{"id":5558,"date":"2023-10-02T12:53:46","date_gmt":"2023-10-02T17:53:46","guid":{"rendered":"https:\/\/blogs.luc.edu\/compliance\/?p=5558"},"modified":"2023-10-02T12:53:46","modified_gmt":"2023-10-02T17:53:46","slug":"cybersecurity-cybersecurity-compliance-safeguarding-sensitive-information","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=5558","title":{"rendered":"Cybersecurity Compliance: Safeguarding Sensitive Information"},"content":{"rendered":"<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><em>Mariam Salmanzadeh <\/em><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><em>Associate Editor<\/em><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><em>Loyola University Chicago School of Law, JD 2025<\/em><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">In today&#8217;s interconnected world, cybersecurity regulations have become crucial for organizations to safeguard sensitive information, mitigating legal and commercial risks. Navigating the complex landscape of regulatory compliance can be a daunting task. However, organizations can effectively meet the regulatory compliance challenge and protect their data with the appropriate standards, procedures, and protocols.<!--more--><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><strong>Taking the first step\u00a0<\/strong><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">Despite cybersecurity being a <a href=\"https:\/\/www.lawfareblog.com\/cybersecurity-idiots\">priority for presidential administrations<\/a> since 1997, little progress has been made within the federal government. The lack of adequate legal regulation for cybersecurity tends to aggravate these issues. Moreover, the administrative practice of regulators <a href=\"https:\/\/www.gao.gov\/products\/gao-21-422t\">leaves a lot to be desired<\/a>; (i) they tend to be cautious when regulating technology, and (ii) they often choose safe but ultimately ineffective approaches. For example, the <a href=\"https:\/\/www.cio.gov\/policies-and-priorities\/FISMA\/#:~:text=Federal%20Information%20Security%20Modernization%20Act%20of%202014%20(FISMA)%2C%20dating,independent%20assessments%20of%20those%20programs.\">Federal Information Security Management Act<\/a> (FISMA) is a law that requires federal agencies to develop, implement, and maintain an information security program. However, FISMA is not a comprehensive cybersecurity law and <a href=\"https:\/\/www.gao.gov\/products\/gao-22-105637\">does not address many of the challenges<\/a> facing the federal government.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">The private sector faces similar challenges. <a href=\"https:\/\/hbr.org\/2021\/12\/navigating-cybersecurity-risks-in-international-trade\">Cybersecurity concerns<\/a>\u00a0can have severe consequences for companies selling digital products internationally. These concerns can lead to\u00a0<a href=\"https:\/\/hbr.org\/2021\/12\/navigating-cybersecurity-risks-in-international-trade\">market restrictions, political entanglements, and damage to global reputations<\/a>. Cybersecurity is crucial for businesses as data loss or theft can have\u00a0<a href=\"https:\/\/www.mdpi.com\/1721788\">severe consequences<\/a>. Cybersecurity standards determine requirements and best practices to protect sensitive data. Many organizations have established standards, but choosing the right one can be challenging. Businesses can learn from others&#8217; experiences and review existing research to select the most appropriate cybersecurity standard or framework for their needs. In addition, the private sector may also be subject to cybersecurity regulations in specific industries or jurisdictions. For example, financial institutions are subject to regulations such as the <a href=\"https:\/\/www.ftc.gov\/business-guidance\/privacy-security\/gramm-leach-bliley-act\">Gramm-Leach-Bliley Act<\/a> (GLBA) and the Cybersecurity Act of 2015. Critical infrastructure operators are subject to regulations such as the Cybersecurity and Infrastructure Security Agency (CISA)&#8217;s <a href=\"https:\/\/www.cisa.gov\/topics\/critical-infrastructure-security-and-resilience\/critical-infrastructure-sectors\">16 critical infrastructure sectors<\/a>.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">In this intricate dance between the private sector and the ever-shifting sands of cybersecurity, the <a href=\"https:\/\/www.ftc.gov\/\">Federal Trade Commission<\/a> (FTC) also plays a pivotal role. The FTC&#8217;s purview extends to scrutinizing and <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/reports\/privacy-data-security-update-2018\/2018-privacy-data-security-report-508.pdf\">enforcing cybersecurity practices<\/a> among businesses, ensuring that they meet the stringent standards necessary to protect consumers&#8217; sensitive information and maintain the integrity of the marketplace.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">The private sector also has a responsibility to take steps to protect its systems and data from cyberattacks. By following cybersecurity standards and regulations, businesses can help mitigate risks and protect their operations. An organization should foster a\u00a0<a href=\"https:\/\/hbr.org\/2021\/12\/navigating-cybersecurity-risks-in-international-trade\">solid strategy<\/a>, engage in political discussions, enhance the cybersecurity image, develop exit and re-entrance plans for markets, and build negotiation leverage as part of a solid strategy. By implementing these measures, companies can better navigate the international cybersecurity landscape.