Data Security Breaches: Lessons from 2013

They say that those who fail to learn from history are doomed to repeat it, and 2013 provided many lessons for those wishing to avoid a data security breach. Let’s review some of 2013’s data security breaches so that they do not have to be repeated in 2014.

Target. During the peak of the 2013 holiday season, Target suffered what may be one of the largest data security breaches in U.S. retail history. Target’s breach involved the credit and debit card accounts of about 40 million customers. Though Target believes the data remains safe because it was strongly encrypted, it may be used to gain access to customers’ accounts. There are estimates that this breach may end up costing Target billions of dollars.

Adobe. Adobe Systems, Inc. suffered a data security breach that compromised nearly 3 million records. Hackers were able to access customers’ IDs, encrypted passwords, names, encrypted credit or debit card numbers, expiration dates and other information related to their orders.

Facebook. Facebook was targeted in a sophisticated attack when a handful of employees visited a website that was compromised. This website hosted an exploit which allowed malware to be installed on employee laptops, even though they were running up-to-date anti-virus software. Facebook analyzed the source of the attack and discovered a previously unseen way to bypass security measures and to install the malware.

Washington State Courts. The Washington State Administrative Office of the Courts suffered a security breach on its public website. Though no court records were altered and no personal financial information is maintained on the website, the breach may have exposed up to 160,000 social security numbers and 1 million driver license numbers.

Twitter. After detecting unusual access patterns, Twitter discovered unauthorized attempts to access user data. According to Twitter, approximately 250,000 users may have had their information accessed by the attackers, including their usernames, email addresses, session tokens and encrypted/salted versions of passwords. These users had their passwords reset and their session tokens revoked by Twitter.

New York Times. Chinese hackers infiltrated The New York Times’ computer systems and obtained corporate passwords for its reporters and other employees. According to The New York Times, over the course of three months, 45 pieces of custom malware were installed on their network and used to gain access to computers. To get rid of the hackers, The New York Times blocked the compromised outside computers, removed every back door into its network, changed every employee password and wrapped additional security around its systems.

Evernote. Evernote appears to have been the victim of a coordinated attempt to access secure areas of its network. Their investigation revealed that hackers were able to access user information, including usernames, email addresses and encrypted passwords. Though Evernote believes that the passwords remain protected by encryption, all users were required to reset their account passwords.

These incidents show that data security breaches can happen to any organization, and that they can be very costly. Every organization must be proactive in protecting against data security breaches. Though protective measures should cover everything from the wireless network to the copy machine, organizations should also consider protecting against data security breaches with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

IRS Modifies “Use-or-Lose” Rule for Flexible Spending Accounts (FSAs)

On October 31, 2013, the Internal Revenue Service (IRS) modified the longstanding cafeteria plan “use-or-lose” rule for health Flexible Spending Accounts/Arrangements (FSAs). Under this rule, unused FSA account balances are forfeited at the end of the plan year. Now, up to $500 of unused money may be carried over to the next plan year.

A cafeteria plan FSA, which is offered with other employer-established benefits, reimburses employees for qualified medical expenses. FSAs are usually funded by employees through voluntary salary reductions of up to $2,500 per year, though employers may also contribute. FSA contributions are not included in an employee’s income and reimbursements for qualified medical expenses are not taxed.

For nearly 30 years, FSAs have been subject to the “use-or-lose” rule. However, last year the IRS asked whether the rule should be modified to provide greater flexibility. The overwhelming response was yes. The reasons for increased flexibility include:

  • Difficulties in predicting future medical expenditures
  • Minimizing incentives for unnecessary spending to avoid forfeiture
  • The possibility that lower paid employees are reluctant to participate in FSAs because even modest forfeitures can be significant
  • Easing and simplifying the administration of FSAs

Under the new rule for cafeteria plan FSAs, employers may allow employees to carryover up to $500 of unused FSA money to the next plan year. Any amounts carried over may be used to pay or reimburse medical expenses incurred during that entire plan year. Employers have the option, not the obligation, to let employees carryover unused FSA money. And, since $500 is the maximum amount that can be carried over, employers may choose a lower amount.

Currently, cafeteria plans are allowed to have a “grace period” of up to two months and 15 days after the plan year during which participants may use remaining FSA money from the previous plan year to pay expenses incurred during the grace period. Since this is a popular feature among many plans, it is important to note that plans may provide employees with a carryover option OR a grace period. A health FSA cannot have both.

Employers wishing to utilize the new carryover option must amend their cafeteria plan. The amendment must be adopted on or before the last day of the plan year and may, in some cases, be effective retroactively to the first day of that plan year. Plans must also be amended to eliminate any grace period by no later than the end of that plan year, though the IRS notes that this may be subject to “non-code legal constraints.”

Given the complexity of providing and managing cafeteria plans, as well as the liability for getting it wrong, employers should consult with appropriate professionals to make sure their plans meet their minimum needs and provide maximum benefits.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Are You Ready for Halloween’s Scary Treats?

Halloween is here! Get ready for the costumes, parties, pranks, trick-or-treaters, candy and…the risk. Every year we are reminded how quickly Halloween celebrations can go wrong. Since cancelling Halloween is not an option, it is important to identify risks that can be controlled and insure against those that cannot.

Vehicle-Pedestrian Accidents

A study by the Centers for Disease Control and Prevention found that the number of childhood pedestrian deaths increased fourfold among children on Halloween. The following tips can limit the likelihood of being involved in a vehicle-pedestrian accident.

  • Slow down and be alert. Children may move in unpredictable and unsafe ways.
  • Take extra time at intersections. Pay attention to medians and curbs.
  • Enter and exit driveways slowly and carefully.
  • Eliminate distractions, such as cell phones and music.
  • Turn headlights on earlier in the day

Standard auto insurance policies would typically provide coverage for damage and liability resulting from a vehicle-pedestrian accident, subject to any policy exclusions.

Slips, Trips and Falls

Whether they are trick-or-treaters or party guests, people typically have more visitors than usual on Halloween. This means a higher risk of slip, trip and fall accidents and liability. To prevent accidents:

  • Keep areas well-lit.
  • Remove all objects that could cause children or guests to slip, trip or fall.
  • Make sure Halloween decorations don’t create a hazard.
  • Repair any broken walkways, sidewalks, driveways, paths and steps.
  • Warn visitors of, and clearly mark, any hazards that cannot be removed or repaired.
  • Keep pets inside and away from guests and trick-or-treaters.

If a guest is injured, standard homeowners’ and renters’ policies will typically provide coverage in the event of a lawsuit. These policies may also provide an injured guest with medical coverage, which may help avoid a lawsuit.

Fire

The National Fire Protection Association says that Halloween ranks among the top 5 days of the year for candle-related fires. The NFPA also found that decorations, like jack-o-lanterns, are often the items first ignited in home fires. To prevent fires:

  • Don’t leave candles unattended and keep them away from flammable materials.
  • Make sure decorations and costumes are flame resistant.
  • For decorations requiring electricity, make sure plugs, wires and cords are not damaged and are used properly.

Fires caused by candles or decorations will typically be covered under standard homeowners’ and renters’ policies.

Vandalism

Homes and vehicles are often damaged by mischievous or malicious trick-or-treaters. To limit the risk:

  • Keep areas well-lit.
  • Move items indoors or to another location.

Vandalism damage that exceeds the deductible will typically be covered under standard homeowners’ and renters’ policies. If a car is vandalized, the comprehensive portion of an auto insurance policy should cover the damage.

If you would like more information about identifying and insuring against various risks, please contact us.

If you would like to subscribe to our newsletters please click here.

Self Storage Facilities: Protecting the Bottom Line

Most businesses rely on their facilities to manufacture products or provide services. In the self storage industry, the facilities typically are the product. If property loss or damage is not fixed quickly, the business may fail. Though most believe their self storage facilities are adequately insured against property loss or damage, many overlook Ordinance and Law coverage. This oversight can be the downfall of any self storage facility.

