Cyber Sip: Recent Episodes

Barclay Damon LLP

Cyber Sip is a biweekly Barclay Damon Live podcast offering practical tips on improving every organization’s cybersecurity. We talk with industry thought leaders to keep you up to date on cybersecurity’s “hot topics,” including:

•Federal, state, and international privacy laws •Responding to data breaches, ransomware attacks, and other cyber incidents •Regulatory investigations •Privacy litigation •Cyber-insurance coverage •Best practices for managing cyber and data-privacy risks

Barclay Damon LLP is a leading law firm with offices in the Northeastern United States and Toronto.

View Details

Kevin Szczepanski and guest Laura Zaroski, managing director of Gallagher's law firms practice, discuss law firms’ varied responses regarding the use of generative AI: some embrace it while others prohibit it. They also explore benefits and risks of using AI, including the importance of checking work, avoiding sanctions, and client disclosures. They then touch on the potential impact on insurance coverage and underwriting. Firms should consider their risk tolerance and their cases’ value when determining coverage limits. Another best practice is to establish and regularly revisit guidelines or policies for AI use. Kevin and Laura emphasize the need for law firms to understand and strategically use AI while also being aware of the potential dangers.

View Details

Kevin Szczepanski welcomes Jessica Copeland of Bond,Schoeneck & King back for a lively discussion on why (and whether) attorneys and firms of all sizes should use artificial intelligence. As a refresher, they remind listeners of the definition of AI and some of its uses. As with many things lawyer related, the answers come down to “it depends.” Lawfirms need to look at their priorities, capabilities, and needs. Other areas to consider are policies, compliance, indemnification, employee training, security, and clients’ expectations. Kevin and Jessica also discuss AI tools’ wide availability, noting that familiar companies like Lexis, Westlaw, and Microsoft Office have all rolled out internal AI features. Listen in for more.

View Details

In this conversation, Kevin Szczepanski and Jessica Copeland of Bond, Schoeneck & King define generative AI as basically the use of large language models to create natural language responses. They note that AI has been used for decades—examples of it in everyday life include personalized recommendations on Amazon and Netflix. They then move on to the use of generative AI and AI governance. Generative AI has both benefits (efficiency and time savings) and risks (including accuracy, bias, confidentiality). Governance is crucial, and listeners will hear some recommendations for developing a robust AI governance plan, including selecting the right tools, identifying decision-makers, assessing security features, andimplementing policies and training.

View Details

Kevin and his guest, Jodi Daniels, founder and CEO of Red Clover Advisors, discuss the importance of privacy as a fundamental human right, noting that building trust is a two-way street. Jodi explains that a privacy consultancy helps companies comply with data privacy laws and build trust with their customers. Jodi emphasizes that privacy is both a legal compliance issue and a market opportunity. By prioritizing privacy and being transparent about data use, businesses can differentiate themselves and gain a competitive advantage. They also discuss the book Jodi coauthored with her husband, Data Reimagined: Building Trust One Byte at a Time, which provides a story-driven approach to help professionals understand the importance of privacy and navigate privacy regulations.

View Details

Kevin and guest Ziming Zhao, assistant professor in the Department of Computer Science and Engineering at the University at Buffalo, discuss Ziming’s work in systems and software security. They focus on ethical hacking and its goal of responsibly disclosing vulnerabilities to vendors. Ziming says that hacking can be fun and doing it ethically serves a purpose, though he emphasizes that ethical hacking is not a guarantee of absolute security. Companies still need to have a security in design mindset. Ethical hackers can help raise the security bar for companies and organizations. Ziming also discusses the relationship between academia and industry in the field of ethical hacking.

View Details

In this episode, host Kevin Szczepanski and his guest, BillHaber of TEKRiSQ, discuss tips to prevent phishing attacks, which, they remind listeners, are “fraudulent attempts to obtain personal information through electronic messages.” Kevin and Bill highlight the prevalence and success ofphishing attacks, emphasizing the need for vigilance from both individuals and organizations. Covering examples and types of phishing attacks—spear phishing, smishing,man-in-the-middle attacks—they offer takeaways including slowing down, being cautious of urgency, verifying suspicious emails, conducting trainings, andimplementing tools like VPN and DNS filtering. These practices can both enhance cybersecurity and improve the chances of obtaining cyber liability insurance.

View Details

Kevin Szczepanski and Arun Vishwanath, chief technologist of Avant Research Group, discuss the urgent need for cyber-hygiene education for children, including about security and privacy. They highlight frequent cyberattacks targeting schools and other education systems, which often have outdated technology and may lack sophisticated IT security skills and resources. The conversation also touches on the role of the private sector in providing cyber-literacy education. Kevin and Arun embrace reforming credit monitoring for children and expanding its scope to include reputation management, and they agree about the importance of protecting the next generation from cyber threats and the need for systemic changes.

