All Articles

8/21/2023 Compliance

New York State DFS 500 Compliance Framework and Technology Mapping for AWS deployments

Digital Edge’s NYS DFS 500 Financial Services Security and Compliance Framework includes our DFS Reference Architecture which specifically guides customers in their AWS deployments and addresses the new requirements that have become a part of the NYS DFS 500 Law. 

 

6/28/2023 Compliance

Notes For Automating Compliance With NYS DFS 500 in AWS

The current cybersecurity laws and regulations landscape is complex and burdensome. Public cloud providers are trying to help automate and offload the weight of program implementation but there is still a long way to go.
New York State DFS introduced its 23 NYCRR 500 regulation that requires implementation of cybersecurity requirements for all covered entities.
 
Digital Edge’s team, backed by our legal, cybersecurity and heavy AWS expertise has analyzed DFS requirements and possible AWS implementation automation suggestions.
 
Download the DFS 500 PDF with highlights and comments that include the joint work of our team.

1/24/2023 Case Studies

teamDigital partners with third-party MSSP, Digital Edge to implement ISO 27001

teamDigital needed to implement an updated management system for governance of information security. They needed a partner to implement ISO 27001, the leading international standard for information security 

1/24/2023 Case Studies

An AWS web hosting solution provides increased reliability and response times for this digital e-commerce platform

The client was using a web hosting solution that was problematic and did not offer good response times.  As an online company and digital platform the client needed a highly reliable web hosting solution that could be both flexible and scalable, they also needed a managed services partner who could provide software support 24/7 and dev-ops for troubleshooting. The platform was being used by their client base mostly on evenings and weekends so a pay as you go pricing model would offer the best solution.

1/24/2023 Case Studies

A Global Fintech engages Digital Edge for Cloud Modernization, Governance and Compliance

Digital Edge pivoted to work with the client to organize and streamline their AWS accounts.  Digital Edge also implemented data governance with rules of engagement and cloud modernization strategies leveraging the AWS Account Factory program.  By leveraging the Account Factory program they could help their client increase speed to market and delivery for their users. By  leveraging “best practices” around an AWS SaaS solution they could also improve their client’s security posture and compliance.

 

12/20/2022 Compliance

The California Privacy Rights Act (CPRA) has been pushed back to April 2023.

The California Privacy Rights Act (CPRA), slotted to go into effect January 1, 2023 has had a recent change.  The California Privacy Protection Agency Executive Director, Askan Solitani, recently announced in a 12/16 board meeting that release of the final rules of the CPRA will be pushed back to April, 2023, leaving a 3 month gap between the regulations effective date and publication of it's rule requirements.

11/21/2022 Case Studies

Case Study- Global Fintech client requires cloud modernization strategy for acceleration and enhanced value to their financial customer base

Digital Edge delivers a digital transformation strategy for global fintech client to re-engineer their existing on-premise IT infrastructure and provide the client with Cloud modernization, acceleration and further transparency they were seeking for internal teams. 

10/31/2022 Case Studies

Case Study - Fund Count, a Boston based Fintech gains edge with modernization of their IT Infrastructure

 

Fund Count was seeking greater flexibility to their on-premise colocation solution and wanted an alternative deployment option for their customers that could reduce lengthy deployment times.  Digital Edge proposed a hybrid solution that would work alongside Fund Count’s on-premise, client private hosted cloud application,  proposing an AWS - Software-as-a Service (SaaS) option.  

 

 

 

10/25/2022 Compliance

“The California CPRA Privacy Law is Coming for You this January”

Does your company do any business with California residents or businesses? Do you have even one employee in California? Do you generate $25 million or more in gross revenue?  Are you a service provider or contractor for a California based company that is subject to the GDPR?

If so, you should know by now that in a mere 2 ½ months the “California Privacy Rights Act” (CPRA) enforcement will begin, and with it some much-expanded privacy rights of California residents, and some much-expanded privacy obligations for businesses. 

Background:

The CPRA is the most robust consumer privacy law in the United States. In November 2020, California voters approved the California Privacy Rights Act of 2020, otherwise known as the CPRA. This is an amendment to the California Consumer Privacy Act (CCPA) that voters approved in 2018. 

The CPRA has now modified, expanded, and clarified privacy rights for California residents, and it takes inspiration from the EU’s GDPR policy in a variety of ways. For instance, the CPRA creates a new enforcement agency. Previously the CCPA was enforced by the California Office of the Attorney General. However, in the EU, GDPR is enforced by data protection authorities –– and now, California has implemented one, too: the California Privacy Protection Agency (CPPA). 

Purpose:

CPRA’s purpose is to redefine and expand the California Consumer Privacy Act (CCPA) in order to strengthen the rights of residents of California. It provides consumers greater opportunity to opt out and requires deliberate data privacy management from businesses.