Ordinance and Law insurance is designed to pay the extra expense of rebuilding to comply with ordinances or laws, such as building codes, which did not exist when the building was originally constructed. Since the costs of improving a structure to bring it up to code are specifically excluded under most property policies, this coverage can be quite valuable.

An insured’s obligation to rebuild according to current and stricter codes is often triggered when an insured building experiences a covered loss, such as a fire or hurricane. Unfortunately, many insureds first learn of this additional obligation and expense after they experience a property loss. To avoid the burden of these additional rebuilding costs, self storage facilities can add Ordinance and Law coverage to their current property insurance policies. Doing so will generally cover:

  • Loss to the undamaged portion of the building;
  • Increased demolition costs; and
  • Increased costs of construction.

Since rebuilding according to current building codes may suspend operations for an extended period of time, self storage facilities can purchase Business Interruption insurance to cover reductions in net income caused by an inability to continue business operations. Since payroll, mortgage/rent payments, money owed to suppliers, taxes, and other continuing expenses must be met, Business Interruption insurance may provide badly needed capital when operations are suspended.

Combining Ordinance and Law coverage with Business Interruption coverage, self storage facilities increase the likelihood of surviving not only the initial property loss, but a protracted suspension of operations resulting from the obligation to rebuild in accordance with current building codes.

While the decision to obtain Ordinance and Law and Business Interruption coverage should be easy, understanding specific policy provisions and terms can be difficult. Since there may be variations among different policy forms, it is important that you consult with an experienced insurance agent to discuss your options.

If you would like more information about protecting your self storage facility or obtaining Ordinance and Law and Business Interruption insurance coverage, please contact us.

If you would like to subscribe to our newsletters please click here.

No Penalty for Noncompliance with ACA’s Notice of Coverage Options

On September 11, 2013, the United States Department of Labor announced that employers will not be fined or penalized under the Affordable Care Act for failing to provide employees with notice about coverage options available through the ACA’s Health Insurance Marketplace (Exchanges). This comes just weeks before the October 1, 2013 deadline for employers to begin providing the notice to their employees.

The announcement, which was posted on the DOL’s website as a “FAQ on Notice of Coverage Options,” states:

Q: Can an employer be fined for failing to provide employees with notice about the Affordable Care Act’s new Health Insurance Marketplace?

  1. No. If your company is covered by the Fair Labor Standards Act, it should provide a written notice to its employees about the Health Insurance Marketplace by October 1, 2013, but there is no fine or penalty under the law for failing to provide the notice.

A day later, the U.S. Small Business Administration posted similar information on its website.

This announcement comes as a surprise to those who assumed that noncompliance would be met with a fine or penalty. Though the ACA’s employer notice requirement does not contain a specific penalty provision, many assumed that the ACA’s general penalty of $100 per day would apply. And, since news of the DOL’s position came informally through its website rather than the formal regulatory process, some believe that fines or penalties for noncompliance remain a possibility in the future.

This new development has understandably left many employers unsure about how to deal with the ACA’s employer notice requirement. Though it is still the law, the DOL’s announcement has undoubtedly left many wondering whether a requirement can really exist without consequences.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the constantly changing health care reform landscape. Check back with us periodically for future informational updates about the Affordable Care Act.

If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, view our health product page.

If you would like to subscribe to our newsletters please click here.

What is a Certificate of Insurance?

Certificates of Insurance are documents provided by Agents to verify the existence of insurance coverage. They are commonly used when an agreement or contract requires a party to maintain specific types of insurance. For example, a Certificate of Insurance can be used when:

  • A general contractor wants to verify that its subcontractor has the statutorily required workers’ compensation insurance;
  • A mortgage lender wants to verify that the homeowner has sufficient property insurance;
  • A commercial landlord wants to verify that its tenant has all the insurance coverage required by the lease; or
  • A homeowner wants to verify that its lawn service company has general liability insurance.

Certificates of Insurance are issued to the certificate holder—the person or entity that needs to verify insurance coverage. Though common and relatively straightforward, there is quite a bit of confusion about what Certificates of Insurance do, and more importantly, do not do.

A Certificate of Insurance provides a superficial snapshot of insurance coverage that is in place at the time it is created. Contrary to what many believe, Certificates of Insurance:

  • Are NOT insurance policies.
  • Do NOT provide certificate holders with any rights under the insured’s policies. This means certificate holders cannot file a claim or request a defense under the insured’s policies.
  • Do NOT amend, extend or alter the coverage provided by the insured’s policies. This can only be accomplished with an endorsement, rider or amendment to the policy.
  • Do NOT create a contract between the insurance company and the certificate holder.
  • Do NOT guarantee that insurance coverages listed on a Certificate of Insurance will continue in the future. A Certificate of Insurance issued today may not be accurate tomorrow.
  • Are provided for informational purposes ONLY.

Though there are various Certificate of Insurance forms, those developed by ACORD (Association for Cooperative Operations Research and Development) are widely used to provide specific information about existing insurance coverage, such as:

  • the insurance companies issuing the policy
  • the policy numbers
  • effective dates
  • types of insurance (ex. general liability, automobile, workers’ compensation, property)
  • policy limits

These forms also provide a space to add additional comments or conditions. This is where problems may arise if an insured or certificate holder wants to add specific language to their Certificates of Insurance. For example, a certificate holder may want to state that there is an additional insured under the policy, or an insured may want the certificate to state that any obligation to indemnify the certificate holder is covered by the policy.

If such statements happen to be true, it is not because they were typed on the certificate. Remember that Certificates of Insurance do not affect, extend, or change the insurance policy, so any incorrect or contradictory statements are meaningless to the insurance company. They can, however, be grounds for a costly lawsuit, so an experienced insurance agent should be used when issuing or receiving Certificates of Insurance.

If you would like to learn more about dealing with Certificates of Insurance or how we can help, please contact us.

If you would like to subscribe to our newsletters please click here.

All About Sinkhole Coverage

One of our Insurance Carriers, Tower Hill Insurance Group has created a great video explaining how Catastrophic Ground Cover Collapse (CGCC) is covered by your homeowners insurance policy.If you’d like to learn more about this coverage in regards to your policy please contact us.

https://www.youtube.com/watch?v=X9Uv_cwZ4GQ

Below please find the transcript from the video featured in this article.

Hi, this is Joel Curran coming to from the Tower Hill Insurance Group, LLC offices in Gainesville, Florida, where we have been serving the insurance needs of Floridians for 40 years.

Florida has changed a lot over those 40 years. We’ve had some of the worst hurricanes on record, like Andrew in 1992 and the 2004 – 2005 season when Tower Hill Insurance Group, LLC paid out more than $2 billion to repair homes in Florida. We have also seen huge changes in the way we communicate and do business.Most recently, Florida’s sinkholes have been getting a lot of attention on TV and radio, on the Internet in general, and on social networking sites especially.

One question we see are seeing more and more frequently on Facebook and Twitter is, “I see I have a 10% sinkhole deductible, can you tell me how that works?” Well I can do that. But let me first give some background information and explain a little bit about sinkhole loss coverage.

Across the country homeowners and dwelling fire policies are rather standard in most coverages. Earth movement is excluded in these policies. While most people think this applies to earthquakes, it also means sinkholes in Florida would not be covered. However, policies are modified in Florida to cover damage from sinkholes.

There are two types of coverage for earth movement in Florida: Catastrophic Ground Cover Collapse, known as CGCC, and Sinkhole Loss Coverage. CGCC covers you in cases you often hear about in the news, where a sinkhole opens up under or near a house and there is considerable damage.

All homeowners’ insurance companies provide it. The normal policy deductible applies, so the same deductible you would have for a theft or a fire loss applies to CGCC. To qualify as a CGCC there needs to be 4 components

  • An abrupt collapse of the ground.
  • A visible depression in the ground.
  • Structural damage to the building.
  • The insured structure being condemned and ordered to be vacated.

Sinkhole Loss Coverage is different. Because there are 2011 Statute changes impacting this coverage, my comments will address policies written new in 2012. First of all, sinkhole loss coverage is optional. You do not have to buy it. Sinkhole loss coverage is also different in that not all the 4 components need to be present.