View Details

Kevin Szczepanski and Kyle Cavalieri, president of Avalon Cyber, discuss the increasing risks of funds transfer fraud, covering topics such as understanding this type of fraud, how it works (including fake invoicing and “vishing” attacks), red flags, and how to respond. Red flags can include unexpected calls or emails, and it’s important to be prepared for when these contacts occur. Kevin and Kyle emphasize the growing threat of such attacks, which can result in significant financial losses. They discuss the importance of immediate action, including updating credentials, notifying the bank, involving an attorney, and reporting the incident to law enforcement. Listen in to learn more.

View Details

More than ever, cybersecurity risk assessments areessential for businesses of all sizes to understand and mitigate their risks. Doneappropriately, assessments can provide help with remediation and a plan formoving forward and can even assist with pursuing insurance coverage. Thisepisode, which features Bill Haber, co-founder of the cybersecurity company TEKRiSQ,emphasizes the need for actionable steps and justifying recommendations basedon an organization's specific risks and compliance obligations. Even if yourorganization is not subject to specific regulations, conducting a riskassessment is crucial for protecting data, limiting liability, and maintainingcyber insurance coverage. Listen in to learn more.

View Details

From Barclay Damon’s new podcast studio, Kevin welcomes back University at Buffalo Professor Siwei Lyu. To start this fast-moving conversation, Siwei notes that what sets generative AI apart from analytical AI is that generative AI focuses on creating content rather than just answering questions or sorting through data, and he shedslight on what seemed to be the technology’s “sudden appearance.” Siwei and Kevin also discuss the introduction of ChatGPT, current and future applications of generative AI, and concerns about generative AI’s misuse. Throughout the talk, Siwei emphasizes the importance of responsible use and the need for safeguards.

View Details

Join Kevin Szczepanski as he explains his five need-to-knowcyber action items for the year. They involve 1) conducting a cyber risk assessment, essential for identifying and prioritizing risks, 2) developing an incident response plan to help respond to and mitigate cyber incidents, 3) conducting tabletop exercises, which give organizations the opportunity to do run-throughs of real incidents, 4) reviewing policies, including determining which ones you need, and 5) considering appointing a virtual chief information security officer (CISO). Kevin also provides a preview of upcoming topics for Season 3 of the podcast, including AI, cybersecurity for kids, risk management, and insurance—all recorded in our new state-of-the-art podcast studio.

View Details

“Compliance” doesn’t have to be a dirty word. Check out the final episode of Season 2 of Barclay Damon Live: Cyber Sip™ when, for the first time ever, host Kevin Szczepanski welcomes two guests: his Barclay Damon colleague Bridget Steele and the founder and CEO of Opollo Technologies, Ryan Young. Using Ryan’s company as an example, you’ll hear how embracing compliance rather than avoiding it can be just the ticket to securing clients. Especially in the health care and other highly regulated sectors, when businesses successfully integrate compliance into their development, they can be more competitive. Listen in now.

View Details

In episode 46 of Barclay Damon Live: Cyber Sip™, Justin Daniels, an attorney with Baker Donelson and cohost of the podcast “She Said Privacy/He Said Security,” shares with host Kevin Szczepanski his thinking around the use—and risks—of AI in business. His concern comes with the explosion of tools like ChatGPT and the attitude of many business owners, investors, and software designers that if (or when) something goes wrong, especially regarding data and privacy, they’ll “fix it later.” Justin, also the coauthor of Data Reimagined: Building Trust One Byte at a Time, says that attitude needs to change and suggests following the nonpartisan NationalInstitute on Standards and Technology (NIST) standards when thinking about AI use within your company. (Hint: It’s probably there already.) Listen for details.

View Details

Episode 45 of Barclay Damon Live: Cyber Sip™ addresses a critically important topic: “Building Trust One Deal at a Time: Due Diligence inM&A Transactions.” Once again, Brian Haugli, CEO of SideChannel, founder of RealCISO, and creator and host of CISO Life Podcast, joins host Kevin Szczepanski. This time, they’re covering cyber due diligence, assessments, and risks related to mergers and acquisitions. Brian notes that, though a deal rarely falls through because of cyber issues, it’s critical for the acquiring organization to know what it’s getting and how any gaps might affect the deal—especially financially. Watch or listen in for more.

