Women in Cybersecurity – Metaverse Law Interviews Malia Mason

Image Credit: Pete Linforth from Pixabay

Metaverse Law recently interviewed Malia Mason, co-founder and president of the Southern California Chapter of Women in CyberSecurity, Navy veteran, and business owner. A transcript of the conversation is available below:

Lily Li: Women make up only 15% of today’s cyber security workforce.  Today, I have brought my good friend, Malia Mason, who’s trying to get that number to 50%.  Malia, thanks for joining me today and talking a little bit about women in the cyber security and tech community.  To get started, can you let us know a little bit about how you got involved in cybersecurity? 

Malia Mason: Yeah, so, my career in cybersecurity actually began in the military when I was in the Navy years ago. I served active duty for four years and worked to secure our nation’s secrets. When I got out of the military, that’s when I wanted to continue to help secure data and decided to get into the cybersecurity realm and I’ve worked as a consultant for a few years and actually, this year, just founded my own small cybersecurity consulting firm called Integrum. We’re working to help secure small businesses, especially in nonprofits. 

Lily Li: Another thing that you’re very involved with is women in cybersecurity. So, tell us a little bit about what that organization does and what’s been happening lately in that space. 

Malia Mason: Yes, so, Women in CyberSecurity is a national nonprofit that was founded in 2012 and I am actually the co-founder and president of the Women in CyberSecurity SoCal chapter.  We boast over a hundred members so far and we have a chapter as well in San Diego and our launch event actually brought over 50 attendees, both women and allies, and it was great to see the community come together and we’re hosting a big Cyber Career Day on October 19th; which should be really, really fun and try to help more people get into this industry, especially women.

Read More
Gold gavel on platform

California Attorney General Releases Proposed CCPA Regulations

Image Credit: 3D Animation Production Company from Pixabay

California Attorney Xavier Becerra unveiled highly-awaited regulations on October 10, 2019 to enforce the California Consumer Privacy Act, a sweeping new privacy law set to take effect on January 1, 2020.

The text of the CCPA proposed regulation is available here. As a few highlights, the proposed regulation:

  • Defines “categories of sources” and “categories of third parties” to include consumer data resellers, among other types of entities. This shows the Attorney General’s increased scrutiny on data brokers.
  • Requires privacy notices to “[b]e accessible to consumers with disabilities” and “[a]t a minimum, provide information on how a consumer with a disability may access the notice in an alternative format.” This is consistent with recent trends towards ADA website compliance.
  • Requires businesses to either (1) notify consumers of the sale of their data, if they collected the data from third party sources, or (2) confirm or receive signed attestations from the source describing how they provided a notice of collection.
  • Requires greater offline rights to notice and opt-outs of sale, for businesses that substantially interact with consumers offline.
  • Contemplates a button or logo opt-out in a modified version of the regulation.
  • Recognizes the security risks of providing specific pieces of information in response to a request, with requirements around verification of identity and security of transmission.

Individuals and businesses interested in shaping the final CCPA regulations can attend public hearings or send comments by mail or email to the following:

  • Email: PrivacyRegulations@doj.ca.gov
  • Privacy Regulations Coordinator
    California Office of the Attorney General
    300 South Spring Street, First Floor
    Los Angeles, CA 90013

The public hearing dates and locations are as follows:

Public Hearing DatesLocations
Sacramento
December 2, 2019
10:00 a.m.
CalEPA Building
Coastal Room, 2nd Floor
1001 I Street
Sacramento, CA 95814
Los Angeles
December 3, 2019
10:00 a.m.
Ronald Reagan Building
Auditorium, 1st Floor
300 S. Spring Street
Los Angeles, CA 90013
San Francisco
December 4, 2019
10:00 a.m.
Milton Marks Conference Center
Lower Level
455 Golden Gate Ave.
San Francisco, CA 94102
Fresno
December 5, 2019
10:00 a.m.
Fresno Hugh Burns Building
Assembly Room #1036
2550 Mariposa Mall
Fresno, CA 93721

More information about the public hearings and proposed CCPA regulation is available on the Attorney General’s CCPA website.

File folders with a small lock in the corner

Will the CCPA and Other State Privacy Laws Face Constitutional Attack?

Image Credit: Pettycon from Pixabay

This article is Part 2 of 3 in a series exploring proposed federal privacy laws and constitutional concerns of privacy laws in the United States. Part 3 will discuss the constitutional challenges facing a proposed federal privacy law. 

In the first part of this series, we examined several federal privacy bills proposed this year, as Congress eagerly tries to pass a single harmonizing federal law. The issue of preemption continues to divide Republican and Democrat lawmakers, however, with the former in favor of an express provision allowing preemption stricter state privacy laws such as the CCPA and the latter largely against such a provision. 

Regardless of whether a federal law passes, with an express preemption provision, state privacy laws are still at risk of constitutional attacks. There are two primary ways that a state privacy law may be challenged: (1) invalidation under the Dormant Commerce Clause, and (2) invalidation under First Amendment grounds. State legislators contemplating the passage of their own privacy laws will need to consider these constitutional issues in the drafting phase, or risk facing opposition on constitutional grounds.

Read More
Gold gavel on platform

Searching for the One Ring to Rule Them All: A Look at 8 U.S. Federal Privacy Bills

Image Credit: 3D Animation Production Company from Pixabay

This article is Part 1 of 2 in a series exploring proposed federal privacy laws in the United States. Part 2 will discuss the constitutional challenges facing not only a proposed federal privacy law but those facing existing state privacy laws as well.

As predicted in our Privacy Law Forecast for 2019, legislators have raced to introduce national privacy regulation in both the House and Senate this year.

In contrast to the European Union’s GDPR, a hodgepodge of sectoral laws govern privacy in specific industries: medical, financial, educational, and marketing sectors, among others. States have enacted laws to protect their residents. And on top of that, Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) grants authority to the FTC to enforce against unfair and deceptive acts and practices.

This all results in a confusing and burdensome “patchwork” of national, state and sectoral rules. (For more in-depth discussion on the current U.S. privacy regulatory landscape, please see American Privacy Laws in a Global Context.)

Given this regulatory environment, legislators are keen to put forth a single federal privacy law to standardize this “patchwork” and forestall the passage of dozens more state privacy bills. Some have set a deadline, hoping to pass a federal privacy law before the CCPA comes into effect on January 1, 2020. Since the start of 2019, lawmakers have introduced about 230 bills that regulate privacy in some way in either the House or Senate.

The following is a sample of comprehensive bills from both sides of the aisle. Though these bills are unlikely to pass committee, they indicate what policies lawmakers are considering in the current negotiations:

Read More
Image of gears directing arrows to shield.

The 2019 Capital One Breach Compared to the 2017 Equifax Breach: Evolving and Improving Attitudes toward Data Security, Breach Detection, and Breach Notification

Image Credit: Khanittha Yajampa via Dreamstime.com

On September 7, 2017, Equifax announced that it had suffered a data breach that exposed the personal data of nearly 147 million people. Two years following the Equifax breach, Capital One also suffered a data breach nearly as massive in scope, affecting approximately 100 million users in the United States and 6 million users in Canada.

A casual observer might think that the two breaches are similar. After all, they both affected a large financial institution and encompassed over a million financial records. The similarities end there, however. Capital One implemented security measures to protect its customer data and engaged in a speedy response to an insider threat. Equifax failed to implement even basic data protection measures and was laggardly in reporting the inevitable breach.

Only time will tell what the full repercussions will be of these two breaches. But based on the facts in front of us, Capital One’s quick response to this breach will ultimately protect more customers in the long run. Comparing the circumstances surrounding the two breaches show a positive trend toward companies taking their customers’ data more seriously and mindfulness of ever-increasing consumer vigilance about their own data.

Read More
1 23 24 25 26 27 29