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><strong>How to remain protected\u00a0<\/strong><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">Cybercriminals\u00a0<a href=\"https:\/\/www.complianceandethics.org\/where-data-breaches-happen-the-most-and-why\/\">commonly target<\/a> the retail industry, financial services sector, healthcare sector, public sector\/government services, and education sector. Retail databases contain private customer information, including names, addresses, and bank account numbers, making them prime targets. Hackers can then sell this information on the black market, where each stolen credit card is\u00a0<a href=\"https:\/\/www.complianceandethics.org\/where-data-breaches-happen-the-most-and-why\/\">worth at least $1<\/a>. Therefore, if a hacker can obtain 1 million credit card numbers from a retailer, that hacker could potentially make $1 million from a single transaction.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">However, companies can take several active precautions to prevent breaches and avoid selling private and proprietary information. An organization&#8217;s first step to stop cyber-attacks is to <a href=\"https:\/\/www.complianceandethics.org\/7-most-common-cybersecurity-mistakes-to-avoid\/\">monitor<\/a> its website constantly. For instance, using easy-to-guess passwords is a significant cybersecurity risk. People often think that hackers will breach their data in an overly\u00a0<a href=\"https:\/\/www.complianceandethics.org\/7-most-common-cybersecurity-mistakes-to-avoid\/\">complex way<\/a>, but the reality is that having easy-to-guess passwords can put you at an extremely high risk. Next, testing the company&#8217;s security is critical to protecting data. Hiring a\u00a0<a href=\"https:\/\/builtin.com\/cybersecurity\/cyber-security-companies\">cybersecurity company<\/a>\u00a0to assess the risk of successful hacking and implement more robust solutions to safeguard information will help a company <a href=\"https:\/\/www.bbc.com\/storyworks\/chubb-future-proof\/the-importance-of-cybersecurity-in-business\">tenfold<\/a>.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">Nevertheless, there are challenges with even protecting your data because of government regulations and the cost of implementation. Unfortunately, the\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/forbestechcouncil\/2022\/01\/13\/cutting-the-cost-and-complexity-of-cybersecurity-compliance\/?sh=53002b4051f9\">increase in sophisticated attacks<\/a>\u00a0has led companies to spend\u00a0<a href=\"https:\/\/cyberriskinstitute.org\/industry-unveils-cybersecurity-profile\/\">up to 40%<\/a>\u00a0of their cybersecurity budget submitting regulatory compliance reports while trying to hold up their defenses.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">The\u00a0<a href=\"https:\/\/www.aba.com\/banking-topics\/technology\/cybersecurity\/cybersecurity-profile\">Financial Services Sector (FSP) Cybersecurity Profile<\/a>\u00a0is a notable framework designed to enable organizations to manage and reduce cybersecurity risk. The FSP aims to\u00a0<a href=\"https:\/\/www.forbes.com\/sites\/forbestechcouncil\/2022\/01\/13\/cutting-the-cost-and-complexity-of-cybersecurity-compliance\/?sh=53002b4051f9\">simplify<\/a>\u00a0and consolidate assessments in compliance reporting into a single process, allowing regulators and cybersecurity experts to focus on emerging threats by freeing up their time.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\"><strong>A path forward <\/strong><\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">Navigating cybersecurity regulations and ensuring regulatory compliance in the digital age is critical for organizations. Understanding the evolving landscape, leveraging industry expertise, and implementing best practices will help organizations navigate the complex regulatory environment and safeguard sensitive information effectively. Organizations prioritizing regulatory compliance can protect their data, build trust, and thrive in an increasingly interconnected world.<\/span><\/p>\n<p style=\"font-weight: 400\"><span style=\"font-family: 'times new roman', times, serif\">The time for companies to fully arm their servers and databases with the proper security is\u00a0<a href=\"https:\/\/www.complianceandethics.org\/where-data-breaches-happen-the-most-and-why\/\">now<\/a>. Data breaches are not stopping anytime soon, and hackers are becoming more skilled with emerging technologies.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In today&#8217;s interconnected world, cybersecurity regulations have become crucial for organizations to safeguard sensitive information, mitigating legal and commercial risks. Navigating the complex landscape of regulatory compliance can be a daunting task. However, organizations can effectively meet the regulatory compliance challenge and protect their data with the appropriate standards, procedures, and protocols.<\/p>\n","protected":false},"author":155,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[554,872,914],"class_list":["post-5558","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-cyber-security","tag-fisma","tag-ftc"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/5558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/155"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5558"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/5558\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}