Towerwall's InfoSec Blog

Content Type

See all

The Darwin defense: can ‘genetic algorithms’ outsmart malware?

darwin defense , darwin , GDPR , malware , Compliance & Privacy , Malicious software , cannabis , Enterprise

Michelle Drolet

Coming to a future near you: software code that mutates and evolves. We often talk about computer systems and information security in biological terms. Threats and defenses evolve, viruses run rampant, and machines learn by emulating the neural networks in our brains. Cybersecurity is an endless war between attackers and defenders, just as biology is a war between predators and prey. What if we could create an automated process of selection for computer programs, where the fittest wouldfalse

Four Important Things Cannabis Businesses Can Learn from the Recent Equifax Data Breach

Cybersecurity Framework , Ponemon Institute , Compliance & Privacy , Compliance , cannabis , Data Breach , Equifax

Michelle Drolet

The headline-making Equifax data breach was one of the worst ever. Equifax exposed approximately 143 million consumers, but did not notify any of them. This data breach exposed vital information, such as driver’s license, credit cards, social security numbers, addresses, and birth dates. According to the Ponemon Institute, which conducts independent research on privacy, data protection and information security policy, the global average cost of data breaches is approximately $3.62 million. Whatfalse

5 questions to ask your CEO about cybersecurity

CEO , NIST , Cybersecurity Framework , GDPR , Chief Security Officer , Compliance & Privacy , penetration testing , Compliance , cannabis , Enterprise

Michelle Drolet

Why you need to go beyond compliance. Businesses will continue to face a ton of cyber threats, some of which will impact organizations severely enough to require security measures that will reach far beyond compliance. A Ponemon Institute study showed that the average compromised record cost approximately $194 per record. Loss of business due to cyber breaches were estimated to be approximately $3 million. As you can see, it's important to make sure that the risk of cyber breaches is takenfalse

Three crucial keys to understanding HIPAA compliance

Health Insurance Portability & Accountability , protected health information (PHI) , PIE , HIPAA , Compliance & Privacy , Compliance , cannabis , Enterprise

Michelle Drolet

You already know how important it is to be HIPAA compliant. A lot of businesses, including registered marijuana dispensaries, get confused about the requirements, when it comes to dealing with protected health information. It can get a little fuzzy, if you're not privy to the big picture. The Health Insurance Portability & Accountability Act was created in order to set a standard for safeguarding private patient information. Any entity dealing with this kind of protected health informationfalse

How much will non-compliance with GDPR cost you?

European Data Protection Board (EDPB) , GDPR , Compliance & Privacy , Compliance , General Data Protection Regulation , cannabis , Enterprise

Michelle Drolet

Any breach of the General Data Protection Regulation could lead to severe fines. The General Data Protection Regulation (GDPR) went through four years of preparation and debate before being passed by the EU parliament last year. Strict GDPR requirements lay out how companies should process, store, and secure the personal data of EU citizens. The enforcement date is May 25, 2018, and any company not in compliance by that date could be in for a very nasty shock indeed. The short answer to ourfalse

Join Michelle Drolet at the Worcester Business Journal IT Forum #WBJITFORUM

Michelle Drolet , Worcester Business Journal , #WBJITFORUM , Compliance & Privacy , penetration testing , Events , cannabis , Enterprise

Michelle Drolet

Date: October 25, 2017 Time: 3:00pm-6:30pm Location: DCU Center 50 Foster Street, Worcester Single Ticket Rate: $40.00

Achieving long-term resilience with NIST’s Cybersecurity Framework

National Initiative for Cybersecurity Education (N , Virtual CISO , Fractional Chief Information Security Officer (CIS , Compliance & Privacy , cybercrime , Compliance , National Institute of Standards and Technology (NI , cannabis , Enterprise

Michelle Drolet

The need for continuous monitoring, effective metrics and skilled workers. The laudable aim of the National Institute of Standards and Technology (NIST) is to build a common language through a set of best practices and security principles that any organization can apply to combat cybercrime. We’ve looked at what NIST’s Cybersecurity Framework can do for you. We’ve also drilled a little deeper to reveal the importance of solid analysis in assessing your risk and requirements to ensure thatfalse

Build it right with NIST’s Cybersecurity Framework

NIST , Cybersecurity Framework , Compliance & Privacy , Compliance , Special Publication 800-53 , cannabis , vCISO , Enterprise

Michelle Drolet

Diving into NIST Special Publication 800-53 for practical advice. We’ve already laid out a broad overview of what NIST’s cybersecurity framework can do for you, so today we’re going to drill into Special Publication 800-53. Published by the National Institute of Standards and Technology, and based on important research from the Information Technology Laboratory, this publication offers a comprehensive set of security controls to help you protect your data. The document refers to Federalfalse

Medical Marijuana Dispensaries: Take Care of Patient Health Information or Pay The Price

cannabis compliance , Banking Cannabis , HIPAA , Compliance & Privacy , Compliance , medical marijuana , SSL , cannabis

Michelle Drolet

Medical marijuana, like any controlled substance, requires a strong system of identifying patients properly. As the industry matures, the federal government has increasingly been more involved in enforcing ever more stringent laws and regulations on medical marijuana dispensaries. While it is easy to dismiss this if you’re running your business on a strictly cash-only basis, the future could change and possibly require you to do this. Why not prepare now, so that you can avoid possible problemsfalse

What NIST’s Cybersecurity Framework is and why it matters

Framework , NIST , Compliance & Privacy , Compliance , cannabis , Enterprise

Michelle Drolet

Practical advice to help you build a solid InfoSec plan The risk of your business falling victim to cybercrime has never been higher. Despite a seemingly endless parade of high profile data breaches, ransomware attacks, and phishing scams, many organizations still lack the necessary defenses to identify, prevent, or recover from an attack. The trouble is that it has become increasingly easy for would-be attackers. Anyone can hire a botnet or buy off-the-shelf malware, complete with technicalfalse