Affordable Care Act Update

Despite becoming law over four years ago, the Affordable Care Act continues to make headlines. Since it’s not easy to keep track of all the changes, let’s take a look at some of the more significant recent developments.

Elimination of Small Group Deductible Limits

A significant ACA change scheduled to take effect in 2014 involves annual deductible limits for small groups. Under this provision, small group health plan deductibles could not be more than $2,000 for individuals or $4,000 for families. Those who were concerned about the lack of flexibility caused by these deductible limits no longer have to worry.

The small group deductible limits were rather unceremoniously eliminated by the Protecting Access to Medicare Act, which was signed into law on April 1, 2014. Since these limits were retroactively eliminated back to the day the ACA was originally enacted, it’s almost like they never existed. This is welcome news for many small groups, which are typically those employers with up to 50 employees, but which may be employers with up to 100 employees.

However, it is important to note that the ACA’s annual out-of-pocket cost-sharing limits have not changed. Since these cost-sharing limits specifically apply to deductibles, among other things, employers must still be aware of indirect deductible limitations. The 2014 annual out-of-pocket limit is $6,350 for individuals and $12,700 for families.

Updated Model COBRA Notices

Under the Consolidated Omnibus Budget Reconciliation Act (COBRA), employees and their families may have the option of staying on their former employer’s health insurance plan for a limited period of time after their employment ends. Despite having to pay the entire premium, including any portion previously paid by their employer, COBRA coverage has typically been cheaper than individual or family coverage because the premiums are based on the employer’s group rates. However, with the new Health Insurance Marketplace created by the ACA, this may no longer be the case.

Phyllis C. Borzi, Assistant Secretary of Labor for Employee Benefits Security, said that, “in many cases, workers eligible for COBRA continuation coverage can save significant sums of money by instead purchasing health insurance through the Marketplace…It is important that workers know that in some cases there is a Marketplace option as well.”

To let employees know they may have an alternative to continuing their health care coverage under COBRA, the Department of Labor updated its Model COBRA General Notice and Model COBRA Election Notice. According to the Department of Labor, these updated notices make it clear to workers that if they are eligible for COBRA continuation coverage when leaving a job, they may choose to instead purchase coverage through the Health Insurance Marketplace.

Employer Mandate

In February 2014, the Internal Revenue Service provided transition relief from the ACA’s employer responsibility provisions. Employers with 100 or more employees wanting to avoid the penalty must offer coverage to 70% of their full-time employees in 2015, and 95% in 2016 and beyond. Large employers that do not meet these standards will have to make employer responsibility payments beginning in 2015. Employers with 50 to 99 full time employees will not be subject to a penalty until 2016, provided they meet certain conditions.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Is a Resident Manager Ideal for Your Self Storage Facility?

Resident managers are not as common as they used to be in the self storage industry. For some self storage facilities, however, a manager living on the premises may be the key to running a successful operation. Though cost is an important factor when deciding whether a self storage facility could benefit from a resident manager, other factors should be considered as well, such as:

Service: Automated facilities may not be enough to create an advantage over the competition. Depending on a self storage facility’s location or specialty, clients may want more than just an access code after signing a contract. Facilities with a resident manager can service clients in ways that others cannot. This is why the existence of a resident manager is often mentioned in promotional and marketing materials.

Security: Even with surveillance cameras and 24-hour monitoring services, it is difficult to deny that resident managers can make a self storage facility even more secure. Their presence alone will likely deter most criminals, and their response time will be quicker than even the fastest police departments.

Operations: Things can and often do go wrong after business hours. Leaking pipes and short-circuits are just two things that can cause significant damage if they are not discovered and fixed quickly. A resident manager can find and fix those problems that cannot wait.

Qualified Candidates: It’s not always easy to find and retain the right people. Providing prospective managers with a place to live may be just the perk required to hire and keep quality talent.

