• Skip to primary navigation
  • Skip to main content

American Cyber Security Management

Secure and certify all your data and processes

  • LinkedIn
  • Twitter
  • YouTube
  • Services
    • MSP/MSSP
    • Privacy
    • Security
    • ISO/IEC 27001:2022 Training & Certification
    • Secure DevOps
    • InfoSec Risk Management
    • Incident Response Planning
    • Artificial intelligence Readiness Offering
    • AppSec-as-a-Service
    • CISO As A Service
    • DPO As A Service
    • Security Monitoring
    • Security Operations
    • Awareness Training
  • Frameworks
    • CPA
    • CCPA/CPRA
    • GDPR
    • ISO 27001:2022
    • NIST 800-171
    • NIST 800-53
    • US Privacy Laws
  • News
  • Careers
    • DPO
    • CISO
  • Partners
  • About Us
    • Privacy Notice
    • Cookie Policy
  • Contact Us

Massive Breach Exposes Social Security Numbers of Billions of U.S. Residents

August 22, 2024 By Paul Herbka

Massive Breach Exposes Social Security Numbers of Billions of U.S. Residents

In what could be the largest data breach in history, the Social Security numbers of nearly every American may now be up for sale on the dark web. The scale of this catastrophe is staggering, with up to 2.9 billion records reportedly stolen, affecting both the living and the deceased. This breach highlights just how vulnerable our most sensitive personal information truly is.

The Breach: What Happened?

Two weeks ago, a class action lawsuit filed in Florida revealed the full extent of this massive breach. National Public Data (NPD), the Florida-based company responsible, initially reported that 1.3 million people were impacted. However, the lawsuit claims that up to 2.9 billion records—including Social Security numbers of almost every U.S. resident—were stolen several months ago.

NPD collects data for background checks on consumers and job applicants, making this breach particularly alarming. Cybersecurity firms are now reporting that billions of personal records from this breach are being sold on the dark web, putting almost every American at risk.

Is Your Information at Risk?

Yes. You should assume that your information is at risk. For those that want confirmation, you can use this resource, but really – just know that you are most likely a part of this breach. Cybersecurity firm “Pentester” has captured the entire list of compromised data. You can check whether your information was involved by visiting npd.pentester.com For those who don’t like to click on links, just assume that your SSN has been compromised, as most people will be involved in this breach. Given the scale of this breach, it’s crucial to act now to protect yourself.

Why Social Security Numbers Are So Valuable

Your Social Security number is more than just a piece of identification—it’s the key to your financial identity. If compromised, it can be used by criminals to:

– Open New Credit Accounts: Fraudsters can use your SSN to open new credit lines, leaving you with debt and a damaged credit score.

– File Fraudulent Tax Returns: Criminals can file taxes in your name, claim a refund, and cause significant delays in processing your legitimate return.

– Access Medical Services: Your SSN can be used to receive medical treatments, leading to incorrect medical histories and financial liabilities.

– Commit Other Crimes: From applying for jobs in your name to engaging in other forms of identity theft, the misuse of your SSN can create endless problems.

Given these risks, the exposure of Social Security numbers in this breach demands immediate attention and action.

How to Protect Yourself

If your SSN has been compromised, here’s what you need to do:

1. Place a Credit Freeze:

Immediately place a freeze on your credit reports with the three major bureaus—Equifax, Experian, and TransUnion. This prevents new credit from being issued in your name. You can always unfreeze your accounts if needed, but this limits what the attackers can do.

2. Monitor Your Financial Accounts:

Keep a close eye on your bank accounts and credit reports for any unauthorized activity. If you see anything suspicious, contact your financial institution immediately.

3. Sign Up for Identity Theft Protection Services:

Consider enrolling in an identity theft protection service that monitors your Social Security number and alerts you to suspicious activity.

4. Update Your Passwords and Enable Multifactor Authentication:

Secure your online accounts with strong, unique passwords and enable multifactor authentication (MFA) wherever possible. MFA adds an extra layer of security, making it harder for unauthorized users to access your accounts.

5. Use a Password Manager:

A password manager can create, store, and manage strong, unique passwords for all your accounts, reducing the risk of using weak or reused passwords. Make sure you use a very long password for this password manager, as it holds all of your other passwords. By long, I mean like 35-40 characters (Examples of password managers are Bitwarden, 1Password, and Dashlane.)

