MikeFleming
04-13-2014, 02:42 PM
--Judge Denies Wyndham Motion to Dismiss FTC Suit
(April 8, 2014)
A US District Court judge has dismissed Wyndham Hotels request to dismiss an FTC lawsuit, supporting the Federal Trade Commission's (FTC's) authority to sue companies that do not adequately protect customer data. That power was being challenged by Wyndham, which maintained that the FTC was overreaching its authority when it filed a lawsuit against the hotel chain for failing to safeguard customer information. The FTC maintains it has the authority to sue companies for inadequate customer data protection because Congress granted it the power to enforce "unfair" business practices. The FTC's original lawsuit alleged that Wyndham had failed to employ even basic security measures, like firewalls and separating networks. Due to the lack of security, thieves accessed Wyndham's system though a network in a hotel in Phoenix and stole 500,000 payment card numbers. Wyndham maintained that inadequate data protection does not fall under the heading of unfair business practices.
http://www.scmagazine.com/judge-denies-wyndham-motion-challenging-ftc-authority/article/341862/
http://www.nextgov.com/cybersecurity/2014/04/court-upholds-ftcs-power-sue-hacked-companies/82084/?oref=ng-channelriver
Denial of Motion to Dismiss:
http://media.scmagazine.com/documents/67/ftc-wyndham_opinion_16575.pdf
[Editor's Note (Pescatore): This is the third recent ruling that validated the FTC's authority in this area. Part of the FTC definition of "unfair business practices" are those that cause unjustified injury to consumers that they could not avoid on their own - having your identity stolen via sloppy security practices seems to fit that definition pretty well. This is also an areas where focusing on the Critical Security Controls to prioritize remediation would easily avoid such FTC actions.]
(April 8, 2014)
A US District Court judge has dismissed Wyndham Hotels request to dismiss an FTC lawsuit, supporting the Federal Trade Commission's (FTC's) authority to sue companies that do not adequately protect customer data. That power was being challenged by Wyndham, which maintained that the FTC was overreaching its authority when it filed a lawsuit against the hotel chain for failing to safeguard customer information. The FTC maintains it has the authority to sue companies for inadequate customer data protection because Congress granted it the power to enforce "unfair" business practices. The FTC's original lawsuit alleged that Wyndham had failed to employ even basic security measures, like firewalls and separating networks. Due to the lack of security, thieves accessed Wyndham's system though a network in a hotel in Phoenix and stole 500,000 payment card numbers. Wyndham maintained that inadequate data protection does not fall under the heading of unfair business practices.
http://www.scmagazine.com/judge-denies-wyndham-motion-challenging-ftc-authority/article/341862/
http://www.nextgov.com/cybersecurity/2014/04/court-upholds-ftcs-power-sue-hacked-companies/82084/?oref=ng-channelriver
Denial of Motion to Dismiss:
http://media.scmagazine.com/documents/67/ftc-wyndham_opinion_16575.pdf
[Editor's Note (Pescatore): This is the third recent ruling that validated the FTC's authority in this area. Part of the FTC definition of "unfair business practices" are those that cause unjustified injury to consumers that they could not avoid on their own - having your identity stolen via sloppy security practices seems to fit that definition pretty well. This is also an areas where focusing on the Critical Security Controls to prioritize remediation would easily avoid such FTC actions.]