<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>breach Archives - Zasio</title>
	<atom:link href="https://zasio.com/tag/breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://zasio.com/tag/breach/</link>
	<description>Digital Records Management Software</description>
	<lastBuildDate>Fri, 05 Apr 2024 21:50:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://zasio.com/wp-content/uploads/2023/05/cropped-zasiopurplefavicon-32x32.png</url>
	<title>breach Archives - Zasio</title>
	<link>https://zasio.com/tag/breach/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What is a Data Leak?</title>
		<link>https://zasio.com/data-leak-breach-what-is-it-zasio/</link>
					<comments>https://zasio.com/data-leak-breach-what-is-it-zasio/#respond</comments>
		
		<dc:creator><![CDATA[Heather Rice]]></dc:creator>
		<pubDate>Tue, 27 Jun 2023 20:17:23 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[By Heather Rice]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[information governance]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Zasio]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1217</guid>

					<description><![CDATA[<p>Refresh your news feed and you will often see yet another company has become the victim of a data leak. Today, most companies are storing sensitive information electronically, making data leaks a major concern.  Information security is becoming more important than ever. Data Leak vs. Data Breach So, what is a data leak? Data leaks and data breaches both involve exposure to sensitive information. The main distinction though, is data leaks are caused internally, usually unintentionally. Data breaches, on the other hand, are intentionally caused by external actors. The most frequent causes of both, however, are a lack of employee training and poor information security. Because they involve external bad actors intentionally breaching a system to attack your data, data breaches are more nefarious than data leaks. But, just because a data leak isn’t as sinister in origin doesn’t mean its consequences are any less severe. Criminals often use information from data leaks for data breaches. You may recall from your newsfeed earlier this year when Samsung became one of the higher profile examples of a company suffering a data leak.[1] In Samsung’s case, employees shared sensitive source code with ChatGPT to have the generative AI app check for errors. Employees [&#8230;]</p>
<p>The post <a href="https://zasio.com/data-leak-breach-what-is-it-zasio/" data-wpel-link="internal">What is a Data Leak?</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Refresh your news feed and you will often see yet another company has become the victim of a data leak. Today, most companies are storing sensitive information electronically, making data leaks a major concern.  Information security is becoming more important than ever.</p>
<p><strong>Data Leak vs. Data Breach</strong></p>
<p>So, what is a data leak? Data leaks and data breaches both involve exposure to sensitive information. The main distinction though, is data leaks are caused internally, usually unintentionally. Data breaches, on the other hand, are intentionally caused by external actors. The most frequent causes of both, however, are a lack of employee training and poor information security.</p>
<p>Because they involve external bad actors intentionally breaching a system to attack your data, data breaches are more nefarious than data leaks. But, just because a data leak isn’t as sinister in origin doesn’t mean its consequences are any less severe. Criminals often use information from data leaks for data breaches.</p>
<p>You may recall from your newsfeed earlier this year when Samsung became one of the higher profile examples of a company suffering a data leak.<a href="https://www.zasio.com/data-leak-breach-what-is-it-zasio/#_ftn1" name="_ftnref1" data-wpel-link="internal">[1]</a> In Samsung’s case, employees shared sensitive source code with ChatGPT to have the generative AI app check for errors. Employees also tried using ChatGPT to convert a recording of a meeting into notes. This information is now available on the internet. ChatGPT is becoming increasingly popular for summarizing documents, which becomes a concern, particularly for privacy professionals worried about exposing personal information.</p>
<p><strong>Types of Leaks</strong></p>
<ul>
<li>Confidential Information: These leaks can include a company’s financial data, trade secrets, and other proprietary business information.</li>
<li>Intellectual Property: These leaks involve a company’s patents, trademarks, copyrights, and trade secrets.</li>
<li>Personal Information: These leaks include customer and employee information. This data type typically includes names, addresses, or credit card information.</li>
</ul>
<p>All types of leaks can have devastating consequences, including damaging a company’s reputation, loss of customers, legal fees, and revenue loss, to name a few.</p>
<p><strong>Data Leak Prevention</strong></p>
<p>It is important to be proactive to prevent data leaks from happening. Here are some things companies can do:</p>
<ul>
<li>Monitor Network Traffic: Increase your network traffic monitoring. Increased monitoring may help identify suspicious activity and pinpoint security vulnerabilities.</li>
<li>Restrict Access: Sensitive or confidential data shouldn’t be accessed by those that don’t require it. Companies should only grant access to employees that require access to sensitive information and are trained to safeguard this data.</li>
<li>Multifactor Identification: It is always a good policy to have strong password requirements for company employees. Implementing multifactor identification ensures that password leaks themselves don’t cause a breach.</li>
<li>Training: Employers need to train employees to recognize the tricky tactics cybercriminals use, particularly for email phishing. Suspicious emails should be reported to your company’s security team. Regular security training keeps security top-of-mind for employees.</li>
<li>Vendor Risk Assessments: Unfortunately, your vendors may not take cybersecurity seriously. Risk questionnaires can be used to determine third-party security risks. Companies should evaluate each vendor’s security risks and ensure they comply with regulatory standards.</li>
</ul>
<p><a href="https://www.zasio.com/data-leak-breach-what-is-it-zasio/#_ftnref1" name="_ftn1" data-wpel-link="internal">[1]</a> Mashable SEA. <a href="https://sea.mashable.com/tech/23047/whoops-samsung-workers-accidentally-leaked-trade-secrets-via-chatgpt" data-wpel-link="external" rel="external noopener noreferrer"><em>Whoops, Samsung Workers Accidentally Leaked Trade Secrets via ChatGPT</em></a>. April 6, 2023.</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></p>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fdata-leak-breach-what-is-it-zasio%2F&amp;linkname=What%20is%20a%20Data%20Leak%3F" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fdata-leak-breach-what-is-it-zasio%2F&amp;linkname=What%20is%20a%20Data%20Leak%3F" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fdata-leak-breach-what-is-it-zasio%2F&amp;linkname=What%20is%20a%20Data%20Leak%3F" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fdata-leak-breach-what-is-it-zasio%2F&#038;title=What%20is%20a%20Data%20Leak%3F" data-a2a-url="https://zasio.com/data-leak-breach-what-is-it-zasio/" data-a2a-title="What is a Data Leak?" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/data-leak-breach-what-is-it-zasio/" data-wpel-link="internal">What is a Data Leak?</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/data-leak-breach-what-is-it-zasio/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Upcoming Changes in International Data Retention Legislation</title>
		<link>https://zasio.com/upcoming-changes-in-international-data-retention-legislation/</link>
					<comments>https://zasio.com/upcoming-changes-in-international-data-retention-legislation/#respond</comments>
		
		<dc:creator><![CDATA[Zasio]]></dc:creator>
		<pubDate>Tue, 29 Nov 2016 19:56:07 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[By Jared Walker]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Cyber security]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[data localization]]></category>
		<category><![CDATA[international law]]></category>
		<category><![CDATA[Jared Walker]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[MDBN]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[records retention]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://wordpress-140425-3498808.cloudwaysapps.com/?p=1075</guid>

					<description><![CDATA[<p>The post <a href="https://zasio.com/upcoming-changes-in-international-data-retention-legislation/" data-wpel-link="internal">Upcoming Changes in International Data Retention Legislation</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">For companies that operate in international jurisdictions, it is vital to stay up-to-date on legislative actions that affect data retention policies and compliance. This allows companies to make internal adjustments as necessary and to avoid costly sanctions and other harmful penalties for non-compliance. Here are just a few upcoming laws worth noting:</p>
<p><strong>European Union – General Data Protection Regulation:</strong> In May of 2016, EU policy makers implemented a comprehensive legislative reform of personal data protection rules. Going into effect on May 25, 2018, it places a high standard of protection on personal data held by companies by regulating the collection, use, storage, and breach notification protocol of such data. The regulation also imposes sharply increased fines and sanctions for violations. Broad in scope, it will particularly affect industries such as the financial sector, which by nature collects and stores large amounts of personal data. Read more <a href="http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2016.119.01.0001.01.ENG&amp;toc=OJ:L:2016:119:TOC" data-wpel-link="external" rel="external noopener noreferrer"><u>here</u></a>.</p>
<p><strong>Australia – Mandatory Data Breach Notification (MDBN):</strong> Introduced into the House of Representatives last month as the Privacy Amendment (Notifiable Data Breaches) Bill and anticipated to take effect in late 2017, the Australia Federal Parliament is expected to pass MDBN. This law will require companies that suffer a suspected data breach that is likely to cause serious harm to both investigate the breach and to notify both the impacted individuals and the Privacy Commissioner of the breach. Previously, companies were not required to notify anyone of a data breach or hack. If passed, MDBN will be implemented as part of Australia’s Privacy Act, broadly affecting companies holding personal data in Australia. <a href="https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r5747" data-wpel-link="external" rel="external noopener noreferrer"><u>Here</u></a> is the current text of the bill, as it reads in the House.</p>
<p><strong>China – Cybersecurity Law:</strong>  On November 7<sup>th</sup>, China’s Standing Committee of the National People’s Congress adopted the Cybersecurity Law. Taking effect on June 1, 2017, this law will have sweeping effects on business operations in China, particularly for internet and technology companies. The law will require network operators to comply with testing and certification requirements that pertain to computer equipment and network operations and will grant the government access to stored data for suspected violations.</p>
<p>This law also includes data localization requirements (personal data on Chinese citizens must be kept on domestic servers), personal data use and disclosure requirements, “real name” polices (users of instant message and other network services are required to register with their real identity), and whistleblower protections, among other things. A variety of penalties are in place for violations, depending on the type and severity of the violation. <a href="http://www.xinhuanet.com/politics/2016-11/07/c_1119867015.htm" data-wpel-link="external" rel="external noopener noreferrer"><u>Here</u></a> is the final authorized version of the law, as provided by China’s official press agency.</p>
<p><a href="https://www.zasio.com/about-us/contact-us/" data-wpel-link="internal">Contact Zasio</a> today to see how our host of software solutions and consulting services can help you stay complaint with your data retention policies and practices.</p>
<p>&nbsp;</p>
<p><em>Disclaimer: The purpose of this post is to provide general education on Information Governance topics. The statements are informational only and do not constitute legal advice. If you have specific questions regarding the application of the law to your business activities, you should seek the advice of your legal counsel.</em></div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row et_pb_row_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_1  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_with_border et_pb_module et_pb_team_member et_pb_team_member_0 clearfix  et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_team_member_image et-waypoint et_pb_animation_off"><img decoding="async" width="96" height="96" src="https://zasio.com/wp-content/uploads/2023/05/Jared-Walker-01-96x96-1.png" alt="Author: Jared Walker, JD" class="wp-image-2021" /></div>
				<div class="et_pb_team_member_description">
					<h4 class="et_pb_module_header">Author: Jared Walker, JD</h4>
					<p class="et_pb_member_position">Senior Research Analyst, Team Lead / Licensed Attorney</p>
					
					
				</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fzasio.com%2Fupcoming-changes-in-international-data-retention-legislation%2F&amp;linkname=Upcoming%20Changes%20in%20International%20Data%20Retention%20Legislation" title="Facebook" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_x" href="https://www.addtoany.com/add_to/x?linkurl=https%3A%2F%2Fzasio.com%2Fupcoming-changes-in-international-data-retention-legislation%2F&amp;linkname=Upcoming%20Changes%20in%20International%20Data%20Retention%20Legislation" title="X" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fzasio.com%2Fupcoming-changes-in-international-data-retention-legislation%2F&amp;linkname=Upcoming%20Changes%20in%20International%20Data%20Retention%20Legislation" title="LinkedIn" rel="nofollow noopener external noreferrer" target="_blank" data-wpel-link="external"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fzasio.com%2Fupcoming-changes-in-international-data-retention-legislation%2F&#038;title=Upcoming%20Changes%20in%20International%20Data%20Retention%20Legislation" data-a2a-url="https://zasio.com/upcoming-changes-in-international-data-retention-legislation/" data-a2a-title="Upcoming Changes in International Data Retention Legislation" data-wpel-link="external" rel="external noopener noreferrer"></a></p><p>The post <a href="https://zasio.com/upcoming-changes-in-international-data-retention-legislation/" data-wpel-link="internal">Upcoming Changes in International Data Retention Legislation</a> appeared first on <a href="https://zasio.com" data-wpel-link="internal">Zasio</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zasio.com/upcoming-changes-in-international-data-retention-legislation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
