12/3/2018 1
NYPWA January 2019
Protecting Our Clients
A guided discussion on privacy, security, confidentiality and compliance
NYPWA January 2019 2
Update: What’s happening in the cybersecurity world
NYPWA January 2019 3
Update: Whats happening in the cybersecurity world NYPWA January - - PDF document
12/3/2018 Protecting Our Clients A guided discussion on privacy, security, confidentiality and compliance NYPWA January 2019 NYPWA January 2019 2 Update: Whats happening in the cybersecurity world NYPWA January 2019 3 1 12/3/2018
NYPWA January 2019
NYPWA January 2019 2
NYPWA January 2019 3
NYPWA January 2019 4 NYPWA January 2019 5
NYPWA January 2019 6
https://www.businessinsider.com/hackers-stole-a-casinos-database-through-a- thermometer-in-the-lobby-fish-tank-2018-4
NYPWA January 2019 7
http://www.govtech.com/security/Student-Behind-Illinois-High-School-Hack.html
NYPWA January 2019 8
https://www.law.com/therecorder/2018/04/24/sec-wallops-yahoo-with-35m-penalty-over- breach-disclosures-or-lack-thereof/
NYPWA January 2019 9
Ineffective Identification Poor Detection No Segmentation, Poor Data Governance No Query Limits
https://www.bankinfosecurity.com/postmortem-behind-equifax-breach-multiple-failures-a-11480
NYPWA January 2019 10
NYPWA January 2019 11
NYPWA January 2019 12
NYPWA January 2019 13
https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf
Fourth Amendment search – Fourth Amendment protects certain expectations of privacy in addition to property interests
fit in existing precedents – Expectation of privacy in physical location and movements – Expectation of privacy in information voluntarily turned over to third parties
NYPWA January 2019 14
NYPWA January 2019 15
NYPWA January 2019 16
NYPWA January 2019 17
NYPWA January 2019 18
NYPWA January 2019 19
NYPWA January 2019 20
http://www.nycourts.gov/rules/jointappellate/ny-rules-prof-conduct-1200.pdf
NYPWA January 2019 21
To maintain the requisite knowledge and skill, a lawyer should (i) keep abreast of changes in substantive and procedural law relevant to the lawyer’s practice, (ii) keep abreast of the benefits and risks associated with technology the lawyer uses to provide services to clients or to store or transmit confidential information, and (iii) engage in continuing study and education and comply with all applicable and continuing legal education requirements under 22 N.Y.C.R.R. Part 1500. (emphasis added)
https://www.nysba.org/DownloadAsset.aspx?id=50671
NYPWA January 2019 22
ABA Commission on Ethics 20/20 Report 105A (Aug. 2012)
https://www.americanbar.org/content/dam/aba/administrative/ethics_2020/20120808_revi sed_resolution_105a_as_amended.authcheckdam.pdf
NYPWA January 2019 23
NYPWA January 2019 24
NYPWA January 2019 25
http://www.abajournal.com/news/article/lawyers_e_discovery_error_led_to_release_of_confidential_wells_fargo_client/ NYPWA January 2019 26
NYPWA January 2019 27
NYPWA January 2019 28
Confidentiality Integrity Availability
NYPWA January 2019 29
NYPWA January 2019 30
NYPWA January 2019 31
NYPWA January 2019 32
Multiple pieces of data are provided to government entities on a daily basis and stored within databases
NYPWA January 2019 33
the data being created, stored, and shared?
breach?
NYPWA January 2019 34
NYPWA January 2019 35
protection of public data
– IRS Publication 1075 – HIPAA – Federal Parent Locator Service Agreement – Security Breach and Notification Act
NYPWA January 2019 36
NYPWA January 2019 37
NYPWA January 2019 38
Examples
Private Individualized Public
Directories, Maps, Lost Phone*, Lost Laptop*, Job Postings, Marketing Material, Press Releases Employment data Software keys Contracts/Budget Meeting information Personal data ** no ss # ** Design /planning /Project documents SS #s Health Plan Info Health Care Info Passwords Driver License Financial Info Tax Info Unencrypted devices
NYPWA January 2019 39
NYPWA January 2019 40
NYPWA January 2019 41
NYPWA January 2019 42
NYPWA January 2019 43
NYPWA January 2019 44
NYPWA January 2019 45
NYPWA January 2019 46
NYPWA January 2019 47
NYPWA January 2019 48
Carmela Pellegrino, Esq. Associate Attorney Division of Legal Affairs OTDA 518-473-8266 Carmela.Pellegrino@otda.ny.gov Meghan A. Deltry, Esq. Assistant Counsel Division of Legal Affairs OTDA 518-474-5638 Meghan.Deltry@otda.ny.gov Scott Rogler, CISSP, GSEC OTDA ISO Division of Legal Affairs OTDA 518-474-4964 Scott.Rogler@otda.ny.gov