View Details

Welcome to Barclay Damon Live: Cyber Sip™. In episode 44, host Kevin Szczepanski welcomes Brian Haugli, SideChannel CEO, founder of RealCISO, creator and host of CISO Life Podcast, and more, for “Your Cybersecurity Roadmap: Targeting Gaps and Assessing Risks.” Brian and Kevin first address a misconception: If you tick off the common boxes for security controls, you’ve done all you need to do. Not true, says Brian. Using his talent for visual explanations, Brian confirms that there’s a lot more to reducing your organization’s risks and making sure you have a solid program in place. Watch or listen for more.

View Details

Welcome to Barclay Damon Live: Cyber Sip™ episode 42, “‘California Emissions’: Is the CCPA a Bellwether for the Rest of Us?” Michelle Merola, leader of Hodgson Russ’s Cybersecurity & Privacy Practice, returns to talk with host Kevin Szczepanski about the changing landscape of privacy laws and specifically how California leads the way with its recently revised California Consumer Privacy Act (CCPA). Kevin and Michelle review the changes, which make the law even more consumer friendly, and touch on how other states across the country may follow suit (or not). Topics include the new regulatory agency the state has established as well as how even businesses based outside California may need to comply with the law. Listen now for this vital information.

View Details

Welcome to Barclay Damon Live: Cyber Sip™. In episode 42, “Social Engineering: The People Problem of Cybersecurity,” host Kevin Szczepanski is joined by Arun Vishwanath, a cybersecurity thought leader, author, and chief technology officer at Avant Research Group. Arun discusses his latest book from MIT Press, The Weakest Link: How to Diagnose, Detect, and Defend Users From Phishing, wrapping it into meaningful information about cybersecurity training and testing. Starting with a definition of “social engineering,” which refers to hackers directly targeting users with technology, Arun and Kevin agree that currently testing and training aren’t solving the problem and discuss potential solutions. Listen in for more.

View Details

Kevin Szczepanski, host of Barclay Damon Live Presents Cyber Sip™, welcomes Chicago-based Brian Dusek, senior vice president and head of Americas cyber with Mosaic Insurance Company. Brian is a cyber insurance underwriter and frequent speaker in this space, and he shares current ideas on a range of topics regarding the sustainability of the cyber insurance market. It’s a constantly evolving industry. In this episode, you’ll hear about trends over the last year, including an inflection point and a turn toward stability. Ransomware and business email compromise haven’t gone away, but brokers and insurers are working to ask potential insureds the right questions. Listen in for a deeper dive into privacy, security, where biometrics come into play—and how all of this can affect businesses.

View Details

It’s episode 40 of Barclay Damon Live: Cyber Sip™. Host Kevin Szczepanski is joined for the first time by Michelle Merola of Hodgson Russ, where she is a partner and leader of the law firm’s Cybersecurity & Privacy Practice. Kevin and Michelle start off by defining “privacy” as it’s currently conceived, which includes the right to protect your personal information and data. They then delve into the difference between cybersecurity and privacy and the recent paradigm shift from a focus on security to privacy. Listen in for more on developing privacy laws and how they may affect businesses across the country.

View Details

Learn about the hot topic of deepfakes in the newest episode of Barclay Damon Live: Cyber Sip™. In episode 39, Siwei Lyu, SUNY Empire Innovation Professor at the University at Buffalo, returns to talk with host Kevin Szczepanski about this polarizing issue, addressing both the notable harms and potential benefits of “generative AI technology” (that’s Siwei’s preferred, less inherently scary term for the field). Like so many issues today, it’s complicated, says Siwei, and neither extreme position—AI? No problem! Or…AI? We’re doomed!—is correct. With his combined background in media forensics, mathematics, neuroscience, and social psychology, Siwei brings a compelling perspective to the conversation. Listen in for more revealing information.

View Details

Episode 38 of Barclay Damon Live: Cyber Sip™ finds host Kevin Szczepanski talking about cybersecurity claims and coverage trends with John Farley, managing director of Gallagher Insurance. The landscape is constantly shifting, says John, and he’s seeing claims rising slightly after they dipped last year. John describes some of the many factors affecting trends in cyberattacks, and hence cyber coverage and claims, asserting that carriers are offering more services to help clients lower their risks and try to prevent attacks to stay insurable. It’s a win-win for the industry and for businesses that are in a constant battle to protect their data, their customers, and their bottom lines. Kevin and John also touch on the potential effects of new developments in artificial intelligence in this arena. Listen in for more information.

