article thumbnail

US banking regulators propose a rule for 36-hour notice of breach

Data Protection Report

The proposed regulation specifically includes as an example of a notification incident a “ransom malware attack that encrypts a core banking system or backup data.” For more information, please see our white paper. Service providers would be required to notify two individuals at each affected banking organization.

Insurance 141
article thumbnail

Preparing for Ransomware: Are Backups Enough?

eSecurity Planet

For ransomware attacks where network data gets encrypted , backups are the definitive method for restoring network infrastructure. Considering these costs, the Sophos State of Ransomware white paper reported the average cost to recover from a ransomware attack had doubled to $1.85 Beyond Encryption: Exfiltration and Extortion.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Regulatory Update: NAIC Spring 2019 National Meeting

Data Matters

The National Association of Insurance Commissioners (NAIC) held its Spring 2019 National Meeting (Spring Meeting) in Orlando, Florida, from April 6 to 9, 2019. ceding insurer could be eligible for the same reduced collateral requirements that would apply to qualifying EU reinsurers under the revised CFR Model Laws.

article thumbnail

An Approach to Cybersecurity Risk Oversight for Corporate Directors

Data Matters

Encrypting critical data assets. Board-management discussions about cyber risk should include identification of which risks to avoid, which to accept, and which to mitigate or transfer through insurance, as well as specific plans associated with each approach. Encrypting Critical Data Assets. Using appropriate access controls.