• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

Cybersecurity

Article 08.26.2024 Autumn Hines

In the digital age, where data drives much of our daily lives, protecting consumer privacy has become paramount. With the introduction of the Kentucky Consumer Data Privacy Act (KCDPA), the state takes a significant step towards safeguarding the personal information of its residents. This act, akin to similar legislation emerging across the United States, reflects a growing recognition of the importance of privacy in the digital economy. Let’s delve into the key aspects and implications of the KCDPA.

What is the Kentucky Consumer Data Privacy Act?

Enacted to enhance consumer privacy rights, the KCDPA empowers Kentucky residents with greater control over their personal data. Signed into law on April 4, 2024, and set to take effect on January 1, 2026, the act imposes obligations on businesses handling consumer data, outlining transparency requirements, data access provisions, and guidelines for data processing practices

Scope

  • control or process personal data of at least 100,000 Kentucky consumers; or
  • control or process personal data of at least 25,000 Kentucky consumers and derive over 50% of gross revenue
    from the “sale” of personal data

Exemptions in the KCDPA

  • Regulated Industries:
    • Certain industries are subject to existing federal or state privacy regulations that preempt the application of the KCDPA.
    • For example, healthcare providers or business associates governed by HIPAA or financial institutions regulated by GLBA are exempt from provisions of the KCDPA.
  • Entity Types:
    • Certain entity exemptions commonly seen in other state privacy laws exist.
    • For example, any city, state agency, or political subdivision of the state; nonprofit organizations; higher education institutions; certain entities collecting data for specific law enforcement activities; first responders in connection with catastrophic events; and small telephone or municipally owned utilities.
  • Data Types:
    • Certain data are exempt.
    • For example, protected health information and various other health-related data, certain types of consumer reporting data, data regulated by the Family Educational Rights and Privacy Act, and emergency contact information of an individual used for emergency contact purposes.

Key Provisions

  • Consumer Rights:
    • Under the KCDPA, consumers have the right to request disclosure of what personal data businesses collect about them.
    • Consumers have the right to request correction of inaccuracies in the consumer’s personal data.
    • Consumers are entitled to request deletion of their data.
    • Consumers may obtain a copy of their personal data in a readily usable format for transmission to another business.
    • Consumers may opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.
  • Transparency Requirements
    • Covered businesses must disclose their data collection and processing practices, including the purposes for
      which data is used.
    • They must notify consumers about their privacy rights and how to exercise them.
  • Data Processing Restrictions:
    • The act imposes limitations on how businesses handle sensitive personal information, such as health or financial
      data.
    • It prohibits businesses from processing data in ways that would discriminate against consumers.
  • Data Security Measures:
    • Covered businesses are required to implement reasonable security measures to safeguard consumer data from
      breaches or unauthorized access.
  • Enforcement and Compliance:
    • The Kentucky Attorney General is tasked with enforcing the KCDPA, with penalties for non-compliance.

Implications for Businesses

  • Compliance Burden:
    • Businesses must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data.
    • Businesses must provide consumers with a reasonably accessible, clear, and meaningful privacy notice that includes the categories of personal data processed, the purpose for processing personal data, how consumers may exercise their consumer rights, the categories of personal data that the controller shares with third parties, and the categories of third parties, if any, with whom the controller shares personal data.
    • Consumer requests must be responded to within 45 days of the request. The act provides guidelines for extensions and refusal to respond.
    • Businesses must establish a process for consumers to submit requests and appeal refusals to respond. This process must be conspicuously available.
    • Information provided to a consumer must be free of charge, up to twice annually per consumer.
    • Businesses must conduct and document a data protection impact assessment of processing personal data for the following activities: targeted advertising, selling personal data, profiling, processing sensitive data, and any processing that presents a heightened risk of harm to consumers.
  • Data Responsibility:
    • Limit the collection of personal data to what is adequate, relevant, and reasonably necessary.
    • Do not process personal data for purposes that are neither reasonably necessary nor compatible with the disclosed purposes.
    • Do not process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers.
    • Do not process sensitive data concerning a consumer without obtaining the consumer’s consent.
  • Legal and Compliance Risks:
    • The Attorney General may request a data protection risk assessment to evaluate its effectiveness.
    • The Attorney General has exclusive authority to enforce violations of this Act. This can include prosecuting any violations.
    • The Attorney General may demand any information, documentary material, or physical evidence from any controller or processor believed to be engaged in or about to engage in any violation.
    • Businesses may receive a written notice from the Attorney General when a violation is noticed. If the violation is remediated within thirty days, no action for damages will be initiated.
    • If violations are not remediated within thirty days, The Attorney General may initiate an action to seek damages for up to $7,500 for each continued violation.
    • The Attorney General may recover reasonable expenses incurred in investigating and preparing the case, court costs, attorney’s fees, and any other relief ordered by the court of any action initiated