View Details

Listen in to episode 37 of Barclay Damon Live: Cyber Sip™, which finds host Kevin Szczepanski delving into the fascinating and sometimes unsettling topic ofartificial intelligence with Siwei Lyu, SUNY Empire Innovation Professor at the University at Buffalo. Siwei and Kevin begin with a basic definition of artificial intelligence, or AI, and how it works. They then move into recent innovations like ChatGPT and both the excitement and concerns around its applications. With an optimistic attitude and a belief in the ability of humans to survive and thrive, Siwei offers insights for all.

View Details

Welcome to Barclay Damon Live: Cyber Sip™ episode 36. Host Kevin Szczepanski talks with Kyle Cavalieri, president of Avalon Cyber, about tabletop exercises. (No sit-ups involved.) Kevin and Kyle define the practice as a moderated exercise that tests an organization's ability to respond to a cyberattack. It’s helpful toevaluate incident-response plans; to gain clarity around stakeholders’ awareness of their roles, responsibilities, and communication; and to learn where its response program may have budget gaps. That’s some of the “whys” of companies conducting such exercises (which should minimally be held annually).They also get to the “who” and the “how.” Listen in for more on this hot topic.

View Details

It’s episode 35 of Barclay Damon Live: Cyber Sip™! Host Kevin Szczepanski and returning guest Reggie Dejean of Lawley Insurance take a look at the future of cyber liability coverage. Kevin kicks it off by noting that some in the insurance industry are making noises about cyber risk becoming uninsurable. Reggie, a 20-year veteran of the field, counters that, because cyber insurance (and reinsurance) are newer areas and because of the enormous disruption that major cyberattacks and breaches can cause, this is a natural phase of testing and potentially correcting the segment. Do we need legislation? What’s happening with litigation? And what’s the best type of cyber insurance for businesses to have? Listen in for answers and tips.

View Details

In episode 34 of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski welcomes back Bryan McCarthy of Transatlantic Reinsurance Company to discuss limiting exposure to biometric privacy claims. They continue the conversation they started in episode 28 about the effects of Illinois’s Biometric Information Privacy Act (BIPA). BIPA is intended to protect residents of Illinois but has ramifications for businesses across the country. Hear Kevin and Bryan review what companies can do to protect themselves through insurance coverage for biometric privacy claims—claims about fingerprints, retinal scans, and other biometric data not being handled properly under BIPA. Beginning with who is subject to the statute (you may be surprised) and then moving on to the wisdom, as Bryan says, of “everyone being on the same page” with regard to coverage, they give a solid overview. Tune in.

View Details

Episode 33 of Barclay Damon Live: Cyber Sip™, with host Kevin Szczepanski, looks at five security controls you need to know about. Kevin talks with guest Dean Mechlowitz of TEKRiSQ about the importance and challenges of establishing security controls within your company, regardless of size or sector. TEKRiSQ is in the business of examining cyber wellness, and as co-founder, Dean has a good handle on the issue. Especially for smaller companies, but also for companies of other sizes, he and Kevin review what can be done to avoid cyber criminals’ crosshairs—and to become insurable. Hot topics include data privacy, passwords, multifactor authentication (Kevin’s favorite!), and everyone’s worry, employee vulnerability. Listen in for more.

View Details

In episode 32 of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski welcomes Brandy Griffin of Crum & Forster Insurance to talk about the ever-changing landscape of cyber security. Brandy, who is senior manager for cyber incident response and e-risk, and Kevin dive deep and cover some newer issues, like board- and executive-level responsibility for all things data privacy and security. What else? For one thing, it’s easier than ever to have resilient backups, but that’s not stopping attackers. Kevin and Brandy also touch on AI, ransom policies, conquering the “alphabet soup,” and taking advantage of helpful resources from the insurance industry. It’s no game!

View Details

In episode 31 of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski welcomes Reggie Dejean of Lawley Insurance to address the burning question “do I need cyber insurance?” You’ll hear why Reggie believes that organizations need this type of coverage—his reasons boil down to the cost of these elements: extortion or ransom fees, legal and forensic fees, and business disruption. As Kevin has discussed with multiple guests, though, the application process can be daunting. In the rare instance that a company can’t get the coverage it needs, they say, it’s smart to have, at minimum, a law firm and a forensics firm on speed dial. Listen in for more.

View Details

In this solo episode of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski fills listeners in on important updates for financial companies—those that are licensed, regulated, chartered, or otherwise authorized to do business under New York State’s banking, insurance, or financial services laws. If the question is whether the new Part 500 Cybersecurity Rules will affect your business, the answer is most likely yes. Over the past year, the New York Department of Financial Services has issued proposed amendments that will have a significant effect not only on the primarily targeted businesses but on the vendors that serve them. And they are coming soon. Listen in for more details.

View Details

Host Kevin Szczepanski is back with episode 29 of Barclay Damon Live: Cyber Sip™. In this segment, Kevin talks with Bill Haber, co-founder of TEKRiSQ, a cybersecurity company that helps small- and medium-sized businesses minimize technology risks quickly and affordably. Bill’s company approaches its work with a “wellness” philosophy—only recommending solutions after the underlying issues are diagnosed. Bill dispels some common myths, describing how and where his company comes into the mix when businesses are seeking cybersecurity insurance. Listen in for more—and be sure to come back to hear Bill’s co-founder, Dean Mechlowitz, cover in an upcoming episode the top ten solutions underwriters like to see in place.

View Details

Host Kevin Szczepanski is back with episode 28 of Barclay Damon Live: Cyber Sip™. Kevin and his guest, Bryan McCarthy of Transatlantic Reinsurance Company, explore Illinois’s Biometric Information Privacy Act (BIPA), its 2008 origins, and what it mandates. Bryan, a senior claims examiner for Trans Re, and Kevin agree that the topic of protecting biometric information is critical and timely—whether that information comes from a fingerprint, retinal scan, or facial recognition. Also critically important: knowing if, when, how, and by whom the information is being collected, stored, and destroyed. You might be surprised to learn how broadly applicable this Illinois-based act is, how non-compliance is punishable, and the trends in class-action lawsuits because of it. Listen for more.

View Details

In episode 27 of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski welcomes back his guest and good friend Brian Rice, chief information technology officer at specialty wholesale insurance broker Synapse LLC. Kevin and Brian explore the ethical and legal ramifications of ineffective cyber defense postures. Addressing the moral obligation for companies—whether a yoga studio, a law firm, or a multi-billion dollar concern—Kevin and Brian cover the duty to protect customer, employee, and business-sensitive data. As they wrap up, Kevin poses this question: What can a company do right now to improve its security posture and minimize exposure to these risks? Listen in for Brian’s top four tips now.

View Details

In this quick yet important chat with Brian Rice of Synapse Partners LLC, Barclay Damon Live: Cyber Sip™ host Kevin Szczepanski discusses security controls for companies of any size and in any sector. Hear Brian’s point of view (which comes in part from working with companies ranging from seven to 700 people over the course of 20 years) on burning questions like: What’s the number one biggest liability for companies? And what’s the number one best defense against a potential invasion of your systems? Answer: Employees. And training them. Sure, having good cyber insurance coverage is important, but, as Brian says, having auto insurance doesn’t stop you from driving mindfully. Tune in for more on this important topic.

View Details

In this quick solo episode of Barclay Damon Live: Cyber Sip™, host Kevin Szczepanski clues listeners in on some lurking online pitfalls. While Kevin uses the example of attorneys being targeted, the information is applicable to non-attorneys as well. Kevin points out some red flags and some useful prevention techniques as he describes a typical potential scam. (Hint: The scam usually starts with an email that might seem just a little bit off.) Listen in as Kevin goes through five specific red flags to avoid being scammed. And stay tuned for another episode coming soon.

View Details

Join Barclay Damon Live: Cyber Sip™ host Kevin Szczepanski as he welcomes Rich Sheridan, senior vice president, chief claims officer for Berkley Cyber Risk Solutions. In this informative episode, “Avoid Cyberattacks: Don’t Click That,” Kevin and Rich review the evolution of cyberspace, especially with regard to the most frequent types of claims insured clients make. Data breaches, malware and ransomware, and fraud frequently trigger claims. Less frequent, due to the rise of encryption, are claims for lost devices. Employee mistakes are still a major driver, asserts Rich, for example, clicking on a link they shouldn’t open. Listen in as Kevin and Rich share more information about how companies and individuals can shore up their defenses against cyber issues.

View Details

Check out episode 23 of the Barclay Damon Live podcast Cyber Sip™, during which host Kevin Szczepanski speaks with Ruth Promislow, a partner at Bennett Jones LLP, one of Canada’s top business law firms. A thought leader in the data-protection, privacy, and security space, Ruth joins Kevin for a lively conversation, starting with the basics: what does a US business with operations, customers, or employees in Canada need to do to comply with Canadian law? Then Ruth covers what constitutes personal information in Canada versus the US definition. Listen in for lots of valuable cross-border information.

