Open Source Licenses: Fast Facts
For a software license to be certified as open source by the Open Source Initiative (OSI), it must meet the ten criteria set forth in the Open Source Definition. The Open Source Definition is a document created by OSI to maintain uniformity across the open source projects.
Most software developers rely on one of the most common OSI-certified open source licenses. These licenses possess variations making some more suitable for certain projects than others. This makes choice of license a strategic decision for a developer and their company.
First, it is important to understand the distinction between the two major categories of open source licenses: copyleft, and permissive. This level of classification refers to whether a modification of open source code is subject to the same license requirements as the original source code, and if so, to what extent. This may limit the user’s choice of license in their modification of a particular open source project.
Copyleft (More restrictive)
Any modifications to open source software under a copyleft license must be kept open source and may even be subject to the exact same license requirements as the original software.
Permissive (Less restrictive)
Modifications to open source software under a permissive license do not have to be kept open source and only require attribution to the original software.
When given a choice of which license, Companies largely prefer permissive licenses and they are among the most popular since there more freedom associated with software created under this type of license. Copyleft licenses, however, are preferable in circumstances where a developers wishes to promote development and improvement of their code by other developers.
Below are the five of the most popular OSI licenses, and some of their requirements/features:
GNU General Public License Version 3 (GPL v3)
Most Strict Copyleft License
User can do almost anything with the original code, but any modifications/uses must also be made available to others under the same GPL.
On any use or modification of the original source code must:
include a copy of the full license text
state all significant changes made to the original software
make available the original source code when you distribute any binaries based on the licensed work
include a copy of the original copyright notice
Allows the original developer the most control over their original code
Mozilla Public License 2.0 (MPL 2.0)
Least Restrictive Copyleft License
User can do almost anything with the original code, but must meet certain requirements to have choice of license
If user wants to distribute modifications made directly to the original code within the same file, the modification must:
Make the source code (including modifications) available under the same license as the original (MPL 2.0) and abide by the same restrictions
Provide notice of the MPL-License
If user wishes to distribute a modified code based on the original code, but keeps the modifications in a separate file, the user must:
Identify the MPL-licensed portions of the source code (including explicit notice that these portions are made available under the terms of the MPL)
Inform recipients how they can obtain the original source code
Operates as copyleft, but on a file level, allowing the user greater freedom of choice with respect to licensing their modifications, as long as they are kept separate from the original source code.
Apache License 2.0 (Apache-2.0)
Lowest Risk
User can do almost anything with the original code and has choice of license
On any use, or modification of the original source code user must include:
original copyright notice
A copy of the license
a statement of any significant modifications to the original code
A copy of the NOTICE file, if any, with attribution notes
Includes explicit patent grant
3-Clause Berkeley Software Distribution License (BSD 3- Clause)
Most Similar to MIT (but with stricter attribution restrictions)
User can do almost anything with the original code and has choice of license
On any use, or modification of the original source code user must include:
Original copyright notice
Full text of the license
Prohibits the use of the owner’s name for promotion of modifications/derivatives
MIT License (MIT)
Most Popular & Least Restrictive
User can do almost anything with the original code and has choice of license
On any use, or modification of the original source code user must include:
original copyright notice
copy of the license
Uses simple language that is easiest to understand
Small Businesses Will Be Required To Comply With The Corporate Transparency Act Starting In January 2024.
With little fanfare or media coverage, Congress passed the Corporate Transparency Act of 2020 (the “CTA”) as part of the William M. Thornberry National Defense Authorization Act for Fiscal Year 2021. Setting aside the very real question of why our republic names its defense spending bills after people, and at what point those bills will start being named after their corporate sponsors (e.g., The Home Depot National Defense Auth. Act for Fiscal Year 2027, or the Walmart National Security Act of 2028?), what does the CTA mean for business owners?
The primary change for entrepreneurs is that the CTA requires most U.S. businesses to report basic information about who owns those businesses. Those reporting requirements take effect in January 2024. Any domestic business entity, including corporations, LLCs, LPs, LLPs, PLLCs, business trusts and any other entity “that is created by filing of a document with a secretary of state or any similar office under the law of a State or Indian tribe”, will be required to comply with the reporting requirements. Foreign entities registered to do business in any state or tribal jurisdiction are also subject to the same requirements.
Several entities are exempted from the reporting requirement. These are primarily companies that are already subject to similar requirements under other regulatory rule-sets, e.g., publicly-traded companies, banks, credit unions, municipal corporations, insurance companies, certain brokers and advisers, accounting firms, pooled investment vehicles, non-profits, and, most interestingly “entities that employ more than 20 employees, operate at a physical office in the United States, and filed federal tax returns demonstrating more than $5 million in gross receipts or sales.” In other words, the CTA is aimed at small businesses operating in the U.S.
The CTA applies to companies whether they are newly formed or already existing. For entities formed before Jan 2024, they must report by Jan 1, 2025. For newly-formed entities, they must file within 30 calendar days of receiving notice from the state of creation of the entity.
Reporting will require:
Entity’s full legal name
Trade names
A complete current address
The jurisdiction it was formed in or jurisdiction in which a foreign company first registers
Internal Revenue Service Taxpayer Identification Number and Employer Identification Number
As well as information about each beneficial owner and company applicant of the reporting company:
Full legal name
Date of birth
Current business or residential address
A unique identifying number from an acceptable identification document (i.e., passport, driver’s license, etc.)
This raises unique issues for companies in the cannabis industry, who are state-compliant by are technically operating an illegal business under federal law.
Small companies will now also have the added burden of having to plan for compliance with the CTA on an ongoing basis. Regulations like these have a tendency to expand over time, not contract, so expect that the reporting requirements will continue to grow.
The Long Law Firm intends to work with its clients to assist with compliance of the reporting requirements, and will price CTA reporting into its corporate formation package so that clients need not worry about running afoul of the CTA. Once we have more information about the form to be used for reporting, we will be reaching out to individual clients to handle.
Licensing Agreement Term Sheet: Fast Facts
Licensing is one of the many ways to commercialize Intellectual Property (IP) rights. When licensing use of your IP to another company, it is important to have in mind a predetermined set of conditions under which you are willing to grant the license. A licensing agreement should also always contain a description of the subject matter of the license. This description should include which IP rights/technology the licensor intends to license.
Some of the other essential terms of an IP licensing agreement are listed in the table below and shown as applied to the Sample Agreement:
Sample Agreement:
Foodstuff Manufacturer (Company A) grants Pizza Shop (Company B) an exclusive license to use Company A’s secret recipe Tomato Sauce. This license permits the use of Company A’s sauce only on pizza sold directly to consumers from Company B’s Pizza Shop locations within the state of New York for a period of three years. Company B shall pay Company A a monthly royalty of $2.00/per pizza sold using Company A’s sauce.
Essential Terms
Exclusivity
Exclusivity refers to whether or not a licensee has an exclusive license to use the technology within the scope of the other terms of the license.
In the example, due to the exclusivity, Company B is the only entity that can use Company A’s sauce on Pizza sold within New York during the designated period.
Generally non-exclusive licenses are far less attractive to licensees since the licensor could grant as many licenses as possible to similar companies within the same geographic area, decreasing the competitive value of the IP license to the original licensee. Exclusive licenses, however, should also be approached with caution, and appropriately limited so as to not pose any antitrust issues or unduly limit the licensor from developing their remaining interest in the IP.
Geographic/Territorial Scope
The geographic/territorial scope of a license limits the area in which the licensee is allowed to use the technology.
In the example, Company B can only use Company A’s sauce within New York State.
Craft your geographic scope carefully as licensing your technology to a Company for use within a larger geographic scope than they are currently operating in can limit your ability to license with other companies in those geographic markets.
Term of Use
The term of use of a license is the period of time over which the licensee has permission to use the technology.
In the example, Company B can use Company A’s sauce for a term of three years.
In deciding the term of the license, consider potential future licensing agreements, advances in technology, and the overall trajectory of your company, as well as that of the potential licensee.
Field of Use
The field of use is a limitation on which industry(s) a licensee can use your technology in.
In this example, Company B can only use Company A’s sauce on pizza sold directly to the public from it’s Pizza Shop locations. Company B cannot bottle the sauce and sell to grocery stores under this Field of Use limitation.
It is important to limit the field of use consistent with the needs of the licensee. Your technology could have applications in other fields, and you want to retain the ability to exploit these uses.
Royalties/Fees
Licensing agreements will also include a royalty fee schedule. This schedule will state the basis for determining the amount of royalties and how often they are to be paid out to the licensor. Licensing agreements often include provisions for the payment of a licensing fee which may include the costs associated with negotiating the licensing agreement.
In the example, Company B is to make a monthly royalty payment to Company A in the amount equal to $2.00/per pizza for each pizza sold using Company A’s sauce.
Royalties and fees are a highly technical business decision that should be determined in light of the value of the technology being licensed as well as the business model of the licensee.
This is just a starting point and there are many other terms that should be included like sublicensing permissions, maintenance requirements, remedies, termination, and confidentiality requirements.
If you would like to discuss your licensing term sheet with an attorney at The Long Law Firm, please go to https://long.law/intake to set up a free 30-minute consultation.
The Basics of Licensing
Overview
In the digital age, Intellectual Property (IP) is often a company’s most valuable asset. Understanding how to commercialize your IP can help uncover new potential revenue streams. The obvious way to gain value from Intellectual Property rights is by using them (i.e. using an invention you have created and patented within your business to increase output). Using IP rights often requires extensive efforts and investment. If your company is not in a position to take full advantage of your IP rights, there are still many other methods of monetizing these assets. One of the most prominent alternative methods of commercializing your IP rights is through licensing.
Licensing
Licensing is one of the most common ways that a company can take advantage of its IP assets or even the IP assets of another in order to more efficiently make use of their own. Licensing occurs when one party (the licensor) gives permission to another party (the licensee) to use the first party’s IP rights with respect to a particular IP asset. Usually, the licensor is paid a licensing fee (covering the cost of negotiating the license and other related fees) as well as royalties consistent with a royalty fee schedule negotiated as part of the licensing agreement.
Licenses are NOT a transfer of IP rights; ownership remains with the licensor. Licenses are simply a grant of permission to use these rights under a set of conditions laid out in a licensing agreement.
First, you should take inventory of your IP assets, ensure they meet the requirements for federal/state protection, and prepare a rough valuation of each of your respective assets.
Then, you should determine what form of licensing could prove most advantageous to your company.
There are two different scenarios that take place with respect to IP licensing:
“Out-licensing"- Giving another company permission to use your IP.
Example: Phone Charger Manufacturing Company A licenses use of Company A's patented Wireless Charging invention to Mobile Phone Company B for use within Company B’s Mobile Phones for a designated period of time and within a predetermined scope.
Here, Company A is out-licensing their invention to Company B.
“In-licensing”- Getting permission to use another company’s IP within your business.
Example: Motion Picture Producing Company X licenses the use of Company Z’s novel in Company X’s production of a film based on Company Z’s novel.
Here, Company X is in-licensing Company Z’s novel for use within Company X.
In determining whether to in-license or out-license consider the balance between what value your IP could bring to another company vs. what resources you would need to fully develop and use your IP yourself.
Next, once you have determined whether to in-license or out-license, you should draft a term sheet. In the case of out-licensing, a term sheet will detail the conditions under which you are willing to license your technology (IP) to another company. In the case of In-licensing you will likely be met with a term sheet drafted by the owner of the IP asset you are trying to license, but keep in mind what terms would make sense for you to get the most out of an in-licensing arrangement.
Some of the important terms of a licensing agreement are exclusivity, geographic scope, term of use, field of use, fees/royalties, termination, and the permissibility of sublicensing.
See Licensing Agreement Terms: Fast Facts for more information.
Finally, a licensor and potential licensee should consult with attorneys in drafting and signing a binding licensing agreement. It is important to ensure that the terms of a licensing agreement do have anticompetitive effects that could render the agreement void. It is also important to ensure that a potential licensing agreement does not conflict with any existing licenses.
To talk to an attorney at The Long Law Firm about your IP needs, complete an intake form to set up a free consultation at https://long.law/intake
N.Y. Adult-Use Cannabis Regulation Update!
Breaking news! In an interview of Axel Bernabe, the Office of Cannabis Management’s (“OCM”) Chief of Staff and Senior Policy Director, by John Schroyer of the Green Market Report, it was disclosed that the proposed regulations for adult-use cannabis are being prepared for passage at OCM’s Cannabis Control Board meeting scheduled for May 11, 2023. If the regulations are prepared in time for the May 11th meeting, then they are likely, although not guaranteed, to be published by the end of August this year. Mr. Bernabe projects that adult-use cannabis license applications should be opening a couple of months after the regulations are finalized.
We are likely to see the award of adult-use licenses to applicants as soon as this coming fall! OCM does state that these dates are tentative, but adult-use dispensary licenses are projected to be awarded after Labor Day. If you are someone seeking an adult-use cannabis license, do not delay in preparing yourself and your business for the application process. The proposed regulations currently published are likely to be as close to the final regulations that are to be released in May as possible, enough to rely on in preparing yourself for operation. Call our office today for guidance on your canna-business journey!
What To Do If You’ve Received A Cease And Desist Letter
Last one today, promise: I asked OpenAI to write a blog post about what to do if you receive a cease and desist letter. Here’s what the AI software returned. By the way, all good advice.
“If you receive a cease and desist letter, it can be a scary and intimidating experience. A cease and desist letter is a legal document sent by a person or company to another person or company, demanding that they stop a certain activity or behavior. It is important to take a cease and desist letter seriously and to understand the implications of ignoring it.
The first step is to read the letter carefully and understand what it is asking you to do. It is important to note that a cease and desist letter is not a court order, but it is a warning that legal action may be taken if the demands are not met.
Once you understand the letter, it is important to consult with a lawyer. A lawyer can help you understand the legal implications of the letter and advise you on the best course of action.
If the letter is asking you to stop a certain activity, it is important to comply with the demands. Ignoring the letter could result in legal action being taken against you. If the letter is asking you to do something that you believe is not legally required, you may be able to negotiate with the sender. A lawyer can help you negotiate a resolution that is acceptable to both parties.
Finally, it is important to keep a copy of the letter and any correspondence related to it. This will help you if the sender decides to take legal action against you.
Receiving a cease and desist letter can be a stressful experience, but it is important to take it seriously and to understand the implications of ignoring it. Consulting with a lawyer is the best way to ensure that you are taking the right steps to protect yourself.”
It is worth noting that I had also attempted a blog post on deciding whether to form an LLC or a corporation and OpenAI appeared to give blatenty incorrect information. So, to the extent you’re wondering, yes, I do proof read this stuff and attest that its essentially the same advice I would have given myself.
Over the next few months, I suspect I’ll be using OpenAI to continue to post useful information, and will be working internally to explore what else we can use this technology for.
GDPR predictions from ChatGPT
Here is another AI-written blog post, this time predicting developments in the GDPR for 2023. Comments, questions, cries for help are all welcome:
Human Prompt: Write a blog post about new developments in the GDPR for 2023.
OpenAI Response: “As the European Union’s General Data Protection Regulation (GDPR) enters its fourth year, the EU is already looking ahead to the next round of changes and updates. The GDPR was introduced in 2018 to protect the personal data of EU citizens and ensure that companies and organizations comply with data protection laws. Since then, the GDPR has been updated several times to keep up with the ever-evolving digital landscape.
The EU is now looking ahead to 2023 and the next round of changes to the GDPR. Here’s what we can expect to see in the coming years:
1. Increased Enforcement: The GDPR has already seen a significant increase in enforcement since its introduction in 2018. This trend is expected to continue in 2023, with the EU likely to increase the number of fines and other penalties for companies and organizations that fail to comply with the GDPR.
2. More Focus on Data Security: Data security is a key component of the GDPR, and the EU is expected to focus even more on this area in 2023. Companies and organizations will be expected to take additional steps to protect the personal data of EU citizens, such as implementing stronger encryption and other security measures.
3. Greater Transparency: The GDPR requires companies and organizations to be transparent about how they use and process personal data. In 2023, the EU is likely to introduce new rules that will require companies and organizations to provide even more detailed information about their data processing activities.
4. More Rights for Individuals: The GDPR already gives individuals a number of rights when it comes to their personal data, such as the right to access, rectify, and delete their data. In 2023, the EU is likely to introduce new rights that will give individuals even more control over their data.
The GDPR is an ever-evolving piece of legislation, and the EU is committed to ensuring that it remains up-to-date and effective. With the changes expected in 2023, companies and organizations will need to stay on top of their data protection obligations to ensure they remain compliant.”
Please Welcome Our New AI Overlords…
As an experiment, I asked ChatGPT, a well known AI designed to answer questions and explain the meaning of life to us humans, to explain the future Artificial Intelligence in the legal industry. Below is a message from our new robot overlords:
”The legal industry is one of the oldest and most established industries in the world, and it is no surprise that it is now being disrupted by the emergence of artificial intelligence (AI). AI is transforming the legal industry in a variety of ways, from automating mundane tasks to providing legal advice. In the near future, AI is expected to become an even more integral part of the legal industry, as it continues to evolve and become more sophisticated.
One of the most significant ways AI is transforming the legal industry is by automating mundane tasks. AI can be used to automate document review, contract analysis, and other tedious tasks that are traditionally done by lawyers. This allows lawyers to focus on more complex tasks, such as providing legal advice and representing clients in court. AI can also be used to provide legal advice, as it can analyze large amounts of data and provide insights that would otherwise be difficult to obtain.
AI is also being used to improve the efficiency of legal processes. AI-powered tools can be used to streamline the discovery process, as well as to automate the filing of legal documents. This can help reduce the amount of time and money spent on legal processes, making them more efficient and cost-effective.
Finally, AI is being used to improve the accuracy of legal decisions. AI-powered tools can be used to analyze large amounts of data and provide insights that would otherwise be difficult to obtain. This can help lawyers make more informed decisions and reduce the risk of making mistakes.
Overall, AI is transforming the legal industry in a variety of ways. In the near future, AI is expected to become an even more integral part of the legal industry, as it continues to evolve and become more sophisticated. AI-powered tools will continue to automate mundane tasks, improve the efficiency of legal processes, and provide more accurate legal decisions. As AI continues to evolve, it will become an even more important part of the legal industry.”
So, here it is. This is our firms’ first official instance of AI co-writing a blog post. In the future, I hope to experiment more with ChatGPT and other AI writers to explore what this new technology can really do for the firm and for its clients. I know a lot of lawyers are getting nervous about being replaced by robots, but I’m actually excited. We aren’t facing replacement by robots, we are facing increased efficiency, expanded access to justice, and a geniune increase in what lawyers can do for their clients. The lawyers that choose to stand still while the world evolves around them, yes, they will be replaced. But we are not among those lawyers. This firm was premised on adopting cutting edge technology to make a better law practice, and here is a fantastic opportunity to do so. So…. Off we go! Expect more AI generated blog posts in the near future. And feel free to send suggested topics to info@long.law.
Cheers!
Cease-and-Desist Letters: Necessary or Discretionary?
What is a cease-and-desist letter? Do I have to send a cease-and-desist before filing suit?