6. File Your Taxes Early:

Filing your tax return early can help prevent criminals from filing in your name first. If you suspect tax fraud, contact the IRS and consider applying for an Identity Protection PIN (IP PIN) to add extra security to your tax account.

Take Control of Your Digital Identity

The National Public Data breach is a stark reminder of how vulnerable our personal information is. With Social Security numbers potentially in the hands of cybercriminals, it’s more important than ever to take action now. By freezing your credit, monitoring your accounts, updating your passwords, using a password manager with a strong password, enabling MFA, and staying vigilant, you can protect yourself from the severe consequences of identity theft.

Stay informed, stay protected, and take control of your digital identity today.

Filed Under: Cyber Security News

Celebrating the GDPR Anniversary: A Milestone in Global Data Privacy

May 25, 2024 By Paul Herbka

As we mark the anniversary of the General Data Protection Regulation (GDPR) on May 25, 2024, it is an opportune moment to reflect on its significant impact on data privacy and protection. The GDPR, which came into effect on May 25, 2018, has revolutionized the way organizations handle personal data, setting a high standard for privacy rights and data security worldwide.

An Overview of GDPR

The GDPR was implemented by the European Union to safeguard the personal data of its citizens. Its primary objectives are to:

1. Enhance Data Protection: Ensure that individuals have greater control over their personal data.

2. Increase Transparency: Mandate organizations to be clear and transparent about how they collect, use, and store personal data.

3. Strengthen Accountability: Require organizations to implement robust data protection measures and be accountable for data breaches.

Key provisions of the GDPR include:

  • The right to access personal data
  • The right to be forgotten
  • Data portability
  • Stringent penalties for non-compliance

These measures have not only enhanced privacy rights for EU citizens but also influenced global data protection norms.

The Significance of the GDPR Anniversary

As we commemorate the GDPR anniversary, it is essential to acknowledge its far-reaching implications:

1. Global Influence: The GDPR has set a benchmark for data privacy regulations worldwide. Many countries have modeled their data protection laws on the GDPR framework, recognizing the importance of safeguarding personal data in the digital age.

2. Catalyst for Change in the U.S.: In the United States, the GDPR has spurred the development and adoption of privacy laws at both state and federal levels. States such as California, with the California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), have introduced stringent data protection regulations. Other states, including Virginia, Colorado, and Connecticut, have followed suit with their privacy laws, reflecting a growing trend towards enhanced data privacy in the U.S.

3. Corporate Compliance and Best Practices: The GDPR anniversary serves as a reminder for organizations to review and update their data protection policies. It highlights the importance of ongoing compliance efforts and the need to stay abreast of evolving privacy regulations. Companies that prioritize data privacy not only avoid hefty fines but also build trust with their customers, gaining a competitive edge in the market.

4. Consumer Empowerment: The GDPR has empowered consumers by granting them more control over their personal data. This anniversary is a celebration of these enhanced rights and the growing awareness among individuals about their privacy. It underscores the importance of data protection as a fundamental right and the need for continuous advocacy for stronger privacy measures.

As we look to the future, the principles of the GDPR will continue to shape data privacy regulations globally. For those in the U.S. we already have numerous states with privacy laws in place (like CCPA in California and CPA in Colorado to name just a few), which require companies understand and ensure the capabilities of adhering to and delivering on some of the key privacy protections and rights – like the right to be forgotten.  This will usually require a change in how data is collected, tracked, shared, and ultimately used and destroyed. Some would say that the momentum towards federal privacy legislation is gaining pace, with discussions around comprehensive privacy laws that mirror the GDPR’s rigor.  Until then, we will have to continue to track and monitor each state law to see how it applies.

The anniversary is also a call to action for organizations to adopt privacy by design, embedding data protection into their core operations. As technology evolves, so too must our approaches to safeguarding personal data, ensuring that privacy remains a priority in an increasingly digital world.

In conclusion, the GDPR anniversary is a significant milestone in the journey towards robust data privacy. It celebrates the progress made and the ongoing efforts to protect personal data. As cybersecurity and privacy experts, we must continue to champion these principles, advocating for stronger regulations and fostering a culture of data protection that respects and upholds individuals’ privacy rights.  The blending and alignment of cybersecurity and privacy are now even more obvious with these types of laws being modeled after GDPR concepts.

American Cyber Security Management is a leader in data privacy, cybersecurity, and Compliance. Our mission is to help enterprises protect their data from internal and external threats. We offer on-demand assessment, implementation, and sustainability services that focus on Privacy and Cybersecurity readiness and compliance, risk reduction and mitigation. https://www.americancsm.com

Filed Under: Cyber Security News

ACSM Speaks at IMIA 2024

May 9, 2024 By Carlin Dornbusch

AmericanCSM.com (https://www.americancsm.com/ ) is excited to announce our involvement with the International Map Industry Association (IMIA) (https://imiamaps.org/). IMIA is holding its annual Mapping Leaders Forum in Denver, Colorado this June 5-6.

The theme for this year’s Mapping Leaders Forum is about building trust.  This event will host speakers with visionary perspectives, cutting-edge mapping methodologies, emerging trends, and innovative applications.

As a company that prides itself on delivering top-notch privacy and cybersecurity services—including Privacy Assessments, and our CISO-as-a-Service and DPO-as-a-Service, AmericanCSM.com understands the importance of fostering a strong privacy and cybersecurity community. IMIA’s Mapping Leaders Forum 2024 is another leading industry gathering where leaders are focused on building trust with their clients, distributors, partners and employees.

Carlin Dornbusch, a seasoned veteran in the realms of privacy and cybersecurity and President of AmericanCSM.com, will discuss the topics of Privacy, Security, and Risk of data in a modern age. Carlin will talk over the modern challenges for businesses and individuals around data protection, as well as the impact of AI and other tools of the threat actors. Attendees will take away the Do’s and Don’t for managing their data, tips for managing data risks, and approaches for their businesses.

We also invite all attendees to connect with Carlin Dornbusch after the event at the cocktail reception and discuss more about trust building.

For more information on IMIA’s Mapping Leaders Forum 2024, please visit their website at https://imiamaps.org/mapping-leaders-forum/ and we look forward to seeing you there and continuing to trust around the globe together.

Filed Under: Cyber Security News

Session Highlight:  A One Hit Wonder

May 1, 2024 By Paul Herbka

The Rocky Mountain Information Security Conference (RMISC.org) is not just a conference; it’s a dynamic hub for learning, networking, and innovation, featuring over 70 sessions led by industry leaders. The conference aims to blend education with practical insights, offering attendees a unique opportunity to dive deep into the latest trends and advancements in cybersecurity.

One of the highlights of this year’s conference is the session titled “A One Hit Wonder,” co-presented by industry experts Carlin Dornbusch and Paul Herbka. Prepare to be part of an immersive “live play” that gives you a front-row seat behind closed doors into the intense world of a ransomware attack scenario. This session isn’t just a presentation; it’s a behind-the-scenes journey into the mechanics of a real-world cybersecurity crisis.  This session is unlike any other you have seen.  

The Experience

Imagine the tension of a ticking clock as a ransomware attack unfolds. In “A One Hit Wonder,” you don’t just learn about ransomware—you live it. This session is crafted to make you feel part of the action, engaging directly with scenarios that test your decision-making under pressure. You’ll gain an inside view of the chaos and critical thinking required when facing a digital extortion crisis.

Why You Can’t Miss This

Interactive Learning: This unique format goes beyond traditional presentations. It’s interactive and designed to pull you into the narrative, making the experience not only memorable but also highly educational.

Real-World Insights: Dive deep into the dynamics of ransomware through a storyline that mirrors true events. Witness first-hand how crucial decisions can lead to triumph or disaster.  Learn what to do before it’s too late!

Skill Enhancement: You’ll be challenged to assess and enhance your own Incident Response (IR) planning skills. The session is structured to help you learn effective strategies for preparing and defending against cyber threats, including ransomware.

Learning Objectives

By participating in this session, you will:

  • Develop a robust Incident Response Plan that’s ready to be enacted at the first sign of trouble.
  • Understand common pitfalls in ransomware defense and how to avoid them.
  • Ensure your Disaster Recovery (DR) plan or Business Continuity/Disaster Recovery (BC/DR) plan fully supports your business operations.
  • Discover remediation steps necessary to recover from a ransomware event effectively.

Join Us at RMISC 2024 – This session, “A One Hit Wonder” will be Thursday June 13, 2024 from 2:30 – 3:30 pm in room 3C.

Also feel free to meet Carlin Dornbusch and Paul Herbka at the American Cyber Security Management booth, located in the expo hall.

