Five Stories That Matter in Michigan This Week – March 28, 2025

  1. FinCEN Update: U.S. Companies No Longer Needed to Report

On Friday, March 21, 2025, the Financial Crimes Enforcement Network (FinCEN) issued an interim final rule regarding the Corporate Transparency Act (CTA), revising the definition of “reporting company” such that entities formed under the laws of any U.S. State or Tribal jurisdiction likely will not have to file a beneficial owner information report (BOIR).

Why it Matters: Through this interim final rule, all entities created in the United States, including those previously known as “domestic reporting companies,” and their beneficial owners will be exempt from the requirement to report BOI to FinCEN. Read more.

———

  1. U.S. Court of Appeals Rules on AI-Generated Copyright Eligibility

On March 18, 2025, the U.S. Court of Appeals for the District of Columbia Circuit issued a decision for Thaler v. Perlmutter, which addressed whether a work created autonomously by artificial intelligence (AI) is eligible for copyright protection.

Why it Matters: This case reaffirms the prevailing legal principle that copyright protection is reserved for works created by humans. As AI continues to evolve, questions about the extent of human involvement necessary for copyright eligibility remain open for future consideration. ​ Indeed, the question will be directly addressed in the upcoming case in Allen v. Perlmutter in the District Court of Colorado. Read more.

———

  1. Michigan CRA Publishes February ’25 Data: Average Price Decreases

Per data released by the Cannabis Regulatory Agency (CRA), the average retail price for adult-use sale of an ounce of cannabis in February 2025 was $65.21, a decrease from $66.50 in January 2025. This is a decrease from February 2024, where the average price was $91.94.

Why it Matters: While the prices of cannabis and cannabis-related products continue to decrease and make consumers happy, growers on the other hand are seeing profits decrease resulting in them seeking ways to halt new licenses to be granted in an effort to steady prices.

———

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the April Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

———

  1. Elizabeth M. Siefker Selected as a Member of Michigan Lawyers Weekly “Up & Coming Lawyers Class of 2025”

Fraser Trebilcock attorney ​Elizabeth M. Siefker has been selected as a member of Michigan Lawyers Weekly’s “Up & Coming Lawy​ers Class of 2025.” This special award recognizes those who have excelled in the profession and are standouts among their peers — all in their first 10 years of practice.

Why it Matters: Ms. Siefker focuses her practice on estate planning, elder law, guardianships and conservatorships, probate litigation, and tax planning. With experience assisting clients in every aspect of the estate planning process, she understands that each plan will be unique to the client’s situation. Ms. Siefker is included in Super Lawyers® as a “Michigan Rising Star” in Estate & Probate, and received the American Jurisprudence Award for civil procedure, contracts, first amendment, and torts. She is an active member of several legal organizations, having previously served on the Board of Directors of the Women Lawyers Association of Mid-Michigan as the Regional Representative. Read more.

Related Practice Groups and Professionals

Business & Tax | Robert D. Burgee
Intellectual Property | Andrew Martin
Cannabis Law | Sean Gallagher
Elizabeth Siefker

Five Stories That Matter in Michigan This Week – March 21, 2025

  1. Corporate Transparency Act BOI Reporting Requirements Deadline is Here

Friday, March 21, 2025, is the deadline for most reporting companies to file their beneficial ownership information (BOI) reports as required by FinCEN under the Corporate Transparency Act (CTA).

Why it Matters: While there is pending legislation that would delay the enforcement of the CTA until January 1, 2026, companies should adhere to the reporting requirements now to avoid any fines or penalties. Contact your Fraser Trebilcock attorney if you have any questions or need assistance.

———

  1. Elizabeth M. Siefker Selected as a Member of Michigan Lawyers Weekly “Up & Coming Lawyers Class of 2025”

Fraser Trebilcock attorney ​Elizabeth M. Siefker has been selected as a member of Michigan Lawyers Weekly’s “Up & Coming Lawy​ers Class of 2025.” This special award recognizes those who have excelled in the profession and are standouts among their peers — all in their first 10 years of practice.

Why it Matters: Ms. Siefker focuses her practice on estate planning, elder law, guardianships and conservatorships, probate litigation, and tax planning. With experience assisting clients in every aspect of the estate planning process, she understands that each plan will be unique to the client’s situation. Ms. Siefker is included in Super Lawyers® as a “Michigan Rising Star” in Estate & Probate, and received the American Jurisprudence Award for civil procedure, contracts, first amendment, and torts. She is an active member of several legal organizations, having previously served on the Board of Directors of the Women Lawyers Association of Mid-Michigan as the Regional Representative. Read more.

