720-891-1663

Feds Fine Boeing $51 Million for ITAR Violations

For decades the DoJ seemed to be ignoring cybersecurity failures on the part of even large companies. That has changed. DoJ has started up an entire bureau for going after companies that ignore the rules. Recently they fined Booz $335 million for False Claims Act violations. Last week they announced they are going after Georgia […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 19, 2024

Regulators Going After Crypto Firms A number of crypto firms have felt the sting of regulators recently. The most recent one is Genesis Global Trading. New York’s DFS fined them $8 million and required them to surrender their license for failure to comply with money laundering and other laws. Of course, a key purpose for […]

Continue reading → [DISPLAY_ACURAX_ICONS]

California Releases Draft Audit and Risk Assessment Regs

The California Privacy Protection Agency, the government agency that enforces the California Privacy Rights Act, has released two DRAFT documents recently. They are going to discuss the drafts at their meeting tomorrow but they have not yet started the rulemaking process. The two regulations are the cybersecurity audit regulations and the cyber risk assessment regulations. […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News Update for the Week Ending August 11, 2023

Police Don’t Know Who Accessed Data Posted in Error This is somewhat hard to believe while at the same time all too common. Would your company do any better. Police in Northern Ireland posted the entire country’s police roster in response to a freedom of information request – by accident. Even though they took it […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Maybe OpenAI Should be Called ClosedAI

ChatGPT 3.5 was basically a beta. They got lots of people to feed data into the system, including sensitive, proprietary data (oops) in order to train it. Now that it is “more” trained, OpenAI released ChatGPT 4. Contrary to the founding principles of investors like Elon Musk, the company, which claimed that it would be […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Minimum Viable Secure Product (MVSP)

Vendor risk must be a core part of every company’s cybersecurity program, but it is hard. Especially when the company is a tech company, developing software that you use. The term Minimum Viable Product or MVP is a term marketing folks have used for years to describe creating a version 1 product that has the […]

Continue reading → [DISPLAY_ACURAX_ICONS]