Do Not Get Caught in the SolarWinds of Change!

By Angela Doughty

Join us as we breeze through the 2021 Privacy and Data Security CLE on October 28, 2021.

The tidal wave of COVID-19 cases was not the only challenge faced in 2021. Blown away by the marked increase in ransomware attacks, both public and private sectors prioritized consumer privacy and data security. Light as rain, the privacy legislation emphasizing consumer choices and business obligations to defend against emerging cybersecurity threats trickled in, while Virginia and Colorado stormed in, passing comprehensive, state-level privacy laws. This whirlwind of legislation with a forecast of more to come, makes it important for all practitioners advising on privacy and data security matters to understand the storm surge of risks created during the 2021 privacy landscape shift.

The SolarWinds of Change 2021 Privacy and Data Security CLE program will update attendees on recent developments in privacy legislation, address ethical considerations in an era of emerging challenges and technology, take artificial intelligence by storm, and provide practical legal guidance on navigating vendor contracting issues based on lessons learned from the SolarWinds incident.

The program will provide 6.0 hours of CLE (including an ethics/professional responsibility hour and technology training hour) and is planned for both in-person and live webcast options. The full agenda and registration details can be found by clicking here.

Mark your calendars for Windsday . . . no, Thursday, October 28, 2021.

Network Segmentation – Perhaps the Only Piece of Good News From the Colonial Pipeline Hack

By Eva Lorenz

Introduction

Now that the situation at the pump seems to have recovered and returned to normal, it is time to figure out what actually happened in the Colonial pipeline attack and what lessons, if any, we can learn from yet another high profile cyberattack involving ransomware.

First, a few introductory words and some background on ransomware: ransomware is a common form of cyberattack in our time, and it involves attackers deploying code onto the victim’s network that results in encrypting files and folders throughout the network. According to the FBI, the best way to contain the attack is to block the code from moving across the network. For recovery from the attack, companies often rely on sound backup practices that allow them to restore encrypted files and folders without losing too much data. Of course, victims of ransomware attacks can also pay ransom, but that practice is still discouraged by the FBI and in some cases actually forbidden since the groups behind the attack are deemed sanctioned foreign entities.

Read more

Managing Risk in Technology Supply Chains After SolarWinds

By Peter McClelland

In December 2020, as many of us were watching all things political and pandemic, current events eclipsed a serious breaking story. The SolarWinds hack exposed a level of data across the nation that was — to use the oft-turned phrase for 2020 — “unprecedented.” Not to be outdone, 2021 has now given America a data breach through the Microsoft Exchange email software that (conservatively) affected 60,000 organizations, spanning every level of size and sophistication. Read more

Privacy and Data Security Section Updates and Library How-To

By Taylor Ey

Hello, section members!

Happy spring! We are beginning to add resources to our online library, including recordings of two recent discussions from last week: (1) the joint YLD/PDS specialist discussion from March 16, “Becoming a Privacy Law Specialist: Exploring NC’s Newest Legal Specialization,” and (2) the Fireside Chat from March 17, “Managing Third-Party Privacy and Security Risks.”

We invite you to review the materials if you weren’t able to join or to revisit the materials at your leisure.

Here is a reminder of how to navigate the library.

How Do I Access the Library?

  1. Click on “Communities.”
  2. Scroll and find your community.
  3. Click on the “Library” tab.

How Do I Find Content in the Library?

  1. On the left side under folders, you will see varying folders.
  2. When you click on a folder, the contents of the folder will pop up on the right side under “Folder Contents.”
  3. To open a document, double click on any document.
  4. Click “Download” under the attachment name.

SolarWinds – What Do We Know and What Can We Learn From It?

By Eva Lorenz and Taylor Ey

SolarWinds made a name for itself as the developer of tools for network monitoring that help small and large companies efficiently run their environment. While not a security-focused company from a product standpoint, the understanding was that the code behind SolarWinds’ tools was protected as intellectual property and that updates were safe to run until it turned out that both of these assumptions were wrong.

How Was the Compromise Detected?

In late 2020, FireEye, a company focused on cybersecurity and internationally involved in helping companies post cyber incident, detected some unusual activity on the FireEye network. FireEye detected it was hacked after the attackers tried to register a device to FireEye’s multi-factor authentication system using stolen credentials. The system then notified the employee, whose credentials were stolen, and alerted the FireEye security team of this new device. This notice triggered an internal investigation to learn who was trying to register this device. FireEye performed in-depth code analysis and determined that the intrusion originated with a SolarWinds product called Orion. Some analysts believe that attacking FireEye was a mistake by the attackers since it sped up detection of the SolarWinds hack.
Read more

Reconciling Emerging Technologies with North Carolina’s Duty of Competence

By Sarah Beth Tyrey

A Multilayered Duty of Competence

The North Carolina State Bar’s Rules of Professional Conduct mandates attorneys in this state to uphold a duty of competence in their practice. Under Rule 1.1, competence in representation “requires the legal knowledge, skill, thoroughness, and preparation reasonably necessary.” Competent and zealous representation for an attorney’s clients is of highest priority. Monitoring changes in case law and the broader legal landscape is imperative to maintain this knowledge and skill.

Read more

Worried about Hackers? Take Proactive Measures by Hiring Someone to Test Your Network

By Eva Lorenz 

You may be an in-house attorney at an organization subject to specific compliance requirements or you may work at a law firm and handle sensitive client information, including information subject to laws such as the N.C. Identity Theft Protection Act. In either case, you need to show your business partners that data managed by your organization is protected. You, as an attorney in the room, can help your organization or law firm reduce the risk of a high-profile breach or ransomware attack. Read on to learn about technical approaches to address these concerns.

Read more

Ketan Soni Presents “The New Community Platform”

By Ketan Soni

What You Need to Know About the New Community Platform

This year, the NCBA has switched to a new online community platform. This new community platform for Sections, Divisions and Councils offers many more features than the previous system. Below is a summary of the basics and what you need to know to utilize this platform and its features.

Read more

Fall and Winter Fireside Chats: Vote for Topics Today

By Shannon Ralich
Privacy & Data Security International Working Group Committee Chair

The NCBA Privacy & Data Security International Working Group will host Fireside Chats this fall and winter.

Vote for the topics you would like to hear about (you can select more than one topic).

The last day to vote is Wednesday, September 30 at 5 p.m.

We look forward to hearing from you! Click here to take the 1-minute survey.

Thank you.

A Lot Has Changed in Privacy and Data Security This Year. Do You Feel Up to Date?

By Karin McGinnis

While the world was quarantining, the privacy and data security world was busy. Now the California Consumer Privacy Act is in full swing with final regulations, the U.S./EU Privacy Shield is no longer valid, and the attorney-client privilege in data breaches has been challenged. With most purchases and interactions happening online, online businesses and virtual meeting spaces are in the crosshairs. Even your old trusty vendor agreement is at risk. All of these changes have significant implications for your clients and your practice, and it is easy to feel behind the curve. Your NCBA Privacy and Data Security Committee has your back! We’ve created a full day seminar (6 MCLE credits*) to get you up to speed. You’ll get ethics and technology credit as well. And with safety in mind, the seminar will be 100% virtual. If you are one of the first 30 people to sign up, you’ll receive a $65 discount. You can sign up here.

Hope to “see” you there!

*6.00 MCLE Hours Includes 1.00 Ethics/Professional Responsibility and 1.00 Technology Training Qualifies for NC State Bar Privacy & Information Security Law Specialization