———

  1. Michigan Cannabis Industry Faces Price Pressure Despite High Sales Volume

According to the Michigan Cannabis Regulatory Agency, Michigan cannabis sales reached $241.3 million in February, down 7.6% year-over-year, with adult-use sales decreasing 4.7% to $246.6 million while medical sales fell 71.1% to just $0.6 million. The average flower price hit a new low of $1,043 per pound, falling 29.1% from last year and 2.0% from January.

Why it Matters: While Michigan’s cannabis market maintains substantial sales volume (despite a slight 3.0% decline in early 2025), the continuing downward trend in prices is creating significant profitability challenges for industry operators. Expanding supply and competition are forcing cannabis businesses to adapt to thinner margins and more challenging business conditions.

———

  1. Michigan Supreme Court Upholds Victory for Firm’s Client

Fraser Trebilcock attorneys Michael P. Donnelly and Laura S. Faussié successfully represented a fiber optic company before the Michigan Supreme Court. On January 24, 2025, the Court, after hearing oral argument from the parties, denied an application for leave to appeal in a case involving the firm’s client, a fiber optic company, effectively upholding the lower courts’ decisions in the client’s favor. The case addressed whether a fiber optic or other telecommunication company was required to obtain permission from, and pay large fees to, a railroad company before installing fiber optic cables under their tracks located at public crossings.

Why it Matters: In a 5-1 decision, with one justice not participating, the Supreme Court left in place the Michigan Court of Appeals’ ruling that the fiber optic company could proceed with installing underground cables beneath railroad tracks at public road crossings after obtaining necessary municipal permits, without requiring additional permission from or fees to the railroad company. Read more.

———

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the April Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

Related Practice Groups and Professionals

Business & Tax | Robert D. Burgee
Elizabeth Siefker
Cannabis Law | Sean Gallagher
Litigation | Michael Donnelly
Litigation | Laura Faussié

Five Stories That Matter in Michigan This Week – March 7, 2025

  1. CTA Update: Treasury Department Issues Statement

The United States Treasury Department recently issued a statement casting doubt on the future enforceability of the Corporate Transparency Act (CTA), at least in its current form. This is particularly relevant for US entities owned by US citizens. While not legally binding, Treasury’s guidance strongly signals that the rules enacting the CTA are likely to be rescinded or significantly revised before implementation. FinCEN has previously announced its intention to issue revised rules and updated reporting deadlines by March 21, 2025.

Why it Matters: Businesses that have already implemented CTA compliance processes, are advised to continue those efforts to ensure ongoing compliance. This recommendation remains in effect until FinCEN issues a new final rule or the law is formally amended. Read more from your Fraser Trebilcock attorney.

———

  1. Whitmer Proposes New Wholesale Tax on Marijuana Products in Road Funding Plan

Governor Whitmer’s $3 billion “MI Road Ahead Plan” proposes closing an alleged “loophole” by imposing a new wholesale tax on marijuana products, similar to taxes on tobacco, potentially generating $470 million for road repairs.

Why it Matters: While details remain scarce about what specific “loophole” is being addressed or how the tax would be structured and implemented, marijuana businesses in Michigan should stay apprised of new developments regarding this proposed tax.

——–

  1. Fraser Trebilcock Welcomes Dakota A. Larson to the Firm

We are pleased to announce the hiring of Dakota A. Larson who will primarily work in the firm’s Lansing office.

Why it Matters: Ms. Larson focuses on insurance defense and business matters. She has experience handling complex liability, coverage, and bad faith claims in multiple lines of insurance and in multiple jurisdictions. Learn more.

———

  1. Keep Your Michigan Cottage in the Family

The family cottage is a place for fun and relaxation in Michigan. For many, the family cottage becomes the meeting place for generations and where lifelong memories are made. As a result, it’s often the intent of the owner to pass the cottage on to future generations to enjoy. Unfortunately, challenges such as high property taxes and family disputes can prevent that from happening. These obstacles can be overcome through careful cottage succession planning.

Why it Matters: If you own a cottage in Michigan, our Cottage Law team can help you think through the issues and take the actions necessary to create a cottage plan. A cottage plan usually addresses the concerns through the creative use of a limited liability company (LLC) or a trust to own the property. Learn more.