California has made it clear that they are serious. These rights can and will be enforced by private citizens, all California district attorneys, and the newly created “California Privacy Protection Agency” mentioned above and created solely to enforce privacy laws.

What are these rights?

The CPRA expands and amends the previous California privacy laws. Taken together they consist of the following bundle of privacy rights:

  1. Right to Access personal information.
  2. Right to Delete personal information.
  3. Right to Correct personal information.
  4. Right to Object to Selling personal information.
  5. Right to Opt-Out of behavioral profiling and automated decision making.
  6. Right to Object to the Use of Sensitive Information.
  7. Right to Data Portability.

But that’s not all:

  1. Purpose Limitation – Personal information can only be used for the purpose it was originally collected.
  2. Children’s Data – Fines are now tripled for violating the privacy rights of children under 16.
  3. Storage Limitation – Personal information must be destroyed once it has been used for its purpose at collection.
  4. *Reasonable Cybersecurity Controls – Security controls must be commensurate with the sensitivity of the data you are protecting. This part by itself is just as big an undertaking as complying with the rest of the CPRA.

What are the penalties? 

$2,000 per offense for mistakes, $2,500 per offense for negligent mistakes, and $7,500 per offense for intentional offenses.

Please be aware – These offenses are accumulative and every California resident impacted by the same event will constitute a separate offence.

This can mean fines well into the millions of dollars

So far, under the CCPA (the current main California Privacy law) there has been numerous private settlements reaching into the millions of dollars including a recent one for $10 million - and just this past August Sephora was fined $1.2 million by the California Attorney General.

Becoming compliant with the CPRA is not an easy task, you will need to find out where every bit of personal data comes from and how it is handled. Then you will need to figure out how to actually comply with the law which will take policies and procedures and technical implementations. We at Digital Edge are experts in compliance and can assist you in developing a strategy and plan to ensure your business is protected and align with the January 2023 deadlines.

For more information contact sales@digitaledge.net

 

9/16/2022 Edgy News

Digital Edge Achieves Level 1 Managed Security Service Provider Competency Status

New York, NY, Sept. 08, 2022 (GLOBE NEWSWIRE) -- Digital Edge announced today that it has achieved Amazon Web Services (AWS) Level 1 Managed Security Service Provider (MSSP) Competency status.  This designation recognizes that Digital Edge has successfully met AWS requirements for a baseline of managed security services to protect and monitor essential AWS resources 24/7, known as Level 1 Managed Security Services.

This new baseline standard of quality for managed services was introduced by AWS to benefit cloud environments of any size and it spans six security domains: vulnerability management, cloud security best practices and compliance, threat detection and response, network security, host and endpoint security, and application security. The six domains contain multiple MSSP services, each with technical skill set and operational process requirements specific to AWS.

AWS launched the AWS Level 1 MSSP Competency program to enable customers to easily acquire ongoing security monitoring and management, validated by AWS. AWS security experts annually validate the tools used and operational processes of each MSSP to address specific cloud security challenges such as continuous event monitoring, triaging, AWS service configuration best practices, and 24/7 incident response. The AWS Level 1 MSSP Competency provides a faster and easier experience for customers to select the right MSSP to help them achieve their goals for business risk and cloud strategy confidence.

Achieving the AWS Level 1 MSSP Competency differentiates Digital Edge as an MSSP and AWS Partner with essential 24/7 managed cloud security skill sets to earn the distinction of Level 1 MSSP.

“ We are thrilled to have achieved AWS Level 1 MSSP Competency. With AWS, we seamlessly provide our clients flexible, scalable, and cost-effective cloud solutions that modernize their IT infrastructure. Our comprehensive cybersecurity offerings ensure our client solutions are compliant with frameworks and meet the certification requirements,”  says Mike Petrov, Chief Executive Officer, Digital Edge.

As an AWS Level 1 MSSP competency-approved and AWS Advanced Technology Partner, Digital Edge has developed a comprehensive cybersecurity offering for AWS customers.  The firm employs a core team of strategic cybersecurity experts who have expertise with the following compliance certifications: NIST, CSF Core, IS0 2700, SSAE18/SOC2, PCI, HITRUST, OSPAR. 

Digital Edge provides 24/7/365 managed service solutions allowing AWS customers to accelerate their organizational growth and business value in the cloud without sacrificing security. Digital Edge also monitors and secures AWS infrastructure in conjunction with existing IT security teams and externally.

 About Digital Edge

Digital Edge brings together a unique combination of talent, partners and products to support digital transformation for start-ups to enterprise wide organizations.  Digital Edge serves the Banking, Fintech, Media, and IT sector with mission-critical expertise in security, networking, data center, collaboration and cloud solutions.  Learn more at www.digitaledge.net. 

 

Amazon Web Services Partner Network