Anthony Feldmann
Research Mentor: Cindy Schipani
Mentor Department: Business Law, Business
Author(s): Not Available
Session: Session 4 (1:00 PM – 1:50 PM)
Presentation Type: Poster 10
Abstract
With technology constantly progressing and new software coming out day after day, the question of cybersecurity in both personal and professional settings naturally comes into play. Many large-scale companies, like TransUnion, have suffered cybersecurity breaches affecting millions of customers and costing them a fortune. This research documents recent breaches to figure out what went wrong and how companies chose to respond to these catastrophes. Additionally, this study analyzed how developing artificial intelligence can be used as both a tool and a weapon in the field of cybersecurity. While AI based defense tools were able to catch and fix zero-day exploits before humans ever could, it is currently very vulnerable to exploits from outside sources, making it very risky to implement in a professional setting. Along with this, this research additionally addresses laws enacted to deal with these issues, and how states and countries are working to regulate a constantly changing field. Unfortunately, in the global landscape, laws and amendments regarding cybersecurity cannot seem to keep up, leading to contradictions and legal nightmares for companies. States like Illinois require an established retention and destruction plan “within 3 years of the individual’s last interaction with the private entity†to satisfy section 14 of their Biometric Information Privacy Act.(BIPA) Meanwhile, New York requires companies to look at historical data when conducting their bias audits (New York City Administrative Code § 20-870 et seq), data which would need to be deleted to comply with Illinois’ BIPA. Thus leaving companies unable to comply with both laws. All this coupled with the uncertainty of what is to come next in the cybersecurity field consistently puts companies in hot water and deep financial trouble, struggling to account for both the legality and technical aspects of cybersecurity. Thankfully, however, the research proves that steps can be made to make this complex field a little easier for everyone.