——–

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the April Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

Related Practice Groups and Professionals

Business & Tax | Robert D. Burgee
Cannabis Law | Sean Gallagher
Dakota Larson
Cottage Law | Mark Kellogg

Five Stories That Matter in Michigan This Week – February 21, 2025

  1. Governor Whitmer Signs ESTA Bills Into Law

This morning, Michigan Governor Whitmer signed bills HB 4002 and SB 8, which amended the Earned Sick Time Act (ESTA) and the tipped minimum wage law standards that were set to go into effect February 21, 2025.

Why it Matters: Employers with 11 employees or more must offer 72 hours of paid sick leave, employers with 10 or fewer employees must offer 40 hours of paid sick leave, and employers are now allowed to frontload sick time. Minimum wage was increased to $12.48 beginning February 21, 2025, $13.71 on January 1, 2026, $15 on January 1, 2027, respectively. Beginning January 1, 2028, and each following year, the minimum wage will increase by the rate of inflation, provided unemployment remains below 8.5%. Read more from your Fraser Trebilcock attorney.

———

  1. FinCEN Update: CTA Reporting Requirement Back On

February 18, 2025, the United States District Court in Texas that had ordered the injunction that had paused enforcement of the Corporate Transparency Act’s (“CTA”) Beneficial Owner Information Reporting (“BOIR”) requirements has granted the government’s request for a stay of that injunction pending appeal.

Why it Matters: This means that FinCEN is authorized to enforce the BOIR requirements, yet again. However, because the Department of the Treasury recognizes that reporting companies may need additional time to comply with their BOI reporting obligations, FinCEN is generally extending the deadline 30 calendar days from February 19, 2025, for most companies. Read more.

———

  1. Sixth Circuit Expands FMLA Coverage to Include Care for Adult Siblings

In Chapman v. Brentlinger Enterprises, the Sixth Circuit Court of Appeals ruled that employees may be eligible for FMLA leave to care for a seriously ill adult sibling if they can establish an “in loco parentis” relationship, reversing a lower court decision that had categorically excluded such care from FMLA coverage.

Why it Matters: This decision directly impacts Michigan employers by expanding potential FMLA obligations beyond traditional familial relationships to adult sibling care.

———

  1. Michigan CRA Publishes January ’25 Data: Average Price Decreases

Per data released by the Cannabis Regulatory Agency (CRA), the average retail price for adult-use sale of an ounce of cannabis in January 2025 was $66.50, a decrease from $69.20 in December 2024. This is a decrease from January 2024, where the average price was $93.20.

Why it Matters: While the prices of cannabis and cannabis-related products continue to decrease and make consumers happy, growers on the other hand are seeing profits decrease resulting in them seeking ways to halt new licenses to be granted in an effort to steady prices.

———

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the March Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

Related Practice Groups and Professionals

Labor, Employment & Civil Rights | David Houston
Business & Tax | Robert D. Burgee
Cannabis Law | Sean Gallagher

Five Stories That Matter in Michigan This Week – February 14, 2025

  1. Large Michigan Cannabis Operator Temporarily Shutters Part of its Operations Due to Market Challenges

Pincanna, which has retail cannabis outlets in East Lansing, Kalamazoo, and Kalkaska, recently announced that it is temporarily closing the greenhouse portion of its cultivation operation (located in Bay County) and laying off part of its workforce.

Why it Matters: One of the company’s co-founders cited an oversupply of cannabis in Michigan, which has created a highly competitive and unsustainable market, as the driving force behind the decision. Despite record sales of product, many Michigan cannabis operators have struggled to remain profitable due to falling prices.

———

  1. Governor Whitmer Unveils Proposed Tax Increases to Fund Roads

This week, Governor Whitmer released a proposal that seeks $3 billion in a long-term plan that will lower vehicle repair costs, invest $1 billion in local roads and $250 million in transit.

Why it Matters: Among the components of the proposal, it seeks to close the gap in road funding, ensuring each dollar paid at the gas pump is invested back into the road infrastructure. Additionally will require businesses, specifically Big Tech, to pay more in taxes for doing business in Michigan, and to introduce a wholesale tax on the marijuana industry.

———

  1. Latest Product Recall from Michigan CRA on Vapes Containing MCT Oil

On February 11, 2025, the Michigan Cannabis Regulatory Agency released a bulletin on a voluntary product recall on certain vapes from the brand BLOOM Classic and BLOOM Live that were found to contain Medium Chain Triglyceride (MCT) Oil, which had been banned for use in 2024.

Why it Matters: The products affected are from the brand Platinum Vapes. MCT Oil is commonly used in inhalable cannabis products, such as vapes, and may pose dangers to respiratory health when inhaled. The CRA banned the use of MCT Oil starting October 1, 2024.

