Federal Trade Commission
Data Breach Response: A Guide for Business
The Federal Trade Commission’s new outlines the steps to take and whom to contact if you suspect that your business has experienced a data breach. Here’s a glimpse of what’s inside:
You’ll need to move quickly to secure your systems. Some immediate steps include:
Secure physical areas potentially related to the breach. Lock them and change codes, if needed.
Stop additional data loss. Take all affected equipment offline right away, but be careful not to destroy evidence. Monitor all access points to your system. If a hacker stole credentials, you’ll need to change those credentials too, even if you’ve removed the hacker’s tools.
Remove improperly posted information from the web. After you clean up your site, conduct a search to make sure other sites haven’t posted the information. If they have, ask them to remove it.
What about breach notification? That’s where many companies have questions. First, take a look at your state’s data breach notification law. If it’s a breach involving health information, also look at the HIPAA Breach Notification Rule and the FTC’s Health Breach Notification Rule. Notify law enforcement, affected businesses and individuals.
Law enforcement – Call your local police, the FBI or the U.S. Secret Service. The sooner they learn about the breach, the more effective they can be.
Businesses – If account information (like credit card numbers) was stolen and you don’t maintain the accounts, notify the institution that does so they can keep an eye out for suspicious activity.
Individuals – The faster you notify people, the faster they can take steps to protect their information. In deciding who to notify and how, consider state laws, the nature of the breach, the type of information taken, the likelihood of misuse and the potential damage if the information is misused. When notifying people, consult with law enforcement and, depending on the type of information breached, consider offering at least a year of free credit monitoring.
FTC To Hold Public Conference on Identity Theft
The Federal Trade Commission will host an all-day conference, “Planning For the Future,” examining the state of identity theft now and how it may evolve in the future. The event will take place on May 24, 2017, in Washington, DC.
2017 will mark the ten-year anniversary of the executive order creating the federal Identity Theft Task Force, which was co-chaired by the FTC. Despite numerous advances in combating identity theft, it remains a top consumer complaint each year to the FTC, and Department of Justice statistics show that millions of consumers are victims of identity theft. The conference will bring together academics, business and industry representatives, government experts and consumer advocates to discuss the ways in which identity theft affects consumers and how that has changed in the last decade. The FTC event will look at the full life cycle of identity theft, addressing how identity thieves acquire consumers’ information and what information they seek most often, as well as the cost and ease with which consumers’ data can be acquired. In addition, the conference will examine how identity thieves use information, and how they may attempt to use it in the future. Further, the conference will examine how to quantify the impact of identity theft, from financial and economic harms to the broader impact on public safety. The conference will also assess what resources are available to identity theft victims and their effectiveness in helping victims recover.
FTC Testifies before Senate Commerce Committee about Agency’s Work to Protect Consumers and Promote Competition
In testimony presented to the US Senate Commerce Committee, the Federal Trade Commission described its work, and called for several changes to the FTC Act that would enhance its ability to protect consumers and promote competition. FTC Chairwoman Edith Ramirez and Commissioners Maureen K. Ohlhausen and Terrell McSweeny testified before the Committee. In their written testimony, they estimated that the agency’s antitrust enforcement efforts have saved consumers over $3.4 billion, while its consumer protection actions have saved consumers $717 million.
The Commission called for repeal of the common carrier exception to the FTC Act, which prevents the FTC from taking action to protect consumers in some cases involving telecommunications firms and other common carriers. “As the telecommunications and Internet industries continue to converge, the common carrier exception is increasingly likely to frustrate the FTC’s ability to stop deceptive and unfair acts and practices and unfair methods of competition with respect to a wide array of activities,” the Commission stated.
Ad libraries and app developers, check out this advice
Here are some things we found in our look at ad libraries:
Most ad libraries require the similar core set of permissions (INTERNET and ACCESS_NETWORK_STATE), which give the app use of the Internet and information about the mobile device’s network connections.
Some ad libraries go a step further and ask – often optionally – for additional information like geolocation (ACCESS_COARSE_LOCATION and ACCESS_FINE_LOCATION).
Some ad libraries sought optional permissions that may be irrelevant to targeting and serving ads, such as permissions that allow the app to read and write on the user’s calendar data (READ_CALENDAR and WRITE_CALENDAR), connect to paired Bluetooth devices (BLUETOOTH), access the device’s vibrate function (VIBRATE), record audio (RECORD_AUDIO), and get a list of all registered Google and other email accounts (GET_ACCOUNTS).
We also looked at ad libraries’ publicly available disclosures. Here’s what we learned:
Some ad libraries had documentation directed at app developers, which explained the types of information they acquired about users through the apps. Other ad libraries had a privacy policy directed at consumers, but few had both.
A few ad libraries had either documentation or a privacy policy that clearly listed the type of information they obtain from mobile users. For example, some specify they collect information about the mobile device’s carrier, make and manufacturer, operating system, language settings, connection speed, IP address, unique device IDs, browser, and more. Others simply state they collect non-personally identifiable information.
Some ad libraries disclose how long they retain a consumer’s information, such as 90 days or 36 months. Others, however, indicate that they keep information as long as needed, or even indefinitely.
Several ad libraries note in their developer documentation that the app developers should have privacy policies, and some note that developers should obtain the appropriate consumer consent to collect, use, and disclose their data to ad libraries.
The NIST Cybersecurity Framework and the FTC
We often get the question, “If I comply with the NIST Cybersecurity Framework, am I complying with what the FTC requires?” From the perspective of the staff of the Federal Trade Commission, NIST’s Cybersecurity Framework is consistent with the process-based approach that the FTC has followed since the late 1990s, the 60+ law enforcement actions the FTC has brought to date, and the agency’s educational messages to companies, including its recent Start with Security guidance.