A cease-and-desist letter is a commonly used pre-litigation tool for protecting intellectual property rights. The purpose of a cease-and-desist letter is to assert your rights to your intellectual property and to put another party on notice that they are infringing on those rights. Typically, a cease-and-desist letter will request (or demand) that the recipient stop the infringing activity or face legal action. A cease-and-desist letter is not, on its own, a legally enforceable document; however, it may serve as evidence of notice and continued infringement should a lawsuit eventually be filed.
A cease-and-desist is, generally, not required prior to taking other legal action: whether a cease-and-desist is required or optional varies by jurisdiction. Sending a cease-and-desist before taking other action is advisable in most situations for a number of reasons: (1) it puts an infringer on notice of their infringing activity and the consequences of continued infringement, making further infringement an intentional act by the infringer; (2) it provides an opportunity to resolve any dispute amicably, and may even provide an opportunity for licensing your intellectual property to the infringer; (3) it demonstrates to courts that you attempted to resolve the matter with judicial efficiency in mind, i.e., without making unnecessary use of the court’s time and resources; and (4) it may avoid the costly, time-consuming process of litigation.
Cease-and-desists need not be combative in tone. Netflix made headlines in 2017 for a cease-and-desist it sent to the Chicago proprietors of a Stranger Things pop-up bar, which referenced themes from the show in politely (but clearly) requesting they cease infringing on the Stranger Things trademark. [1] The goal of a cease-and-desist is, after all, to protect your intellectual property by getting an infringer to stop the infringing activity: not every circumstance calls for heavy-handedness. Starting with a polite but direct request does not preclude you from taking a more contentious tone—or from filing suit—should the infringing activity continue.
Whatever the tone of your letter may be, a cease-and-desist should be sent promptly upon learning of infringing activity, as it is important to demonstrate that you are actively protecting your rights.
Do you believe another person or business is infringing upon your intellectual property rights? Contact us here to discuss sending a cease-and-desist letter and other ways to protect your rights.
[1] The Atlantic, Not a Regular Cease-and-Desist, A Cool Cease-and-Desist (Sept. 21, 2017).
Section 15 Declarations of Incontestability vs. Standard Trademark
What is an incontestable mark? What is a declaration of incontestability? Should I declare my mark incontestable?
Let’s start with the basics: what exactly is a trademark, anyway? A trademark is “[a] word, phrase, design, or a combination that identifies your goods or services, distinguishes them from the goods or services of others, and indicates the source of your goods or services.” [1] While you acquire certain rights to a mark when the mark is first put into use, registration “[p]rotects the trademark from being registered by others without permission and helps you prevent others from using a trademark that is similar to yours with related goods or services.” [2]
You can only protect your trademark on a national scale by registering your mark with the United States Patent and Trademark Office (“USPTO”)—absent registration, your mark may only be protected in your geographic area. What this means is that if you sell calculators under the registered trademark AweSum calculators, you can prevent others from selling similar products under a similar mark nationwide; however, you likely cannot prevent an antique automotive appraisal service from using a similar mark, since the product is a service rather than a good, and since the service falls into a different “class” than the product you are offering.
A mark may be registered on one of two federal registers as determined by the USPTO: the Principal Register or the Supplemental Register. The Principal Register provides greater protection for marks that have the requisite distinctiveness—this includes marks that are fanciful, arbitrary, suggestive, or inherently distinctive. The Supplemental Register provides less protection and is for marks that have not acquired the distinctiveness requisite to placement on the Principal Register. A mark placed on the Supplemental Register may be moved to the Principal Register once the mark can be shown to be distinctive.
| Strong Trademarks | |||||
|---|---|---|---|---|---|
| Fanciful | Invented words. They only have meaning in relation to their goods or services. For example, Exxon® for petroleum or Pepsi® for soft drinks. | ||||
| Arbitrary | Actual words that have no association with the underlying goods or services. Think of the term "apple." If an apple orchard tried to register the word "apple" as a trademark for the type of apples they grow, that trademark wouldn't be registerable. But, Apple® has been registered as a trademark for computers. Apple® for computers is unique. | ||||
| Suggestive | Words that suggest some quality of the goods or services, but don’t state that quality of the goods or services outright. Consider Coppertone® for sun-tanning products. The trademark gives the impression that using Coppertone® suntan oil will make your skin shimmer like copper. | ||||
|   | |||||
| Weak Trademarks or Non-Trademarks | |||||
| Descriptive | Merely describe some aspect of your goods or services without identifying or distinguishing the source of those goods or services. They’re only registrable in certain circumstances, such as your trademark gaining secondary meaning through extensive use in commerce over many years. | ||||
| Generic | Merely the common, everyday name for your goods or services. As such, they do not indicate source and cannot function as trademarks. Therefore, generic trademarks are not federally registrable. | ||||
| Source: [3]. | |||||
Trademarks—even if on the Principal Register—may have their validity contested legally. Such challenges are often a response to a cease-and-desist letter: that is, a letter requesting that someone using a mark similar to or the same as yours cease using the mark in a way that infringes on your exclusive rights. To protect against legal challenges, the owner of a mark on the Principal Register may file a Section 15 Declaration of Incontestability. [4] An incontestable registration “is conclusive evidence (subject to certain statutory defenses) of the validity of the registered mark and its registration; the registrant’s ownership of the mark; and the registrant’s exclusive right to use the registered mark in commerce.” [5]
Continuous use of a mark for five years is required before a declaration of incontestability may be filed. Among other requirements, a Section 15 Declaration of Incontestability “must state that there has been no final decision adverse to the owner’s claim of ownership of the mark for the goods or services, or to the owner’s right to register or maintain registration of the mark[, and] must also state that there is no proceeding involving these rights pending in the USPTO or in a court.” [6] A fee of $200 per class of goods or services must be paid, as well.
The importance of a Section 15 Declaration of Incontestability for trademark owners is that the Declaration creates a presumption of a mark’s validity: in other words, the burden in a court proceeding will be on the other party to demonstrate that your particular trademark is invalid. This presumption may serve to expedite the resolution of—or altogether avoid—claims of invalidity in response to a cease-and-desist letter. At minimum, a Declaration puts the owner of a mark on more solid legal ground to defend against claims of invalidity.
Do you have intellectual property in need of protection? Have you received a challenge to your use of a particular brand or product name? Contact us here to set up a quick call with one of our attorneys.
[1] USPTO, Patent, Trademark, or Copyright.
[2] USPTO, Patent, Trademark, or Copyright.
[3] USPTO, Strong Trademarks.
[4] See 15 U.S.C. §§ 1065, 1115(b).
[5] LexisNexis, Trademark Registrations: Maintenance and Renewal.
[6] LexisNexis, Trademark Registrations: Maintenance and Renewal.
Overview of Looming Federal Data Privacy Legislation
The American Data Privacy and Protection Act (ADPPA), H.R. 8152
Executive Summary
The ADPPA would prohibit covered entities from engaging in at least eight practices:
Collecting, processing, or transferring social security numbers, except when necessary;
Transferring geolocation information to a third party;
Collecting, processing, or transferring biometric information;
Transferring any password, except to a designated password manager or if the transfer is solely for the identification of passwords being re-used;
Collecting, processing, or transferring known nonconsensual intimate images;
Collecting, processing, or transferring genetic information;
Transferring an individual’s aggregated internet search or browsing history; and
Transferring an individual’s physical activity information from a smart phone or wearable device.
Most of these restrictions can be waived through affirmative express consent of the consumer. The bill appears to have bi-partisan support yet was unable to pass in 2022. With a divided congress coming, passage may be even less likely in 2023. Yet, hope springs eternal. Many businesses believe that federal legislation would make navigation of U.S. privacy law significantly less complex, while also protecting consumers more effectively.
Background
On July 20, 2022, the House Energy and Commerce Committee voted 53-2 to advance the American Data Privacy and Protection Act (ADPPA), H.R. 8152, to the full House of Representatives. The ADPPA would create a comprehensive federal consumer privacy framework. Some commentators have noted the bill’s novel compromises on two issues that have impeded previous attempts to create a national privacy framework: whether to preempt state privacy laws and whether to create a private right of action. Both of these issues remain hotly contested as the bill moves forward.
Highlights
Covered Entities. The bill would apply to most entities, including nonprofits and common carriers. Some entities, such as those defined as large data holders that meet certain thresholds and service providers that use data on behalf of other entities (including covered entities, government entities, and other service providers), would face different or additional requirements.
Covered Data. The bill would apply to information that “identifies or is linked or reasonably linkable” to an individual.
“Sensitive” Covered Data. The ADPPA would also provide special treatment to “Sensitive” covered data, which includes information such as government-issued ID numbers (e.g., SSN), private communications, information relating to individuals under age seventeen, and several other categories., “Sensitive” covered data would also include several requirements applicable only to “large data holders” (based on revenues or collection/processing activity). General exceptions exist under the ADPPA for certain types of collection, processing, and transfer, as well as for certain smaller entities in terms of revenues or collection/processing activity.
Excluded data. “Covered data” under the proposed ADPPA does not include de-identified data, employee data, or publicly available information. This is significant, especially if federal preemption remains in the bill, as it would render unenforceable all employee-related requirements in the CCPA except for the obligation to maintain reasonable security measures and the private right of action for data breaches.
Duties of Loyalty. The bill would prohibit covered entities from collecting, using, or transferring covered data beyond what is reasonably necessary and proportionate to provide a service requested by the individual, unless the collection, use, or disclosure would fall under one of seventeen permissible purposes. It also would create special protections for certain types of sensitive covered data, defined as covering sixteen different categories of data. Among other things, the bill would require covered entities to get a consumer’s affirmative, express consent before transferring their sensitive covered data to a third party, unless a specific exception applies.
Transparency. The bill would require covered entities to disclose, among other things, the type of data they collect, what they use it for, how long they retain it, and whether they make the data accessible to the People’s Republic of China, Russia, Iran, or North Korea.
Consumer Control and Consent. The bill would give consumers various rights over covered data, including the right to access, correct, and delete their data held by a particular covered entity. It would further require covered entities to give consumers an opportunity to object before the entity transfers their data to a third party or targets advertising toward them.
Youth Protections. The bill would create additional data protections for individuals under age seventeen, including a prohibition on targeted advertising, and would establish a Youth Privacy and Marketing Division at the Federal Trade Commission (FTC). These additional protections would only apply when the covered entity knows the individual in question is under age seventeen, though certain social media companies or large data holders would be deemed to “know” an individual’s age in more circumstances.
Third-Party Collecting Entities. The bill would create specific obligations for third-party collecting entities, which are entities whose main source of revenue comes from processing or transferring data that they do not directly collect from consumers (e.g., data brokers). These entities would have to comply with FTC auditing regulations and, if they collect data above the threshold amount of individuals or devices, would have to register with the FTC. The FTC would establish a searchable registry of third-party collecting entities and a “Do Not Collect” mechanism by which individuals could request that all registered entities refrain from collecting covered data relating to the individual.
Civil Rights and Algorithms. The bill would prohibit most covered entities from using covered data in a way that discriminates on the basis of protected characteristics (such as race, gender, or sexual orientation). It would also require large data holders to conduct algorithm impact assessments. These assessments would need to describe the entity’s steps to mitigate potential harms resulting from its algorithms, among other requirements. The bill would require large data holders to submit these assessments to the FTC and make them available to Congress on request.
Data Security. The bill would require a covered entity to adopt data security practices and procedures that are reasonable in light of the entity’s size and activities. It would authorize the FTC to issue regulations elaborating on these data security requirements.
Small- and Medium-size Businesses. The requirements the bill would impose are significantly reduced for entities that fit certain criteria under what could be considered the “small business exception.” Businesses fall under the ADPPA’s small business exception if, for the prior three calendar years, they
did not exceed $41 million in average annual gross revenues, or
did not collect or process covered data of more than 100,000 individuals on average annually, or
did not derive more than 50% of their revenue from transferring covered data during any of the prior three calendar years.
This would exempt the business from having to respond to any consumer request (such as a request to produce a copy of the consumer’s data) and from having to hire a data security officer or data privacy compliance officer, as well as from other requirements. The proposed bill leaves room for the FTC to issue regulations providing more clarity on the full scope of this exception.
Enforcement. The bill would be enforceable by the FTC, under the agency’s existing enforcement authorities, and by state attorneys general and state privacy authorities in civil actions. The bill also would give the California Privacy Protection Agency authority to enforce the ADPPA in the “same manner it would otherwise enforce” California’s privacy law, the California Consumer Privacy Act (CCPA).
Private right of action. The bill would create a delayed private right of action starting two years after the law’s enactment, giving covered entities lead time to comply. After the two years is up, injured individuals, or classes of individuals, would be able to sue covered entities in federal court for damages, injunctions, litigation costs, and attorneys’ fees. Individuals would have to notify the FTC or their state attorney general before bringing suit. Before bringing a suit for injunctive relief or a suit against a small- or medium-size business, individuals would be required to give the violator an opportunity to address the violation. The bill also would render pre-dispute arbitration agreements or joint-action waivers with individuals under the age of eighteen unenforceable in disputes arising under the ADPAA.
Preemption. The bill would generally preempt any state laws that are “covered by the provisions” of the ADPPA or its regulations, although it would expressly preserve sixteen different categories of state laws, including consumer protection laws of general applicability and data breach notification laws. It would also preserve several specific state laws, such as Illinois’ Biometric Information Privacy Act and Genetic Information Privacy Act and California’s private right of action for victims of data breaches.
NYS Cannabis Delivery Could Be the Pinnacle of Jumpstarting Adult-Use Retail Sales
New York is likely going to see the start of adult-use cannabis retail sales via courier delivery prior to CAURD dispensaries opening their storefront doors.
The Office of Cannabis Management (“OCM”) announced the new retail delivery system during the November 21st Cannabis Control Board meeting. In a statement made to THE CITY, Aaron Ghitelman, a spokesperson for the OCM explained: “We are allowing adult-use retail dispensary non-storefront delivery as a means of jumpstarting adult-use cannabis product sales.”[1]
OCM’s delivery guidelines now permit[2]:
· Retail licenses to secure a warehouse from which to fulfill delivery orders while building permanent dispensary locations for up to one year;
· Customers to place orders online and by phone only – no in-person sales or pick-up from warehouse options available;
· Customers must pre-pay – no cash payments from the cannabis consumer to the delivery employee are permitted;
· Deliveries can be made by bicycles, scooters, or motor vehicles;
· Consumers must be at least 21 years old with valid identification upon sale and delivery;
· Businesses can have up to 25 full-time delivery staff per business, or the hourly equivalent.
See Conditional Adult-Use Retail Dispensary (CAURD) Delivery Guidelines, Office of Cannabis Management, last updated December 9, 2022.[3]
The new delivery guidance loosens the previous rule that required CAURD licensees to receive their storefronts from the State prior to beginning sales. Licensees are now able to acquire their own locations, provided that the location is approved by the State. Guidelines for the way in which these locations will be approved by the State has yet to be released. The very first businesses among the 36 licensed for CAURD dispensaries are expected to begin delivery sales in the coming weeks, as some licensees have already begun lease negotiations for the warehouse needed to make this delivery system a reality.
Some have opined that OCM’s move towards non-storefront delivery is in response to the Dormitory Authority’s struggle to provide license holders with access to real estate and financing.[4] New York State has yet to fulfill the promise of turnkey storefronts and millions of dollars in start-up loans to CAURD license holders. In fact, it has been reported that the State has only contributed $20 million of its $50 million promised to the Social Equity Fund. An additional $150 million is supposed to come from private investors by way of fund-raising steered by the Dormitory Authority in partnership with Social Equity Impact Ventures, a private investment firm. It remains unclear how much money the Social Equity Fund has raised or how many locations the Dormitory Authority has currently leased.
The Dormitory Authority’s struggle may be the “behind the curtain” reason that OCM has chosen to take a step back from their insistence that CAURD licensees receive their fully built retail storefront locations from the Dormitory Authority through the Social Equity Fund. The provisions regarding delivery not only allow licensees to deliver from warehouses, but it allows them the ability to build their own storefront in their own vision, given that the location complies with the coming regulations. In turn, this grant of independence may lessen the financial burden on the Dormitory Authority when they have less licensees needing State-provided retail storefronts.
Licensees embarking on the warehouse delivery grant of independence are facing new obstacles in their hunt for warehouses; few municipalities have yet to tackle the issue of cannabis zoning.[5] Some licensees have been siting warehouses in commercial districts, but commercial districts are insufficient for retail dispensary storefront locations. Not many municipalities have addressed the issue of where these canna-businesses will be housed in the grand scheme of their community, and many municipalities are looking for guidance on the issue. As zoning is left up to the Towns and Villages who opted into dispensaries and/or on-site consumption lounges, counties and the State have been hesitant to direct these smaller municipalities on how to solve the current zoning issues.
Whether the hurdle is completing the application process to receive the final go-ahead from OCM, negotiating a lease for a commercial warehouse to begin your CAURD retail delivery sales, or figuring out how to secure and build your own retail storefront in compliance with the State’s not yet released regulations (as well as your municipalities zoning regulations), professional advice would be of benefit to you. Having an experienced attorney in your corner can provide your business with the knowledge necessary to advance your head start in the legal cannabis industry. Call our office today for help along your canna-business journey!
[1] NYC Legal Weed Delivery Likely Approved Soon by Cannabis Regulator - THE CITY
[2] Marijuana delivery is now permitted in New York: Here’s what you need to know - silive.com
[3] https://cannabis.ny.gov/system/files/documents/2022/12/caurd-delivery-guidance.pdf
[4] New York Loosens Rules on Locations for Weed Dispensaries - The New York Times (nytimes.com)
[5] ‘A way to expedite’: New regulations in NYS to jumpstart retail cannabis | RochesterFirst
Issuance of the CAURD Licenses Enjoined in Five NYS Regions
On November 10, 2022, U.S. District Court Judge Gary L. Sharpe of the New York Northern District granted a preliminary injunction against the State of New York (“NYS”), the N.Y.S. Office of Cannabis Management (“OCM”), and Christopher Alexander as Executive Director of OCM (collectively the “Defendants”), enjoining the Defendants from issuing any cannabis licenses under the CAURD application program in the following geographic areas: Finger Lakes; Central New York; Western New York, Mid-Hudson; and Brooklyn during the pendency of the litigation commenced by Michigan-based Plaintiff, Variscite NY One, Inc., alleging a violation of the Dormant Commerce Clause.
Plaintiff Variscite NY One, Inc. filed a Motion for Preliminary Injunction and Temporary Restraining Order on October 4, 2022 against the Defendants arguing that the CAURD application program discriminates against interstate commerce. The court agreed, finding that the CAURD application requirements, specifically the rule requiring “significant presence” of the applicant in NYS and the rule requiring the justice involved individual have a NYS marijuana-related conviction, will have a discriminatory effect on out-of-state residents seeking a CAURD license.
The Norther District evaluated whether the discriminatory cannabis law was narrowly tailored to advance a legitimate local purpose, as that would allow this challenged law to survive scrutiny. Unfortunately, Defendants failed to make a showing that the challenged law was narrowly tailored. Plaintiff argued and the court agreed that Plaintiff would be irreparably harmed by being excluded from the NYS retail cannabis market, and that even if it could join at a later date, all advantages to early entrants in the market, such as access to customers who have not developed loyalty to other businesses, will have been claimed. Defendants argued that if the injunction is ordered, the 261 already State licensed cannabis cultivators who have already grown cannabis would face spoilation or diversion into the illicit market and would delay the enactment of the Cannabis Law and Regulations which will allow the illicit market to continue to thrive. Despite this, the court found that the Plaintiff would suffer more egregiously in the absence of the injunction as OCM had not yet begun issuing licenses and as they were not enjoined from issuing licenses to the eight other regions in NYS. Finally, the court found that there is no public interest served by maintaining an unconstitutional policy when constitutional alternatives are available to achieve the same goal.
The grant of this preliminary injunction does not enjoin OCM from issuing CAURD licenses in the following districts: Capital Region; Long Island; Manhattan; Mohawk Valley; North Country; Queens; Southern Tier; and Staten Island. In fact, in a Cannabis Control Board Meeting having occurred on November 21, 2022, OCM issued 36 CAURD licenses to applicants within New York City (excluding Brooklyn), Capital Region, Southern Tier, Mohawk Valley, Long Island, and North Country. Although the current litigation blocked the release of 63 CAURD licenses from the enjoined regions, OCM stuck to its word wherein these 36 CAURD dispensaries are projected to open for business before the new year.
In response to the injunction, OCM made its own motion requesting the modification of the preliminary injunction, or in the alternative, requesting a stay of the litigation pending appeal. OCM’s Director of Operations, Herb Barbot, submitted a supplemental declaration alongside the motion, arguing that because the geographic area covered by the injunction includes a significant amount of license applicants, the injunction is doing more harm than good when OCM only considers geographic locations after the applicant’s first choice in limited circumstances. OCM argues that the preliminary injunction should be narrowed to Plaintiff’s first geographic choice only, the Finger Lakes region. Further, OCM claims that the modification of the injunction is necessary to prevent manifest injustice specifically to the cultivators in the Central New York, Western New York, Mid-Hudson, and Brooklyn regions relying on the CAURD program. These cultivators will have immense difficulty selling their retail harvest product with the injunction as it currently stands.
The Plaintiff here has a chance to oppose OCM’s motion, and the Court will then decide whether to limit the preliminary injunction as requested. OCM has made known that if the Court does not modify the injunction, they will be appealing. We are standing by to see how this litigation will affect not only the currently enjoined regions and their CAURD applicants’ access to dispensary licenses, but also the already licensed cultivators and processors looking to pass their cannabis product down an incomplete supply chain. Inevitably, problems for current licensees and CAURD applicants will arise no matter the outcome of this litigation and having a skilled cannabis professional in your corner can make all the difference when navigating licensing obstacles. Give our office a call if you need guidance or support in your cannabis endeavors!
The Biden Announcement and What This Could Mean for Cannabis Nationwide
On October 6, 2022, President Biden announced three steps he is taking to end the government’s failed approach at cannabis reform.[1] First, President Biden pardoned all prior federal offenses of simple possession charges in an effort to help the thousands of people with cannabis convictions who may be denied employment, housing, or educational opportunities as a result. Second, he urges State Governors to take the same pardon action for State based convictions. Third, President Biden asks the Secretary of Health and Human Services and the Attorney General to review how cannabis is federally scheduled.
President Biden pardoning all minor federal cannabis possession convictions is a necessary step to right the wrongs created by President Nixon’s War on Drugs. This is a sign of good faith. It validates all of the prior expungement efforts focused on achieving this redress. The momentum created by this restitution will encourage a new era of acceptance for cannabis.
President Biden’s third step, in asking the Secretary of Health and Human Services to review the federal scheduling of cannabis, raises questions and concerns. Essentially, there are two ways this review could go: (1) cannabis can be re-scheduled, meaning it would be placed in Schedule 2 rather than Schedule 1 of the Controlled Substances Act; or (2) cannabis can be de-scheduled, meaning it is removed from the Controlled Substances Act altogether.
If the Secretary of Health and Human Services returns an opinion that results in cannabis being re-scheduled to Schedule 2 of the Controlled Substances Act, rather than de-scheduled, state-legal businesses would be offered little no relief from their current struggles operating in a legally gray area. Although re-scheduling cannabis is not likely to change the federal government’s tolerance of state-legal recreational cannabis businesses as they currently operate[2], every medical cannabis program would be required to evolve into licensed and regulated pharmacy programs. Dispensaries and other ancillary businesses selling medical product would be required to become a licensed pharmacy under strict DEA scrutiny. Re-scheduling would not eliminate the issues of Section 280E of the federal tax code, nor would it solve the dichotomy between federal and state law as states do not have the authority to establish their own regulatory policies on Schedule 2 substances.[3]
Some people argue that there is an upside to re-scheduling: that businesses would then be able to receive federal funding to conduct cannabis-related research, and they would have access to federal credit, banking, stock market trading, and interstate commerce[4]…but these perks only come with the businesses that applied for and were granted a Schedule 2 license, not state-legal recreational businesses operating in the same legally gray areas they are forcefully subjected to now.
The better option would be for the Secretary of Health and Human Services to return an opinion that encourages the de-scheduling of cannabis. The de-scheduling of cannabis would give cannabis businesses access to federal credit, banking, private research opportunities with federal oversight, and the States would retain their right to control their own cannabis laws. With cannabis de-scheduled, it would be regulated more akin to alcohol and tobacco rather than pharmaceuticals. De-scheduling cannabis would allow private companies to create original and proprietary formulas of cannabis product that could then be legally tested in FDA-approved controlled clinical trials.[5] Most importantly, de-scheduling cannabis solves the discrepancies between federal and state law precluding the current cannabis industry from truly blossoming.
The clear answer here is the one that would remove the federally illegal perimeter around state-legal cannabis businesses without imposing onerous DEA requirements and numerous other hoops to jump through. If we were to see cannabis become a Schedule 2 substance, we may witness an industry striving for equal access become yet another privilege for the wealthy when only the largest cannabis companies have the resources to receive Schedule 2 licensing. The answer is to de-schedule cannabis to create an open market managed by governmental regulation while allowing the current state-legal medical AND recreational cannabis programs to step out of the legally gray area precluding the market from booming.
Only time will tell whether cannabis will be re-scheduled or de-scheduled, and while you are navigating these gray waters that are the current cannabis industry, do so with a skilled professional behind you. Give our office a call if you have any questions regarding what your cannabis-related business can and cannot do in this current legal landscape.
[1] https://www.whitehouse.gov/briefing-room/statements-releases/2022/10/06/statement-from-president-biden-on-marijuana-reform/
[2] https://www.brookings.edu/blog/fixgov/2016/05/27/clearing-up-misconceptions-about-marijuana-rescheduling-what-it-means-for-existing-state-systems/
[3] https://www.wikileaf.com/thestash/cannabis-schedule-2/
[4] https://mjbizdaily.com/pros-and-cons-of-rescheduling-marijuana/
[5] https://norml.org/marijuana/fact-sheets/how-to-end-marijuana-prohibition-with-regard-to-the-controlled-substances-act/#:~:text=By%20contrast%2C%20descheduling%20cannabis%20would,bringing%20such%20products%20to%20market.
What’s Next for Recreational Cannabis and How to Get There Faster
In a valiant effort to fulfill the promise of making legal purchases of cannabis available in New York State before the end of the year, the Cannabis Control Board and the Office of Cannabis Management have instituted surprising temporary emergency measures. Apparently, it takes longer than projected to create a revolutionary road to cannabis legalization designed to serve the individuals harmed and the communities destroyed by discriminatory enforcement of invidious laws.
Although we are celebrating the start of granting licenses for adult use dispensaries to legally sell cannabis, the final steps of opening legal consumer venues, the envisioned results, will not be substantially accomplished until at least mid-2023. In an effort to combat the delay, specific provisions have been implemented for the conditional adult-use cultivator[1] and dispensary licenses. The emergency measures include:
1. Allowing CAURD licensees to depend upon delivery to sell their product before being supplied with their storefronts by DASNY.
2. Directing adult-use cultivators, not just to grow, but to process, distribute and package consumer ready cannabis flower.
The dispensaries and cultivators are asked to follow the processor, distributor, sales, and delivery regulations to the extent possible. This temporary authority will expire on June 30, 2023.
As of November 21, 2022, 277 conditional cultivator licenses have been approved, and as of the same date, only 33 conditional processor licenses have been granted. There are simply not enough licensed processors or available purchase venues. The cultivators, who have additional tasks to perform, need employees to help with processing. Once the full number of CAURD licenses have been issued and there are not enough physical stores, the future store owner will need help making deliveries. The measures taken to reach the goal of legal sale under a revolutionary law are perhaps more difficult to achieve than hoped.
Advisors to justice people seeking priority points on their applications encouraged them to intern, take classes, and seek ways to gain experience. That opportunity still exists. If you are interested in a license or a job related to selling, packaging, processing, or delivering, you should check out some of the licensed cultivators who are surely looking to hire people willing to work for a temporary period, at least until June, or for as long as the emergency licensing systems are in force. A list of the growers and their locations is available here:
There is room for helping and benefiting from MRTA created activities.
[1]Consolidated Laws of New York, Cannabis Chapter 7-A, Article 4, Section 68-C (NYsenate.gov)
The Very First CAURD Licenses Have Been Issued in New York…What’s Next?
During the November 21, 2022, Cannabis Control Board meeting, 37 CAURD license applicants were approved, 29 to justice involved businesses and 8 to non-profit organizations. This is the very first issuance of dispensary licenses in the state, completing the supply chain of legal adult-use cannabis in New York. The State’s Office of Cannabis Management (“OCM”) claims the first adult-use dispensaries will be open for business before the end of the year.
Now, these 37 CAURD licensees will undergo a second application process with OCM and will have to disclose all True Parties of Interest (“TPIs”). TPIs are strictly prohibited from holding any direct or indirect interest in another licensing tier, otherwise known as a vertical ownership restriction.
A TPI in a CAURD license that has equal to or greater than 20% ownership or profit distribution percentage may only have an interest in up to three retail dispensary licenses, a form of horizontal ownership restriction. OCM has defined True Parties of Interest as someone who receives a right to, or actual payment of, either 10% of gross revenues, 50% of net profits, or $100,000 from a licensee over the course of a calendar year. TPI disclosures to OCM require the filing of several forms per TPI, including an entity history disclosure, personal history disclosures for all TPIs within the entity, and a NYS Department of Tax and Finance Clearance Form for each individual and entity TPI.
In the meantime, the NYS Dormitory Authority (“DASNY”) has been working diligently through financing and real estate efforts to secure locations for the very first CAURD licensees. DASNY has already begun negotiating leases and terms with landlords for the state’s very first retail dispensaries. Soon, DASNY will engage with each one of the licensees to secure retail locations and assist with banking. Unfortunately, this aid comes from the Social Equity Cannabis Fund, a fund inaccessible to the non-profit licensees. Non-profit licensees are required to provide their own compliant retail storefronts.
Prior to securing retail storefronts, licensees are permitted to commence delivery sales from a location that has been approved by OCM. This delivery allowance is an effort to jumpstart adult-use cannabis sales in the state. Cannabis cultivators and processors are finally able to move product down the supply chain, and now thanks to this delivery allowance, New York may see its very first legal adult-use retail cannabis sales during the holiday season.
If you are a recent licensee, professional guidance and support in these next steps could be a gamechanger in opening your retail business before the new year. If you are aiming for one of the licenses not yet available (nurseries, cultivators, cooperatives, processors, distributors, microbusiness), adequate preparation can help you get a jumpstart on applying for these licenses when the time comes. OCM recently published its proposed guidelines for these adult-use programs and the Long Law Firm PLLC can help you navigate the process.
The U.S. and the European Union are Further from a Privacy Shield Agreement than Before.
The Supreme Court’s decision in FBI v. Fazaga[1], a case challenging FBI surveillance, will make it significantly harder for people to pursue surveillance cases and for the U.S. and European Union (“E.U.”) negotiators to secure a lasting agreement for transatlantic transfers of private data.
Prior to the Fazaga decision, the European Union’s Court of Justice (“C.J.E.U.”) struck down the U.S.-E.U. Privacy Shield[2], legal guidelines used by thousands of U.S. companies to accomplish data transfers, because the U.S. failed to provide adequate protection for data belonging to people of the E.U. by permitting unjustifiably broad government surveillance and failing to provide proper redress for people of the E.U. whose data was transferred to the U.S. In the strike down of the U.S.-E.U. Privacy Shield, it was made incredibly clear that no data-transfer agreement will survive the C.J.E.U.’s scrutiny until two things take place:
1. The U.S. narrows the scope of its surveillance; and
2. The U.S. ensures that individuals subject to potentially illegal surveillance have a real, meaningful way to pursue accountability.
The Fazaga decision follows from a case wherein an FBI operation sent a paid informant into some of the largest mosques instructed to pose as a convert to Islam while he indiscriminately gathered names, phone numbers, email addresses, and information on each person’s religious and political beliefs of hundreds of Muslim Americans who were exercising their constitutional right to religious freedom. The Supreme Court ruled that the state secrets privilege continues to apply in spying cases, meaning that the government will now have an easier time shielding sensitive information from a court of law with the state secrets privilege, making it even more difficult for people challenging surveillance to prove their claims and obtain justice.
Essentially, the Fazaga decision persists the notion that safeguards for data transfers in the U.S. are inadequate and continuously fail to satisfy the E.U.’s privacy rules, which requires that (1) people must be able to seek redress before an independent decision-maker, (2) the remedies must be binding, and (3) people must be able to raise fundamental legal challenges to the surveillance. Should another proposed privacy agreement be struck down, small and medium-sized companies become at risk as they lack the capital necessary to cover the costs and legal risks associated with data transfers from Europe, yet Congress could prevent this. If Congress were able to establish clear procedures for a court to examine secret evidence in lawsuits challenging illegal spying, then Congress would prevent the government from using the state secrets privilege to frustrate court review in lawsuits going forward and allow citizens proper recourse for unlawful surveillance.[3]
[1] https://www.scotusblog.com/wp-content/uploads/2022/03/20-828.pdf
[2] https://curia.europa.eu/juris/fiche.jsf?id=C%3B311%3B18%3BRP%3B1%3BP%3B1%3BC2018%2F0311%2FJ
[3] https://thehill-com.cdn.ampproject.org/c/s/thehill.com/opinion/judiciary/598899-the-supreme-court-just-made-a-us-eu-privacy-shield-agreement-even-harder?amp
The Russian Cyber War Began Years Ago…
It is extremely important for small businesses and individuals alike take steps towards preventing cyber-attacks. Here is a list of simple measures you can implement to take the target off your back…
In response to Russia’s most recent attempts to dissolve Ukraine, the United States alongside its allies and many other geopolitical actors have taken sudden action to suppress their relations with Russia. These include sanctions limiting the transfer of goods, money, and resources to and from the country. Both as a statement and as an effort to slow down Putin’s agenda, these sanctions are designed to create heavy blows to the Russian economy. However, in a matter of days, Americans have found themselves caught in the crossfire.
Russia is known for its talented hackers, ransomware, and cyber breaching technology. In 2021, it is suggested that 74% of all money made through ransomware attacks went to Russian hackers. Every year the number of these attacks increase, and the Russian attacks on Ukraine have only caused attacks to skyrocket.
According to Stellar Cyber chief technology officer, Aimei Wei: “Immediately after the conflict broke out, suspected Russian-sourced cyber attacks were observed over a 48-our period at an increase of over 800%.”
Who are the hacker’s primary targets? Surprisingly, they are not looking to rob rich CEOs or major governmental organizations. Rather, they target small businesses and average-income earning Americans. Compared to the Fortune 500, small businesses are less likely to protect their software against cyber threats. Their lack of protections makes it easy for hackers to make small profits from a lot of small businesses. By the end of a hacker’s workday, they could make tens of thousands off of unsuspecting businesses.
It is extremely important for small businesses and individuals alike take steps towards preventing cyber-attacks. Here is a list of simple measures you can implement to take the target off your back:
Use multi-factor authentication where you can. The more steps you have to take to log into precious accounts, the more difficult they are to hack.
Download antivirus software.
Educate yourself and your employees/coworkers how to identify scams and security threats. It is safest to be suspicious of unfamiliar emails. Do not open links from unknown senders. If it seems sketchy, it most likely is unsafe!
Back up your devices and files. If your device becomes infected with ransomware, you should be able to restore with a backup.
Keep login credentials secure. Using a password manager can help with that.
As the Russian attacks on Ukraine continue, it would be wise to expect more frequent cyber-attacks from both the Kremlin and patriotic vigilantes. Implement as many precautions as you can, and keep your digital information safe!
Syracuse Startup Podcast - Episode 8
In this episode, I had the good fortune to speak with Kasey Almanzi of Bowers & Company. Kasey is a certified public accountant and a tax supervisor at Bowers & Company, which is a Central New York located accounting firm of approximately 90 accounting professionals…
Episode 8 is up!
In this episode, I had the good fortune to speak with Kasey Almanzi of Bowers & Company. Kasey is a certified public accountant and a tax supervisor at Bowers & Company, which is a Central New York located accounting firm of approximately 90 accounting professionals.
Kasey and I had a great conversation talking about some of the basic taxes issues to think about when starting a business or operating a small startup. I learned a lot myself, and anyone who is just getting started in building a business really needs to listen up here.
Note that there some minor audio quality issues with this recording, as we did the podcast via zoom, and for reasons I never could figure out, I had to use my phone, rather than a computer mic to get it to work. Such is life I suppose.
Anyway, thanks to Kasey for coming on the podcast. I really enjoyed it, and I appreciate the time and effort involved in providing this great tax information.
The podcast can be accessed on our website at https://www.long.law/syracuse-startup, on Spotify at https://open.spotify.com/episode/20xnYODHrReaOQyg5EdvD8?si=a1fab684d1c941a9 , Apple Music, Google, Stitcher or anywhere else you get your podcasts.
Rundown of the Top 15 Cybersecurity Threats of 2019-2020
Every year the European Union Agency for Cybersecurity (ENISA) releases a series of reports itemizing the top cybersecurity threats of the past year. I asked my best people to gather the data and report back with a rundown of the biggest threats.
Every year the European Union Agency for Cybersecurity (ENISA) releases a series of reports itemizing the top cybersecurity threats of the past year. As part of a cybersecurity risk assessment, reports like these are invaluable because they tell us how best to allocate security resources.
In our office, I wanted to organize some of our thinking around the threats identified in the ENISA report.
Me: Hi. I need a rundown of the top threats in the most recent ENISA report, can you get that to me?
Jim: Sure!
Me: Yeah.
Jim: Okay.
“46.5% of all malware in e-mail messages were found in the ‘.docx’ file type.”
I knew this rundown would be helpful to our clients, because the combination of increased capabilities among bad actors along with the coronavirus pandemic together brought significant changes in the cyber threat landscape over the past year. Unfortunately, our reporting on the issue took a little longer than usual as we worked very hard to get this information to you in a useful format for distribution.
“What the hell’s a rundown?”
