News and analysis for the well-informed compliance or audit exec. Select an option and click continue.
Annual Membership $499 Value offer
Full price one year membership with auto-renewal.
Membership $599
One-year only, no auto-renewal.
- Chief Compliance Officer and VP of Legal Affairs, Arrow Electronics
By Aly McDevitt2022-02-03T13:00:00
DISCLAIMER: This case study depicts a fictional cyber incident based on real-life scenarios described by expert interviewees, media reports, and other publicly available resources. While the details surrounding the characters, company, and ransomware attack are imagined, the business concerns and legal issues raised are plausible and based on actual cases.
It is impossible to quantify the comparative costs of the ransomware attack in Vulnerable Electric’s (VE) two parallel universes. According to a chief information security officer (CISO) who wished to remain anonymous, “The ransom payment almost always comes down to the recovery time cost versus ransom payment cost. The secondary factor is the public image or brand damage.”
Although VE’s two pathways start off with the same binary question—pay the ransom or not—the resultant narratives quickly splinter off in different directions with varied endings.
THIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.
News and analysis for the well-informed compliance or audit exec. Select an option and click continue.
Annual Membership $499 Value offer
Full price one year membership with auto-renewal.
Membership $599
One-year only, no auto-renewal.
Take this self-directed, interactive immersive study of a fictional cyber event based on real-life scenarios to deepen your understanding of the importance of crisis management planning and put you in the shoes of a compliance leader during a ransomware attack.
2024-12-20T17:39:00Z By Aaron Nicodemus
USAA Federal Savings Bank has been hit with its third cease and desist order from the Treasury Department’s Office of the Comptroller of the Currency in the past five years for failing to correct unsafe and unsound banking practices.
2024-12-20T16:47:00Z By Neil Hodge
Any product that uses AI needs to be safety assessed for its entire lifespan under new rules that went into effect recently across the EU. Experts warned companies using AI to tailor products could be classed as “manufacturers” and face the same duty of care as developed.
2024-03-21T16:00:00Z By Aly McDevitt
Both JPMorgan Chase and Deutsche Bank retained their respective Jeffrey Epstein relationships for too long. Yet, there is a case to be made for why exiting a high-risk relationship too soon can become an inverse form of recklessness.
2024-03-20T16:00:00Z By Aly McDevitt
Why did JPMorgan Chase retain Jeffrey Epstein for more than a dozen years? How did the relationship persist despite glaring red flags? The “why” is straightforward; the “how” is more complicated.
2024-03-19T16:00:00Z By Aly McDevitt
Jeffrey Epstein’s designation as a high-risk client should have subjected him to enhanced due diligence that never appeared to occur, most notably at Deutsche Bank. Instead, Epstein was allowed to continue his misconduct despite numerous red flags.
Site powered by Webvision Cloud