Privacy & Compliance
NYDFS Cybersecurity Regulation in Plain English
Mar 29, 2020
Learn about the new NYDFS cybersecurity regulation and the rules for basic principles of data security, documentation of security policies, and much more.
How Privacy Policies Have Changed Since GDPR
Jun 25, 2018
In March the EU's General Data Protection Regulation went into effect. The data privacy law aims to create greater transparency around how personal data is handled. As a result of GDPR, privacy policies across the web were changed. We look at how GDPR changed the policies of some of tech's biggest names.
Canada’s PIPEDA Breach Notification Regulations Are Finalized!
May 02, 2018
While the US — post-Target, post-Sony, post-OPM, post-Equifax — still doesn’t have a national data security law, things are different north of the border. Canada, like the rest of the...
Another GDPR Gotcha: HR and Employee Data
Apr 20, 2018
Have I mentioned recently that if you’re following the usual data security standards (NIST, CIS Critical Security Controls, PCI DSS, ISO 27001) or common sense infosec principles (PbD), you shouldn’t...
SHIELD Act Will Update New York State’s Breach Notification Law
Apr 12, 2018
Those of you who have waded through our posts on US state breach notification laws know that there are few very states with rules that reflect our current tech realities....
What Experts Are Saying About GDPR
Apr 11, 2018
You did get the the memo that GDPR goes into effect next month? Good! This new EU regulation has a few nuances and uncertainties that will generate more questions than...
GDPR By Any Other Name: The UK’s New Data Protection Bill
Oct 23, 2017
Last month, the UK published the final version of a law to replace its current data security and privacy rules. For those who haven’t been following the Brexit drama now...
Data Security Compliance and DatAdvantage, Part III: Protect and Monitor
Apr 20, 2017
At the end of the previous post, we took up the nuts-and-bolts issues of protecting sensitive data in an organization’s file system. One popular approach, least-privileged access model, is often...
Data Security Compliance and DatAdvantage, Part II: More on Risk Assessment
Apr 14, 2017
I can’t really overstate the importance of risk assessments in data security standards. It’s really at the core of everything you subsequently do in a security program. In this post...
Data Security Compliance and DatAdvantage, Part I: Essential Reports for Risk Assessment
Apr 03, 2017
Over the last few years, I’ve written about many different data security standards, data laws, and regulations. So I feel comfortable in saying there are some similarities in the EU’s...
Cybercrime Laws Get Serious: Canada’s PIPEDA and CCIRC
Mar 20, 2017
In this series on governmental responses to cybercrime, we’re taking a look at how countries through their laws are dealing with broad attacks against IT infrastructure beyond just data theft....
Cybersecurity Laws Get Serious: EU’s NIS Directive
Feb 21, 2017
In the IOS blog, our cyberattack focus has mostly been on hackers stealing PII and other sensitive personal data. The breach notification laws and regulations that we write about require...
Try Varonis free.
Deploys in minutes.