How State Laws Incentivize Better Cybersecurity

60 views
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How State Laws Incentivize Better Cybersecurity

TL;DR

State incentive laws can encourage stronger cybersecurity by giving organizations an affirmative defense against certain civil lawsuits when their security programs conform to recognized frameworks and are followed in practice. Ohio’s approach connects the evolving legal concept of reasonable security with standards such as NIST, CIS, FedRAMP, ISO, HIPAA, Gramm-Leach-Bliley, FISMA, and PCI, while recognizing that no security program can prevent every breach.

Transcript

So welcome, everybody. Appreciate you joining us, uh, this morning, and, and I think we're the second session of the morning. Uh, we've got a, a, a little bit of a different topic, um, blending law and cyber-technical cybersecurity, and we have two excellent panelists who represent each side, um, of that equation. Um, as for myself, uh, I'm an acad... Read More

Key Insights

  • • Reasonable security is an evolving standard of care because practices considered adequate in 2000 may not satisfy expectations in 2022, while current practices may become inadequate later. Encryption illustrates this evolution, moving from limited affordability and availability toward broader use on web pages, devices, storage, and some end-to-end systems.
  • • The Ohio Data Protection Act is an incentive-based cybersecurity law designed to encourage organizations to follow recognized practices. It does not mandate a single uniform security standard, but connects potential protection from civil lawsuits to demonstrable conformity with established technical or regulatory frameworks.
  • • The law’s protection is an affirmative defense, not an automatic safe harbor or a get-out-of-jail-free card. A defendant bears the burden of demonstrating that its cybersecurity program meets the law’s conditions before the defense can provide effective immunity from covered civil lawsuits.
  • • Compliance with an information security policy is essential because merely creating or possessing a policy does not qualify an organization for the defense. The organization must show that its policy generally tracks one or more recognized standards and that its operations conform to the policy in practice.
  • • Ohio recognizes multiple frameworks and regulatory regimes, including NIST, FedRAMP, CIS, the ISO family, HIPAA, Gramm-Leach-Bliley, FISMA, and PCI. This range allows organizations to align their cybersecurity policies with standards appropriate to their existing obligations, circumstances, and security programs.
  • • Perfect security is not the legal objective because an organization can suffer a breach even after doing everything reasonably possible with its available technology, people, processes, and current practices. The incentive model evaluates the organization’s security program rather than treating every successful intrusion as proof of inadequate care.
  • • The NIST Cybersecurity Framework was the foundational standard in Ohio’s initial draft because its scalability made it potentially useful for organizations ranging from individual business operators to Fortune 100 companies. The law later accommodated several additional technical frameworks and regulated-industry requirements.
  • • Attorney general enforcement actions are not included in the protection described for Ohio’s law because their inclusion was rejected during the political compromise. Kirk Herath expressed interest in revisiting that limitation so attorneys general might eventually operate on the same footing as other civil claimants.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the Ohio Data Protection Act’s cybersecurity incentive?

The Ohio Data Protection Act gives qualifying organizations an affirmative defense against civil lawsuits when they can demonstrate an appropriate cybersecurity program. Their information security policy must generally track one or more recognized frameworks or regulatory standards, and they must comply with that policy in practice. The protection is therefore conditional and evidence-based, not automatic immunity following a data breach.

Q: How can a company qualify for Ohio’s cybersecurity affirmative defense?

A company must establish that its information security policy generally tracks one or more standards recognized by Ohio and that it actually follows the policy. The listed options include NIST, FedRAMP, CIS, the ISO family, HIPAA, Gramm-Leach-Bliley, FISMA, and PCI. A written policy alone is insufficient because operational conformity is a separate and essential condition.

Q: Is Ohio’s cybersecurity law a safe harbor from all legal action?

No. Although supporters initially described the protection as a safe harbor, the law provides an affirmative defense. The defendant must demonstrate that the required conditions are satisfied and bears the burden of establishing the defense. The described protection applies effectively to civil lawsuits, while attorney general enforcement actions were excluded as part of the political compromise behind the law.

Q: Why is reasonable cybersecurity considered an evolving standard?

Reasonable cybersecurity changes because available technology and accepted practices develop over time. Conduct regarded as reasonable in 2000 may not be reasonable in 2022, and current safeguards may not remain sufficient twenty years later. Encryption provides the panel’s example: it moved from limited affordability, scalability, and availability toward wider use across web pages, devices, storage, and some end-to-end systems.

Q: Does a data breach prove that an organization lacked reasonable security?

No. The panel states that perfect security does not exist and that an organization can experience a breach despite doing everything reasonably possible with its current technology, people, processes, and practices. The incentive-based approach focuses on whether the organization maintained and followed a security program aligned with recognized standards, rather than assuming that every successful attack establishes unreasonable conduct.

Q: Which cybersecurity frameworks does Ohio’s law recognize?

The standards identified in the discussion are NIST, FedRAMP, CIS, the ISO family, HIPAA, Gramm-Leach-Bliley, FISMA, and PCI. An organization’s information security policy can generally track one or more of these options. This structure connects the legal concept of reasonable security with established technical frameworks and requirements already used within regulated industries.

Q: Why was the NIST Cybersecurity Framework central to the original proposal?

The NIST Cybersecurity Framework served as the foundational threshold standard in the initial draft because the drafters viewed it as scalable. Kirk Herath said it could be used by a Fortune 100 company such as Nationwide or by an individual business operator. Its adaptable structure made it suitable for encouraging better technology, practices, and policies across organizations of different sizes.

Q: What experience led to the creation of Ohio’s cybersecurity incentive law?

Kirk Herath traced the law’s origins to frustration following Nationwide’s 2012 data breach, in which several million records were stolen. The company then faced regulatory scrutiny and a 37-state attorney general investigation that lasted five years. Negotiating that matter repeatedly raised the unresolved question of what organizations must do to demonstrate reasonable security and satisfy the applicable standard of care.

Summary & Key Takeaways

  • Ohio developed an incentive-based cybersecurity law after Kirk Herath’s experience responding to a 2012 Nationwide data breach and a 37-state attorney general investigation lasting five years. The experience highlighted a persistent legal problem: organizations are commonly expected to maintain reasonable security, but the meaning of that standard changes as technology, practices, and threats evolve.

  • The Ohio Data Protection Act encourages organizations to adopt recognized cybersecurity practices by offering an affirmative defense in civil litigation. An organization must show that its information security policy generally tracks an accepted framework and that it actually complies with the policy. Merely possessing a written security program is not enough to establish the defense.

  • Ohio’s law links legal expectations to technical frameworks, including NIST, CIS, FedRAMP, the ISO family, HIPAA, Gramm-Leach-Bliley, FISMA, and PCI. The approach does not demand perfect security or guarantee that breaches will never occur. Instead, it seeks a flexible, scalable, and measurable basis for evaluating reasonable cybersecurity practices across differently sized organizations.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