———

  1. U.S. Supreme Court’s Decision on TikTok

On January 17, 2025, the Supreme Court delivered a landmark decision in TikTok Inc. v. Garland, upholding the constitutionality of the Protecting Americans from Foreign Adversary Controlled Applications Act. TikTok argued that the law infringed upon its First Amendment rights, claiming that it was being unfairly targeted as a foreign adversary-controlled application and that the divestiture requirement placed an unconstitutional burden on free speech. However, the Supreme Court disagreed, ultimately finding that the Act was a content-neutral law that was not in violation of the First Amendment.

Why it Matters: This Supreme Court decision marks a pivotal moment in the ongoing struggle between the protection of technology-based free speech and national security concerns. When or if Congress considers applying the Act’s prohibitions to other social media platforms, how the Court addresses the constitutionality of those future challenges will be crucial to watch. Read more.

———

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the March Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

Related Practice Groups and Professionals

Cannabis Law | Sean Gallagher
Intellectual Property | Andrew Martin

Five Stories That Matter in Michigan This Week – February 7, 2025

  1. Update: FinCEN – Supreme Court – CTA Injunction

FinCEN has given notice of its appeal in the Smith case: the lawsuit that led to the current nationwide injunction that makes Beneficial Ownership Information (BOI) reporting voluntary under the Corporate Transparency Act (CTA). If the court grants FinCEN’s appeal and lifts the injunction, BOI reporting would again become mandatory.

Why it Matters: In that event, the government has informed the court that FinCEN plans to implement a 30-day filing extension and “assess whether it is appropriate to modify the CTA’s reporting requirements to alleviate the burden on low-risk entities.” Read more.

———

  1. Michigan Cannabis Grower Wins $32M Verdict in Contract Dispute

A federal court jury awarded Michigan-based Hello Farms $32 million last week after finding that Curaleaf, a large cannabis company, breached its purchase agreement from 2020-2021. The dispute arose when Curaleaf, after purchasing only 2,000 of the contracted 16,000 pounds of cannabis, demanded to renegotiate the agreement due to rapidly falling market prices.

Why it Matters: This case highlights the significant challenges facing Michigan’s cannabis industry as it grapples with volatile market conditions and plummeting prices. Particularly for those operating under long-term purchase agreements, this verdict underscores the importance of carefully considering the various business and legal risks of making significant purchase production commitments in an unstable market environment. It’s crucial to seek out experienced legal counsel in such situations.

———

  1. U.S. Supreme Court’s Decision on TikTok

On January 17, 2025, the Supreme Court delivered a landmark decision in TikTok Inc. v. Garland, upholding the constitutionality of the Protecting Americans from Foreign Adversary Controlled Applications Act. TikTok argued that the law infringed upon its First Amendment rights, claiming that it was being unfairly targeted as a foreign adversary-controlled application and that the divestiture requirement placed an unconstitutional burden on free speech. However, the Supreme Court disagreed, ultimately finding that the Act was a content-neutral law that was not in violation of the First Amendment.

Why it Matters: This Supreme Court decision marks a pivotal moment in the ongoing struggle between the protection of technology-based free speech and national security concerns. When or if Congress considers applying the Act’s prohibitions to other social media platforms, how the Court addresses the constitutionality of those future challenges will be crucial to watch. Read more.

———

  1. Michigan CRA Issues Product Recall on Vapes Due to MCT Oil

The Michigan Cannabis Regulatory Agency recently released a bulletin on a voluntary product recall on certain vapes that were found to contain Medium Chain Triglyceride (MCT) Oil, which had been banned for use in 2024.

Why it Matters: The products affected are from the brand Platinum Vapes. MCT Oil is commonly used in inhalable cannabis products, such as vapes, and may pose dangers to respiratory health when inhaled. The CRA banned the use of MCT Oil starting October 1, 2024.

———

  1. Business Education Series: Anatomy of a Data Breach

Data breaches can wreak havoc on your company and almost always lead to litigation. With each new breach, we gain valuable insight into what companies could have done better. Your legal, contractual, and business obligations can sometimes be confusing and in conflict with each other.

Why it Matters: During the March Business Education Series facilitated by Nate Steed and Kelly R. Hollingsworth, this session will examine recent cases and best practices to protect your company from a breach including: lessons learned from recent data breaches; proactive strategies to insulate your business. Learn more.

