Friday, April 28, 2023

Five Eyes Issues Guidance for the Deployment of “Smart City” Technologies

 Privacy Plus+

Privacy, Technology and Perspective

Five Eyes Issues Guidance for the Deployment of “Smart City” Technologies.  This week, we welcome new “smart city” cybersecurity guidance issued by the Five Eyes intelligence alliance, which consists of Australia, Canada, New Zealand, the United Kingdom, and the United States.  For our municipal clients (and for vendors who provide these technologies), this guidance is as long overdue as it is important.

Background: The term “smart cities” refers to communities that:

  • ·        Integrate information and communications technologies (ICT), community-wide data, and intelligent solutions to digitally transform infrastructure and optimize governance in response to citizens’ needs; and

  • ·       Connect the operational technology (OT) managing physical infrastructure with networks and applications that collect and analyze data using ICT components—such as internet of things (IoT) devices, cloud computing, artificial intelligence (AI), and 5G.

“Smart city” technologies include interconnected networks, sensors, and advanced analytics that manage various aspects of city life, from traffic and waste management to public safety and energy consumption. Many communities and commercial developments have deployed these technologies in an effort to improve the quality of life for their citizens, enhance public services, and create more efficient urban environments (think of parking and urban-transit planning, to name just two examples).

But smart city technologies are accompanied by substantial cybersecurity risks, and specifically introduce “potential vulnerabilities that, if exploited, could impact national security, economic security, public health and safety, and critical infrastructure operations.”

Don’t just take our word for it. The preceding quote appears on page 4 of the new Five Eyes guidance, which is available for you to read by clicking on the following link:

https://www.cyber.gov.au/sites/default/files/2023-04/Joint-guidance-cybersecurity-best-practices-for-smart-cities.pdf

Here are more details:

Five Eyes’ Guidance: On April 19, 2023, Five Eyes issued its “Cybersecurity Best Practices for Smart Cities.”  The guidance aims to help governments, city planners, and technology partners build secure, resilient, and privacy-respecting smart cities. Generally, the guidance highlights the risks to “smart cities” and makes recommendations.

Smart City Risks. Summarized, the guidance identifies key smart city risks, including the creation of an expanded and interconnected attack surface, and the potential loss of visibility into components owned and operated by vendors.  The guidance notes that communities that deploy such technologies may find it difficult to maintain awareness and control of their evolving network topology.  Additional risks include those presented by automating critical operations (e.g. wastewater treatment), and poor security practices associated with the supply chain and vendors. These can lead to disruption of availability in operational technology, network failures, theft of data and intellectual property, and worse.

Recommendations.  The guidance suggests the following recommendations:

  1. Secure planning and design: Communities should be strategic and exercise “proactive cybersecurity risk management processes in their plans and designs for integrating smart city technologies into their infrastructure systems.”  This means assessing the risks associated with deploying smart city technologies and prioritizing mitigations based on potential consequences before deploying such technologies. Secure planning and design should focus on accounting for both physical and cyber risk as the cyber-physical environment converge.  Organizations should ensure that Information Technology (IT) and OT security issues are adequately considered and addressed

  2. Prioritize cybersecurity and data privacy: The guidance specifically encourages organizations implementing smart city technologies to take some prescriptive cybersecurity and privacy steps, including:

    • ·       Applying the principle of least privilege throughout their network environments,

    • ·       Utilizing and enforcing multi-factor authentication,

    • ·       Implementing zero trust network design principles,

    • ·       Maintaining awareness of changes to network architecture,

    • ·       Securely managing smart city assets, including sensors and monitors,

    • ·       Protecting internet-facing services and devices by securing remote access,

    • ·       Timely patching apps and systems, and

    • ·       Reviewing the legal, security, and privacy risks associated with deployments.

  3. Proactive Supply Chain Risk Management: The guidance encourages communities to gain and maintain control of their supply chains, recognizing that “a vulnerable…supply chain could allow the degradation or disruption of infrastructure operations and the compromise or theft of sensitive data from utility operations, emergency service communications, or visual surveillance technologies…” and that “smart city IT vendors may also have access to vast amounts of sensitive data from multiple communities to support the integration of infrastructure services—including sensitive government information and personally identifiable information (PII)—which would be an attractive target for malicious actors.” The guidance therefore encourages procurement officials to establish minimum security requirements and controls for vendors, and to require vendors to be transparent with how their systems will collect and process data. The guidance further urges that product vendors should assume some of the risk associated with their products, and develop their technologies in adherence to secure-by-design and secure-by-default principles.  Additionally, it prescribes due diligence on hardware and IoT device components, and appropriate contracting that includes organizational security standards with all vendors, including managed service and cloud service providers.

  4. Ensuring Operational Resilience.  The guidance also suggests that deployments of smart city technologies need a back-up plan if the technologies fail, and particularly have manual operations of all critical infrastructure functions. Staff should also be trained accordingly, and incident response and recovery plans should be robust.

Our thoughts:

Lower Cost, Higher Risk. Many “smart city technology” vendors pitch to cities not only the benefits to the cities, but a high value for a low, low cost, offering discounts or even free installations in return for being able to sell advertising. Nirvana! This is obviously eye-grabbing to city planners and department heads who are watching their budgets. But selling advertising requires more and better surveillance, in order to gather potential-customer data to sell to advertisers or data brokers (or to real estate agents, brokers, or developers). This raises a host of data-privacy issues across an increasing number of states and even nationally (FTC).

What about the Data? “Smart city” vendors may amass, sell, and otherwise leverage data associated with the technologies, unless specifically restricted by contract, then monitored regularly.  This means that communities that consider deploying these technologies need to be particularly sensitive to data issues.  Yet, anecdotally, we have noticed that the backgrounds of lawyers who run “smart city” deals often consider data issues only tangentially, if at all. This is a huge mistake, especially at a time when vendors everywhere are chasing additional revenue streams. If left unrestricted, vendors may sell the data to data brokers or chase the AI “Golden Goose” by “decanting” the data into huge vats of data from other sources – namely, the “training sets” for AI models, which are being created by AI developers and perhaps even the smart city vendors themselves. See above – then take the existing complexity and risk, and multiply it.

Here, Security Breaches may Mean Literal Danger.  More, better, and interconnected surveillance over where you live, drive, or ride (and when you leave), where and when you park, when you leave work (and walk to the parking lot in the dark), etc., would strike many people as creepy – and dangerous – enough. (The Drivers’ Privacy Protection Act and state analogues, inspired from stalking incidents, already exist for a reason. We think their concepts should be expanded to exploitation of “smart city” data.)

No matter how snazzy it is and how free it sounds, “smart city” technology must be secured like the critical-infrastructure technology it often is.  We’ve already seen oil-rig technology penetrated, water-dam controls hijacked, and more, often by indirect attacks through innocent-looking controls that are interconnected with larger ones. (Remember the Target stores breach, years ago? Hackers gained entry through the controls to a Target building’s smart HVAC system.)  We emphatically do not need hackers taking control of – for example – light-rail streetcars, running through downtown cities.

If You’re Already “Smart,” revisit your deployments, and particularly scrutinize the contracts, components, system access and data use rights associated with those technologies. If you’re hungry for progress, take the necessary steps in order to be ready for the attendant risks.

Hosch & Morris, PLLC is a boutique law firm dedicated to data privacy and protection, cybersecurity, the Internet and technology. Open the Future℠.



from Texas Bar Today https://ift.tt/74zUSds
via Abogado Aly Website

Wednesday, April 26, 2023

Rules Are Rules

Badger Tavern LP v. City of Dallas

Dallas Court of Appeals, No. 05-23-00299-CV (April 20, 2023)
Chief Justice Burns (opinion available here) and Justices Molberg and Goldstein

The
rules authorizing interlocutory appeals are strictly construed—really strictly.
Rule 168 requires that a court’s permission to appeal an otherwise unappealable
order “must be stated in the appealed order.” In this case, the trial court
denied a Rule 91a motion to dismiss and then later signed a separate order
granting permission to appeal that denial. The Dallas Court of Appeals, relying
on the plain language of the rule and similar cases out of other jurisdictions,
dismissed the appeal. It held: “[b]ecause the trial court did not sign a single
order that both denied appellants’ rule 91a motion to dismiss and granted
permission to appeal the order, this Court has no jurisdiction over this
appeal.”



from Texas Bar Today https://ift.tt/Sgi7tsG
via Abogado Aly Website

Thursday, April 20, 2023

Modifying your Texas Divorce Decree is Not a Do-it-Yourself Project

Avoiding the courts may seem like a simple solution to modifying your Texas divorce decree, but it can create a more complex case than taking proper legal avenues from the start.

The post Modifying your Texas Divorce Decree is Not a Do-it-Yourself Project appeared first on Goranson Bain Ausley.



from Texas Bar Today https://ift.tt/o3QqmHW
via Abogado Aly Website

Wednesday, April 19, 2023

Insurance Coverage Not Limited by a Texas Service Agreement

As you negotiate your master service agreements are you confident that you know how insurance choices might affect indemnity obligations? Me neither. That’s why I turn to my Gray Reed partner Darin Brooks and his insurance coverage lawyers. I didn’t consult them about this post so all errors are on me, not them.

A basic principle of Texas insurance law is that a separate contract may be incorporated by reference into an insurance policy only if that reference is clearly manifested in the terms of the policy itself.  A court will consult the separate contract only to the extent that the policy requires it.

The question in Exxon Mobil v. National Union Fire Insurance Company was whether an insurance policy incorporated payout limits in an underlying service agreement. It did not.

The facts

Savage Refinery Services was an independent contractor at the Exxon refinery in Baytown. In the service agreement Savage promised to obtain at least a minimum stated amount of liability insurance for its employees and to name Exxon as an additional insured. Fulfilling its obligation, Savage procured five different insurance policies. Two Savage employees were severely burned in a workplace accident, sued Exxon for compensation for their injuries, and settled for $24 million. $5 million was paid from Savage’s primary insurance policies. National denied Exxon coverage under an umbrella policy. Exxon sued for breach of contract.

Summary judgments were heard on the question of Exxon’s status as an insured under the umbrella policy and whether the Exxon-Savage service agreement otherwise limited Exxon’s entitlement to further policy proceeds.

The Court’s reasoning

The policies defined “Insured” as “any person or organization, other than the Named Insured, included as an additional insured under Scheduled Underlying Insurance, but not for broader coverage than would be afforded by the Scheduled Underlying Insurance.”

The first question was easily resolved: National had recognized Exxon as an additional insured under its primary policy. The primary policy was incorporated for the limited purpose of identifying who was an insured.

The real inquiry was invited by the umbrella policy’s reference to the primary policy. The umbrella policy disclaimed “broader coverage” than what the primary policy offered. Exxon was not demanding broader coverage. It sought only the same coverage as the primary policy but at the umbrella policy’s higher limits because the primary policies had been exhausted.

National Union argued that the limit on “broader coverage” invoked payout limits of the service agreement, but the umbrella policy did not say anything about the service agreement’s payout limits.

To the extent it could read the umbrella policy to reference the service agreement, the Court found no limits that the umbrella policy could adopt. The primary policy had its own payout limits, which was the very reason that the parties needed an umbrella policy. Interpreting “broader coverage” to refer to payout limits would give the umbrella policy a self-defeating meaning.  An umbrella policy springs into action only when the primary policy is exhausted. To conclude that “broader coverage” referred to payout limits could be the result only if the language the parties use clearly required it. There was no such language here.

The Court considered conventional usage of the words “coverage” and “umbrella insurance”. The former contemplated the risks covered, the latter was triggered only by reason of the limits under other policies. Coverage does not include payout limits in this context. The umbrella policies provide greater limits for risks already covered by primary policies.

The Court of Appeals’ decision in National’s favor was reversed and the case remanded.

Your musical interludes, sponsored by GM … and Ford



from Texas Bar Today https://ift.tt/8U6txsN
via Abogado Aly Website

Monday, April 17, 2023

What is The Frozen Embryo Law In Texas?

Modern reproductive technology has in recent years helped many parents who would have otherwise had difficulty having children. For example, in vitro fertilization is often effective for those who want to be parents but cannot do so through traditional means. The in vitro process involves harvesting mature eggs from the female and fertilizing them in the lab. Thereafter, they are often frozen to be used later.

However, a couple may divorce before the frozen eggs are used, and questions arise about what to do with the eggs or who owns them. This is why some Texas courts have addressed the matter recently. Our Dallas divorce lawyers at Orsinger, Nelson, Downing, & Anderson can help with questions about this and other divorce-related issues.

How Texas Views Frozen Embryos

Laws about frozen embryos in Texas view the matter from a contractual point of view to decide who owned the frozen eggs before the couple divorced. When a couple decides to freeze embryos, they must sign a contract detailing how the embryos are owned in the event of a divorce. The document must be signed at the fertility center or in front of an attorney.

Laws in this area stem from a case that eventually made it to a Texas Court of Appeals. It involved a couple who filed for divorce before their frozen embryos were implanted. The contract signed by the couple stated that the embryos had to be thrown out if they divorced. The Court of Appeals ruled that the contract had to be followed; the embryos should be destroyed.

While this would seem to resolve the issue, there are still uncertainties in specific situations involving frozen embryos today. Depending on the circumstances, Texas legal experts say a court could rule on frozen embryo ownership during a divorce as follows:

  • If the couple does not have an agreement that states what happens to the embryos after divorce, the court would not force one person to be a parent if they do not want it.
  • If the couple has an agreement and the embryos go to one person, the Court could disregard it so one person is not forced to have children they do not want.
  • If they agree that the embryos must be donated to another couple or for scientific research, the court could disregard it with additional conditions so one party is not forced to be a parent when they do not want it.

Are You Planning To Freeze Embryos?

If you and your spouse want to freeze embryos for later use, there are steps you can take now to reduce the chances of future disagreements.

First, before freezing the embryos talk about all of the possibilities with your partner. For example, talk about who would take possession of the embryos in case of divorce or what you would do with them if that happened. It may not be the most comfortable conversation, but it can avoid future complications by having a frank discussion now.

Second, check the policies of the fertility clinic you intend to use; different clinics may view this matter in different ways. You may want to choose a different clinic if the policies of one do not meet your expectations.

Third, talk to an experienced family law or divorce lawyer to help you determine how to handle the frozen embryo ownership. Planning in case of divorce, especially with such a potentially contentious topic, in this area is critical to ensure your rights and wishes are respected.

Contact Our Dallas Divorce Lawyers Today

If you have questions about divorce or how the Texas embryo laws affect you during or after a divorce, we understand your concerns. Our Dallas divorce lawyers at Orsinger, Nelson, Downing, & Anderson can help, so call (214) 273-2400.

The post What is The Frozen Embryo Law In Texas? appeared first on ONDA Family Law.



from Texas Bar Today https://ift.tt/YdaLiXE
via Abogado Aly Website

Copyright Discovery

A copyright action is governed by a three-year statute of limitations. In Martinelli v. Hearst Newspapers, LLC, the Fifth Circuit confirmed that recent Supreme Court decisions did not overruled Circuit precedent that applies a discovery rule to that statute. No. 22-2033 (April 13, 2023).

The post Copyright Discovery appeared first on 600 Camp.



from Texas Bar Today https://ift.tt/f7cGBwj
via Abogado Aly Website

Friday, April 14, 2023

Mediation Reminders

When preparing for mediation, attorneys and clients often are focused on the “mechanics of the deal.” However, all too often a successful strategy that is well implemented leading to an apparent “good deal” is circumvented as the result of mistakes in the closing of the deal.

The post Mediation Reminders appeared first on Goranson Bain Ausley.



from Texas Bar Today https://ift.tt/WxZpKYJ
via Abogado Aly Website