Cyber Security, Data Management & Privacy

These days, if your business or organization even touches data about individuals or other protected information – let alone collects, stores or shares it – it is likely subject to an ever-growing and complex web of state, federal and foreign laws, regulatory schemes and industry standards. These rules require your company or organization to implement and support appropriate privacy and data security safeguards, as well as mitigate the harm of any breach. Privacy and data security compliance also requires you to identify, understand and meet the increasingly heightened standards often included in contracts with customers, vendors, lenders, members and others.

Our privacy and data protection team can guide your compliance with those laws and contract duties, helping you manage, use and dispose of information in a way that is both practical and cost-effective. In the event of a breach, we walk our clients through all facets of the crisis, including by assisting with internal and external forensic investigations, communicating with law enforcement, determining the extent of any required notifications, ensuring that notices and other actions comply with applicable laws, mitigating the harm done, managing the damage to reputation, and defending against regulatory penalties and lawsuits.

Our team understands the technology, the laws and the underlying principles of privacy, data security and data management. For well over a decade, we have worked with clients to reduce privacy and data security exposure in a landscape of rapidly changing risks, while accounting for their unique circumstances and resources.

Use our experience to protect your business

  • Compliance:  The alphabet soup of U.S. laws requiring compliance includes HIPAA, HITECH, CAN-SPAM, COPPA, FISMA, FERPA, FCRA and others. And that is just at the U.S. national level. Most states have their own, unique laws, such as California’s CCPA. At the same time, foreign jurisdictions are increasingly adopting strict data protection laws with extraterritorial application that reaches U.S. organizations, including GDPR and ePrivacy laws (European Economic Area), PIPEDA (Canada) and other laws that are either copycats of, or inspired by, GDPR.
  • Industry standards:  You may also be subject to binding industry standards, such as the Payment Card Industry – Data Security Standards (PCI-DSS), which apply to any business that accepts credit or debit card payments.
  • Understand where you are today: We have developed a comprehensive information governance audit/privacy audit to help you with a comprehensive overview of your information governance processes and policies and determine which aspects may be vulnerable, or out of compliance, with applicable legal and industry requirements.
  • Vendor contracts:  Outside of your own facilities and processes, you may be vulnerable because of your agreements with vendors, such as cloud service providers and web hosting firms. We will review your existing contracts and negotiate or renegotiate them to ensure compliance, as well as protection if the vendor defaults.
  • Policies and processes:  Weak passwords, flash drives and memory sticks, and laptops loaded with unprotected confidential data can all lead to exposure for a breach. Employees need to be trained to understand the vulnerability of your data. The right policies and processes can reinforce this training, including penalties for carelessness, two-factor authentication, and preventing employees from downloading apps and software programs onto the organization's devices. We partner with computer and system experts to ensure that you have the proper technical, administrative and physical safeguards in place.
  • Insurance policy assessments: While major insurance companies offer insurance against the cost of a breach, there is as yet no agreement on industry standards. With a full understanding of the policy language and how it would apply in the event of a breach, we can provide you the room you need to negotiate with insurance companies.
  • Practical, pragmatic advice: As business lawyers, we understand the need to balance risk against costs.  We are experienced in helping clients manage the differing needs and interests of their internal stakeholders, including accounting, marketing, human resources, IT and legal.


And if a data breach does occur...

A security breach has financial, reputational, operational, physical and legal costs. When a breach occurs, it is important to react swiftly and comprehensively. Our Cybersecurity team has developed strategies for managing the risks that follow a breach, from crisis management to responding to governmental inquiries and investigations. And, in the disputes that can often follow a breach, we represent clients in all phases of resolution, whether in negotiated settlements or contentious litigation.

Name
Title
Contact
Counsel
Email
410.347.8709
Counsel
Email
410.347.8709
Partner
Email
410.347.8707
Partner
Email
410.347.8707
Partner
Email
804.977.1244
Partner
Email
804.977.1244
Partner
Email
410.347.9441
Partner
Email
410.347.9441
Partner
Email
410.347.8721
Partner
Email
410.347.8721
Partner
Email
443.263.8209
Partner
Email
443.263.8209
Senior Counsel
Email
646.618.8653
Senior Counsel
Email
646.618.8653

Quantum Computing Is a Present-Tense Governance Issue: A General Counsel’s Roadmap for Privacy, Security and Compliance

Quantum computing poses an unusual problem for general counsel: the deadline is uncertain, but waiting for certainty may itself create material risk.

No publicly known quantum computer can presently defeat the public-key cryptography on which modern commerce depends. The timing of a “cryptographically relevant” quantum computer remains contested. Yet adversaries do not need to wait. They can collect encrypted information today and attempt to decrypt it later—a strategy commonly called “harvest now, decrypt later.” At the same time, large organizations may need years to locate cryptography embedded across applications, cloud services, connected products, operational technology, certificates, digital signatures, and third-party platforms.

Client Alert: Maryland Adopts Groundbreaking Online Data Privacy Act of 2024: What You Need to Know

On May 9, 2024, Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (“MODPA”). MODPA will take effect on October 1, 2025, but will not apply to personal data processing activities occurring before April 1, 2026. MODPA is the latest in a series of state data privacy laws that impose comprehensive obligations on businesses that collect, process, or sell personal data of consumers and otherwise meet certain jurisdictional thresholds.  

Client Alert: Maryland Adopts Groundbreaking Online Data Privacy Act of 2024: What You Need to Know

On May 9, 2024, Governor Wes Moore signed into law the Maryland Online Data Privacy Act of 2024 (“MODPA”). MODPA will take effect on October 1, 2025, but will not apply to personal data processing activities occurring before April 1, 2026. MODPA is the latest in a series of state data privacy laws that impose comprehensive obligations on businesses that collect, process, or sell personal data of consumers and otherwise meet certain jurisdictional thresholds.  