Implications for Compliance

  • Assessment and Documentation:
    • Businesses must carefully assess whether they fall within any of the exempt categories outlined in the KCDPA.
    • Documenting the basis for exemptions and ensuring compliance with other privacy laws are essential steps in the compliance process.
  • Risk Mitigation
    • While exemptions provide relief from certain compliance obligations, they also introduce potential risks, such as reputational harm or legal challenges.
    • Businesses should conduct thorough risk assessments to evaluate the implications of relying on exemptions and implement appropriate risk mitigation strategies.
  • Transparency and Consumer Communication:
    • Even when exemptions apply, businesses should maintain transparency and communicate clearly with consumers about their data processing practices.
    • Providing accessible privacy notices and mechanisms for consumers to exercise their rights remains essential for building trust and accountability.

Navigating Complexity

As businesses adapt to the evolving privacy landscape, proactive compliance efforts, robust risk management practices, and transparent communication with consumers are critical for success. By embracing privacy as a fundamental value and integrating it into their operations, businesses can navigate the complexities of the KCDPA while fostering trust and loyalty among their customer base.

Looking Ahead

The passage of the Kentucky Consumer Data Privacy Act reflects a broader trend toward enhanced consumer privacy protections at the state level. As more states consider similar legislation, businesses face a complex regulatory landscape that demands proactive compliance measures.
Moving forward, businesses must prioritize privacy as a fundamental aspect of their operations, integrating privacy by design principles into their products and services. By prioritizing transparency, accountability, and consumer empowerment, businesses can navigate the evolving privacy landscape while building trust and loyalty among their customer base.
In conclusion, the Kentucky Consumer Data Privacy Act represents a significant milestone in the journey toward empowering consumers and enhancing privacy protections in the digital age. By embracing the principles outlined in the act, businesses can not only comply with regulatory requirements but also foster a culture of privacy and trust in their interactions with consumers.

Filed Under: Cybersecurity Tagged With: Cybersecurity, Technology

Article 07.19.2024 Autumn Hines

Business email compromise (BEC) attacks are on the rise. In 2023, IC3, the Internet Crime Complaint Center, reported receiving approximately 21,000 reports of business email compromises from organizations. The organizations reported $2.9 billion in losses from these attacks. Business email compromises are big business for cyber-criminals, often resulting in hefty losses, whether reputational or financial. So, how are cyber-criminals getting to the business emails?

What to Know About AitM Attacks

A newer acronym has entered the chat in the acronym-happy landscape of cybersecurity: Adversary-in-the-middle, or AitM, for short. Adversary-in-the-middle attacks allow a threat actor to trick users into entering their credentials and multi-factor authentication into a site they control and relay that information to the legitimate email provider in real-time.

This allows the threat actor to steal the session token for the user and log in until that token expires (which is 90 days for refresh by default for Microsoft, by the way). From there, the threat actor can log in as the user and take any actions on behalf of the compromised user. The ease of this attack is compounded by the fact that there are publicly available tools on GitHub that allow a threat actor to quickly spin up the tooling to use. All they need at that point is a registered domain for the landing page.

Standard multi-factor authentication (MFA) implementations (SMS, push notification, number challenge, etc.) are also no match for this threat. If the user enters their password and accepts the push, for example, the threat actor will then have access to their account in real time. Microsoft has posted an excellent article regarding this threat, which can be found here.

How You Can Combat AitM Attacks

An organization can choose from several options to protect itself and its assets from these threats. This should be considered a layered model in which organizations attempt to use as many as possible to provide in-depth defense.

  1. Utilize phish-resistant MFA. Phish-resistant MFA utilizes certificates or hardware-based tokens (YubiKey, for example) to ensure that even if a threat actor convinced an end user to provide their password, they could not capture the multi-factor prompt and gain a session token for the user. See this article from our catalog for more information on why common MFA methods are not enough to cure all cyber ailments.
  2. If using Microsoft Entra, utilize conditional access policies to enforce trusted authentication. This means that users can only log in from Entra-joined devices. This ensures that if a threat actor gains access to the session token, they cannot use it because it does not originate from a joined device in the tenant. This is a very effective control to use.
  3. Leverage end-user awareness training to ensure users are aware of these threats. The biggest indicator is threat actors will often use standard phishing schemes, such as an invoice, to convince the user to click it and enter credentials. Educate users not to trust these emails by default and be mindful of the web page. If the URL appears off when prompting for your credentials, exit the web page and report it to your security team.
  4. Utilize strong email security filtering to prevent phishing emails from reaching the inbox. A strong email filter will recognize the attempt and, ideally, hold the email in quarantine.
  5. Utilize security monitoring. Monitor your tenant for suspicious sign-ins and set up alerts to notify people who can respond. Organizations should seek out solutions that can automate these steps. If the solution determines an account to be compromised, alert it, send notifications, and take proactive steps to disable it so that a threat actor cannot begin to conduct nefarious activities. Microsoft refers to this in their platform as Attack Disruption.