View Details

Host Kevin Szczepanski is back with a new season of the Barclay Damon Live podcast Cyber Sip™. Listen to episode 22 as Kevin welcomes Bill Prohn, director of information technology for Dopkins & Company, an accounting and consulting firm, as well as the managing director of Dopkins System Consultants, an affiliate focused on technology. Bill is also a self-described cyber evangelist, who for years has urged people to try new technology and now advises with absolute conviction that cybersecurity is the underpinning for businesses. As we enter October and Cybersecurity Awareness Month, Kevin and Bill take a look at the month’s theme as described by the Cybersecurity Infrastructure Security Agency (CISA), an agency of the US Department of Homeland Security, focusing on four key messages CISA has delineated. Tune in, and stay tuned for new episodes coming soon.

View Details

Join host Kevin Szczepanski for episode 21 of Barclay Damon Live: Cyber Sip™. Kevin and guest Lizzie Cookson, director of incident response for ransomware remediation firm Coveware, offer an informative and wide-ranging discussion of Lizzie’s work, which includes data-driven profiling of ransomware actors to both predict their patterns and achieve better outcomes for victims. They also talk about how ransomware threats have evolved over the last few years and how they continue to evolve. Kevin and Lizzie then delve into possible results after a ransomware attack. Considering all the factors involved, Lizzie recommends that, when it comes to strategy, companies emphasize resilience over prevention. Listen in for more insights.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

Host Kevin Szczepanski of Barclay Damon Live: Cyber Sip™ is back with Yosha DeLong, senior vice president and global head of cyber for Mosaic Insurance, to continue their discussion on the past, present, and future of cyber coverage. Kevin and Yosha consider the quickly shifting landscape, including hot topics carriers, underwriters, and policyholders are exploring. They cover what is included in policies, what is not, and how various policies may be worded (it can be difficult to find clarity). Kevin and Yosha agree that risk is increasing—and while the market is tightening, the industry response is expansion. Listen in to hear how underwriters are thinking about coverage in key areas to enable policyholders to manage their ever-increasing risks.

Disclaimer: 

Barclay Damon Live podcast transcripts and captions are automatically generated through artificial intelligence, and the texts may not have been thoroughly reviewed. The authoritative record of Barclay Damon Live programming is the audio file.

View Details

On this episode of Barclay Damon Live: Cyber Sip™, Barclay Damon colleague Nick DiCesare joins host Kevin Szczepanski to continue their conversation from Episode 17 about how companies can reduce their risk if and when they experience a data breach or other negative cyber event. Nick introduces his “wave” theory of data breach or ransomware incidents; from his experience as a breach response coach, Nick has noticed a pattern of post-incident activities repeatedly cresting and then subsiding. Reiterating some information from their previous conversation—such as preparedness, cyber insurance, and knowing your data—they dive deeper into the breach scenario, touching on additional cybersecurity elements that business owners and companies should keep top of mind.

DISCLAIMER: 

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

Host Kevin Szczepanski of Barclay Damon: Live Cyber Sip™introduces another leader in the cybersecurity world: Yosha DeLong, senior vice president and global head of cyber for Mosaic Insurance, a NexGen global specialty lines insurer. Yosha’s 25-plus years of experience managing liability, professional, and cyber lines make her the perfect guest for episode 18, where she helps Kevin continue his exploration of cyber risk coverage, touching on its history, its shift from a “do we need it?” to a “gotta have it” product, and how Yosha helps educate those who, despite evidence to the contrary, may still not be convinced. And it’s only going to become more imperative, she says. Listen in for more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 17 of Barclay Damon Live: Cyber Sip, host Kevin Szczepanski welcomes first-time guest and Barclay Damon colleague Nick DiCesare to discuss “Four Keys to Prepare for a Data Breach.” Nick, who serves as co-leader of the Barclay Damon Cybersecurity Team along with Kevin and past guest Charles Nerko, frequently counsels clients on best practices to securely maintain electronically stored information. He’s also a “breach coach,” essentially quarterbacking for clients during data breaches and other cyber incidents. In this informative chat, Nick and Kevin break down the basics that can help businesses be better prepared for the inevitable breach. Listen to learn more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 16 of Barclay Damon Live: Cyber Sip, host Kevin Szczepanski welcomes back Laura Zaroski, managing director of Arthur J. Gallagher & Co.’s Law Firms Group, to continue their discussion about the cyber-insurance environment for law firms. They pick up where they left off in episode 14 (available here) with a discussion about the types of cyber coverage law firms should look for. They also address the complex question of whether a firm should purchase ransomware coverage since much of the current best practice is not to pay ransom. Laura gives a valuable reminder of the many free resources available on her company’s website and other sites to help inform shoppers in this market. Listen in for more.

Disclaimer: 

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 15 of Barclay Damon Live: Cyber Sip, host Kevin Szczepanski welcomes back Drew McNichol, HEALTHeLINK’s director of technology and information security officer. They discuss the differences between the skillsets required for IT versus cybersecurity (there is some overlap), the benefits of using a security dashboard, and some of the ways companies can develop a real culture of compliance, from governance, policies, and procedures to the role individual employees play. Does the fact that you’re certified mean you have a strong information security program? Listen in to learn more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 14 of Barclay Damon Live: Cyber Sip, host Kevin Szczepanski introduces listeners to Laura Zaroski, managing director of Arthur J. Gallagher & Co.’s Law Firms Group, to discuss the increasingly competitive environment of cyber insurance specifically for law firms. After addressing the questions of why bad actors target law firms and what the American Bar Association’s rules are around professional conduct vis a vis technology and security, Kevin and Laura get into the nitty gritty of what types of risks law firms face and the most frequent types of claims they file. Laura then shares her experience about law firm applications to carriers for insurance. What are underwriters looking for on those applications? Listen in to learn more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

It’s episode 13 of Barclay Damon Live: Cyber Sip, and host Kevin Szczepanski welcomes back Kelly Geary of Epic Insurance Brokers & Consultants to discuss trends and coverage issues in cyber insurance. Kelly says terms like “computer system” and “network” are the heart and soul of a cyber-insurance policy and advises, when reviewing a policy, to make sure the definition in the policy matches the reality of your technology setup and usage. Just the word “cyber” in a policy doesn’t mean you’re covered. And what about coverage in a ransomware context? Can you get reimbursed if you’ve paid ransom? There’s more to look out for, so listen in with Kevin and Kelly.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

Join host Kevin Szczepanski for episode 12 of the Barclay Damon Live podcast Cyber Sip, where Kevin introduces listeners to Drew McNichol, HEALTHeLINK’s director of technology and information security officer. HEALTHeLINK is one of six health information exchanges in SHIN-NY, the Statewide Health Information Network for New York. Drew speaks from long experience about the challenges and importance of cybersecurity and controls to ensure the massive amounts of protected data in the highly regulated health care space stay protected. He discusses topics like assessment and certification and notes that, even for small to mid-size companies (and not just in health care), it can make sense to hire vendors to help pinpoint what needs to be done before diving in on your own. Listen in for more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 11 of Barclay Damon Live: Cyber Sip,10 Traps in Technology Contracts,” host Kevin Szczepanski speaks with his colleague Charles Nerko, co-leader of Barclay Damon’s Cybersecurity Team. Referring to various technology vendors, you’ll hear conversation on maximizing the value and reducing the risk in critical business transactions. Many traps can be avoided, say Kevin and Charles, either during the contract process or by making sure you’ve got processes implemented to account for certain contract clauses, like non-renewals. From trap #1, what Charles calls the “entire agreement provision,” to #10, audits, count on this episode. And stay tuned for more soon.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 10 of Barclay Damon Live: Cyber Sip, a bonus segment featuring Sultan Meghji, host Kevin Szczepanski learns more about the former FDIC chief innovation officer’s experience at the federal agency and why he left after a year. Not surprisingly, Sultan, an innovative 30-year veteran of the security and technological sectors, found politics and bureaucracy to be impediments to accomplishing his goals. As Sultan wrote in a recent Bloomberg opinion piece, he has recommendations for overcoming tech hesitancy and maximizing the public sector’s use of innovative technologies that include civil service reform, education and training, and more government collaboration with companies, universities, and international partners. Listen in for more.

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 9 of the Barclay Damon Live podcast Cyber Sip, host Kevin Szczepanski talks with industry leader and scholar Sultan Meghji, who recently served as the first chief innovation officer at the Federal Deposit Insurance Corporation (FDIC). The episode, the first in a two-part series, delves into Sultan’s experience at the FDIC, where despite his mandate to transform how the agency operates; assess the US banking ecosystem in terms of cybersecurity, resilience, and equity; and strategize the agency’s interoperations with all of its regulatory partners, he encountered a gamut of attitudes, from hesitant to resistant. Listen in to hear Sultan speak to why he doesn't want “analog people making digital decisions.”

Disclaimer:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In Episode 8 of the Barclay Damon Live Cyber Sip Podcast, Kevin welcomes Kelly Geary, national executive risk and cyber practice leader of Epic Insurance Brokers & Consultants, for a conversation about the “State of the Market—Cybersecurity Insurance.” Kelly, a recognized leader in cyber insurance, shares a little history as well as practical takeaways that listeners can benefit from when shopping the market for cyber insurance. While there are many policies out there, Kevin and Kelly explain, there is little standardization. And with quickly changing risks and the increasing demand, finding coverage can be challenging.

