BreachExchange mailing list archives

Incident Response: How BB&T Handles Client Notification After a Breach (fwd)


From: security curmudgeon <jericho () attrition org>
Date: Tue, 7 Apr 2009 08:31:47 +0000 (UTC)



---------- Forwarded message ----------
From: InfoSec News <alerts () infosecnews org>

http://www.bankinfosecurity.com/articles.php?art_id=1350

By Tom Field
Editorial Director
Bank Infosecurity
April 6, 2009

What happens after a major security breach? How do banking institutions go 
about notifying their customers - whose responsibility is it?

At BB&T in Winston-Salem, NC, the role is filled by Dick Langford, Vice 
President and Manager, Information Security Compliance Management. In an 
exclusive interview, Langford discusses:

* How BB&T approaches client notification;

* Lessons learned from security breach response;

* The different ways the bank approaches customer awareness to meet all
   customers' needs.

Langford has 19 years experience in information protection in the 
financial sector. Previously with the Federal Reserve Bank of Kansas City, 
he has managed elements of BB&T's information protection program since 
1998. His current responsibility is directing a network of over 100 
Information Security Compliance Managers representing each line of 
business, subsidiary, and affiliate company in BB&T Corporation, thereby 
ensuring compliance with federal and state information protection 
legislation and regulations.

BB&T Corporation, headquartered in Winston-Salem, N.C. , is among the 
nation's top financial holding companies with $152 billion in assets. Its 
bank subsidiaries operate approximately 1,500 financial centers in the 
Carolinas, Virginia, West Virginia, Kentucky, Georgia, Maryland, 
Tennessee, Florida, Alabama, Indiana and Washington, D.C.

[..]
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss


Current thread: