Taking Care of HR Business
        A blog from the attorneys of Verrill

        It’s Not Just Hillary Clinton Who Has to Worry About Security Protocols

        by Robert Laplaca on August 7, 2015

        Last month, the FTC issued new “guidance” on data security for companies that collect, store, and use consumer data. This guidance “summarizes the lessons learned from more than 50 law enforcement actions the FTC has announced so far.” The full text of the FTC’s Start with Security: A Guide for Business can be found at https://www.ftc.gov/tips-advice/business-center/guidance/start-security-guide-business. Considering the implications that a security breach can result in, it is important that employers have in place policies and procedures that direct employees on how they should handle and use sensitive information.

        The ten lessons to learn from FTC enforcement actions are summarized as follows:

        1. Start with security. Factor security into the decision making in every part of your business – personnel, sales, accounting, IT. Don’t collect personal information you don’t need such as consumer passwords. Hold onto this information only as long as you need it; if the sales transaction is complete, get rid of it. And don’t use personal information when it’s not necessary, such as training sessions.
        2. Control access to data sensibly. Keep the data accessible on a “need to know” basis. Restrict employees’ access to sensitive information stored on your network and don’t give every employee administrative control over your customer’s sensitive information.
        3. Require secure passwords and authentication. Businesses may want to consider protections such as a two-factor authentication. Don’t make it easy for unauthorized persons to guess administrative passords; “1234” is not a secure password. Store passwords securely, not in clear, readable text on in cookies. Guard against brute force attacks, such as a hacker’s use of automated programs to mine for passwords. Restrict the number of login attempts and suspend or disable accounts after repeated login attempts fail.
        4. Store sensitive personal information securely and protect it during transaction. Use strong cryptography to secure confidential material during storage and transmission. Keep sensitive information secure through its lifecycle, make sure your service cannot easily decrypt the information. Use industry-tested and accepted methods for encryption.
        5. Segment your network and monitor who’s trying to get in and out. Use tools like firewalls and intrusion detection to limit access between computers and monitor your network activity. Limit computers from one in-store network from connecting to computers on other in-store and corporate networks. Monitor activity on your network to detect unauthorized access early.
        6. Secure remote access to your network. Make sure the cellphones you give out to employees are properly secured. And don’t allow unlimited access to third parties, such as clients, make sure they have firewalls and updated antivirus software, restrict connections to specified IP addresses and grant temporary, limited access to third parties.
        7. Apply sound security practices when developing new products. Think about security during the development process of new apps, software, etc. This should include training your engineers in securing code, following platform guidelines for security, verifying that privacy and security features work, and testing for common vulnerabilities.
        8. Make sure your service providers implement reasonable security measures. Before hiring an outside service provider, tell them about your security expectations and ensure that they can implement appropriate security measures. It helps to put the appropriate security standards in your contract with the provider and to verify that the service provider implements an information collection system consistent with your requirements.
        9. Put procedures in place to keep your security current and address vulnerabilities that may arise. Securing your software and networks is an on-going process. You need to update and patch third-party software when it becomes outdated, heed credible security warnings and act quickly to fix them.
        10. Secure paper, physical media, and devices. The lessens for network security apply equally to paper and physical media such as hard drives, laptops, flash drives and disks. Don’t allow sensitive consumer information to be easily accessible. Protect devices that process personal information. And keep safety standards in place when the data is en route. For example, use mailing methods with tracking capability and limit your employees’ ability to take sensitive files outside of the office.

        Employers should keep these factors in mind when hiring and terminating staff. At the hiring or promotion stage, in addition to having strong consistent policies already in place, confidentiality agreements can be instituted to further protect data and provide an additional means of legal relief. Additionally, at the termination stage, make sure that you have the ability to wipe data from separating employees’ devices, and the ability to change passwords/access so that you don’t have employees breaching security as they are being kicked out the door. For further information on the FTC’s guidance and your responsibilities as they relate to employee management, contact Verrill Dana’s Promotions or Labor and Employment Practice Groups to discuss.

        Taking Care of HR Business

        Human resource professionals, supervisors, and company executives are constantly confronted with a changing legal landscape. Verrill’s Taking Care of HR Business blog is designed to keep you informed about the latest and most significant legal developments that affect employers.

        Key Contacts

        Subscribe

        Looking for more great content? Subscribe for regular legal updates and information delivered right to your inbox.

        Firm Highlights

        Press Releases

        97 Verrill Attorneys Recognized by Best Lawyers® 2027, Including Four Named Lawyers of the Year

        AUGUSTA, Maine, BANGOR, Maine, BOSTON, Mass., PORTLAND, Maine, and WESTPORT, Conn., (August 20, 2026) – Verrill is proud to announce that 97...
        Alerts and Newsletters

        SEC’s Proposed “Reg Crypto”: What Founders Need to Know

        Startup founders and emerging-growth companies have a number of options for raising capital under the federal securities laws, including Regulation D...
        Blog

        After 45 Years, the IRS Speaks on DCAP Nondiscrimination Testing – And It’s Good News

        Employers that provide a Dependent Care Assistance Program will be pleased to learn that for the first time in 45 years, the IRS has issued guidance...
        Media Mentions

        Robert Keach Discusses Bankruptcy Auction Strategy in Law360

        Verrill attorney Robert Keach spoke with Law360 article examining the complex bankruptcy auction process that resulted in the sale of 23 summer...
        Media Mentions

        Martha Gaythwaite Featured in Portland Press Herald Coverage of Sig Sauer Trial Victory

        Verrill attorney Martha Gaythwaite was highlighted in media coverage of a federal trial in Bangor involving firearm manufacturer Sig Sauer. As...
        Media Mentions

        Law360 Quotes Robert Keach on Senate Bill Affecting Small Business Restructurings

        Verrill attorney Robert Keach was recently quoted in a Law360 article discussing federal legislation that would permanently restore the $7.5 million...
        Alerts and Newsletters

        SAFEs and Preferred Stock – Key Deal Terms Every Founder Should Know

        SAFEs Before negotiating a term sheet for preferred stock, many early-stage companies, particularly at the seed stage, first raise capital through...
        Press Releases

        Verrill Welcomes Business Restructuring and Insolvency Attorney Nimra Tariq

        BOSTON, Massachusetts – Verrill is pleased to announce that Nimra Tariq has joined the firm’s Business Restructuring and Insolvency Group as an...
        Media Mentions

        Robert Keach Provides Commentary on First Brands Restructuring in Law360

        Verrill attorney Robert Keach was quoted in the Law360 article, "First Brands' Ch. 11 Plan Revives Angst Over Admin Claims," discussing First Brands...
        Press Releases

        Verrill Welcomes Construction Attorney Cassie Dufon

        PORTLAND, Maine – Verrill is pleased to welcome Cassie Dufon to the firm’s Construction Group as an Associate, resident in the firm’s Portland...
        Press Releases

        Verrill’s Wide-Ranging Private Wealth Law Practice Recognized in 2026 Chambers and Partners High Net Worth Guide

        BANGOR and PORTLAND, Maine and BOSTON, Mass. – Verrill attorneys Kenneth P. Brier, Anya F. Endsley, Kurt E. Klebe, Mary McQuillen, Nathaniel S....
        Blog

        Update on Status of Maine Packaging EPR

        In December 2024, Verrill published a blog post, Unwrapping Maine's Gift to the Environment: A New Packaging Stewardship Program Set to Launch in...