Client Alert: New Laws Prohibit Certain Data Transfers to China, Russia, Iran, and other Foreign Adversaries of the U.S.

In addition to its well-publicized move to prohibit more than 150 million Americans from posting embarrassing dance videos of themselves on TikTok (at least while it is Chinese-owned), the U.S. federal government recently adopted two significant federal data transfer prohibitions: (1) the Protecting Americans’ Data from Foreign Adversaries Act of 2024 (“PADFA”); and (2) an Executive Order entitled “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” Any organization that currently shares, or is considering sharing, sensitive personally identifiable information with anyone in China, Russia, Iran or any other “foreign adversaries” of the United States should determine whether these new prohibitions require them to change their data transfer activities.

Client Alert: New Laws Prohibit Certain Data Transfers to China, Russia, Iran, and other Foreign Adversaries of the U.S.

In addition to its well-publicized move to prohibit more than 150 million Americans from posting embarrassing dance videos of themselves on TikTok (at least while it is Chinese-owned), the U.S. federal government recently adopted two significant federal data transfer prohibitions: (1) the Protecting Americans’ Data from Foreign Adversaries Act of 2024 (“PADFA”); and (2) an Executive Order entitled “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” Any organization that currently shares, or is considering sharing, sensitive personally identifiable information with anyone in China, Russia, Iran or any other “foreign adversaries” of the United States should determine whether these new prohibitions require them to change their data transfer activities.

Client Alert: New Jersey Privacy Law

On January 16, 2024, New Jersey became the fourteenth state to enact comprehensive privacy legislation after the passage of the New Jersey Data Privacy Act (“NJDPA”), adding to the growing national focus on consumer personal data protections, albeit at the state level. 

Client Alert: New Jersey Privacy Law

On January 16, 2024, New Jersey became the fourteenth state to enact comprehensive privacy legislation after the passage of the New Jersey Data Privacy Act (“NJDPA”), adding to the growing national focus on consumer personal data protections, albeit at the state level. 

Client Alert: Is Your Credit Union Ready to Comply with Updated NCUA Cyber Incident Notification Requirements?

Under final regulations updated on March 1, 2023 and effective as of September 1, 2023, the National Credit Union Administration (“NCUA”) imposed stringent new cyber incident reporting requirements on federally chartered corporate credit unions and federally insured, state-chartered corporate credit unions (“FICUs”). FICUs that experience a cyber incident that rises to the level of a “reportable cyber incident” must now notify the NCUA (a) as soon as possible; and (b) no later than 72 hours after the FICU reasonably believes that it has experienced a reportable cyber incident or received a notification from a third party regarding a reportable cyber incident.

Client Alert: Is Your Credit Union Ready to Comply with Updated NCUA Cyber Incident Notification Requirements?

Under final regulations updated on March 1, 2023 and effective as of September 1, 2023, the National Credit Union Administration (“NCUA”) imposed stringent new cyber incident reporting requirements on federally chartered corporate credit unions and federally insured, state-chartered corporate credit unions (“FICUs”). FICUs that experience a cyber incident that rises to the level of a “reportable cyber incident” must now notify the NCUA (a) as soon as possible; and (b) no later than 72 hours after the FICU reasonably believes that it has experienced a reportable cyber incident or received a notification from a third party regarding a reportable cyber incident.

Client Alert: State Privacy Laws and Nonprofit Organizations

The U.S. data privacy regulatory framework is complex and is becoming more so with each passing day. On July 18, 2023, Oregon became the eleventh state to enact comprehensive privacy legislation, joining five other states (Iowa, Indiana, Montana, Tennessee, and Texas) that have passed “comprehensive” privacy legislation this year.

Client Alert: State Privacy Laws and Nonprofit Organizations

The U.S. data privacy regulatory framework is complex and is becoming more so with each passing day. On July 18, 2023, Oregon became the eleventh state to enact comprehensive privacy legislation, joining five other states (Iowa, Indiana, Montana, Tennessee, and Texas) that have passed “comprehensive” privacy legislation this year.

Client Alert: Texas and Tennessee Join the Cacophony of State Data Privacy Laws 

On June 18, 2023, Texas became the eleventh state to enact comprehensive privacy legislation after the recent passage of the Texas Data Privacy and Security Act (“TDPSA”). Texas now joins Tennessee as the latest entry into an increasingly complex web of state privacy laws. On May 11, Gov. Bill Lee signed into law the Tennessee Information Protection Act (“TIPA”), which itself follows recent enactments of data privacy laws in Iowa, Indiana, Florida, and Montana.  
 

Client Alert: Texas and Tennessee Join the Cacophony of State Data Privacy Laws 

On June 18, 2023, Texas became the eleventh state to enact comprehensive privacy legislation after the recent passage of the Texas Data Privacy and Security Act (“TDPSA”). Texas now joins Tennessee as the latest entry into an increasingly complex web of state privacy laws. On May 11, Gov. Bill Lee signed into law the Tennessee Information Protection Act (“TIPA”), which itself follows recent enactments of data privacy laws in Iowa, Indiana, Florida, and Montana.  
 

Data Breaches and Your Privacy/Cybersecurity Program

Data breaches have become a commonplace occurrence. Nearly every business, including nonprofits , collects, stores and uses personal information (PI) that is valuable to bad actors. All organizations store and process PI about their employees. Many nonprofit organizations store and process PI about their donors and volunteers. Bad actors can cause financial harm to the individuals whose PI is stolen.