All of these steps will help protect your organization from threats. You are the first line of defense for your organization. Be cautious and be cyber-aware. For more information, contact Dean Dorton to help with your security needs.

Filed Under: Cybersecurity Tagged With: Cybersecurity, Technology

Article 05.6.2024 Autumn Hines

Data privacy and security have never been more important in a digital age where information flows freely. Despite warnings as recently as 2023 to enhance and bolster cybersecurity defenses, ransomware attacks continue resulting in significant operational impact to all sectors of healthcare.

Recently, two major healthcare providers, Kaiser Permanente and City of Hope, found themselves in the spotlight regarding data privacy concerns. Let’s delve into what transpired and how these organizations responded.

Kaiser Permanente

Kaiser Permanente apologized to its vast network of 13.4 million members after discovering that certain search information may have inadvertently been shared with external platforms, including Google and social media sites. The company attributed this data transmission to previous online technologies installed on its websites and apps. While the shared information did not include sensitive details like usernames or financial information, it did encompass IP addresses, usernames, indications of account activity, and health-related search terms.

Upon identifying the issue, Kaiser Permanente promptly removed the problematic technologies from its online platforms and assured members that there had been no reported instances of personal information misuse. Nevertheless, the organization took proactive measures by informing all affected members, both current and former, about the incident. Additionally, they expressed regret for the oversight and outlined steps, guided by experts, to prevent similar incidents in the future.

City of Hope

In a parallel scenario, City of Hope, another healthcare provider, faced a data breach affecting its members. The breach, which took place between September 19 and October 12, 2023, involved unauthorized access to a plethora of member information, ranging from email addresses to sensitive data like Social Security numbers and medical records.

City of Hope responded swiftly upon discovering the breach, implementing mitigation measures, and bolstering security protocols with the assistance of cybersecurity experts. Furthermore, they extended a gesture of goodwill to affected members by offering two years of free identity monitoring services. In tandem with this, they promptly notified relevant authorities, including law enforcement and regulatory bodies, and launched an internal investigation into the incident to ascertain its scope and impact.

Cybersecurity is an urgent issue in healthcare, but the risk is growing exponentially, and it’s poised to keep rising with no signs of stopping. Consequently, the expansive landscape of healthcare creates additional vulnerabilities where data attackers can outpace your organization, disrupting patient care. What steps is your organization taking to prepare?

Contact Dean Dorton for expertise in healthcare, cybersecurity, and the dynamic place where they intersect.

Filed Under: Cybersecurity, Healthcare, Technology Tagged With: Cybersecurity, Healthcare IT, Technology

Article 10.23.2023 Dean Dorton

Explore the latest insights that can reshape your business’s approach to cybersecurity disclosure and gain a deeper understanding of how the evolving landscape of cybersecurity disclosure impacts privately owned businesses.

1. Identify Gaps in SEC’s Proposed Disclosure Requirements

  • First, analyze the differences between what the SEC is suggesting for disclosures and what your company currently does.
  • Assign responsibility for making the necessary improvements.

2. Integrate Disclosure Processes

  • Avoid the mistake of creating a new, complex process. Instead, figure out how your cybersecurity practices can be seamlessly incorporated into your existing disclosure procedures.
  • Identify the people who need to be involved, including legal experts.

3. Update Incident Management Process

  • Adapt your incident management procedures to account for factors like the significance of the event and continuous reporting and monitoring.
  • Ensure consistency in how you determine what is significant and how you disclose cybersecurity incidents, similar to how you handle operational or financial issues.

4. Engage Board of Directors Early

  • Start a dialogue with your board of directors about the new disclosure requirements.
  • Collaborate to identify any changes in governance that may be necessary.

5. Leverage Technology

  • Invest in the right technology tools that can help streamline your disclosure processes and communication.
  • This could be a single, all-in-one solution or a combination of individual tools that work together effectively.

Companies must take cybersecurity more seriously than ever before after a new rule passed by the SEC.