Disclaimer

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

It’s episode 7 of the Barclay Damon Live podcast Cyber Sip! Tune in with host Kevin Szczepanski for an overview of media stories about all things cyber and what your response to the constant coverage might be. There’s an onslaught of information, says Kevin, and it can be difficult to make sense of it all. Regardless of your industry, what are the implications for your business? What should you do? Listen as Kevin lists three practical tips to take away from stories about topics like the Log4j vulnerability and FTC updates to the Gramm-Leach-Bliley Act Safeguards Rule. Tune in for this important information.

DISCLAIMER:  

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 6, host Kevin Szczepanski welcomes back Mike McCartney, national director of Avalon Cyber and a 22-year veteran of law enforcement with decades of experience in digital forensic investigation. Kevin and Mike discuss how to respond when (not if) your company experiences a cyber or data incident. Pro tip: don’t call it a “breach” right away—you don’t know until you know. Who do you call first, second, third? What are the questions you need answered? Why is attorney-client confidentiality so important in the process? Check out this episode for important information, and keep tuning in for more insights. 

DISCLAIMER: 

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In episode 5, host Kevin Szczepanski gives an overview of five things you should know about cyber insurance. Here’s a hint as to the first one: another way of looking at cyber insurance is as a risk-management tool that can mitigate the threat (and cost) of breaches to your networks and systems. Kevin walks listeners through the process of applying for cyber insurance, noting that, although it’s becoming more difficult, it’s not impossible—especially if you already have good cyber practices in place. Join Kevin in this episode for a few more details, and stay tuned for more!

DISCLAIMER:  This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening. 

View Details

In episode 4, host Kevin Szczepanski welcomes colleague Bridget Steele to discuss five steps to compliance regarding HIPAA and cybersecurity. This is a crucial topic for anyone in the health care space, considering the many specific HIPAA rules, the need to protect patient data, and cybercriminals’ determination to access that data. Kevin and Bridget discuss the various steps that health care entities can and must take, also exploring how to create business associate agreements with vendors and subcontractors. Tune in to learn what might constitute a reportable breach as well as other tips on best practices.

DISCLAIMER:

This material is for informational purposes only and does not constitute legal advice or a legal opinion, and no attorney-client relationship has been established or implied. Thanks for listening.

View Details

In Episode 3, host Kevin Szczcepanski welcomes back Mike McCartney, the national director of cybersecurity for Avalon Cyber, for part two of their deep dive on ransomware. We heard from him in the last episode, but as a quick reminder, Mike’s impressive career includes being a highly decorated 22-year veteran of law enforcement (NY Attorney General’s office, FBI Cyber Crime Division, etc.) instrumental in the inception of the field of cybersecurity; he wrote the book that law enforcement still uses today. In this continuing conversation, “Ransomware with Mike McCartney, Part 2: Threat Landscape, Protection, and Response,” Kevin and Mike discuss the likelihood of a company being attacked (hint: it’s high), what company and organizations can do to protect themselves ahead of time (talk to experts; follow best practices for policies, employee training and more). And, if and when you are attacked, what are your first steps, who do you call? Should you pay the ransom to possibly get your data back? What is required if you are in a deeply regulated field? Perk your ears up for this critical talk to learn more.

View Details

In this episode, host Kevin Szczepanski welcomes his first guest, Mike McCartney, the national director of cybersecurity for Avalon Cyber. In his intro, Kevin briefly describes Mike’s impressive career as a highly decorated 22-year veteran of law enforcement (NY Attorney General’s office, FBI Cyber Crime Division, etc.) who was instrumental in early days of cybersecurity, digital forensics, and internet investigations; he literally wrote the book on the subject that law enforcement still uses today. After touching on the evolution of the field since the 1990s, Kevin and Mike take a deep dive into all things ransomware, from what it actually is, to what do to if it happens to you, and how to preplan for the eventuality that it will happen. Mike has practical advice and deep insights into what he calls a “multi-tiered organized crime syndicate,” and one that is very lucrative for its perpetrators. Questions they explore include: How can you protect your systems and data? Should you pay the ransom to possibly get your data back? What are the ramifications? Are you in a deeply regulated field—what is required if your systems are hacked? Check out this crucial episode, discussed in plain talk, to learn more.

View Details

Welcome to the Cyber Sip, a Barclay Damon Live Production, where our host Kevin Szczcepanski will provide practical talk about cybersecurity. In this first episode, Kevin will cover the 3 Cs of cybersecurity for vendor relationships and will talk through a roadmap on protecting your business, while placing yourself in the strongest position to defend your organization in case anything goes wrong.