The Framework is not, and isn’t intended to be, a standard or checklist. It’s meant to be used by an organization to determine its current cybersecurity capabilities, set individual goals, and establish a plan for improving and maintaining a cybersecurity program, but it doesn’t include specific requirements or elements. In this respect, there’s really no such thing as “complying with the Framework.” Instead, it’s important to remember that the Framework is about risk assessment and mitigation. In this regard, the Framework and the FTC’s approach are fully consistent: The types of things the Framework calls for organizations to evaluate are the types of things the FTC has been evaluating for years in its Section 5 enforcement to determine whether a company’s data security and its processes are reasonable. By identifying different risk management practices and defining different levels of implementation, the NIST Framework takes a similar approach to the FTC’s long-standing Section 5 enforcement.
What is your phone telling your rental car?
What happens when you rent a connected car? When you use the car’s infotainment system, it may store personal information. It may keep locations you entered in GPS or visited when travelling in the rental car – like where you work or live. If you connect a mobile device, the car may also keep your mobile phone number, call and message logs, or even contacts and text messages. Unless you delete that data before you return the car, other people may view it, including future renters and rental car employees or even hackers.
If you decide to rent a connected car, here are some steps you can take to protect your personal information:
- Avoid connecting your mobile phones or devices to the infotainment system just for charging.
- Check your permissions.
- Delete your data from the infotainment system before returning the car.
FTC Seeks Comment on Safeguards Rule
The Federal Trade Commission is seeking public comment on Standards for Safeguarding Customer Information (the “Safeguards Rule”) as part of its systematic review of all FTC rules and guides. The Safeguards Rule, which took effect in 2003, requires financial institutions to develop, implement and maintain a comprehensive information security program for handling customer information.
The FTC seeks comments on a number of questions, including the economic impact and benefits of the Rule; possible conflict between the Rule and state, local or other federal laws or regulations; and the effect on the Rule of any technological, economic or other industry changes. The Commission vote approving the Federal Register Notice was 3-0. The notice will be published shortly and instructions for filing comments appear in the Notice. Comments must be received on or before November 7, 2016.
FTC Approves Final Order in ASUS Privacy Case
After a public comment period, the Federal Trade Commission has approved a final order resolving the Commission’s complaint against ASUSTeK Computer, Inc., charging that critical security flaws in its routers put the home networks of hundreds of thousands of consumers at risk. The settlement was first announced in February 2016. In its complaint, the FTC alleged that ASUS failed to take reasonable steps to secure the software on its routers, despite making promises to consumers about their security.
Under the terms of the consent order, ASUS is required to establish and maintain a comprehensive security program subject to independent audits for the next 20 years. In addition, ASUS must notify consumers about software updates or other steps they can take to protect themselves from security flaws, including through an option to register for direct security notices (e.g., through e-mail, text message, or push notification). The consent order also prohibits the company from misleading consumers about the security of the company’s products, including whether a product is using up-to-date software. The Commission vote to approve the final order and letters to commenters was 3-0.
What happens when the sun sets on a smart product?
A recent Federal Trade Commission investigation into one company’s decision to stop providing support for an Internet of Things (IoT) device illuminates some pitfalls IoT businesses should avoid in introducing and marketing these innovative products.
In that case, a company acquired the marketer of a “Smart Home Hub” and then decided to shut down support for the device, thereby rendering it inoperable. Although we closed that investigation, it raises broader issues about what happens when an IoT product or service, or the updates and support for them, stops. First, there are serious issues at play when consumers purchase products that unexpectedly stop functioning due to a unilateral decision by the company that sold it. Second, when a company stops providing technical support, including security updates, for an IoT device, consumers may be left with an out-of-date product that is vulnerable to critical security or privacy bugs. So, if you’re an IoT business, product designer, or marketer, this scenario should make a light bulb go on in your head.
Ask yourself:
- Are you selling a device, a service, or both? What are you telling consumers you’re selling?
- Are consumers getting a fixed-term rental or subscription, or are they getting something they will own and can rely on for the life of the device?
- Would reasonable consumers expect to be able to keep using the device – and have it be fully functional – if the company, even many years later, rides off into the sunset? Would they expect the device to have an “expiration date”?
- Could consumers keep using your device in the ways they would reasonably expect based on their experience with similar devices?
- What did you tell consumers at the outset – or what would they otherwise expect – about the security you would provide for the life of the device?
FTC and Florida Charge Tech Support Operation with Tricking Consumers Into Paying Millions for Bogus Services
The Federal Trade Commission and State of Florida have taken action against defendants who ran an international tech support operation and allegedly misrepresented to consumers that malware or hackers had compromised their computers and that the operation was associated with or certified by Microsoft and Apple to fix their computers. A federal court has temporarily shut down the defendants’ operation, frozen their assets, and placed control of the businesses with a court-appointed receiver. The complaint alleges that defendants, based in Florida, Iowa, Nevada, and Canada, relied on a combination of deceptive online ads and misleading, high-pressure sales tactics to frighten consumers into spending hundreds of dollars for dubious computer “repairs” and antivirus software.
“Scammers like these use incredibly deceptive tactics that make consumers think they are receiving warnings from legitimate technology companies,” said Jessica Rich, director of the FTC’s Bureau of Consumer Protection. “We are proud to work with the Florida Attorney General’s Office to put an end to these fraudulent practices.” According to the complaint, the defendants caused consumers’ computers to display advertisements designed to resemble security alerts from Microsoft or Apple. These ads warned consumers that their computers could be infected with malware and urged them to call a toll-free number in the ad to safeguard both their computer and sensitive personal information stored on it.