Have questions? Reach out today!

Filed Under: Cybersecurity, Services, Technology Tagged With: Cybersecurity, Tech

Article 08.22.2023 Dean Dorton

Public companies must prepare to meet higher standards for cybersecurity.

The SEC recently issued a rule requiring public companies to disclose when they fall victim to a material cyber attack. Companies will also have to file annual disclosures about their cybersecurity risk profile.

As cyber attacks become more common and costly, it’s important for businesses to be forthcoming about their cyber risk. This fact along with inconsistent public company reporting of cyber events compelled the SEC to mandate public companies to disclose material attacks in Form 8-K filings within 4 days of the incident being discovered along with a better appreciation of the company’s cyber risk environment.

What Requirements are in the New Rule?

The requirements fall into two categories:

  • Incident Disclosure – Within 4 days of a cybersecurity incident being discovered that has a “material” impact, companies must report what happened, when/how it was discovered, who was affected and how, and what remediation is underway, among other details. All this information enters the public record.
  • Yearly Reporting – Once a year, companies must file a Form 10-K report outlining their cybersecurity risk assessment program, highlighting how it aligns with strategy and planning, and what third party experts it includes.

What Does This Mean for Public Companies?

Many companies already disclose breaches and report on their security environment but not to the level the SEC expects for proper investor evaluation.

The new SEC rule will require all companies to act quickly in the wake of a cyber incident. Gathering the required information within a four-day window means starting immediately after discovery and working methodically from there. Companies will need to assess whether they have the staff and tools to understand incidents in a matter of days. Investing the time now in developing a cyber incident policy is paramount.

Closely related, companies will need to review their entire approach to cyber risk before, during, and after an attack. Reporting on cybersecurity activities will be the easy part. Much harder will be managing cyber risk effectively, month after month, even as new threats and vulnerabilities emerge.

The new SEC rule means new compliance and reporting requirements which require immediate attention.

How Do You Become Compliant?

The first step will be to perform a gap analysis between current practices and those required by the SEC. That will, in most cases, be followed by a systematic effort to close gaps. Otherwise, companies expose themselves to compliance penalties, legal action, and reputational damage—not to mention increased exposure to cyber attacks.

Public registrants will need to comply with the new annual disclosures for fiscal years ending after December 15, 2023, excluding small reporting companies that have until fiscal years ending after December 15, 2024. Incident reporting will be effective 90 days after the date of publication in the Federal Register or December 18, 2023 (later of). For small reporting companies 270 days after publication in the Federal Register or June 15, 2024 (later of).

Beyond just boosting cybersecurity, companies will need to rethink how cyber risk affects every facet of the organization. The team at Dean Dorton, with expertise spanning from cybersecurity to board oversight, is your resource for getting the new SEC rule right.

The deadline for compliance is fast approaching. Contact Dean Dorton to put a plan in place.

Filed Under: Cybersecurity, Services, Technology Tagged With: Cybersecurity, Tech

Article 08.9.2023 Dean Dorton

What is Juice Jacking?

Juice jacking is when bad actors place a corrupted USB port in a public location, such as an airport or coffee shop with the goal of an unknowing person plugging their cable into it to charge their phone. The port is then used to install malware on the device and steal personal information. In terms of implementation, this type of attack is fairly easy to execute.

Charging kiosks in the era of smartphones have become commonplace in public locations. This is another prime example of hacker using legitimate, everyday technology for nefarious intent. While the attacks thus far have not been common, it is anticipated that these sorts of attacks will increase over the next few years.

How to Protect Yourself

Situational awareness is imperative in cases such as this.

If public USB ports are your only option, be sure to inspect the port prior to plugging in a cable. If it appears off, do not use it. The Federal Communications Commission also said, “If you plug your device into a USB port and a prompt appears asking you to select ‘share data’ or ‘trust this computer’ or ‘charge only,’ [you should] always select ‘charge only.'” Experts also recommend using a USB write blocker. This prevents threat actors from passing any data over USB.

However, the safest option is to avoid public USB ports altogether. If you are anticipating that your device will need to be charged, bring your own charger and plug it in directly to a power outlet or portable charger.

Further Steps

To learn more about cyber threats facing your organization, contact Dean Dorton today.

And for more information on juice jacking, here are some helpful articles:

Traveling? This $7 gadget protects your phone from treacherous USB charging ports

FBI office warns against using public phone charging stations at airports or malls citing malware risk

Filed Under: Cybersecurity, Services, Technology Tagged With: Cybersecurity, Tech

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Interim pages omitted …
  • Page 8
  • Go to Next Page »
  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved