California AG Takes Lead In Cybersecurity

Published on

Data breaches at major retailers Target and Neiman Marcus during last year's holiday shopping season affected more than 100 million people and focused new attention on the need to protect person information stored online.

While it's clear that tough data breach legislation must be enacted, California Attorney General Kamala Harris is taking action to improve cybersecurtity in the state before new laws are passed. Today she released recommendations to California businesses to help protect against and respond to the increasing threat of malware, data breaches and other cyber risks.

In addition Harris is leading an investigation by state attorneys general into the Target and Neiman Marcus breaches, Don Thompson of The Associated Press reported:

Harris' office also disclosed that California is leading a multistate investigation into the massive holiday season consumer data theft at discount retailer Target Corp. and luxury retailer Neiman Marcus, breaches that left tens of millions of customers at risk. More than 7 million Californians were affected by the Target breach alone, Special Assistant Attorney General for Law and Technology Jeff Rabkin said.

The U.S. Justice Department is taking the lead in trying to identify the culprits, who are suspected to be based overseas, while the multistate investigation focuses on whether the retailers share blame because they lacked the necessary precautions to prevent the thefts. The state investigation also will explore whether Target and Neiman Marcus acted properly as soon as they learned of the problem, Rabkin said in a telephone interview

The guide, Cybersecurity in the Golden State, offers suggestions focused on small to mid-sized businesses, which are particularly vulnerable to cybercrime and often lack the resources to hire cybersecurity personnel. In 2012, 50 percent of all cyber attacks were aimed at businesses with fewer than 2,500 employees and 31 percent were aimed at those with less than 250 employees, Harris said.

Key recommendations for small business owners include:

  • Assume you are a target and develop an incident response plan now.
  •   Review the data your business stores and shares with third parties including backup storage and cloud computing. Once you know what data you have and where it is, get rid of what is not necessary.
  •   Encrypt the data you need to keep. Strong encryption technology is now commonly available for free, and it is easy to use.
  • Follow safe online practices such as regularly updating firewall and antivirus software on all devices, using strong passwords, avoiding downloading software from unknown sources and practicing safe online banking by only using a secure browser connection.

In 2003 California was the first state to pass a data breach notification.  In 2012 the law was amended to require any breach that involved more than 500 Californians be reported to the attorney general.

The 170 breaches reported to the attorney general's office in 2013 represent a 30 percent increase over the 131 identified the year before,  according to figures provided to The Associated Press. Among entities reporting breaches in 2012 were American Express Travel Related Services Co., Kaiser Permanente and several state government agencies, including the departments of Public Health and Social Services.

Given the current data breach laws Harris is taking meaningful action.  But, what's ultimately needed is a law that would make her best practice recommendations legal mandates.  We need a California Financial Information Privacy Act that would:

  •  Change breach notification standards to be immediate.
  • Set limits on the time data can be retained. And limits on what information can be collected and retained.
  •  Write minimum-security standards into the law so that they are no longer voluntary.
  •  Most importantly: create a private right of action. Put a price tag on retailers’ mistreatment of our private financial information.

 

Until there is a real price to pay, Target, Neiman Marcus and other retailers will continue to make us targets.