Related Practice Groups and Professionals

Business & Tax | Robert D. Burgee
Cannabis Law | Sean Gallagher
Intellectual Property | Andrew Martin

Michigan House and Senate Pass Bills Imposing 45-Day Data Breach Notification Requirement

The Michigan House of Representatives recently voted to approve legislation that will impose a 45-day data breach notice requirement on Michigan businesses. House Bills 4186 and 4187, which were passed on December 16, 2020, will become law if signed by Governor Whitmer. Identical bills were passed by the Michigan Senate on December 10.

Data security is a major concern for many businesses across industries. A report issued by the FBI, Department of Health and Human Services, and Cybersecurity and Infrastructure Security Agency in October warns of “an increased and imminent cybercrime threat” to businesses, particularly those in the health care sector. Recent revelations of a sophisticated cyberattack on the U.S. government shows how vulnerable even the most secure systems are to a breach. This new legislation, if enacted, will impose new obligations on Michigan businesses when a data breach occurs.

Key Provisions of New Legislation

The legislation requires a “covered entity” to provide notice within 45 days to state residents whose “sensitive personally identifying information” (PII) was exposed in a data breach.

A “covered entity” includes an individual or a sole proprietorship, partnership, government entity, corporation, limited liability company, nonprofit, trust, estate, cooperative association, or other business entity, that has more than 50 employees and owns or licenses sensitive personally identifying information, or a franchisee of any of the foregoing.

The scope of PII that gives rise to an obligation to notify state residents in the event of a data breach includes a state resident’s first name or first initial, and last name, in combination with one or more of the following data elements that relate to that state resident:

  • A nontruncated Social Security number.
  • A nontruncated driver license number, enhanced driver license number, state personal identification card number, enhanced state personal identification card number, passport number, military identification number, or other unique identification number issued on a government document that is used to verify the identity of a specific individual.
  • A financial account number.
  • A state resident’s medical or mental history, treatment, or diagnosis issued by a health care professional.
  • A state resident’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the state resident.
  • A username or electronic mail address, in combination with a password, security question and answer, or similar information, that would permit access to an online account affiliated with the covered entity that is reasonably likely to contain or is used to obtain sensitive personally identifying information.

All covered entities and third-party agents are required to implement and maintain reasonable security measures designed to protect PII against a breach of security. The legislation lays out a long series of factors covered entities must consider in developing reasonable security measures, including the size of the covered entity and the amount of PII it maintains and processes.

If a covered entity determines that a breach of security has or may have occurred, the covered entity must conduct a good-faith and prompt investigation into the scope and extent of the breach.

If a covered entity determines that a breach has occurred, it must notify state residents whose PII was acquired in the breach, as expeditiously as possible and without unreasonable delay. Notification must occur within 45 days of a determination that a breach has occurred unless law enforcement determines that such notification could interfere with a criminal investigation or national security. Written notice must at least include the following:

  • The date, estimated date, or estimated date range of the breach.
  • A description of the PII acquired by an unauthorized person as part of the breach.
  • A description of the actions taken to restore the security and confidentiality of the PII involved in the breach.
  • A description of steps a state resident can take to protect against identity theft, if the breach creates a risk of identity theft.
  • Contact information that the state resident can use to ask about the breach.

A covered entity may provide substitute notice in lieu of direct notice, if direct notice is not feasible because of excessive cost or lack of contact information. Under the legislation, the cost of direct notification to state residents is considered excessive if it exceeds $250,000 or if notice must be provided to more than 500,000 state residents. Substitute notice must include a conspicuous notice on the covered entity’s website (if it has one) for at least 30 days, and notice in print and broadcast media.

Penalties for Noncompliance with Notification Requirements

A covered entity that fails to comply with the notice requirements set forth in the legislation faces potentially steep fines. Penalties may include a civil fine of not more than $2,000 for each violation, or not more than $5,000 per day for each consecutive day that the covered entity fails to take reasonable action to comply with applicable notice requirements. Aggregate liability for civil fines for multiple violations related to the same security breach shall not exceed $750,000.

This legislation is not yet law, but soon may be. This article touches upon many of the important provisions of the legislation, but there are additional details to be aware of. Businesses and other entities covered by this legislation should take steps to assess their preparedness to comply with the new obligations imposed by these bills. If you have any questions, or require assistance in planning for the implications of this legislation, please contact Fraser Trebilcock shareholder  Thad Morgan.