Data Breaches and Your Privacy/Cybersecurity Program

Data breaches have become a commonplace occurrence. Nearly every business, including nonprofits , collects, stores and uses personal information (PI) that is valuable to bad actors. All organizations store and process PI about their employees. Many nonprofit organizations store and process PI about their donors and volunteers. Bad actors can cause financial harm to the individuals whose PI is stolen.

Client Alert: Maryland Considers Adoption of Biometric Data Privacy Act

If your organization collects or uses, or is thinking about collecting or using, biometric data, such as fingerprints, DNA scans, retinal scans or voice prints obtained from customers, employees or others, the Maryland Biometric Data Privacy Act (the “Biometric Act”) currently under consideration by the Maryland General Assembly should be of keen interest to you. If adopted, House Bill 33  (“HB 33”) (and its companion, Senate Bill 169), would regulate “private entities’” which collect or possess biometric data and subject those who violate those regulations to investigations and claims brought by the Maryland Attorney General or private litigants.

Client Alert: Maryland Considers Adoption of Biometric Data Privacy Act

If your organization collects or uses, or is thinking about collecting or using, biometric data, such as fingerprints, DNA scans, retinal scans or voice prints obtained from customers, employees or others, the Maryland Biometric Data Privacy Act (the “Biometric Act”) currently under consideration by the Maryland General Assembly should be of keen interest to you. If adopted, House Bill 33  (“HB 33”) (and its companion, Senate Bill 169), would regulate “private entities’” which collect or possess biometric data and subject those who violate those regulations to investigations and claims brought by the Maryland Attorney General or private litigants.

Data Privacy and Security in the Remote Work Era

During the course of the pandemic, IT departments were overwhelmed by the pressing need to provide employees with remote access in a very short time. That need may have, in some cases, overridden established processes and procedures around data security.

Data Privacy and Security in the Remote Work Era

During the course of the pandemic, IT departments were overwhelmed by the pressing need to provide employees with remote access in a very short time. That need may have, in some cases, overridden established processes and procedures around data security.

Client Alert - The Colorado Privacy Act: Both Bark and Bite

Europe began the trend, California followed suit shortly after, and now the flood gates have opened.  Colorado is the third state that is on the brink of enacting a strict and extensive privacy law that has significant implications for a wide variety of organizations that control or process personal data.

Client Alert - The Colorado Privacy Act: Both Bark and Bite

Europe began the trend, California followed suit shortly after, and now the flood gates have opened.  Colorado is the third state that is on the brink of enacting a strict and extensive privacy law that has significant implications for a wide variety of organizations that control or process personal data.

Client Alert: Executive Order on Cybersecurity – What Government Contractors Need to Know

In the wake of the Colonial Pipeline Hack, on May 12, 2021, the Biden Administration issued an Executive Order (EO) on Improving the Nation’s Cybersecurity. The Government is proposing broad changes to the Federal Acquisition Regulation (FAR) and Department of Defense FAR Supplement (DFARS) in two areas. What do government contractors need to know?

Client Alert: Executive Order on Cybersecurity – What Government Contractors Need to Know

In the wake of the Colonial Pipeline Hack, on May 12, 2021, the Biden Administration issued an Executive Order (EO) on Improving the Nation’s Cybersecurity. The Government is proposing broad changes to the Federal Acquisition Regulation (FAR) and Department of Defense FAR Supplement (DFARS) in two areas. What do government contractors need to know?

Privacy Compliance and Personal Data Processing 101 - Tips for Businesses and Nonprofit Organizations

Whiteford attorneys Razvan Miutescu and Kristen Bertch from our Intellectual Property and Technology group were interviewed by Dorothy Deng in this presentation. Over the past few years, the general public has grown to be much more aware about data privacy issues. With the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and new U.S. privacy legislations being introduced to protect personal data, we discuss observations on business trends, privacy principles, legal compliance and more. The presenters also provide action items and practical suggestions to help businesses and nonprofit organizations navigate the evolving privacy law landscape.

Privacy Compliance and Personal Data Processing 101 - Tips for Businesses and Nonprofit Organizations

Whiteford attorneys Razvan Miutescu and Kristen Bertch from our Intellectual Property and Technology group were interviewed by Dorothy Deng in this presentation. Over the past few years, the general public has grown to be much more aware about data privacy issues. With the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and new U.S. privacy legislations being introduced to protect personal data, we discuss observations on business trends, privacy principles, legal compliance and more. The presenters also provide action items and practical suggestions to help businesses and nonprofit organizations navigate the evolving privacy law landscape.

Client Alert: Washington DC Increases Breach Response Requirements and Focuses on Data Security

A recent amendment to the District of Columbia’s data breach notification law (the “D.C. Breach Law”) highlights the nation’s increased focus on data security standards. Generally, the changes to the D.C. Breach Law fall into three categories: (1) expanding what is considered a reportable incident; (2) expanding the notification requirements for breaches; and (3) emphasizing proactive data security measures.

Client Alert: Washington DC Increases Breach Response Requirements and Focuses on Data Security

A recent amendment to the District of Columbia’s data breach notification law (the “D.C. Breach Law”) highlights the nation’s increased focus on data security standards. Generally, the changes to the D.C. Breach Law fall into three categories: (1) expanding what is considered a reportable incident; (2) expanding the notification requirements for breaches; and (3) emphasizing proactive data security measures.

Client Alert: Guidance Issued for Ed Tech Companies and Schools during the COVID-19 Crisis

The Children’s Online Privacy Protection Act (“COPPA”) generally requires that operators of commercial websites and online services take certain steps to protect online privacy and safety of children under the age of 13.  Those steps include COPPA’s requirement that companies covered by COPPA provide notice of their data collection and use practices and obtain verifiable parental consent before collecting certain data and that they maintain reasonable data security safeguards.