After evaluating all the pros and cons in the context of each facility’s own particular situation, an informed decision can be made about whether a resident manager could improve operations. However, before making a final decision, it is important to understand the ramifications of hiring a resident manager, particularly how doing so may create an unexpected relationship.

In addition to creating an employer-employee relationship, hiring a resident manager can also create a landlord-tenant relationship. While employers can often terminate employees at-will and without advance notice, the same cannot usually be done with tenants. Depending on applicable law, a self storage facility will generally be required to provide advance written notice to terminate the landlord-tenant relationship. As a result, a resident manager may be legally entitled to continue renting the property for a period of time after his or her employment has been terminated.

There are steps that can be taken to minimize the scope and impact of the landlord-tenant aspects of a resident manager’s employment relationship. For example, a self storage facility can address landlord-tenant issues in a written employment agreement or in a separate lease agreement. However, since specific legal requirements must be met, it is advisable to seek the advice of a locally licensed attorney.

As is often the case, it is necessary to understand the risks in order to control them. Since self storage facilities face unique risks, it helps to have an insurance program that is specifically designed for the self storage industry. If you would like more information about Setnor Byer Insurance & Risk’s Self Storage Insurance Program, please contact us.

If you would like to subscribe to our newsletters please click here.

Why Did I Get a Reservation of Rights Letter?

Upon receiving notice of a claim, an insurance company must determine whether it is covered by a policy. If a claim is clearly covered, the insurance company will begin the process of defending or indemnifying the insured. Alternatively, claims that are clearly not covered will be denied. A Reservation of Rights letter is used when the insurance company isn’t sure whether a claim is covered.

Assume a customer files a lawsuit after being injured by a falling box. If the box fell because it was carelessly placed on a high shelf, a general liability policy would likely cover the claim. Coverage would be unlikely, however, if the box was intentionally dropped on the customer.

Though it may take months to find out what happened, the insurance company may only have days to take action. Rather than risk denying a covered claim, the insurance company can send the insured a Reservation of Rights letter, which gives the insurance company time to investigate the claim, and defend it, if necessary, without waiving its right to deny all or part of a claim at a later time if the facts ultimately establish a lack of coverage.

A Reservation of Rights letter also puts the insured on notice that all or part of a claim may not be covered. According to the California Supreme Court, by providing a Reservation of Rights letter, “the insurer gives the insured notice of how it will, or at least may, proceed and thereby provides it an opportunity to take any steps that it may deem reasonable or necessary in response–including whether to accept defense at the insurer’s hands and under the insurer’s control or, instead, to defend itself as it chooses.”

Reservation of Rights letters are used when the facts or the policy language may justify denying coverage for a claim. For example, insurance companies may use a Reservation of Rights letter when:

  • An exclusion in the policy does or may apply
  • The allegations in a lawsuit may be beyond the scope of coverage under a policy
  • Some or all of the damages are not covered by the policy
  • The insured may have failed to satisfy their obligations under the policy

A Reservation of Rights letter will typically:

  • Identify the specific policy covered by the letter
  • Summarize relevant facts
  • Quote relevant policy language
  • Identify and explain coverage and policy defenses

Though a Reservation of Rights letter does not necessarily mean that a claim will be denied, it must still be taken seriously. Depending on the nature of the claim and the potential exposure, professional guidance may be necessary when responding to a Reservation of Rights letter. An experienced and reputable insurance agent can help identify concerns, evaluate options and prepare a response.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Developing a Cybersecurity Framework

In February 2013, President Obama issued Executive Order 13636 on Improving Critical Infrastructure Cybersecurity. This Order calls for the development of a framework of industry standards and best practices to help organizations manage increasing cybersecurity risks. On February 12, 2014, the National Institute of Standards and Technology (NIST) responded to the President’s order with its Cybersecurity Framework.

The Cybersecurity Framework, which was created in collaboration with the private sector, focuses on using business drivers to guide cybersecurity activities. It is a risk-based approach that uses common language to address and manage cybersecurity risks in a business-specific, cost effective way. This voluntary framework is made up of three parts, each of which reinforces the connection between business drivers and cybersecurity activities.

