How Can States Strengthen U.S. Cybersecurity?

148 views
•
May 16, 2019
by
RSAC Cybersecurity
YouTube video player
How Can States Strengthen U.S. Cybersecurity?

TL;DR

State governments can strengthen national cybersecurity by combining legislation, executive action, advisory councils, and locally organized partnerships. Ohio illustrates an incentive-based approach: organizations facing qualifying data-breach tort claims may assert an affirmative defense by proving that their cybersecurity programs reasonably conform to recognized frameworks, while broader state activity can influence practices beyond state borders.

Transcript

So, uh, good afternoon, everyone, and thanks for making your way through the rainy streets of, uh, San Francisco to attend this panel. Uh, we're up against a challenge. Uh, this is a lunch hour, and, and we, uh, we appreciate your, your joining us. Um, my role at, at the university, uh, one of my roles is to staff a state-level cybersecurity counci... Read More

Key Insights

  • State cybersecurity action is grounded in reserved powers that allow states to protect the health, safety, and welfare of their populations. This authority enables state executive branches and legislatures to address cybersecurity even while federal agencies, Congress, executive orders, and federal courts receive greater public attention.
  • State communities are comparatively compact cybersecurity ecosystems that may find it easier to organize around shared needs. Their work includes government initiatives and activity within civil society, creating opportunities for local coordination while potentially producing consequences that reach beyond a single state's borders.
  • The Ohio Data Protection Act is an incentive-based cybersecurity law developed in a Republican-dominated political environment that favored a business-friendly approach. It emerged from a cybersecurity advisory board created by then Ohio Attorney General Mike DeWine to assist small and midsize enterprises and examine the legal landscape.
  • The Ohio Data Protection Act provides an affirmative defense rather than a complete safe harbor. It does not eliminate every form of liability, and it applies within a relatively narrow scope to qualifying tort actions brought in Ohio courts or under Ohio law after a data breach.
  • An organization seeking Ohio's affirmative defense must prove that its cybersecurity program reasonably conforms to an eligible cybersecurity framework. The phrase reasonably conforms preserves flexibility and discourages rigid check-the-box compliance, but it also leaves factual questions for courts to resolve when litigation tests the law.
  • Eligible frameworks under the Ohio law include general industry frameworks, certain industry-specific frameworks, and frameworks tied to federal regulatory regimes. An organization regulated under one of those federal regimes may use the associated framework when attempting to qualify for the statutory defense.
  • PCI compliance is not sufficiently comprehensive by itself under the Ohio approach. When a breach concerns PCI-related data, the organization must demonstrate conformity both with PCI and with one of the recognized general industry cybersecurity frameworks to seek the affirmative defense.
  • An affirmative defense places the burden of proof on the organization asserting it after being sued. Litigation is therefore expected to examine what evidence demonstrates reasonable conformity, how the defense operates mechanically, and whether those factual issues differ from the underlying merits of the breach claim.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can state governments strengthen national cybersecurity?

State governments can use their reserved powers concerning public health, safety, and welfare to develop cybersecurity laws, executive initiatives, councils, task forces, and partnerships. State communities can also organize through their civil-society networks. Although these activities respond to local conditions, the panel argues that state initiatives can have national implications when their approaches attract attention or influence conduct beyond state borders.

Q: What is the Ohio Data Protection Act?

The Ohio Data Protection Act is a business-friendly cybersecurity law that offers a qualifying organization an affirmative defense against certain tort actions arising from a data breach. It is not a complete safe harbor and does not erase every form of liability. The defense can apply to qualifying claims brought in Ohio courts or under Ohio law, including potentially when another state's court determines that Ohio law governs.

Q: How does an organization qualify for Ohio's cybersecurity defense?

An organization must develop a cybersecurity program that reasonably conforms to one of the frameworks recognized by the Ohio Data Protection Act. The eligible choices include general industry frameworks, certain industry-specific frameworks, and frameworks associated with particular federal regulatory regimes. Because the statute requires reasonable conformity rather than simple formal compliance, the organization must be prepared to prove that its program genuinely satisfies the applicable standard.

Q: Why is Ohio's cybersecurity protection not a true safe harbor?

Ohio's law does not automatically shield an organization from liability merely because it claims to follow a cybersecurity framework. It creates an affirmative defense within a limited category of tort claims arising from data breaches. The organization must assert that defense after it is sued and bears the burden of proving reasonable conformity, leaving courts to evaluate the relevant facts and evidence.

Q: Why did Ohio use an incentive-based cybersecurity law?

The law was designed as a carrot that encourages organizations to address cybersecurity proactively. Its developers did not want to create a private cause of action, expand state regulators' authority, lower the security bar, or establish a superficial checklist. The incentive reflects a political environment that favored a business-friendly measure while still requiring thoughtful, proactive, and dynamic cybersecurity practices.

Q: Can PCI compliance alone qualify for Ohio's affirmative defense?

PCI compliance alone does not qualify because the law's developers considered it insufficiently comprehensive. If an organization experiences a breach involving PCI-related data, it must demonstrate conformity with PCI and with one of the recognized general industry frameworks. This combined requirement is intended to ensure that the organization's security program addresses broader cybersecurity concerns rather than only PCI obligations.

Q: What must a company prove when asserting the Ohio defense?

A company must prove that the claim is a qualifying tort action arising from a data breach and that its cybersecurity program reasonably conforms to an eligible framework. Because the protection is an affirmative defense, the company bears the burden of proof. Important unresolved questions include what evidence establishes conformity and how facts supporting the defense relate to the merits of the underlying claim.

Q: Why can different state cybersecurity policies have national consequences?

State initiatives can draw attention and interest outside the jurisdiction where they originated. Ohio's approach, for example, attracted activity within and outside the state, and the Conference of Western Attorneys General examined it and produced a white paper. More broadly, state laws and organized cybersecurity communities can influence discussions, organizational practices, and possible policy approaches across the United States even without uniform state rules.

Summary & Key Takeaways

  • State governments possess reserved powers concerning the health, safety, and welfare of their populations, giving them an important cybersecurity role alongside federal institutions. Their executive branches, legislatures, advisory bodies, and civil-society communities can organize around local needs while producing initiatives that may influence cybersecurity practices and policy beyond individual state borders.

  • Ohio's Data Protection Act emerged from a business-friendly policy environment and uses an incentive instead of creating a new private cause of action or additional state regulatory authority. It allows an organization sued over a qualifying data-breach tort claim to assert an affirmative defense, although the organization must prove that the defense applies.

  • To qualify for Ohio's defense, an organization must show that its cybersecurity program reasonably conforms to an eligible framework. Options include general industry frameworks, certain industry-specific frameworks, and frameworks connected to federal regulatory regimes. PCI compliance alone is insufficient, so relevant breaches require PCI plus a general industry framework.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