This session is just a glimpse of what RMISC 2024 has to offer. We encourage all cybersecurity professionals and enthusiasts to join us at this premier event. It’s more than a conference; it’s an opportunity to network, learn, and prepare for the challenges ahead in the cybersecurity realm.

Don’t miss out on this chance to transform your approach to cybersecurity. Register now for RMISC 2024, and be sure to join us for “A One Hit Wonder” to see cybersecurity in action like never before!

For more details on the conference and to register, please visit: (https://rmisc.org/). For more information on how AmericanCSM supports our clients visit: (https://AmericanCSM.com)

Filed Under: Cyber Security News

Session Highlight:  How is AI Impacting Privacy?

April 26, 2024 By Paul Herbka

How is AI Impacting Privacy: The Intersection of AI and Privacy

As we approach the Rocky Mountain Information Security Conference (RMISC) 2024, the conversation around artificial intelligence (AI) and its implications on privacy is more vital than ever. The session is scheduled for June 12, from 1:15 p.m. to 2:15 p.m., titled “How is AI Impacting Privacy?” promises to be a cornerstone event, bringing together distinguished experts in the fields of cybersecurity, legal, privacy, and data protection.

AI technologies are integrating deeper into our daily lives, from personalized marketing and smart home devices to complex decision-making systems that can influence everything from credit approvals to healthcare outcomes. With this pervasive deployment, the intersection of AI and privacy is increasingly fraught with complex challenges and risks.

The ability of AI systems to collect, analyze, and store vast amounts of personal data raises significant privacy concerns. These systems often operate as “black boxes,” with opaque processes that make it difficult for users and regulators to understand how data is being used or misused. This lack of transparency can undermine the trust essential for the healthy adoption of technology.

Expert Panel Insights

The panel of experts at RMISC, including Carlin Dornbusch from American Cyber Security Management, Jill Stacey from Holland & Hart, Elizabeth Schweyen from Druva, and Janis Preese, will delve into these challenges. Each brings a unique perspective on how to navigate the evolving landscape of AI-driven technologies while protecting individual privacy rights.

Ethical Considerations

The ethical dimensions of AI and privacy are profound. AI systems that analyze personal data can inadvertently lead to biased outcomes or discrimination if not carefully managed. Ensuring ethical AI usage involves scrutinizing the data inputs, the algorithms themselves, and the resultant decisions for fairness and equity.  What if an AI tool is used by one company, developed and hosted by another company, yet the data collected is about Colorado residents.  Who has ethical responsibility for the data?

Regulatory Landscape

With GDPR in Europe and various state laws in the U.S., such as the California Consumer Privacy Act, the Colorado Privacy Act (CPA), and many others, the regulatory landscape is becoming increasingly complex. Our panelists will discuss how these regulations impact AI development and deployment and the role of compliance in fostering consumer trust and safety. Also, who owns the data, what rights do people have for data about themselves, and how can we ensure we protect people’s privacy as well as their data rights?

Practical Strategies for Data Protection

Balancing innovation with privacy is a delicate act but not insurmountable. The experts at RMISC will share practical strategies that organizations can employ. These might include the implementation of privacy-by-design principles, regular audits of AI systems for compliance and ethics, and the adoption of technologies like federated learning that can help minimize privacy risks.

The session at RMISC is not just about discussing the problems but also about forging pathways towards solutions. It’s an invitation to IT professionals, legal experts, policymakers, and industry leaders to come together to ensure that as AI capabilities grow, they do so in ways that respect and protect personal privacy.

In conclusion, as AI continues to evolve, the dialogue about its impact on privacy must not only keep pace but anticipate and shape future developments. The RMISC 2024 session on AI and privacy is poised to be a pivotal moment in this ongoing conversation. We are on the brink of a new era in cybersecurity and privacy, and the decisions we make now will resonate well into the future. Join us to contribute to this critical discourse and help shape the landscape of AI and privacy for a safer digital world.

For more details on the conference and to register, please visit: (https://rmisc.org/). For more information on how AmericanCSM supports our clients visit: (https://AmericanCSM.com)

Filed Under: Cyber Security News

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • Interim pages omitted …
  • Page 26
  • Go to Next Page »
  • ISSA
  • ISACA
  • ISC2
  • IAPP
  • CSA
  • CIS
  • Privacy Notice
  • Cookie Policy
  • Services
  • Frameworks
  • News
  • Careers
  • Partners
  • About Us
  • Contact Us

Copyright © 2026 American Cyber Security Management