The Framework Core provides a set of activities designed to achieve specific cybersecurity outcomes. The core is made up of five broad functions that help organizations express their management of cybersecurity risks.

  • Identify: Develop organizational understanding to manage cybersecurity risks to systems, assets, data and capabilities.
  • Protect: Develop and implement appropriate safeguards to ensure delivery of critical infrastructure services.
  • Detect: Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.
  • Respond: Develop and implement appropriate activities to respond to a cybersecurity event.
  • Recover: Develop and implement appropriate activities to maintain operations and restore capabilities or services impaired by a cybersecurity event.

Framework Implementation Tiers provide context on how organizations view cybersecurity risks and the processes in place to manage that risk. Tiers are used to describe an organization’s commitment and sophistication in managing cybersecurity risks. They also describe the extent to which cybersecurity risk management is informed by business needs and integrated into an organization’s overall risk management practices.

The four tiers reflect a progression from informal, reactive responses to cybersecurity risks to approaches that are agile and risk-informed.

  • Tier 1 (Partial)
  • Tier 2 (Risk Informed)
  • Tier 3 (Repeatable)
  • Tier 4 (Adaptive)

Determining which tier applies to an organization depends on current risk management practices, threat environment, regulatory requirements, business objectives and organizational constraints. However, the NIST notes that tiers do not represent maturity levels, so progression to higher tiers is encouraged when it would reduce cybersecurity risks in a cost effective manner.

The Framework Profile is the alignment of an organization’s cybersecurity framework with its business requirements, risk tolerance and resources. Profiles enable organizations to establish a roadmap for reducing cybersecurity risk that meets organizational goals, implements best practices, considers regulatory requirements and reflects priorities.

Profiles can be used to describe an organization’s current state or target state of cybersecurity activities. Comparing current and target profiles can be used to identify gaps in an organization’s cybersecurity risk management practices. Given the need for flexibility, the NIST did not impose or require a specific form or format that must be followed when creating and implementing a profile.

It is important to remember that the Cybersecurity Framework is voluntary and that, according to the NIST, it will not place additional regulatory requirements on businesses. Nevertheless, it should serve as a reminder that data security breaches can happen to any organization.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches

If you would like to subscribe to our newsletters please click here.

Insurance for Tech Companies

Since most businesses rely on technology, providing technology services has become big business. Technology companies provide goods, services and expertise that can increase efficiency, productivity and profitability. These businesses may involve:

  • System / network development and administration
  • Application and website programming and design
  • Hardware installation and repair
  • Website hosting, maintenance and optimization
  • Information Technology consulting, staffing and training
  • Project management
  • Consulting

Technology companies face the same risks as other businesses, so traditional insurance coverages are required, such as general liability, property, automobile and workers compensation insurance. However, additional insurance coverage may also be necessary to address the unique risks facing technology companies.

For example, many technology companies do not believe they need Errors & Omissions (Professional Liability) insurance. The reality is that technology companies, just like doctors and lawyers, can be held liable for errors and omissions committed in the performance of their professional services.

Unfortunately, a traditional E&O policy may not protect against many of the risks unique to technology companies. This is why technology-specific insurance is needed to cover technology-specific risks. To ensure adequate insurance coverage, technology companies should look for an E&O policy that, at a minimum:

  • Broadly defines “Computer Technology Services”
  • Provides coverage for failure to prevent unauthorized access to or use of any electronic system or program of a third party
  • Provides coverage for unauthorized, corrupting or harmful pieces of code, including, computer viruses, worms and Trojan Horses
  • Covers personal injury claims alleging wrongful entry, wrongful eviction, wrongful detention, false arrest, false imprisonment, libel, slander or defamation, advertising injury or violation of any right of privacy
  • Provides sufficient coverage limits

The right E&O policy lets technology companies focus on their business knowing that they are protected in the event of a claim. And, since clients are increasingly requiring proof of E&O insurance from their technology vendors, an E&O policy may also create new opportunities.

