Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Business Email Compromises: Current Legal Trends and Key Strategies
Blog April 03, 2026
Businesses have for years suffered from a sophisticated, targeted cybercrime that exploits trust, human relationships, and our reliance on digital communication: the business email compromise (BEC)…
CISA and Partners Update the #StopRansomware Guide, Developed through the Joint Ransomware Task Force
Blog May 24, 2023
On May 23, 2023, CISA, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published an updated version of the #StopRansomware Guide, as ransomware actors have accelerated their tactics and techniques since its initial release in 2020. The update incorporates lessons learned from the past two years and includes additional recommended actions…
Fifth Circuit Addresses Scope of “Use” Under Federal Identity Theft Statute
Blog December 30, 2020
You may have forgotten that there is a federal criminal identity theft statute, 18 U.S.C. § 1028A, which says: Whoever, during and in relation to any felony violation enumerated in subsection (c), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 2 years. Section 1028A is not frequently invoked…
SEC Brings First Enforcement Action for Identity Theft Red Flags Rule Violations
Blog October 15, 2018
On September 26, in the Securities and Exchange Commission's (“SEC”) first enforcement action for violations of Regulation S-ID (the “Identity Theft Red Flags Rule”), Voya Financial Advisors Inc. (“VFA”), an SEC-registered investment adviser and broker-dealer, has agreed to settle charges relating to failures in its cybersecurity policies and procedures concerning a cyber-intrusion that compromised thousands of customers' personal information. VFA agreed to pay a $1 million penalty as well……
Senator Warner's White Paper Gives Congress Options for Regulating Social Media and Technology Companies
Blog October 09, 2018
Senator Mark Warner of Virginia has released a white paper outlining policy proposals for regulating social media and technology companies. The paper has gained significance in recent weeks as pressure builds on Congress to pass federal data privacy legislation. In the wake of Europe's GDPR and California's Consumer Privacy Act, industry groups, tech companies, and privacy activists alike have urged Congress to act…
New Law Provides Free Credit Freezes and Year-Long Fraud Alerts
Blog October 04, 2018
As summarized nicely in the FTC FAQs below, there is a new law, the Economic Growth, Regulatory Relief, and Consumer Protection Act, that makes credit freezes free and extends fraud alerts to last a full year.  Here are some of the most common questions raised about this new law, and the FTCs answers: Q: I already had a credit freeze in place when the new law took effect on September 21…
Presentation: The Legal Benefits and Practical Problems of Data Encryption in the Workplace (and Elsewhere)
Blog March 05, 2018
Partner Colin Zick was recently invited to speak to the Union College Computer Science Department's Seminar Series. His presentation addressed the difficulties in implementing encryption in the workplace, the challenges to encryption from law enforcement, and the future of encryption in light of U.S. v. Microsoft and the coming GDPR. Click here to download the presentation…
Yes, You Were Likely a Victim of the Equifax Hack, But Here's What You Can Do Now
Blog September 12, 2017
As we previously said, the Equifax breach affects approximately 143 million Americans. While the hackers stole data that includes addresses, birth dates, full names and Social Security numbers, there are steps you can take today that will protect you from an identity theft worst-case scenario. Assume the hackers stole your data While no one wants to be in a situation where personal information was exposed…
Stolen Tax Returns?  Virginia Seeks a Solution.
Blog July 05, 2017
Did someone steal your tax return?  You are not alone.  Indeed, the rise in tax-related identity theft has been well documented.  In 2015, the FTC reported a 50% increase in identity theft complaints.  A primary cause for that increase was the rise in tax-related identity theft.  In response to this increase, the IRS has made stopping identity theft and refund fraud a top priority.  From 2011-2014, the IRS reported that it stopped 19 million suspicious returns and protected more than $63……
1 of 8

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors