Taking Care of HR Business
        A blog from the attorneys of Verrill

        It’s Not Just Hillary Clinton Who Has to Worry About Security Protocols

        by Robert Laplaca on August 7, 2015

        Last month, the FTC issued new “guidance” on data security for companies that collect, store, and use consumer data. This guidance “summarizes the lessons learned from more than 50 law enforcement actions the FTC has announced so far.” The full text of the FTC’s Start with Security: A Guide for Business can be found at https://www.ftc.gov/tips-advice/business-center/guidance/start-security-guide-business. Considering the implications that a security breach can result in, it is important that employers have in place policies and procedures that direct employees on how they should handle and use sensitive information.

        The ten lessons to learn from FTC enforcement actions are summarized as follows:

        1. Start with security. Factor security into the decision making in every part of your business – personnel, sales, accounting, IT. Don’t collect personal information you don’t need such as consumer passwords. Hold onto this information only as long as you need it; if the sales transaction is complete, get rid of it. And don’t use personal information when it’s not necessary, such as training sessions.
        2. Control access to data sensibly. Keep the data accessible on a “need to know” basis. Restrict employees’ access to sensitive information stored on your network and don’t give every employee administrative control over your customer’s sensitive information.
        3. Require secure passwords and authentication. Businesses may want to consider protections such as a two-factor authentication. Don’t make it easy for unauthorized persons to guess administrative passords; “1234” is not a secure password. Store passwords securely, not in clear, readable text on in cookies. Guard against brute force attacks, such as a hacker’s use of automated programs to mine for passwords. Restrict the number of login attempts and suspend or disable accounts after repeated login attempts fail.
        4. Store sensitive personal information securely and protect it during transaction. Use strong cryptography to secure confidential material during storage and transmission. Keep sensitive information secure through its lifecycle, make sure your service cannot easily decrypt the information. Use industry-tested and accepted methods for encryption.
        5. Segment your network and monitor who’s trying to get in and out. Use tools like firewalls and intrusion detection to limit access between computers and monitor your network activity. Limit computers from one in-store network from connecting to computers on other in-store and corporate networks. Monitor activity on your network to detect unauthorized access early.
        6. Secure remote access to your network. Make sure the cellphones you give out to employees are properly secured. And don’t allow unlimited access to third parties, such as clients, make sure they have firewalls and updated antivirus software, restrict connections to specified IP addresses and grant temporary, limited access to third parties.
        7. Apply sound security practices when developing new products. Think about security during the development process of new apps, software, etc. This should include training your engineers in securing code, following platform guidelines for security, verifying that privacy and security features work, and testing for common vulnerabilities.
        8. Make sure your service providers implement reasonable security measures. Before hiring an outside service provider, tell them about your security expectations and ensure that they can implement appropriate security measures. It helps to put the appropriate security standards in your contract with the provider and to verify that the service provider implements an information collection system consistent with your requirements.
        9. Put procedures in place to keep your security current and address vulnerabilities that may arise. Securing your software and networks is an on-going process. You need to update and patch third-party software when it becomes outdated, heed credible security warnings and act quickly to fix them.
        10. Secure paper, physical media, and devices. The lessens for network security apply equally to paper and physical media such as hard drives, laptops, flash drives and disks. Don’t allow sensitive consumer information to be easily accessible. Protect devices that process personal information. And keep safety standards in place when the data is en route. For example, use mailing methods with tracking capability and limit your employees’ ability to take sensitive files outside of the office.

        Employers should keep these factors in mind when hiring and terminating staff. At the hiring or promotion stage, in addition to having strong consistent policies already in place, confidentiality agreements can be instituted to further protect data and provide an additional means of legal relief. Additionally, at the termination stage, make sure that you have the ability to wipe data from separating employees’ devices, and the ability to change passwords/access so that you don’t have employees breaching security as they are being kicked out the door. For further information on the FTC’s guidance and your responsibilities as they relate to employee management, contact Verrill Dana’s Promotions or Labor and Employment Practice Groups to discuss.

        Taking Care of HR Business

        Human resource professionals, supervisors, and company executives are constantly confronted with a changing legal landscape. Verrill’s Taking Care of HR Business blog is designed to keep you informed about the latest and most significant legal developments that affect employers.

        Key Contacts

        Subscribe

        Looking for more great content? Subscribe for regular legal updates and information delivered right to your inbox.

        Firm Highlights

        Published Works

        Four Verrill Attorneys Co-Author Massachusetts Trends and Developments Chapter for Chambers and Partners Child Relocation 2026 Guide

        Verrill attorneys Mary H. Schmidt, Rachel A. Deering, Hannah R. Zukoff, and Mariah G. Tappan co-authored the “Trends and Developments” chapter...
        Blog

        A New Protected Class in Maine: Holders of Final Protection Orders

        In the lead-up to Domestic Violence Awareness Month in October, employers may be taking a closer look at how their policies and practices respond to...
        Alerts and Newsletters

        Verrill Secures SJC Victory for Boston Legacy FC in White Stadium Litigation

        Verrill has secured a significant appellate victory for Boston Legacy FC in the litigation challenging the redevelopment of White Stadium in...
        Blog

        Hurry Up and Wait

        This is the third in a series of Verrill blog posts on Maine’s packaging extended producer responsibility (“EPR”) law[1]. In July we reported...
        Media Mentions

        Robert Keach Discusses First Brands Chapter 11 Case in Law360

        Verrill attorney Robert Keach was recently quoted in a Law360 article examining the rejection of First Brands Group's Chapter 11 plan and the...
        Media Mentions

        Cybersecurity and AI Governance: Scott Anderson Featured in Massachusetts Lawyers Weekly

        Verrill Managing Partner Scott Anderson was recently featured in Massachusetts Lawyers Weekly discussing how law firms can build attorney buy-in for...
        Blog

        Section 530A Account Update: ERISA Status of Trump Accounts

        The Department of Labor has issued important guidance addressing whether employer programs that permit contributions to Section 530A accounts (and...
        Press Releases

        97 Verrill Attorneys Recognized by Best Lawyers® 2027, Including Four Named Lawyers of the Year

        AUGUSTA, Maine, BANGOR, Maine, BOSTON, Mass., PORTLAND, Maine, and WESTPORT, Conn., (August 20, 2026) – Verrill is proud to announce that 97...
        Alerts and Newsletters

        SEC’s Proposed “Reg Crypto”: What Founders Need to Know

        Startup founders and emerging-growth companies have a number of options for raising capital under the federal securities laws, including Regulation D...
        Blog

        After 45 Years, the IRS Speaks on DCAP Nondiscrimination Testing – And It’s Good News

        Employers that provide a Dependent Care Assistance Program will be pleased to learn that for the first time in 45 years, the IRS has issued guidance...
        Media Mentions

        U.S. Courts Highlights Annabel Rodriguez’s Journey from Fellow to Mentor

        Verrill attorney Annabel Rodriguez was featured in a recent U.S. Courts article titled “From Fellows to Mentors: Alumni Share Lasting Lessons from...
        Media Mentions

        Robert Keach Discusses Bankruptcy Auction Strategy in Law360

        Verrill attorney Robert Keach spoke with Law360 article examining the complex bankruptcy auction process that resulted in the sale of 23 summer...