One of the biggest developments over the year was the marked increase in employees working from home all over the world . The ability to do this was a major component in our economy’s ability to persevere despite brick-and-mortar shutdowns. While working from home, cybersecurity specialists had to adapt existing defenses to new infrastructure, particularly where the entry points were employees’ home networks and devices. In other words, while cybersecurity frameworks, for the last decade, have been trying to increase management of employee devices, suddenly the world’s banks, insurance carriers, and industrial conglomerates were being run off of employees’ unprotected home networks.
“Considering the popularity of Content Management Systems (CMS) among internet users, these systems are an attractive target for malicious actors.”
The landscape was changing quickly, so I needed to get this information out to our clients asap…
Jim: When did you need that rundown by?
Me: As soon as possible.
Jim: Okay.
Me: Just get it right.
Jim: Yeah. Gotcha. Of course. I’m gonna dive in. To the rundown. I’ll be exhausted ’cause it’s like a triathlon. [At door.] Do you want to close this? Close, or keep it?
“ENISA recorded a 667% increase in phishing scams in only 1 month during the COVID-19 pandemic.”
Fortunately, ENISA provided a summary that would make this rundown easier to explain, with ten main trends in the threat landscape over the last year:
The attack surface in cybersecurity continues to expand as we are entering a new phase of the digital transformation.
There will be a new social and economic norm after the COVID-19 pandemic even more dependent on a secure and reliable cyberspace.
The use of social media platforms in targeted attacks is a serious trend and reaches different domains and types of threats.
Finely targeted and persistent attacks on high-value data (e.g. intellectual property and state secrets) are being meticulously planned and executed by state-sponsored actors.
Massively distributed attacks with a short duration and wide impact are used with multiple objectives such as credential theft.
The motivation behind the majority of cyber-attacks is still financial.
Ransomware remains widespread with costly consequences to many organizations.
Still many cybersecurity incidents go unnoticed or take a long time to be detected.
With more security automation, organizations will be invest more in preparedness using Cyber Threat Intelligence as its main capability.
The number of phishing victims continues to grow since it exploits the human dimension being the weakest link
Jim: Hey dude, you know what a “rundown” is?
Oscar: Use it in a sentence.
Jim: “Uh, can you get this rundown for me?” [impersonating me]
Oscar: Try another sentence.
Jim: “This rundown better be really good”?
Oscar: I don’t know but it sounds like the rundown is really important.
Jim: He asked me to do this rundown of the Enisa Top 15.
Oscar: Why don’t you just ask him–
Jim: No. I can’t. It was like, hours ago.
Oscar: What have you been doing?
Kevin: Try it in another sentence.
“The threat landscape is becoming extremely difficult to map. Not only attackers are developing new techniques to evade security systems, but threats are growing in complexity and precision in targeted attacks.”
Because of the increased complexity of cyber threats worldwide, assessments like these are becoming more and more important for businesses trying to address the most likely cyber threats. They are becoming more costly, and in some cases harder to prevent. So I wanted my best people to gather the data and report back with a rundown of the biggest threats.
Me: You started on that rundown yet? [Looks at Jim’s screen.]
Jim: Oh, this is just something I’m taking a break with.
Me: Oh.
Jim: I will get back to the rundown, uh, right now.
Me: Okay, great.
Jim: Hey you know what? Do you have a rundown that I could take a look at, just so I know what type of rundown you’re looking for ?
Me: Just keep it simple.
Jim: Keeping it simple -that’s what I’m doing. But I am working hard on this one. Real hard.
Me: You’re working hard? On this?
Jim: No. Not too hard. Not harder than I should.
After a short delay as we determined to best way to present this information, we were able to assemble ENISA’s Top 15 cybersecurity threats, with executive summaries for each topic. Enjoy!
“46.5%_of all malware in e-mail messages found in ‘.docx’ file type”
ENISA’s Top 15 Security Threats
Malware
Malware is a common type of cyber-attack in the form of malicious software.Families of malware include cryptominers, viruses, ransomware, worms and spyware. Its common objectives are information or identity theft, espionage and service disruption.
During 2019, cryptominers were one of the most prevalent malware family in the threat landscape, resulting in high IT costs, increased electricity consumption and reduced employee productivity. Ransomware presented a slight increase in 2019 compared with 2018, though still remaining at the bottom of the malware type list.
Web and e-mail protocols were the most common initial attack vectors used to spread malware. However, using brute force techniques or exploiting system vulnerabilities, certain malware families were able to spread even further inside a network. Although global detections of attacks have remained at the previous year’s levels, there was a noticeable shift from consumer to business targets.
Web-based Attacks
Web-based attacks are an attractive method by which threat actors can delude victims using web systems and services as the threat vector. This covers a vast attack surface, for instance facilitating malicious URLs or malicious scripts to direct the user or victim to the desired website or downloading malicious content (watering hole attacks1, drive-by attacks) and injecting malicious code into a legitimate but compromised website to steal information (i.e. formjacking) for financial gain, information stealing or even extortion via ransomware. In addition to these examples, internet browser exploits and content management system (CSM) compromises are important vectors observed by different research teams being used by malicious actors.
Brute-force attacks, for example, operate by overwhelming a web application with username and password login attempts. Web-based attacks can affect the availability of web sites, applications and application programming interfaces (APIs), breaching the confidentiality and integrity of data.
Phishing
Phishing is the fraudulent attempt to steal user data such as login credentials, credit card information, or even money using social engineering techniques. This type of attack is usually launched through e-mail messages, appearing to be sent from a reputable source, with the intention of persuading the user to open a malicious attachment or follow a fraudulent URL. A targeted form of phishing called ‘spear phishing’ relies on upfront research on the victims so that the scam appears more authentic, thereby, making it one of the most successful types of attack on enterprises’ networks.
An emotional response justifies many people actions when they are phished and is exactly what hackers are looking for. In a training context, that is what a phishing simulation should try to achieve. Training e-mail users is one of the often used measures for preventing phishing, but results are not convincing since threat actors are constantly changing their modus operandi. The domain-based message authentication, reporting, and conformance (DMARC) standard ensures that e-mail from fraudulent domains is blocked, diminishing the rate of success of phishing, spoofing and spam attacks.
In the future, e-mail continues to be the number one mechanism for phishing but not for long. We are already seeing an increase in the use of social media messaging, WhatsApp and others to conduct attacks. The most relevant change will be in the methods used to send the messages, which will become more sophisticated with the adoption of adversarial Artificial Intelligence (AI) to prepare and send the messages. Phishing and spear phishing are major attack vectors of other threats such as unintentional insider threats
Web application attacks
Web applications and technologies have become a core part of the internet by adopting different uses and functionalities. The increase in the complexity of web application and their widespread services creates challenges in securing them against threats with diverse motivations from financial or reputational damage to the theft of critical or personal information.1Web services and applications depend mostly on databases to store or deliver the required information. SQL Injection (SQLi) type of attacks are a well-known example and the most common threats against to such services. Cross-site scripting (XSS) attacks are another example. In this type of attack, the malicious actor misuses weaknesses in forms or other input functionalities of web applications that leads to other malicious features such as being redirected to a malicious website.
While organizations are becoming proficient and developing more consistent automation in their web application lifecycle, they are demanding security as the most crucial part of their offering and prioritization. This introduction of complex environments drives the adoption of new services such as Application Programming Interfaces (APIs). APIs, which create new challenges for web application security the organizations involved to consider more prevention and detection measures. For instance, roughly 80% of organizations adopting APIs deployed controls on their ingress traffic. In this section, we review the threat landscape of web applications during 2019.
Spam
The first spam message was sent in 1978 by a marketing manager to 393 people via ARPANET. It was an advertising campaign for a new product from the company he worked for, the Digital Equipment Corporation. For those first 393 spammed people it was as annoying as it would be today, regardless of the novelty of the idea. Receiving spam is an inconvenience, but it may also create an opportunity for a malicious actor to steal personal information or install malware. Spam consists of sending unsolicited messages in bulk. It is considered a cybersecurity threat when used as an attack vector to distribute or enable other threats.
Another noteworthy aspect is how spam may sometimes be confused or misclassified as a phishing campaign. The main difference between the two is the fact that phishing is a targeted action using social engineering tactics, actively aiming to steal users’ data. In contrast spam is a tactic for sending unsolicited e-mails to a bulk list. Phishing campaigns can use spam tactics to distribute messages while spam can link the user to a compromised website to install malware and steal personal data.
Spam campaigns, during these last 41 years have taken advantage of many popular global social and sports events such as UEFA Europa League Final, US Open, among others. Even so, nothing compared with the spam activity seen this year with the COVID-19 pandemic.
Denial of service
Distributed Denial of Service (DDoS) attacks are known to occur when users of a system or service are not able to access the relevant information, services or other resources. This stage can be accomplished by exhausting the service or overloading the component of the network infrastructure.1Malicious actors increased the number of attacks by targeting more sectors with different motives. While defense mechanisms and strategies are becoming more robust, malicious actors are also advancing their technical skills. Reports suggest that the usage of reflected and amplified attack techniques facilitating new vectors other than the commonly known ones (UDP amplification etc.) has increased. Malicious actors are also improving their commercial tactics by starting to advertise their services on the web. Historically, DDoS services were advertised in the dark web forums, but now they use common social media channels such as YouTube and Reddit to promote their services.
In 2019, we saw new entries in the top 10 list of source countries generating DDoS traffic (Hong Kong, South Africa, etc.). It was also the year that saw an increase in DDoS activity by botnets. IoT devices are a ‘hotbed’ for DDoS botnets, and China (24%), Brazil (9%) and Iran (6%) were considered as the countries most infected with botnet agents.3A security researcher predicted that, the implementation and distribution of 5G networks will exponentially increase the number of connected devices, hence the expansion of botnet networks.
Although DoS attacks are not new to cybersecurity and network defenders, their level of sophistication is increasing, and malicious actors are observed to be actively running more reconnaissance activities than before.