Client Alert: Guidance Issued for Ed Tech Companies and Schools during the COVID-19 Crisis

The Children’s Online Privacy Protection Act (“COPPA”) generally requires that operators of commercial websites and online services take certain steps to protect online privacy and safety of children under the age of 13.  Those steps include COPPA’s requirement that companies covered by COPPA provide notice of their data collection and use practices and obtain verifiable parental consent before collecting certain data and that they maintain reasonable data security safeguards.

Client Alert: OCR Issues Guidance About Sharing Patient Information and Telehealth Communications during Pandemic

The Office of Civil Rights (“OCR”) recently issued bulletins with important guidance for health care providers during the COVID-19 pandemic. 

The OCR has recognized that, during the COVID-19 national emergency, health care providers may seek to communicate with patients, and provide so-called “telehealth” services, through remote communications technologies.  Some of these technologies, and the manner in which they are used by HIPAA-covered healthcare providers, may not fully comply with the requirements of the HIPAA Rules.  However, in light of the national emergency, the OCR said that it will not impose penalties against covered health care providers for the lack of a HIPAA business associate agreement (“BAA”) with video communication vendors, or any other noncompliance with the HIPAA Rules that relates to the good faith provision of telehealth services during the COVID-19 nationwide public health crisis.

Client Alert: OCR Issues Guidance About Sharing Patient Information and Telehealth Communications during Pandemic

The Office of Civil Rights (“OCR”) recently issued bulletins with important guidance for health care providers during the COVID-19 pandemic. 

The OCR has recognized that, during the COVID-19 national emergency, health care providers may seek to communicate with patients, and provide so-called “telehealth” services, through remote communications technologies.  Some of these technologies, and the manner in which they are used by HIPAA-covered healthcare providers, may not fully comply with the requirements of the HIPAA Rules.  However, in light of the national emergency, the OCR said that it will not impose penalties against covered health care providers for the lack of a HIPAA business associate agreement (“BAA”) with video communication vendors, or any other noncompliance with the HIPAA Rules that relates to the good faith provision of telehealth services during the COVID-19 nationwide public health crisis.

Client Alert: COVID-19 Cyber Scams: Protect Your Organization

With everyone’s attentions devoted to the COVID-19 crisis and the disruptions it has caused to the normal rhythms of business and personal affairs, it should come as no surprise that criminals and scammers are seeking to take advantage of the situation.

Client Alert: COVID-19 Cyber Scams: Protect Your Organization

With everyone’s attentions devoted to the COVID-19 crisis and the disruptions it has caused to the normal rhythms of business and personal affairs, it should come as no surprise that criminals and scammers are seeking to take advantage of the situation.

Autopsy Of A Cyber Nightmare - WTP Speaking

Using today’s business technology is a double-edged sword – you need it to compete, yet it exposes you to a ghastly horde of cyber monsters. The ever-evolving cyber threat landscape is a dark and mystifying realm for non-technical executives, obscured by nightmarish tales spattered throughout the daily headlines.

Don’t let the fear of the unknown entomb your business. Our panel of spirited cyber experts will arm you with a goodie bag of straight-forward strategies to help protect your organization.

Autopsy Of A Cyber Nightmare - WTP Speaking

Using today’s business technology is a double-edged sword – you need it to compete, yet it exposes you to a ghastly horde of cyber monsters. The ever-evolving cyber threat landscape is a dark and mystifying realm for non-technical executives, obscured by nightmarish tales spattered throughout the daily headlines.

Don’t let the fear of the unknown entomb your business. Our panel of spirited cyber experts will arm you with a goodie bag of straight-forward strategies to help protect your organization.

ASAE Annual Meeting - WTP Speaking

Keith Moulsdale will be leading a Cybersecurity Roundtable on behalf of the ASAE Healthcare Community Committee.

ASAE Annual Meeting - WTP Speaking

Keith Moulsdale will be leading a Cybersecurity Roundtable on behalf of the ASAE Healthcare Community Committee.

Developing an Insider Threat Program: Risk Mitigation and Compliance

Wednesday, November 30, 2016, marks the deadline by which affected contractors must comply with new US Government insider threat mitigation requirements. The US National Industrial Security Program (NISPOM) mandates measures companies must take to secure classified information. On May 18, 2016, the Department of Defense issued Change 2 to NISPOM, significant because it requires contractors (defined as any "industrial, educational, commercial, or other entity that has been granted a facility security clearance (FCL) by a Cognizant Security Agency") to implement an Insider Threat Program no later than November 30, 2016. We're two weeks away from that deadline, and yesterday the Chesapeake Regional Technology Council convened a forum in which experts discussed mitigating the insider threat at the Chesapeake Innovation Center in Odenton, Maryland, to give companies some perspective on what NISPOM Change 2 means to them.

Developing an Insider Threat Program: Risk Mitigation and Compliance

Wednesday, November 30, 2016, marks the deadline by which affected contractors must comply with new US Government insider threat mitigation requirements. The US National Industrial Security Program (NISPOM) mandates measures companies must take to secure classified information. On May 18, 2016, the Department of Defense issued Change 2 to NISPOM, significant because it requires contractors (defined as any "industrial, educational, commercial, or other entity that has been granted a facility security clearance (FCL) by a Cognizant Security Agency") to implement an Insider Threat Program no later than November 30, 2016. We're two weeks away from that deadline, and yesterday the Chesapeake Regional Technology Council convened a forum in which experts discussed mitigating the insider threat at the Chesapeake Innovation Center in Odenton, Maryland, to give companies some perspective on what NISPOM Change 2 means to them.

bwtech@UMBC Cybertini - WTP sponsoring

bwtech@UMBC and its regional economic development partners will host its renowned CyberTini networking social at the Columbus Center (Pier Five) in downtown Baltimore’s Inner Harbor on October 19th from 5 p.m. to approximately 7:30 p.m. Please Save the Date and spread the word!

A high end C-level cocktail party, and official event of the CyberMaryland Conference, which includes announcements and comments by the "movers and shakers" in the cybersecurity world.



 

bwtech@UMBC Cybertini - WTP sponsoring

bwtech@UMBC and its regional economic development partners will host its renowned CyberTini networking social at the Columbus Center (Pier Five) in downtown Baltimore’s Inner Harbor on October 19th from 5 p.m. to approximately 7:30 p.m. Please Save the Date and spread the word!

A high end C-level cocktail party, and official event of the CyberMaryland Conference, which includes announcements and comments by the "movers and shakers" in the cybersecurity world.



 

Cybersecurity and Cloud Summit - WTP sponsoring

With today’s cybersecurity threats and rapidly evolving malware, your company faces data security risk exposures from internal and external sources every day. It’s truly not a matter of if, but when, you will experience an incident.

Join Whiteford, Taylor & Preston and RSM on Sept. 27 for an event designed to help you prepare for, identify and mitigate a data breach.

Topics to be discussed during this informative session include:

  • Top tips for increasing operational efficiency in your organization

Cybersecurity and Cloud Summit - WTP sponsoring

With today’s cybersecurity threats and rapidly evolving malware, your company faces data security risk exposures from internal and external sources every day. It’s truly not a matter of if, but when, you will experience an incident.

Join Whiteford, Taylor & Preston and RSM on Sept. 27 for an event designed to help you prepare for, identify and mitigate a data breach.

Topics to be discussed during this informative session include:

  • Top tips for increasing operational efficiency in your organization

Risk Summit - WTP speaking

Keith Moulsdale will be a featured speaker at the Nonprofit Risk Management Center's 2016 Risk Summit in Chicago.  The topic is "Solving the Data Security Puzzle: How to Prepare for and Respond to Data Security Threats."  For more information, please contact events@wtplaw.com. 

 

Risk Summit - WTP speaking

Keith Moulsdale will be a featured speaker at the Nonprofit Risk Management Center's 2016 Risk Summit in Chicago.  The topic is "Solving the Data Security Puzzle: How to Prepare for and Respond to Data Security Threats."  For more information, please contact events@wtplaw.com. 

 

Moulsdale on Cyber Security Panel

Keith Moulsdale will serve as a panelist on a cybersecurity program co-hosted by Cybersecurity Association of Maryland, the Better Business Bureau and the Maryland Department of Commerce.  Ken McCreedy of the MD Department of Commerce will moderate the panel, which will also include Valerie Corekin of PSA Insurance and Julian Waits, CEO of Pivot Point Risk Analytics. 

Moulsdale on Cyber Security Panel

Keith Moulsdale will serve as a panelist on a cybersecurity program co-hosted by Cybersecurity Association of Maryland, the Better Business Bureau and the Maryland Department of Commerce.  Ken McCreedy of the MD Department of Commerce will moderate the panel, which will also include Valerie Corekin of PSA Insurance and Julian Waits, CEO of Pivot Point Risk Analytics. 

Cyber Panel - WTP speaking

Howard Feldman will be on a panel, along with Joanne Wood of Hartman Advisors and Remmie Butchko, CEO of Georgetown Insurance.  The topic will be "What Executives Need to Know About Cyber Risks: Essential steps you can take to protect your business."  For more information, please contact events@wtplaw.com. 

Cyber Panel - WTP speaking

Howard Feldman will be on a panel, along with Joanne Wood of Hartman Advisors and Remmie Butchko, CEO of Georgetown Insurance.  The topic will be "What Executives Need to Know About Cyber Risks: Essential steps you can take to protect your business."  For more information, please contact events@wtplaw.com. 

Cybersecurity Association of Maryland - WTP speaking

Keith Moulsdale will speak at the Cybersecurity Association of Maryland's first signature event, taking place at the Columbus Center in Baltimore.  the topic will be "Identifying, Quantifying, Insuring & Mitigating Cyber Risk:  An Executive's Guide to a Conprehensive Cybersecurity Strategy.  for more information, please contact events@wtplaw.com.

Cybersecurity Association of Maryland - WTP speaking

Keith Moulsdale will speak at the Cybersecurity Association of Maryland's first signature event, taking place at the Columbus Center in Baltimore.  the topic will be "Identifying, Quantifying, Insuring & Mitigating Cyber Risk:  An Executive's Guide to a Conprehensive Cybersecurity Strategy.  for more information, please contact events@wtplaw.com.

HELP! I've been Hacked - WTP speakers

Associations have developed a false sense of security, thinking they are safe from hackers. The truth is, when it comes to keeping valuable information safe, associations are just as vulnerable as everyone else. Discuss how a cybersecurity breach can happen, the prevention and planning actions you need to take, and what to do if it happens to you.

HELP! I've been Hacked - WTP speakers

Associations have developed a false sense of security, thinking they are safe from hackers. The truth is, when it comes to keeping valuable information safe, associations are just as vulnerable as everyone else. Discuss how a cybersecurity breach can happen, the prevention and planning actions you need to take, and what to do if it happens to you.

CYBERInnovation Briefing - WTP speaker

The Cyber Incubator at bwtech@UMBC is hosting a presentation on the challenges of shifting from a services-focused business model to a product-focused business model.  The panel will be moderated by WTP's Keith Moulsdale, and the panelists are:

CYBERInnovation Briefing - WTP speaker

The Cyber Incubator at bwtech@UMBC is hosting a presentation on the challenges of shifting from a services-focused business model to a product-focused business model.  The panel will be moderated by WTP's Keith Moulsdale, and the panelists are:

Cybertini - WTP sponsor

The CyberTini is CyberHive's flagship event that connects members, sponsors, supporters, partners and those passionate about cybersecurity and Internet of Things technologies from across the globe.

For the first time ever, bwtech’s CyberHive and CyberHive San Diego will co-host a CyberTini on the evening of October 28, 2014 at Betamore in Baltimore City. Expected attendance is 150, with the event expected to draw from the Cyber Maryland Conference 2014 being held on October 29-30, 2014.

For parking information and directions please visit http://bmo.re/1sgBoD8.

Cybertini - WTP sponsor

The CyberTini is CyberHive's flagship event that connects members, sponsors, supporters, partners and those passionate about cybersecurity and Internet of Things technologies from across the globe.

For the first time ever, bwtech’s CyberHive and CyberHive San Diego will co-host a CyberTini on the evening of October 28, 2014 at Betamore in Baltimore City. Expected attendance is 150, with the event expected to draw from the Cyber Maryland Conference 2014 being held on October 29-30, 2014.

For parking information and directions please visit http://bmo.re/1sgBoD8.

Cyber Security Threats for Businesses - WTP hosting

WTP presents an exclusive breakfast event that will enhance the way you approach cyber security for your business.

Last November, over 120 senior business leaders gathered in Baltimore for a presentation by former senior intelligence agency experts from the NSA and the FBI, cyber threat prevention consultants and data breach remediation experts. We will gather again on June 25th to hear a fresh, non-biased perspective, present real time issues and discuss solutions and strategies to protect your critical IT infrastructure against attack.

Cyber Security Threats for Businesses - WTP hosting

WTP presents an exclusive breakfast event that will enhance the way you approach cyber security for your business.

Last November, over 120 senior business leaders gathered in Baltimore for a presentation by former senior intelligence agency experts from the NSA and the FBI, cyber threat prevention consultants and data breach remediation experts. We will gather again on June 25th to hear a fresh, non-biased perspective, present real time issues and discuss solutions and strategies to protect your critical IT infrastructure against attack.

Cybersecurity for Your Business - WTP speakers

This is part of a monthly speakers' series hosted by the Loyola University Center for Closely Held Firms, and is offered in cooperation with the University of Maryland's Sellinger School of Business.

Cybersecurity for Your Business - WTP speakers

This is part of a monthly speakers' series hosted by the Loyola University Center for Closely Held Firms, and is offered in cooperation with the University of Maryland's Sellinger School of Business.

NYSE Governance Services: Regional Roundtable on Cybersecurity - WTP speaker

NYSE Governance Services will host a complimentary thought leadership roundtable discussion with senior level ethics and compliance professionals in Washington D.C. in early May.

Attendees will hear from industry leaders and gain real insight into what other organizations are doing to enhance and extend their ethics and compliance programs. During this regional roundtable, we will address the legal and risk issues in today’s economy, specifically the impact of emerging technologies and cyber risk.

NYSE Governance Services: Regional Roundtable on Cybersecurity - WTP speaker

NYSE Governance Services will host a complimentary thought leadership roundtable discussion with senior level ethics and compliance professionals in Washington D.C. in early May.

Attendees will hear from industry leaders and gain real insight into what other organizations are doing to enhance and extend their ethics and compliance programs. During this regional roundtable, we will address the legal and risk issues in today’s economy, specifically the impact of emerging technologies and cyber risk.

Cyber Risk Management for Professionals - WTP speaker

The CRTC Joint Workforce Development & Commercial Cyber Forum present a panel discussion, Cyber Risk Management for Professionals

Please join the CRTC Workforce Development Forum and Commercial Cyber Forum in an engaging discussion where our expert panelists will provide an overview of the threat landscape, discuss how the human factor is exposed and most importantly identify strategies to manage risk in the cyber age.

Cyber Risk Management for Professionals - WTP speaker

The CRTC Joint Workforce Development & Commercial Cyber Forum present a panel discussion, Cyber Risk Management for Professionals

Please join the CRTC Workforce Development Forum and Commercial Cyber Forum in an engaging discussion where our expert panelists will provide an overview of the threat landscape, discuss how the human factor is exposed and most importantly identify strategies to manage risk in the cyber age.

Cyber Security for the C-Suite - WTP hosted

This exclusive breakfast event will gather former senior intelligence agency experts from the NSA and the FBI, cyber threat prevention consultants, cyber liability lawyers, and data breach remediation experts who will give you a fresh, non-biased perspective, present real time issues and discuss solutions and strategies to protect your critical IT infrastructure against attack.

Cyber Security for the C-Suite - WTP hosted

This exclusive breakfast event will gather former senior intelligence agency experts from the NSA and the FBI, cyber threat prevention consultants, cyber liability lawyers, and data breach remediation experts who will give you a fresh, non-biased perspective, present real time issues and discuss solutions and strategies to protect your critical IT infrastructure against attack.