Given the complexity of the risks facing technology companies, evaluating insurance needs and options is not always easy. For example, in addition to E&O insurance, technology companies may also need coverage for cyber liability claims, including data security breaches, which are becoming more common.

An experienced insurance agent can guide you through the process of protecting your technology company. If you would like to learn more about insuring a technology company, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Offering Health Insurance to Same-Sex Spouses

Under the Affordable Care Act, health insurance issuers in the individual and group markets are generally required to guarantee insurance coverage to every employer and individual that applies. Beginning in 2015, this guarantee will extend to same-sex spouses.

On March 14, 2014, the Department of Health & Human Services (HHS) announced that insurance companies offering non-grandfathered health insurance plans can no longer refuse to offer health insurance coverage to same-sex spouses. In taking this position, the HHS relied on federal regulations prohibiting health insurance issuers from employing marketing practices or benefit designs that discriminate on the basis of, among other things, an individual’s sexual orientation.

According to HHS, an issuer is considered to employ discriminatory marketing practices or benefit designs if the issuer:

  • Offers health insurance coverage to a spouse in an opposite-sex marriage; and
  • Does not offer the same coverage to a spouse in a same-sex marriage that was validly consummated in a jurisdiction where the law authorizes same-sex marriages.

Importantly, the prohibition against discriminating against same-sex spouses applies regardless of the jurisdiction in which the insurance policy is offered, sold, issued, renewed, in effect, or operated, and regardless of where the policyholder resides. This means that insurance companies must offer coverage to legally married same-sex spouses even if they live in a state that does not allow same-sex marriages.

HHS noted that its position regarding coverage for same-sex spouses does not require a group health plan to provide coverage that is inconsistent with the terms of eligibility for coverage under the plan, or that otherwise interferes with the ability of a plan sponsor to define a dependent spouse for purposes of eligibility for coverage under the plan. It only prohibits an issuer from refusing to offer the option to cover same-sex spouses on the same terms and conditions as opposite sex-spouses.

According to HHS, it is only clarifying the current regulations’ prohibition against discrimination based on sexual orientation in a manner that is consistent with the policy of ensuring that all individuals have access to health coverage. However, since “some issuers may not have understood the prohibition,” HHS is not requiring immediate compliance. Rather, health insurance issuers must implement changes for plans or policies years beginning on or after January 1, 2015.

Though fewer than half the states allow same-sex marriages, employers in every state need to be aware of health insurance requirements for same-sex spouses. Beginning in 2015, the focus will need to be on the legality of the marriage rather than the gender of the spouses.

Recent developments with the Affordable Care Act suggest that change rather than stability should be expected. At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014 and beyond. Check back with us periodically for future informational updates about the Affordable Care Act.

If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you would like to subscribe to our newsletters please click here.

Implementing a Drug-Free Workplace Program

Though many believe substance abuse is not a problem in their workplace, statistics suggest otherwise. According to the National Institute on Drug Abuse (NIDA), nearly 75% of substance and alcohol abusers are employed. In addition to costing employers billions of dollars per year, substance abusers are more likely to:

  • Change jobs frequently
  • Be late to or absent from work
  • Be less productive
  • Be involved in a workplace accident
  • File a workers’ compensation claim

To help combat the problem, many employers have implemented a Drug-Free Workplace program. These programs incorporate various elements designed to prevent substance abusers from entering the workplace, identify and assist those already in the workplace, and eliminate continuing abusers from the workplace.

According to NIDA, employers with Drug-Free Workplace programs:

  • Report improvements in morale and productivity, and decreases in absenteeism, accidents, downtime, turnover, and theft
  • Report better health status among employees and family members and decreased use of medical benefits by these same groups

Employers can also reduce their workers’ compensation insurance premiums by implementing a Drug-Free Workplace program. For example, a 5% premium credit is available in Alabama, Florida, South Carolina and Virginia. Employers can save up to 7% in Ohio, and 7.5% in Georgia. Additionally, employers with fewer workplace accidents can also see reduced premiums due to an improved experience modification rating.

States have their own requirements for determining whether a Drug-Free Workplace program qualifies for a workers’ compensation premium credit. Since they can be very specific and technical, it is important to consult with a licensed professional prior to implementing a Drug-Free Workplace program.

If you have any questions about implementing a Drug-Free Workplace program or you would like to learn more about reducing your insurance premiums, please contact us.

If you would like to subscribe to our newsletters please click here.   

Let’s Talk About Data Security Breaches

The theft of credit and debit card information from Target’s computer systems should serve as a reminder that the risk of a data security breach must be taken seriously. Every organization must have a plan to not only prevent data security breaches, but to respond to them as well.

The first step is to identify vulnerabilities with a risk assessment. Unfortunately, this can be difficult because data security breaches can come from pretty much anywhere, including employees, laptop computers, copy machines and wireless networks. To make the process easier, organizations can perform a self-audit.

The Online Trust Alliance has come up with a series of risk assessment questions that are designed to help organizations identify vulnerabilities and gauge their level of preparedness. For example:

  • Are there any regulatory requirements that are specifically applicable to your business operations or geographic location?
  • What customer-specific data is collected? How, where and by whom is this data stored, maintained and archived? Can you identify points of vulnerability and risk?
  • Is the kind of customer-specific data you collect necessary for business operations? For example, is it necessary to request drivers’ license information or social security numbers?
  • Do you follow best practices for encryption and de-identification processes?
  • Is there an incident response team in place? Is there a clear reporting process in the event of an accidental data loss or a breach?
  • Is there a plan for communicating to employees, customers, partners, stockholders and the media in the event of a breach?
  • Are generally accepted security and privacy best practices followed? If not, why?
  • Is there a privacy policy reflecting current data collection and sharing practices, including the use of third-party advertisers and cloud service providers? Have systems been audited to confirm compliance with written policies?
  • Is there a contact person in the event of a breach? Has a person been assigned to work with the authorities, such as the FBI, Secret Service and State Attorney General Office?
  • Are you willing to sign off on your Data Incident Plan and represent to board members, investors and regulators that it contains best practices for preventing and responding to data security breaches?

This kind of self-audit should encourage discussion and evaluation of an organization’s specific data security risks. And, since the questions are general in nature, they can be used by most organizations, regardless of industry or location.

As we have seen, preventative measures are not foolproof, so organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like a professional audit please contact us to learn more.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Affordable Care Act’s Employer Mandate Delayed…Again

On February 10, 2014, the U.S. Department of the Treasury and the Internal Revenue Service (IRS) issued final regulations implementing the employer responsibility provisions under the Affordable Care Act (ACA). Despite being previously delayed, the final regulations provide transition relief to employers with 50 or more employees, which, according to the administration, should ensure a gradual phase-in of the employer mandate.

Since the employer mandate does not apply to employers with fewer than 50 employees, small employers are not required to provide coverage or fill out any forms in 2015, or in any year, under the ACA. For employers with 50 or more full-time employees, the final regulations provide the following transition relief.

Large Employers (100 or more employees): The final regulations reduce the percentage of full-time employees that must be offered health coverage. To avoid paying a penalty, large employers must offer coverage to 70% of their full-time employees in 2015, and 95% in 2016 and beyond. Large employers that do not meet these standards will have to make employer responsibility payments beginning in 2015.

Medium Employers (50 to 99 employees): The employer responsibility provisions will not apply to employers with 50 to 99 full-time employees until 2016. However, to be eligible for this transition relief, employers must certify that they meet the following conditions:

  • Limited Workforce Size. The employer must employ an average of at least 50 but fewer than 100 full-time employees (including full-time equivalents) on business days during 2014. The number of full-time employees (including full-time equivalents) is determined in accordance with the otherwise applicable rules in the final regulations for determining status as an applicable large employer.
  • Maintenance of Workforce and Aggregate Hours of Service. From February 9, 2014 to December 31, 2014, the employer may not reduce the size of its workforce or the overall hours of service of its employees in order to qualify for the transition relief. However, an employer that reduces workforce size or overall hours of service for bona fide business reasons is still eligible for the relief.
  • Maintenance of Previously Offered Health Coverage. From February 9, 2014 to December 31, 2015 (or, for employers with non-calendar-year plans, the last day of the 2015 plan year), the employer does not eliminate or materially reduce the health coverage, if any, it offered as of February 9, 2014. An employer will generally not be treated as eliminating or materially reducing health coverage if: (i) the employer contributes at least 95 percent of the dollar amount or at least the same percentage of the cost of coverage that was offered on February 9, 2014; (ii) any changes in benefits to employee-only coverage continue to provide minimum value; and (iii) the employer does not narrow or reduce the classes of employees (or the employees’ dependents) to whom coverage under was offered on February 9, 2014.

Since the final regulations cover a number of different topics and are highly technical, employers looking to take advantage of the transition relief should consult with a licensed professional.

Though many welcome the transition relief provided in the final regulations, it doesn’t look like 2014 will bring stability and predictability to health care under the Affordable Care Act. At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Data Security Breaches: Lessons from 2013

They say that those who fail to learn from history are doomed to repeat it, and 2013 provided many lessons for those wishing to avoid a data security breach. Let’s review some of 2013’s data security breaches so that they do not have to be repeated in 2014.

Target. During the peak of the 2013 holiday season, Target suffered what may be one of the largest data security breaches in U.S. retail history. Target’s breach involved the credit and debit card accounts of about 40 million customers. Though Target believes the data remains safe because it was strongly encrypted, it may be used to gain access to customers’ accounts. There are estimates that this breach may end up costing Target billions of dollars.

Adobe. Adobe Systems, Inc. suffered a data security breach that compromised nearly 3 million records. Hackers were able to access customers’ IDs, encrypted passwords, names, encrypted credit or debit card numbers, expiration dates and other information related to their orders.

Facebook. Facebook was targeted in a sophisticated attack when a handful of employees visited a website that was compromised. This website hosted an exploit which allowed malware to be installed on employee laptops, even though they were running up-to-date anti-virus software. Facebook analyzed the source of the attack and discovered a previously unseen way to bypass security measures and to install the malware.

Washington State Courts. The Washington State Administrative Office of the Courts suffered a security breach on its public website. Though no court records were altered and no personal financial information is maintained on the website, the breach may have exposed up to 160,000 social security numbers and 1 million driver license numbers.

Twitter. After detecting unusual access patterns, Twitter discovered unauthorized attempts to access user data. According to Twitter, approximately 250,000 users may have had their information accessed by the attackers, including their usernames, email addresses, session tokens and encrypted/salted versions of passwords. These users had their passwords reset and their session tokens revoked by Twitter.

New York Times. Chinese hackers infiltrated The New York Times’ computer systems and obtained corporate passwords for its reporters and other employees. According to The New York Times, over the course of three months, 45 pieces of custom malware were installed on their network and used to gain access to computers. To get rid of the hackers, The New York Times blocked the compromised outside computers, removed every back door into its network, changed every employee password and wrapped additional security around its systems.

Evernote. Evernote appears to have been the victim of a coordinated attempt to access secure areas of its network. Their investigation revealed that hackers were able to access user information, including usernames, email addresses and encrypted passwords. Though Evernote believes that the passwords remain protected by encryption, all users were required to reset their account passwords.

These incidents show that data security breaches can happen to any organization, and that they can be very costly. Every organization must be proactive in protecting against data security breaches. Though protective measures should cover everything from the wireless network to the copy machine, organizations should also consider protecting against data security breaches with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.