Why Your Clients Need to Be Concerned About Cybersecurity
Cybersecurity is everyone's business who accepts credit cards. Photo: Typgraphy Images / Pixabay

Why Your Clients Need to Be Concerned About Cybersecurity

I attended Interface's recent cybersecurity conference in Phoenix as a volunteer with the Cloud Security Alliance's Southwest chapter.

I attended only one session (after all, I was there to staff CSA's booth) I figured I'd understand. This was a presentation by Tucson business attorney Kathy Delaney Winger, who speaks about why clients need to concern themselves with cybersecurity.

I drew two conclusions from Winger’s talk:

  1. Any business that issues credit cards must take steps to protect consumer information.
  2. Any business that sells online or collects other personal information must do the same.

Businesses That Issue or Back Credit Cards Must Protect Consumer Accounts

Banks are responsible for breaches and fraud that, as Winger notes, used to be part of doing business.

It’s not just that consumers can only be held liable for the first $50 charged to a credit card. Any business that offers a credit card must do more to protect consumers beyond paying off a few hundred or thousand dollars fraudulently charged to credit accounts.

The 2013 Target card breach changed expectations for how banks protect consumer information

It all started with the 2013 Target breach. Banks that underwrote Target’s cards and its card-holding customers sued Target for negligence. In the past, courts would have dismissed these charges—after all, that’s the reason why customers are only held responsible for $50 in the case of fraud. It was a cost of doing business.

But by the time lawsuits were being heard in 2015, state and Federal courts were catching up to the reality of point of service (POS) electronic payments. (Several were hearing lawsuits against Target brought by lawyers for consumers and banks.) It’s more than a $50 loss—a stolen financial account can open the doors to access a range of personal information that can devastate consumers and companies that hold their personal information.

Think of what goes into a credit application:

  • Social security numbers
  • Banking information
  • Private residential and workplace addresses

This is pretty personal stuff. No one wants the first two to be in the public domain or revealed without our express permission, while others may prefer to keep their whereabouts private for any number of reasons.

Courts concluded that businesses that issue or back credit cards have a responsibility to take specific steps to protect their customers against hackers. In Target’s case, it failed to take these steps and it should have.

And consequently, banks and credit unions credit cards have the same responsibility to consumers who use their cards.

Cybersecurity Responsibility Trickles Down

The second message I took away from Winger’s presentation is that if your clients sell anything online, or handle any kind of personally identifiable information (PII), they had better pay attention to the security on their websites.

Credit card issuers want to be sure that other businesses that collect their customers' information are just as secure as they.

Small businesses are just as liable for data breaches as any international bank. Pretty much all banks now have cyber insurance policies. You can be sure that these insurance companies will go after businesses whose breaches have impacted their customers.

Over 60% of data breaches happen at small and medium sized businesses, Winger says. And half of all small businesses shut down within six months of a cybercrime against them.

Winger shared what she advises her business clients to take with vendors who can access personal information, including:

  • Making sure their vendors meet security standards for storing information listed by HIPAA (for medical data) and the FTC (for consumer data)
  • Including an indemnification clause in vendor contracts for losses they suffer if the vendor fails to protect sensitive information
  • Making sure vendors have cyber insurance coverage


要查看或添加评论,请登录

Ruth Ann Monti的更多文章

  • When Elon Bought Twitter

    When Elon Bought Twitter

    So Elon Musk bought Twitter after all. Is anyone surprised this is announced on a Friday, one of the slowest news days…

  • Make Your Emails Stand Out

    Make Your Emails Stand Out

    Do you "still" use email? It's "still" my preferred way to communicate but I use it less often these days. Most of my…

  • First Day on the Job? Yeah.

    First Day on the Job? Yeah.

    Getting started as an Arizona Notary. Last year, I applied to become a Notary in Arizona and am now licensed to provide…

    6 条评论
  • Oh G+, Where Art Thou?

    Oh G+, Where Art Thou?

    Google Plus (G+) is gone. You noticed this, right? I sort of did.

  • Can Artificial Intelligence Replace the Human Touch?

    Can Artificial Intelligence Replace the Human Touch?

    The Phoenix Mobility Conference has been an annual event for the past six years. This year, it was hosted by Arizona…

  • Comma Comedian

    Comma Comedian

    I was lucky to catch a terrific and funny article by Kristin Long for PR Daily in my LinkedIn feed this morning. It was…

  • Can You Write More Than 1999 Words?

    Can You Write More Than 1999 Words?

    Neil Patel has been saying it for a while: the new SEO rules want to see 2000-word blogs. I heard it repeated last week…

  • Hiking the OS Sierra

    Hiking the OS Sierra

    Have you hiked the new Sierra? I’m talking about the one for Macs. I just did and so far my experience is a lot…

  • Cloudy With a Forecast of Security

    Cloudy With a Forecast of Security

    I attended the Cloud Security Alliance's (CSA) Southwest Summit to learn more about what's going on to make the cloud a…

  • How to Harness the Headline

    How to Harness the Headline

    Lately I've been thinking a lot about how to write a really good headline. This is an area I sometimes think I…

社区洞察

其他会员也浏览了