Last week, we defined a data breach and personal information generally. This week we are going to more specifically deal with the Georgia statute and explain some of the big takeaways for the SMB market in our state. Even if your business does not operate in Georgia, your state probably has a statute in place that is almost identical, so you might want to read this anyway.
When a small business network is hacked and the safety of users’ personal information is breached, the business is forced to take action within a reasonable timeframe. The specific wording is: “in the most expedient time possible and without unreasonable delay…”
For third parties who manage information for businesses, such as value-added resellers (VARs)/cloud providers (like Centerpoint Direct), the timing is more explicit: a notification must be sent within 24 hours following discovery.
This ensures that consumers are notified as early as possible, so that they can take the appropriate countermeasures to prevent identity theft (ie. credit card theft, fraudulent bank account activity…).
Breaches of under 10,000 people require that notification be sent to each customer whose information was exposed. These communications can be made privately, but they must be made. Larger hacks require the business to notify the Consumer Protection Bureau, which often means public shaming by the media.
States differ on this application of the statute. California mandates that any data breach of over 500 customers be communicated to the Office of the Attorney General, for instance.
The structure of notifications filters down from the information aggregator (ie. cloud provider) down through its business customers. Then, in turn, businesses are forced to inform their customers. In other words, the business is held responsible for its own security and the protection of its customers – even if the breach occurs at a higher level.
From a technical standpoint, this implication makes sense because a business can always isolate its sensitive data, protecting its customers should a data breach take place farther up the chain. This tactic protects customers, but it also protects the business from upstream security threats.
We recommend that the SMB market seek out an information security partner – someone who will recommend the appropriate protection plan for your business. With all the cloud security options on the market today, in addition to advanced 2-step validation and cloud backups, there are cost-effective options out there, which can mitigate risk and use information technology to gain a competitive advantage.
Come back next week for the security implications to you as a consumer.
Call our business managed IT services department directly at (404) 777-0147 or simply fill out this form and we will get in touch with you to set up a getting-to-know-you introductory phone call.
Fill in our quick form
We'll schedule an introductory phone call
We'll take the time to listen and plan the next steps
11285 Elkins Rd Suite E1, Roswell, GA 30076
© Copyright 2024 Centerpoint IT. All Rights Reserved. Website in partnership with Tech Pro Marketing. | Privacy Policy
Get Immediate Help For All Your Technology Issues (404) 777-0147
If you want our team at Centerpoint IT to help you with all or any part of your business IT, cybersecurity, or telephone services, just book a call.
Fill in your information below to get started today.
"*" indicates required fields
Fill in your information below to schedule now.
"*" indicates required fields
Before your organization commits to 1, 2, 3 or even longer managed IT services contract, understand what you’re getting. Centerpoint IT gives you the facts in our Managed IT Services Buyer’s Guide.
Enter your information below and we’ll send it over.
"*" indicates required fields
We are turning 15 and want to celebrate this milestone with you because without you this would not have been possible. Throughout this year look for special promotions on services and tools aimed at Making IT Simple for You so you can focus on your business.
We are turning 15 and want to celebrate this milestone with you because without you this would not have been possible. Throughout this year look for special promotions on services and tools aimed at Making IT Simple for You so you can focus on your business.
https://calendly.com/centerpoint-it/discovery-call