Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Information Technology and Cybersecurity

Posted on October 29, 2014 by Doug Cornelius
Print Friendly, PDF & Email

IMG_2059[1]

These are my notes from the NRS Fall Compliance Conference.

Ted Kobus, Baker Hostetler
Karen M. Aavik, First Niagara Financial Group
Tammy Eisenberg, CLS Bank International

In 2012 the average cost of a data breach was $5.4 million. IBM 2014 Cost of Data Breach Study

More breaches happen from lost laptops and media than third-party hackers. Malicious employees may steal information. Ill-informed employees may leave systems open inadvertently. Also keep an eye on employee’s departure. Make sure you shut down the employee’s remote access.

Malware is hard to stop, but it takes a concerted effort. Phishing and spear-phishing are more common. The attacker tries to cause you to voluntarily open a breach by giving them your account information and password.

Vendors cause a substantial portion of breaches. They may not be as careful as you. At the end of contract, you need to make sure you get the data back and they delete the information.

Data Breach Decisions

  • Is it a breach?
  • Who are the key internal personnel that should be involved in the response?
  • Do you involve law enforcement?
  •  Do you hire a forensics company?
  • Do you retain outside counsel?
  • Do you involve regulatory agencies?
  • Is crisis management necessary?
  • Do you offer credit monitoring?
  • Do you get relief from a “law enforcement” delay?

One silver lining. You will be better prepared for the next breach.

What do regulators expect?

  • Transparency
  • prompt and thorough investigation
  • Corrective action
  • appropriate and prompt notification to regulators and customers

Best practices

  • Prepare and practice a response plan
  • respond quickly
  • Bring in the right team
    • Preserve evidence
    • Contain & remediate
    • Let the forensics drive the decision-making
    • Law enforcement
    • Document analysis
    • Involve the C-suite
    • Plan for likely reaction of customers, employees, & key stakeholders
    • Mitigate harm

FTC Recommended Internal Safeguards

Over 50% of data breaches originate from inside the company.
Train and retrain all employees to:
(1) Limit access to customer information to employees who have a business reason to view;
(2) Secure deal jackets and information;
(3) Lock rooms and file cabinets;
(4) Use strong passwords on computers (and don’t share);
(5) Remove access for terminated employees;
(6) Securely dispose of customer information;
(7) Think about what data is provided to a vendor;
(8) Protect customer information.

Identity Theft Red Flag Rules

The key is to see if you are a “covered account” or “financial institution”

Policies/procedures must be based on a periodic identification of client accounts and a risk assessment of potential identity theft, including:
– account opening processes;
– account access processes; and
– previous experiences with identity theft.

The procedures must include the following four elements:
– identifying red flags;
– detecting red flags;
– responding to red flags; and
– periodically updating the program.

 

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • Extending Compliance Dates for Form PF
  • The Massive Scope of Digital Asset Investment Scams
  • SEC Proposes Rescission of Political Contribution Rule for Investment Advisers
  • Is Failure to Disclose Misappropriation Committing Securities Fraud?
  • SEC Sweep of Fake Form ADV Filers
  • New Custody Rule Is On Its Way
  • Can a Farm of Hardwood and Citrus Trees be a Security?
  • The Corporate Transparency Act is Finally Dead
  • The SEC 2026 Rulemaking Agenda
  • The Alignment Gap: Rethinking Costs in Private Equity Fund Formation

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.

© 2026 Compliance Building | Powered by Superbs Personal Blog theme