Cyber Maryland Conference & National Hall of Fame - WTP sponsor

This two-day conference will feature:

  • 20+ sessions
  • TECHEXPO Cyber Security Hiring Event
  • Cyber Challenge - a competition for teams of high school students, college students, and professionals
  • Cyber Exhibit Hall
  • National Cyber Security Hall of Fame

Cyber Maryland Conference & National Hall of Fame - WTP sponsor

This two-day conference will feature:

  • 20+ sessions
  • TECHEXPO Cyber Security Hiring Event
  • Cyber Challenge - a competition for teams of high school students, college students, and professionals
  • Cyber Exhibit Hall
  • National Cyber Security Hall of Fame

ASAE's Law Symposium - WTP speakers

This annual symposium on nonprofit law is targeted to association in-house counsel and their outside legal advisors, and will feature three sessions with WTP lawyers.

ASAE's Law Symposium - WTP speakers

This annual symposium on nonprofit law is targeted to association in-house counsel and their outside legal advisors, and will feature three sessions with WTP lawyers.

Cyber Security Lightning Talk - WTP speaker

An evening of fast-paced lightning presentations that explore the growing cybersecurity industry in Maryland. Presented by TechnicallyBaltimore, Cynergy, AT&T, ETC, and CoFounders Lab, bringing together local experts from all corners of the field including universities, economic development organizations, startups, law firms, established businesses and more to discuss:

Cyber Security Lightning Talk - WTP speaker

An evening of fast-paced lightning presentations that explore the growing cybersecurity industry in Maryland. Presented by TechnicallyBaltimore, Cynergy, AT&T, ETC, and CoFounders Lab, bringing together local experts from all corners of the field including universities, economic development organizations, startups, law firms, established businesses and more to discuss:

CyberInnovation Briefing - WTP speaker

The fourth CYBERInnovation Briefing hosted by the Cyber Incubator and Cync Program at bwtech@UMBC is on the topic of the President's Cybersecurity Executive Order directing the Government to share threat information with private industry – “Are They Ready and Able? Does Industry See the Value?"

The panel, to be moderated by Keith Moulsdale of WTP, will include Donna Dodson, Deputy Cyber Security Advisor at NIST, Ed Hammerslea, COO, Raytheon Trusted Computer Solutions, and Ron Ritchey, Chief Scientist Information Security, Bank of America.

CyberInnovation Briefing - WTP speaker

The fourth CYBERInnovation Briefing hosted by the Cyber Incubator and Cync Program at bwtech@UMBC is on the topic of the President's Cybersecurity Executive Order directing the Government to share threat information with private industry – “Are They Ready and Able? Does Industry See the Value?"

The panel, to be moderated by Keith Moulsdale of WTP, will include Donna Dodson, Deputy Cyber Security Advisor at NIST, Ed Hammerslea, COO, Raytheon Trusted Computer Solutions, and Ron Ritchey, Chief Scientist Information Security, Bank of America.

The Board IT Challenge: oversight of cloud, cyber risk & social media - WTP speaker

The all-day forum is hosted by Corporate Board Member for company directors to educate them on cyber-risks and data security, and the board's responsibility to prevent damage to their companies.

Keith Moulsdale will speak at the panel addressing "Cloud Computing - a New Layer of Complexity for the Board," with co-panelists Sam Curry, CTO - Identity and Data Protection, from RSA, and Siki Giunta, VP - Cloud Computing & Software Services, from CSC.

 

The Board IT Challenge: oversight of cloud, cyber risk & social media - WTP speaker

The all-day forum is hosted by Corporate Board Member for company directors to educate them on cyber-risks and data security, and the board's responsibility to prevent damage to their companies.

Keith Moulsdale will speak at the panel addressing "Cloud Computing - a New Layer of Complexity for the Board," with co-panelists Sam Curry, CTO - Identity and Data Protection, from RSA, and Siki Giunta, VP - Cloud Computing & Software Services, from CSC.

 

Cyber Security Hall of Fame - WTP sponsor

 

 

On October 16 & 17, 2012, Maryland will be hosting the inaugural “CyberMaryland Conference” at the Baltimore Convention Center. The conference is being produced by the Federal Business Council (FBC) in conjunction with a number of entities from academia, government and industry.

 

Cyber Security Hall of Fame - WTP sponsor

 

 

On October 16 & 17, 2012, Maryland will be hosting the inaugural “CyberMaryland Conference” at the Baltimore Convention Center. The conference is being produced by the Federal Business Council (FBC) in conjunction with a number of entities from academia, government and industry.

 

Maryland-India Business Forum - WTP sponsored

A business delegation of 25 CEOs from India will meet for an all-day business development event to include B2B meetings and remarks by India's Minister of Science & Technology, the president and secretary general of the Federation of Indian Chambers of Commerce, and Christopher Johansson, Maryland's Secretary of Economic Development.

The industries represented include life sciences; information and communication technologies; cybersecurity; and clean technologies.

Maryland-India Business Forum - WTP sponsored

A business delegation of 25 CEOs from India will meet for an all-day business development event to include B2B meetings and remarks by India's Minister of Science & Technology, the president and secretary general of the Federation of Indian Chambers of Commerce, and Christopher Johansson, Maryland's Secretary of Economic Development.

The industries represented include life sciences; information and communication technologies; cybersecurity; and clean technologies.

Practical Lessons Learned: an Overview of Cyber Security Law & Information Governance - WTP speakers

Get a high-level overview of the Cybersecurity law landscape, discuss misconceptions about data security risks, and share practical corporate and litigation lessons in this rapidly evolving area of the law – and liability -- for companies of all kinds and sizes. The presenters are the co-chair of Whiteford’s Cybersecurity practice and the head of the firm’s ESI task force.

Practical Lessons Learned: an Overview of Cyber Security Law & Information Governance - WTP speakers

Get a high-level overview of the Cybersecurity law landscape, discuss misconceptions about data security risks, and share practical corporate and litigation lessons in this rapidly evolving area of the law – and liability -- for companies of all kinds and sizes. The presenters are the co-chair of Whiteford’s Cybersecurity practice and the head of the firm’s ESI task force.

BBJ Cyber Security Summit - Keith Moulsdale panelist

 

Learn what impact the state's cyber security industry has on Maryland's economy, what opportunities there are for our local businesses and how to protect your business from cyber attacks.  Maryland is quickly becoming the hub for cyber security related companies and that could mean new opportunities for our local business community.

Keynote speaker:  Dr. Freeman Hrabowski

BBJ Cyber Security Summit - Keith Moulsdale panelist

 

Learn what impact the state's cyber security industry has on Maryland's economy, what opportunities there are for our local businesses and how to protect your business from cyber attacks.  Maryland is quickly becoming the hub for cyber security related companies and that could mean new opportunities for our local business community.

Keynote speaker:  Dr. Freeman Hrabowski

Maryland Cyber Challenge & Conference - sponsored by WTP

Whether you’re an industry executive, a tech-savvy professional or just a cyber enthusiast, the two-day MDC3 conference has something for you: •Hear pre-eminent keynote speakers discuss the industry’s hot-button issues. •Participate in a host of educational breakout sessions targeted to your interests. •Network with the industry’s top talent, employers, partners and vendors at the Career Fair and Exhibition Hall. •Enjoy complimentary continental breakfast, lunch and snacks each day, as well as a cocktail reception on Friday.

Maryland Cyber Challenge & Conference - sponsored by WTP

Whether you’re an industry executive, a tech-savvy professional or just a cyber enthusiast, the two-day MDC3 conference has something for you: •Hear pre-eminent keynote speakers discuss the industry’s hot-button issues. •Participate in a host of educational breakout sessions targeted to your interests. •Network with the industry’s top talent, employers, partners and vendors at the Career Fair and Exhibition Hall. •Enjoy complimentary continental breakfast, lunch and snacks each day, as well as a cocktail reception on Friday.

"Don't be evil"? Security breaches catch even the best-intentioned companies off guard

As Google and Facebook and countless others have discovered, most netizens tend to be pretty blasé about privacy – until all of a sudden they aren’t. While we all love the detailed photo views on Google Maps, the revelation that Google’s camera cars were also sweeping WiFi networks as they captured those images was met with outrage.  And, Facebook users seemed to carelessly love that app’s ability to track down long-lost friends, until last week it pulled friends’ phone numbers into a handy online directory “for you”.

"Don't be evil"? Security breaches catch even the best-intentioned companies off guard

As Google and Facebook and countless others have discovered, most netizens tend to be pretty blasé about privacy – until all of a sudden they aren’t. While we all love the detailed photo views on Google Maps, the revelation that Google’s camera cars were also sweeping WiFi networks as they captured those images was met with outrage.  And, Facebook users seemed to carelessly love that app’s ability to track down long-lost friends, until last week it pulled friends’ phone numbers into a handy online directory “for you”.

Whiteford, Taylor going after cyber security clients with new group

A Baltimore law firm sees a business opportunity in helping thwart the growing number of online crooks trying to swipe a company’s sensitive data or disrupt its computer network.

Whiteford, Taylor & Preston LLP, a 153-lawyer business law firm, has launched a new industry group to advise clients on the legal issues related to cyber security and the protection of online data.

Whiteford, Taylor going after cyber security clients with new group

A Baltimore law firm sees a business opportunity in helping thwart the growing number of online crooks trying to swipe a company’s sensitive data or disrupt its computer network.

Whiteford, Taylor & Preston LLP, a 153-lawyer business law firm, has launched a new industry group to advise clients on the legal issues related to cyber security and the protection of online data.

Leading Corporate Lawyer Clare Lewis Joins Whiteford in Richmond

Whiteford has announced that Clare Lewis has joined the firm as a Partner in Richmond. Ms. Lewis represents independent sponsors, private equity and venture capital fund investors, and emerging growth and middle market companies on mergers and acquisitions, equity financings, corporate governance, fund formations and other matters.

Leading Corporate Lawyer Clare Lewis Joins Whiteford in Richmond

Whiteford has announced that Clare Lewis has joined the firm as a Partner in Richmond. Ms. Lewis represents independent sponsors, private equity and venture capital fund investors, and emerging growth and middle market companies on mergers and acquisitions, equity financings, corporate governance, fund formations and other matters.

Whiteford Nominated for Cyber Award

Whiteford, Taylor & Preston LLP is honored to be nominated for the Cyber Resource of the Year Award by the Cybersecurity Association of Maryland, Inc. (CAMI). 

Whiteford Nominated for Cyber Award

Whiteford, Taylor & Preston LLP is honored to be nominated for the Cyber Resource of the Year Award by the Cybersecurity Association of Maryland, Inc. (CAMI). 

Cyber Alert: Anthem Data Breach: Self-Insured Plans

On February 4, Anthem, Inc., the second largest health insurer in the U.S., reported that hackers breached one of its IT systems and stole personal information relating to consumers and employees.  Described as “very sophisticated,” the attack involved the records of an estimated 80 million people.  While information accessed apparently did not involve medical information or credit card numbers, it did include such personally identifiable information as names, social security numbers, and income data. 

Cyber Alert: Anthem Data Breach: Self-Insured Plans

On February 4, Anthem, Inc., the second largest health insurer in the U.S., reported that hackers breached one of its IT systems and stole personal information relating to consumers and employees.  Described as “very sophisticated,” the attack involved the records of an estimated 80 million people.  While information accessed apparently did not involve medical information or credit card numbers, it did include such personally identifiable information as names, social security numbers, and income data.