Stay informed and regularly check your security procedures to protect yourself, your business, and your customers. Photo via Getty Images

As news comes out every week about new technologies, from new crypto wallets to generative AI to self-driving taxis, it can get overwhelming for most of us to keep up or to understand the new intricacies of technology, and it can get easy to say, “The IT department has it covered.” Well, do they have it covered?

Far too often, companies fail to protect its data with the same muster as its financial security until it is too late. Just as a healthy business will regularly conduct audits of its accounting processes to detect potential fraud, ensure regulatory compliance, and locate areas of improvement for the organization, the same should be done for a business’s data security practices. Key components of any organization are its people and its information, and the IT department is in charge of protecting that information.

We as business people need to ensure that the company’s technology personnel are indeed securing one of the company’s most valuable assets: information.

Big picture: Your business needs to follow an audit process

  1. Confirm the scope of your data
  2. Conduct an internal review of all security practices
  3. Conduct a review of all vendor practices that have access to your data
  4. Confirm compliance with regulations and contractual obligations
  5. Prepare a report with detailed findings and recommendations to improve on year-over-year

Data: What do you have and what duties does it require?

Personal information, particularly when it belongs to customers, is the most frequently compromised type of data. Under laws like the newly passed Texas Data Privacy and Security Act (TDPSA), businesses can have additional obligations to keep this information protected. Personal information can include any information “that is linked or reasonably linkable to an identified or identifiable individual.”

Sensitive data also requires extra precaution, which means protecting (1) personal data that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data that is processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child; or (4) precise geolocation data.

Other types of data to watch out for include the business’s intellectual property, anonymized customer data, employee personal information, and any other type of proprietary business data. Depending on the industry, the cost of a breach of any of these types of data could be incredibly high, particularly for healthcare and finance.

Ultimately, Texas businesses are required to maintain reasonable procedures to protect personal information, and there may be other laws implicated such as HIPAA, GLBA, CCPA/CPRA, BIPA, GDPR, PIPEDA, and many more, depending on where business is done, the industry implicated, and, in some cases, where customers are located.

"But I think the vendor is responsible."

Check your contracts, and check if the law requires you to have a duty to protect the compromised information, as many do. Involve your IT department in the review of technical compliance whenever you are sharing data with a third party. Further, it is important to make sure that however the Data Processing Addendum says the vendor is processing data is how they are actually processing data. To that point, if you are processing someone else’s data, your business also needs to be doing what it says it is doing, in contracts with third parties and in your Privacy Policy.

Software as a service arrangements, end user license agreements, and other internet and software-based services may require you to hand over data and not give you the opportunity to customize and shift risk. This is why it is important to thoroughly evaluate what technical protections are in place because the risk and duty may still fall on your business regarding the data of your customers and employees. Ask yourself (or your IT professionals) if the vendor actually needs the data they receive to provide services to you.

Key takeaway: Stay informed

Your business needs checks and balances in place with the IT department to ensure you know what they are (or are not) doing and what they are supposed to do. You need policies and procedures, and they need to regularly be tested.

Do you know where your data is stored, both internally and with third parties? Who controls it? How is it being processed, and is anything being shared? Are encryption procedures in place? Firewalls, Intrusion Protection Systems, and End-Point Detection and Response? Do you and your vendors have Incident Response Plans? Stay informed and regularly check your security procedures to protect yourself, your business, and your customers.

------

Courtney Gahm-Oldham is partner at Frost Brown Todd. Lauren Cole is associate at Frost Brown Todd.

Ad Placement 300x100
Ad Placement 300x600

CultureMap Emails are Awesome

$5B Austin medical center, anchored by MD Anderson, to break ground this fall

moving forward

Construction on the $1 billion first phase of the AI-native University of Texas Dell Medical Center in Austin—which will feature a hospital operated by Houston’s UT MD Anderson Cancer Center—is set to start this fall.

The UT System Board of Regents approved funding for first-phase construction on Aug. 12.

The medical center—now expected to cost $5 billion, up from the initial $2.9 billion estimate—will span about 2.5 million square feet. It will include 300 to 500 patient beds, outpatient facilities, an emergency department and specialized care for cancer patients.

MD Anderson will bring its world-renowned oncology programs to the center’s integrated health care model, Dr. Claudia Lucchinetti, senior vice president of medical affairs at UT Austin and dean of the university’s Dell Medical School, tells Health Leaders.

Earlier this year, Austin tech billionaire Michael Dell and his wife, Susan, pledged $750 million for development of the medical center. The medical center, scheduled for completion in December 2030, will be a cornerstone of the new 300-acre UT Dell Campus for Advanced Research, a medical education and research hub.

“Through this new campus and medical center, Texas will lead America in health care innovation,” Gov. Greg Abbott said when the research campus was announced in April. “The next generation of medical breakthroughs will take place in Central Texas.”

The medical center will fold AI tools and other technology into the infrastructure, rather than having them added after it’s built. Among other capabilities, the technology will monitor real-time medical data, automate data entry, and help health care professionals quickly predict and identify risks to patients, according to Health Leaders.

“We are not just building a new medical center,” Lucchinetti says. “We are building a fundamentally new model of health. It’s not just a new facility. It’s not just a new collaboration. It is a convergence of capabilities that rarely come together at the same time.”

Rice lands $15M U.S. Army award to launch next-gen wireless research center

defense funding

The U.S. Army Research Office has awarded Rice University $15 million to establish a new center for next-generation sensing and communications.

The five-year research center—dubbed the Center for Large Aperture Secure Sensing, Imaging and Communications (CLASSIC)—will unite researchers from universities and national laboratories to develop advanced antenna technologies for future wireless systems. Edward Knightly, the Sheafor-Lindsay Professor of Electrical and Computer Engineering at Rice, will lead the center that “combines expertise in wireless networking, antennas, radar, artificial intelligence, circuits and physics to address growing demands on wireless systems,” according to Rice.

“The challenges we’re tackling require advances that span physics, hardware, communications and computing," Knightly said in a news release. “By combining those strengths in a single center, we can accelerate the development and demonstration of technologies that would not be possible through individual efforts alone.”

Joining Knightly will be Ashutosh Sabharwal of Rice, Sensen Li of the University of Texas at Austin, Hou-Tong Chen of Los Alamos National Laboratory, Danijela Cabric of UCLA, Josep M. Jornet and Tommaso Melodia of Northeastern University, Daniel M. Mittleman of Brown University, and Willie Padilla of Duke University.

Industry partners include Booz Allen Hamilton, Intel, Keysight, Lockheed Martin, MITRE, Northrop Grumman, Qualcomm and Raytheon.

CLASSIC researchers will investigate how large-scale antenna arrays (ELSAAs) can expand the capabilities of wireless systems where technology is limited.

ELSAAs use thousands of coordinated antenna elements to direct radio waves. Researchers aim to develop ways to use the technology to help maintain steady communication when signals are blocked or disrupted and to detect and generate detailed images of concealed objects.

Along with ELSAAs, the center will work to develop sensing techniques for threat detection, study wireless jamming and build resilient high-speed wireless networks. Researchers will ultimately validate the technology in labs and via drone-based field trials.

CLASSIC will also work on developing an AI-driven modeling framework that will simulate complex electromagnetic environments in real time.

“This award demonstrates Rice’s leadership in tackling complex national research challenges through collaboration across disciplines and institutions,” David Sholl, executive vice president for research at Rice, added in the release.