John M. Simpson
John M. Simpson
John M. Simpson is an American consumer rights advocate and former journalist. Since 2005, he has worked for Consumer Watchdog, a nonpartisan nonprofit public interest group, as the lead researcher on Inside Google, the group's effort to educate the public about Google's dominance over the internet and the need for greater online privacy.
Latest Privacy Videos
Video thumbnail
KCAL CBS: New Tool For Scrubbing Online Data
03:03
Video thumbnail
KTVU FOX: Protecting Your Privacy
04:02
Video thumbnail
Consumer Alert — Don't Sign Uber's "License to Kill" Ballot Initiative
01:16
Video thumbnail
KX Television (KXMD): Surveillance Pricing Costing Consumers Big
02:01
Video thumbnail
Consumer Alert: Uber Says One Thing Does Another On Surveillance Pricing
02:38
Video thumbnail
KGO-SF (ABC) - San Francisco, CA: Bill To Ban Higher Prices Based On Phone Data
02:21
Video thumbnail
KCAL-LA - Los Angeles, CA: Personal Data Used To Target Shoppers
06:36
Video thumbnail
KCBA (FOX) - Monterey, CA: CA Bill Aims To Put An End To Surveillance Price Gouging
00:55
Video thumbnail
KLAS-LV (CBS) - Las Vegas, NV: Surveillance Pricing
00:46
Video thumbnail
KIRO-SEA (CBS) - Seattle, WA: CA Lawmakers Consider Bill On Price Gouging
00:51
Video thumbnail
AB 446 Press Conference
13:52
Video thumbnail
Consumer Alert: Surveillance Pricing
02:07
Video thumbnail
KTTV-LA (FOX) - Los Angeles, CA: Prices Are being Adjusted Based On Your Shopping Habits
03:42
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Surveillance Price Gouging
05:49
Video thumbnail
KCAL-LA - Los Angeles, CA: Surveilance Price Gouging
03:17
Video thumbnail
KBCW 44 Cable 12 - San Francisco, CA: Meta Holiday Hack
03:25
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Several Tech Bills Head To Governor's Desk
06:12
Video thumbnail
Al Jazeera: Google antitrust law trial US court says google is a monopolist, violated law
02:16
Video thumbnail
Consumer Alert — National Data Breach
01:24
Video thumbnail
KTVU-SF (FOX) - San Francisco, CA: Calm App, Doordash Software Sued For Data Sharing
05:40
Video thumbnail
Consumer Alert: No Opt Out
00:49
Video thumbnail
KCAL-LA - Los Angeles, CA: Investigation Into California's Newborn DNA Database
03:39
Video thumbnail
Consumer Alert: Data Parasites
02:07
Video thumbnail
KCBS - Los Angeles, CA: California Biobank Stores Every Baby's DNA; Parents Had No Idea
04:26
Video thumbnail
Consumer Alert: Wall Street using AI
01:48
Video thumbnail
KCBA (FOX) CA: Clearview AI Is Creating An AI Facial Recognition Software That Violates Privacy Laws
00:35
Video thumbnail
KGO CA: Consumer Watchdog Calls Attorney General to Investigate Clearview AI For Violating State Law
03:06
Video thumbnail
KNTV-SF (NBC) - San Francisco, CA: Tesla Recalls Millions of Cars
02:29
Video thumbnail
Consumer Alert: Clearview AI
01:19
Video thumbnail
Californians Now Have More Power Over Their Data
01:07
Video thumbnail
KPIX CBS TV-5 San Francisco, CA: Your Car's Computer Could Be Tracking And Reporting Your Every Move
00:48
Video thumbnail
California Votes YES on Privacy- Prop 24
13:14
Video thumbnail
Rage For Justice Report Podcast- Prop 24 For Your Privacy
19:18
Video thumbnail
Consumer Watchdog Hacks Tesla
02:00
Video thumbnail
FOX KSWB: New Internet-Connected Cars Could Get Hacked
01:05
Video thumbnail
ABC: Kill Switch Report Highlights Widespread Hacking Vulnerability of Connected Cars
02:12
Video thumbnail
KTTV FOX: Consumer Watchdog Report Warns That Hackers Can Take Over Your Car
05:02
Video thumbnail
SPECNEWS1: Watchdog Warns Cars With Internet Connection Vulnerable to Hacking
00:37
Video thumbnail
KBCW: Connected Cars Pose Risk to Driver Safety Due to Hacking Vulnerability
02:31
Video thumbnail
ABC KGO: Whistleblower Engineers Warn Connected Cars Need A Kill Switch to Stop Hacking
02:10
Video thumbnail
KCAL: Alarming Watchdog Report Shows Connected Cars Are Vulnerable to Hacking
02:51
Video thumbnail
ABC KGTV: Report Says Internet-Linked Cars Are Vulnerable To Hackers
00:30
Video thumbnail
KTTV Fox 11: Consumer Watchdog Report Shows How Vulnerable Connected Cars Are To Dangerous Hacking
01:05
Video thumbnail
NBC: Watchdog Report Show Connected Cars Lack of Cybersecurity Put Drivers at Risk
03:38
Video thumbnail
CBS KGPE: Connected Cars Pose A Cybersecurity Risk
03:05
Video thumbnail
Fox WDAF: High-Tech Cars Put Drivers At Risk Of Hacking Interference
00:47
Video thumbnail
ABC WXYZ: Connected Cars Can Be Hacked Says Kill Switch Report
01:36
Video thumbnail
KTTV GDLA: US Senators Write NHTSA About Connected Car Concerns
01:17
Video thumbnail
FOX KPTV: Kill Switch Report Details Cybersecurity Issues With Internet Connected Cars
02:28
Video thumbnail
CBS LA: Kill Switch Study Finds Connected Cars Are Vulnerable to Hacking
01:41

Privacy In The News

Latest Privacy Report

Support Consumer Watchdog

Subscribe to our newsletter

To be updated with all the latest news, press releases and special reports.