Results for

Sort by:
  • Blog
    March 20, 2019
    What is important to the business community with the advent of the California Consumer Privacy Act (CCPA), which goes into effect on January 1, 2020? At a recent California Consumer Privacy Act rulemaking workshop held by the California Department of Justice (DOJ), the constant refrain from attendees was for the California Attorney General to offer clarity and guidance on the anticipated impact…
  • Blog
    March 26, 2019
    Every week seems to introduce new developments with the California Consumer Privacy Act (CCPA) either from consumer concerns, business compliance and/or how the California Attorney General (AG) will handle enforcement. One notion is clear; companies must have an operationalized privacy program in place to demonstrate compliance. Doing nothing will give rise to risks of litigation and enforcement…
  • Blog
    April 17, 2019
    According to the recent survey conducted by North Carolina State University’s ERM Initiative and Protiviti (2019 Executive Perspectives on Top Risks), C-suite executives and board members continue to view cyberthreats as a top risk behind the risks of competing against “born digital” firms, retaining top talent, and regulatory changes. Additionally, these leaders continue to view identity…
  • Blog
    April 24, 2019
    Two proposed amendments to the California Consumer Privacy Act (CCPA) are sure to generate mixed reactions if either passes. The first would expand individual consumer rights while the second modifies the definition of “consumer” to exclude California employees as consumers under a separate amendment, if passed. The CCPA will affect any business collecting or storing data about California…
  • Blog
    May 3, 2017
    The UK Financial Conduct Authority (FCA) has issued its annual business plan for fiscal year 2017-2018. The FCA is the conduct regulator for 56,000 financial services firms and financial markets in the UK and the prudential regulator for over 18,000 of those firms. Its annual business plan and mission statement gives firms and consumers greater clarity about how the regulator intends to…
  • Blog
    May 5, 2017
    Last month, in New York City, Protiviti hosted a gathering of scores of financial service industry representatives to discuss the recently enacted New York Department of Financial Services’ (DFS) Part 500, Cybersecurity Requirements For Financial Services Companies. Similar in design to the previously enacted DFS Part 504, Transaction Monitoring and Filtering Program Requirements and…
  • Blog
    May 8, 2017
    With increasing demands for broader, more accurate and more efficient risk assurance, internal audit departments have officially entered the age of analytics. According to Protiviti’s 2017 Internal Audit Capabilities and Needs Survey, two thirds of internal audit functions have begun using data analytics on at least a limited basis, with two-thirds of the remaining respondents indicating that…
  • Blog
    May 9, 2017
    Adaptability has always been critical to retail success. But in the digital era, where disruptive change is constant, many retailers find it difficult to evolve fast enough to remain competitive — let alone relevant. That is especially true for companies burdened by the weight of legacy business models, inefficient back-office processes and outdated technology infrastructure. A proof point: The…
  • Blog
    May 12, 2017
    I recently had the honor of attending the ISACA’s 2017 North America CACS Conference in Las Vegas, where I discussed how the Internet of Things (IoT) continues to transform the mission of IT auditors. The IoT is a perfect example of an all-around disruptor, including in IT audit departments, as businesses collect, analyze and act on data captured outside of the traditional IT boundaries. As a…
  • Blog
    May 15, 2017
    Less than a month ago, my colleague Adam Brand talked about the need to include ransomware in the cybersecurity repertoire of companies, emphasizing a business outcome-driven approach to cybersecurity, rather than a narrow-focused sensitive data perspective. Last Friday’s global ransomware attack brought this message home with a bang. The wide-spread attack struck hospitals, companies and…