Identity theft
Identity theft or identify fraud is the illicit use of a victim’s personal identifiable information (PII) by an impostor to impersonate that person and gain a financial advantage and other benefits.
According to an annual security report, at least 900 international cases of identity theft or identity-related crimes were detected. The most significant incidents reported were:
the exposure of nearly 106 million American and Canadian bank customers’ personal information from the Capital One data breach incident in March 2019;
the exposure of 170 million usernames and passwords used by digital game developer Zynga in September 2019;
the stealing of 20 million accounts from the British audio streaming service Mixcloud;
the compromise of 600,000 drivers and 57 million users personal information from Uber’s data breach incident in November 2019;
and the theft of 9 million personal records from EasyJet customers including identity cards and credit cards.
The trend of identity theft is reflected to a great part in data breaches, which, compared with 2018, saw a record number of 3.800 publicly disclosed cases, 4,1 billion records exposed and an increase of 54% in the number of breaches reported.
Data breaches
A data breach is a type of cybersecurity incident in which information (or part of an information system) is accessed without the right authorization, typically with malicious intent, leading to the potential loss or misuse of that information. It also includes ‘human error’ that often happens during the configuration and deployment of certain services and systems, and may result in unintentional exposure of data.
In many cases, companies or organizations are not aware of a data breach happening in their environment because of the sophistication of the attack and sometimes the lack of visibility and classification in their information system. Based on research, it takes approximately 206 days to identify a data breach in an organization. Thus, the time to contain, remediate and recover the data means that it takes longer to return to normal.
Despite all the risks involved, organizations keep even more data4using cloud storage infrastructures and complex on-premises environments. These environments are gradually more exposed to new and different risks, proportional to the sensitiveness of the information stored. It comes as no surprise that, the number of data breaches increased in 2019 and 2020. New findings also suggest that the impact is not felt exclusively when a data breach is discovered -the financial impact can remain for more than 2 years after the initial incident.
Insider threat
An insider threat is an action that may result in an incident, performed by someone or a group of people affiliated with or working for the potential victim. There are several patterns associated with threats from the inside. A well-known insider threat pattern (also known as ‘privilege misuse’) occurs when outsiders collaborate with internal actors to gain unapproved access to assets. Insiders may cause harm unintentionally through carelessness or because of a lack of knowledge. Since these insiders often enjoy trust and privileges, as well as knowledge of the organizational policies, processes and procedures of the organization, it is difficult to distinguish between legitimate, malicious and erroneous access to applications, data and systems.
The five types of insider threat can be defined according to their rationales and objectives:
the careless workers who mishandle data, break use policies and install unauthorized applications;
the inside agents who steal information on behalf of outsiders;
the disgruntled employees who seek to harm their organization;
the malicious insiders who use existing privileges to steal information for personal gain;
the feckless third-parties who compromise security through intelligence, misuse or malicious access to or use of an asset.
All five types of insider threats should be continuously studied, as acknowledging their existence and their modus operandi should define the organization’s strategy for security and data protection.
Botnets
A botnet is a network of connected devices infected by bot malware. These devices are typically used by malicious actors to conduct Distributed Denial of Service (DDoS) attacks. Operating in a peer-to-peer (P2P) mode or from a Command and Control (C2) center, botnets are remotely controlled by a malicious actor to operate in a synchronized way to obtain a certain result.
Technological advancements in distributed computing and automation have created an opportunity for malicious actors to explore new techniques and improve their tools and attack methods. Thanks to this, botnets operate in much more distributed and automated ways and are available from self-service and ready-to-use providers.
Malicious bots, referred as ‘bad bots’, are not only constantly evolving but people’s skill sets and the bots’ level of development are becoming highly specialized in certain applications, such as defense-providers or even evasions techniques. From a different perspective, botnets provide a vector for cyber-criminals to launch various operations from e-banking fraud to ransomware, mining cryptocurrencies and DDoS attacks.
Physical manipulation, damage, theft and loss
Physical tampering, damage, theft and loss has drastically changed in the past few years. The integrity of devices is vital for technology to become mobile and for most implementations of the Internet of Things (IoT). IoT can enhance physical security with more advanced and complex solutions. This way, IP security-based systems with smart sensors, Wi-Fi cameras, smart security lighting, drones and electronic locks can provide surveillance data that are evaluated by Artificial Intelligence (AI) and Machine Learning (ML) mechanisms to identify threats and respond with minimum delay and maximum accuracy.2However, intelligent buildings, mobile devices and smart wearables can be exploited to bypass physical security measures.
In 2019, ATM and POS related physical attacks continued in Europe and worldwide, but the resulting losses were lower than the average over the past decade. The good news is that the companies, IT managers and decision makers are leaning towards hybrid cyber and physical security plans, although in the past physical security was not a priority.
Information leakage
A data breach occurs when data, for which an organization is responsible, is subject to a security incident resulting in a breach of confidentiality, availability or integrity.1A data breach frequently causes an information leakage, which is one of the major cyber threats, covering a wide variety of compromised information from personal identifiable information (PII), financial data stored in IT infrastructures to personal health information (PHI) kept in healthcare providers’ repositories.
When security breaches are encountered in the headlines of bulletins, blogs, newspapers, and technical reports, the focus is mostly either on adversaries or on the catastrophic failure of the cyber-defense processes and techniques. Nevertheless, the indisputable truth is that, despite the impact or scope of such an event, the breach is usually caused by an individual’s action or by an organizational process failure.
Ransomware
Ransomware has become a popular weapon in the hands of malicious actors who try to harm governments, businesses and individuals on a daily basis. In such cases, the ransomware victim may suffer economic losses either by paying the ransom demanded or by paying the cost of recovering from the loss, if they do not comply with the attacker’s demands. In an incident in 2019, Baltimore, Maryland suffered a lockout and recovery is expected to pay US $18.2 million (ca. €15,4 million), although the city refused to pay the ransom. With the growing number of incidents growing, it is evident that becoming a victim is not an ‘if’ but rather a ‘when’ hypothesis. However, in the majority of countries’ fights against ransomware, several challenges need to be addressed, such as the lack of coordination and collaboration between agencies and authorities, and the lack of legislation, that clearly criminalizes ransomware attacks.
Although cyber insurance policies exist since early 2000, ransomware attacks are one of the main reasons for the increased interest in this type of insurance during the last 5 years. In some of the 2019 incidents, the ransom or the costs of recovery was covered by such contracts. Unfortunately, if potential ransomware targets are known to be insured, the attackers assume that they will most probably be paid. Another downside for the victim is that insurance providers are paying the ransom in advance to mitigate the damage and to keep the victim’s reputation intact. However, such compliance by paying ransoms encourages the hacker community and ensures neither the victim’s recovery nor their reputation.
Cyberespionage
Cyber espionage is considered both a threat and a motive in the cybersecurity playbook. It is defined as the use of computer networks to gain illicit access to confidential information, typically that held by a government or other organization.
In 2019, many reports revealed that global organizations consider cyber espionage (or nation-state-sponsored espionage) a growing threat affecting industrial sectors, as well as critical and strategic infrastructures across the world, including government ministries, railways, telecommunication providers, energy companies, hospitals and banks. Cyber espionage focuses on driving geopolitics, and on stealing state and trade secrets, intellectual property rights and proprietary information in strategic fields. It also mobilizes actors from the economy, industry and foreign intelligence services, as well as actors who work on their behalf. In a recent report, threat intelligence analysts were not surprised to learn that 71% of organizations are treating cyber espionage and other threats as a ‘black box’ and are still learning about them.
In 2019, the number of nation-state-sponsored cyber-attacks targeting the economy increased and it is likely to continue this way. In detail, nation-state-sponsored and other adversary-driven attacks on the Industrial Internet of Things (IIoT) are increasing in the utilities, oil and natural gas (ONG), and manufacturing sectors. Furthermore, cyber-attacks conducted by advanced persistent threat (APT) groups indicate that financial attacks are often motivated by espionage. Using tactics, techniques and procedures (TTPs) akin to those of their espionage counterparts, groups such as the Cobalt Group, Carbanak and FIN7 have allegedly been targeting large financial institutions and restaurant chains successfully.
The European Parliament’s Committee of Foreign Affairs called upon Member States to establish a cyber-defense unit and to work together on their common defense. It stated that ‘the Union’s strategic environment has been deteriorating ... in order to face the multiple challenges that directly or indirectly affect the security of its Member States and its citizens; whereas issues that affect the security of EU citizens include: armed conflicts immediately to the east and south of the European continent and fragile states; terrorism –and in particular Jihadism –, cyber-attacks and disinformation campaigns; foreign interference in European political and electoral processes’.
Threat actors motivated by financial, political, or ideological gain will increasingly focus attacks on supplier networks with weak cybersecurity programs. Cyber espionage adversaries have slowly shifted their attack patterns to exploiting third-and fourth-party supply chain partners.
Crytojacking
Cryptojacking(also known as cryptomining) is the unauthorized use of a device’s resources to mine cryptocurrencies. Targets include any connected device, such as computers and mobile phones; however, cybercriminals have been increasingly targeting cloud infrastructures. This type of attack has not attracted much attention from law enforcement agencies and its abuse is rarely reported, mainly because of its relatively few negative consequences. Nevertheless, organizations may notice higher IT costs, degraded computer components, increased electricity consumption and reduced employee productivity caused by slower workstations.
Jim: There’s the rundown you asked for. I may have expanded some areas that you weren’t prepared for.
Charles: Great. Fax that to everyone on the distribution list.
Jim: Yeah sure. You want to look at it first?
Charles: Do I need to?
Jim: No. No, I just wanted to make sure, it was in the same format. So that distribution list is gonna be my…?
Charles: What’s that?
Jim: The one I have. I’ll use the one I have.