However, there must be actual structural damage to the house and/or foundation, not just cracks to things like exterior walls, driveways, or interior walls around doors or windows. Of course, the damage must also be shown to have been caused by sinkhole activity. If the damage is eligible for coverage, then your policy will require you to pay the sinkhole loss deductible, then the insurer will pay the remaining costs of repair.

The sinkhole loss deductible applies to sinkhole loss coverage only, and at Tower Hill Insurance Group, LLC it is 10% of your Coverage A amount. Coverage A applies to the house itself, as opposed to other structures, or your possessions in the house. Let’s say you insure your home for $200,000. The sinkhole deductible is 10% or $20,000. In the event of a Sinkhole Loss Coverage claim, you would need to pay the first $20,000 in repairs, and as repairs are completed, Tower Hill Insurance Group, LLC would pay the remaining amount to repair your house.

Let me give you an example for a policy that would be written today. OK, the home is valued at $200,000 and the deductible is $20,000. The initial testing is paid for by the insurance company. Further testing may include a contribution from the insured, but if there is structural damage and sinkhole activity is present, then the company pays for all the testing. Then we get a contractor estimate and bids. Let’s say the cost to repair the foundation is $45000, and the cost to repair the home is $10,000. Once you contract to repair the home you will pay the contractor the first $20,000. As work continues we will pay the balance of the foundation repairs which are $25,000. We will also pay the $10,000 to repair the home.

Well that’s a quick recap of sinkhole coverages and how the deductible works. We at Tower Hill Insurance Group, LLC certainly hope that you do not experience damage to your home, but if you do, we pride ourselves on handling your claim promptly and fairly. After all, we have been doing it for 40 years.

Thanks for watching and thanks for using our social media sites.

Preventing Data Security Breaches

Every business must be able to identify the likeliest source of a data security breach so that they can also identify how to prevent it. Is it an executive’s laptop computer, the copy machine or the office’s wireless network? Could it be something else? Since the first step to preventing a data security breach is understanding the risk, it’s time to learn more about your business’s sensitive data.

Effective data security starts by assessing the kind of information a business has and identifying who has access to it. Evaluating data security vulnerabilities requires an understanding of how sensitive data moves into, through, and out of a business, and who has or could have access to it. Here are some tips from the Federal Trade Commission.

Take Inventory

Take an inventory of all devices and equipment capable of storing sensitive data, such as laptop computers, mobile devices, flash drives, off-site servers, disks and digital copiers. Do employees work from home? If so, add their home computers to the list.

The type and location of sensitive data should also be inventoried. Don’t stop with the office’s filing cabinets and computer systems. Sensitive data may also be received from other sources, such as websites, contractors or call centers. Every possible source and destination for sensitive data must be considered.

Track Sensitive Data

It is important to know how the business obtains, stores, shares and disposes of sensitive data. Every department should be consulted, including sales, information technology, human resources and accounting. Don’t forget about contractors and other third-party service providers.

This process should provide a business with a thorough understanding of:

  • Who provides sen­sitive data? Does it come from customers, credit card companies, banks or other financial institutions, credit bureaus, job applicants, contractors, third-party service providers?
  • How is sensitive data received? Does it come via phone, fax, mail or email? Is there a website designed to request and receive sensitive data? Are there any other possible entry points?
  • What kind of sensitive data is collected? Do business operations require or permit collecting financial information (credit cards, bank accounts, credit reports), personally identifying information (drivers’ licenses, social security numbers) or medical information?
  • Where is sensitive data stored? Is it kept on disks, tapes, laptops, smartphones, tablets or other mobile devices? Employees’ personal computers or mobile devices? Where are data backups and copies stored?
  • Who can access sensitive data? Is access to sensitive data limited to only those who need it? Are there security measures in place? Is sensitive data protected against unauthorized access by contractors or other third-party service providers?

Throughout this process, pay particular attention to certain kinds of sensitive data. Identity thieves typically look for social security numbers, credit card and other financial information.

Organizations should also consider protecting against data security breaches with insurance.Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to subscribe to our newsletters please click here.

Affordable Care Act’s Employer Mandate Delayed Until 2015

Shortly before the July 4th holiday, the U.S. Department of the Treasury announced that enforcement of the Employer Shared Responsibility requirement under the Affordable Care Act (Act) will be delayed until 2015. The employer mandate, which generally requires employers with at least 50 full-time or full-time equivalent employees to offer health care benefits or pay a penalty, was scheduled to go into effect on January 1, 2014.

Through a dialogue with businesses about the Act’s employer and insurer reporting requirements, the administration learned of concerns about the complexity of the requirements and the need for more time to implement them effectively. As a result, the administration decided to delay the Act’s mandatory employer and insurer reporting requirements.

According to the announcement, this delay is designed to:

  • Provide the administration more time to consider ways to simplify the new reporting requirements consistent with the law.
  • Provide more time to adapt health coverage and reporting systems while employers are moving toward making health coverage affordable and accessible for their employees.

The administration recognized that delaying the Act’s mandatory employer and insurer reporting requirements will make it impractical to determine which employers owe shared responsibility payments for 2014. As a result, the administration decided to also delay enforcement of the employer mandate, stating that “these payments will not apply for 2014. Any employer shared responsibility payments will not apply until 2015.”

The Treasury says it will be publishing formal guidance regarding the delayed enforcement soon and that proposed rules will be published this summer. Once these rules have been issued, the administration says it will work with employers, insurers and other reporting entities to strongly encourage them to voluntarily implement this information reporting in 2014, in preparation for the full application of the provisions in 2015.

So what should employers be doing now? The Employer Shared Responsibility provision is still the law, it just isn’t being enforced. Not surprisingly, talking heads are making predictions and debating whether it’s really speeding if nobody can pull you over. Unfortunately, the manner in which employer’s will be affected by the delay will not be known until additional guidance is issued.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changing health care reform landscape. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Sensitive Data: How Secure is Your Wireless Network?

In previous articles we discussed how laptop computers and the office copy machine increase the risk of data security breaches. Another significant risk to an organization’s sensitive data is the wireless network. Since today’s workplaces are increasingly “going wireless,” the Federal Trade Commission recommends taking the following steps to protect wireless networks.

Understand how a wireless network works. Going wireless generally requires connecting an internet access point to a wireless router, which sends a signal through the air, sometimes as far as several hundred feet. Any computer within range can pull the signal from the air and access the internet. Unless precautions are taken, others can “piggyback” on the network or access information on the computer.

Use encryption. Encryption encodes the information so that it’s not accessible to others. It is the most effective way to secure a network. Two main types of encryption are available: Wi-Fi Protected Access (WPA) and Wired Equivalent Privacy (WEP). WPA2 is strongest so it should be used whenever possible. Since some older routers use the less secure WEP encryption, consider upgrading to a newer, more secure router. Note that wireless routers often come with the encryption feature turned off, so be sure to turn it on.

Use anti-virus and anti-spyware software. Since hackers are constantly developing new ways to attack computers and networks, security software is necessary. This software needs to be updated periodically so systems should be set to update automatically whenever possible.

Change the name of the router. The name of the router (often called the service set identifier or SSID) is likely to be a standard, default ID assigned by the manufacturer. Change the name to something private and unique.

Change the router’s pre-set password. Manufacturers typically assign a standard default password to a wireless router. Default passwords should be changed. Visit the manufacturer’s website to learn how to change the password.

Limit access to the wireless network. Every computer that is able to communicate with a network is assigned a unique Media Access Control (MAC) address. Wireless routers usually have a mechanism to allow only devices with particular MAC addresses to access the network. However, since MAC addresses can be mimicked, don’t rely on this step alone.

Turn off wireless network when it’s not being used. A wireless network cannot be accessed when it is turned off.

Be cautious when using a public wireless network. Many cafés, hotels, airports and other public places offer wireless networks for their customers to use. These “hot spots” are convenient, but they may not be secure.

Organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you’d like to subscribe to our weekly newsletters please click here.