Webinar: The Risks of Data Breach
This is the second in a series of webinars on Data Privacy and Data Breach.
Click here for Support Material
Held on: June 20, 2007 Duration: 1 hour Presenters: Jim Leonard, Business Development, National Sales, Kroll John Hall, Executive Vice President, EthicsPoint, Inc.
Who Attended:
- Privacy Officers and Practitioners
- Ethics and Compliance Officers
- General Counsels
- Security Officers
- Corporate Responsibility Officers
Almost all organizations retain the sensitive personal information of current and former employees, consumers, and investors in multiple locations and formats. Identity thieves target this information, and legislation mandates action when it’s compromised - but what action? Where is the line drawn between ‘recommended’ and ‘required’? How does a breached company manage the experience and the exposure? While some companies have written policies around handling sensitive personal information, many still don’t.
Kroll’s Fraud Solutions will debunk some common identity theft myths, help you and your organization gain a better understanding of your exposure, and explore ways you can minimize it. We will also examine best practices for safeguarding personal information within your organization. Kroll’s Fraud Solutions has more experience and resources than any other company to help organizations effectively navigate a data breach and minimize both financial and reputation risks. The following questions will be answered:
- What fundamentals should the policy contain?
- How should it be distributed?
- What control environment should exist around it?
- Who should the stakeholders be?
- What tools should be used to manage the data before and after a breach incident?
Goals of the Session:
- Clarify the legislated mandates that affect an enterprise’s actions when a breach occurs
- Distinguish between mandates that are required and mandates that are “recommended”
- Examine how to respond to a data breach and minimize exposure
- Examine the value of an internal policy on handling personal information, what it should contain, and best practices around creating and implementing one
Presenters' Bios:
Jim Leonard, Business Development, National Sales Jim joined Kroll’s Fraud Solutions Practice in early 2005. Jim has 8 years of experience assisting companies in identifying risk, creating security policies and procedures, vetting and implementing network security products and training corporate security practitioners. Jim’s principal focus with Kroll is aiding clients in understanding their potential for exposure to breaches of security and assisting in the development of their investigation and response strategy. Jim is a founding member of the Nashville Chapter of the ISSA (Information Systems Security Association); a member of the APWG, (Anti-Phishing Working Group), which is committed to wiping out internet scams and fraud globally; and FBI’s InfraGard, a public-private partnership and platform for the confidential exchange of information.
Kroll provides a broad range of investigative, intelligence, financial, security and technology services to help clients reduce risks, solve problems and capitalize on opportunities. Kroll began providing identity theft solutions in response to increasing requests from clients for counsel and services associated with the loss of personal information and related identity protection and restoration issues facing organizations and individuals.
John Hall, Executive Vice President, EthicsPoint, Inc. Leveraging more than 20 years of executive leadership experience, John has helped lead EthicsPoint's development into one of the leading providers of governance application services that assist organizations mitigate risk and manage regulatory compliance. Through John’s leadership and working with privacy practitioners, EthicsPoint has developed a data breach management tool that helps bridge the gap between data loss prevention and breach notification procedures. EthicsPoint’s innovative Issue, Event and Loss Management solutions provide a comprehensive framework of data intake, investigative management and event resolution, ultimately delivering a more accurate picture of enterprise risk.
EthicsPoint delivers solutions to efficiently integrate and manage Governance, Risk, and Compliance (GRC) activities: web- and telephone-based reporting mechanisms; easy-to-use tools for managing and resolving incidents across the enterprise; analytical tools to measure and assess GRC performance; and communication and education programs to support awareness, adoption, and effectiveness of GRC programs.
|