a data breach; when your customer’s private and financial infor...

Privacy Awareness: Training lays the foundation

A successful privacy awareness program includes ongoing activities to keep privacy “top of mind” for the members of an organization. It supplements a privacy training program that conveys information in a formal learning environment. For an awareness program to meet its goals, a train...