Morgan, Thaddeus.jpgThaddeus E. Morgan is a shareholder with Fraser Trebilcock and formerly served as President of the firm. Thad is the firm’s Litigation Department Chair and serves as the firm’s State Capital Group voting representative. He can be reached at tmorgan@fraserlawfirm.com or (517) 377-0877.

Seven Tips About Data Breach Prevention and Cybersecurity for Small Businesses

We see it in the news regularly. Major corporations like Anthem, eBay, Equifax, Sony Pictures, and Target have all suffered major data security breaches. But these breaches don’t only happen to large organizations. Companies of all sizes are targets. Sometimes, smaller companies are even bigger targets because protections may not be as secure.

So how do businesses of all sizes go about data breach prevention and cyber security? Here are seven tips to strengthen your business against a data breach.

1. Train employees and users on data breach prevention

Human error is often to blame for most breaches. The easiest way for a hacker to invade your network is by preying on an employee who doesn’t recognize the risk. Whether through a malware email attachment, or by downloading a document from an unreliable resource, there is a wide variety of easy phishing attempts that can lead to a data breach. The key to prevention is teaching your employees how to avoid making these common mistakes. Also, include a technology protocol section in your employee handbook where your team can easily access it. This section should cover proper steps to take to protect your technology, especially anything that could be considered a trade secret, or private customer/client information and data.

2. Store customer data in an encrypted database

Another tip for data breach prevention is to use a secure database and encrypt any items containing customer/client information or trade secrets. The encryption process converts that information or data into a code, which then works to prevent unauthorized access. A common example of this process is the one used when you make an online purchase. Once you enter your payment information onto an ecommerce website and it has been approved, your information is encrypted before it is stored on the website. When you later go back to the website to make another purchase from your account, your information is ready to use.

3. Improve cybersecurity with two-factor authentication

Two-factor authentication adds an extra layer of protection to logging into a website. After a user inputs the required login and password, an extra step is initiated to ask the user for another piece of information that only he or she would have. For example, a text message with a one-time code may be sent to the user’s phone, which is tied to the account. Two-factor authentication is very important for data breach prevention if your business has devices that go in and out of the office, such as tablets or laptops, making sure they are secure in the event they become lost or stolen.

4. Malware detection software on both servers and workstations

Each workstation inside your business, as well any servers, need to have malware detection software installed to help with data breach prevention. The detection software prevents malware from being installed. Malware can be hidden in a variety of formats, the detection software helps scan each item to ensure its safety. There are a variety of different software packages available for businesses, depending on the level of security needed.

5. Perform regular vulnerability checks

It’s critical that you perform regular vulnerability checks to minimize the risk and prevent data breaches. For example, it’s important that firewall configurations be reviewed regularly with penetration testing, to make sure only trusted networks are given access. Software updates may also vary with your malware protection software. There are programs that can run regular checks, or you can look to a third-party IT company for assistance. It’s also important that you continue to test and train employees through phishing emails to ensure they stay vigilant.

6. Require frequent remote data backups

Whether routinely completed on the cloud or on an external hard drive, remote data backups ensure that your data is stored securely. A routine backup allows you to have a reference point if your data is breached in the future. Most backup providers allow you to pick the frequency of the backup, time of day it occurs, and what level of information detail you would like to store.

7. Have a disaster plan ready in case of a data breach

Protecting your business against a data breach is an ongoing process. Under the Michigan Identity Theft Protection Act, in the event of a data breach that is likely to cause harm or result in identify theft, a business must provide a notice of the security breach to each affected Michigan resident, customers and vendors affected by the breach, as well as consumer reporting agencies. Keep in mind, the notifications must be precise and meet certain statutory requirements.

Unfortunately, even with planning, a cyberattack can still happen. Be prepared by having a disaster plan ready, and be sure to include the proper steps for employees to take both during and after an attack. Review the plan as an internal team frequently to ensure that everyone has a clear understanding of timelines and responsibilities. Time is of the essence during a data breach, and having a disaster plan prepared will make that stressful time more efficient.

To learn more, contact an attorney at Fraser Trebilcock at 517.482.5800 or by clicking here to fill out this form on our website.


business-legal-checklist

Business Legal Compliance Checklist

A critical overview of laws and regulations governing businesses of all sizes.

Download the Checklist

7 Tips About Data Breach Prevention and Cybersecurity for Small Businesses

We see it in the news on a regular basis. Major corporations like Anthem, eBay, Sony Pictures, and Target have all suffered major data security breaches. But these breaches don’t only happen to major businesses. Companies of all sizes are targets. Sometimes, smaller companies are even bigger targets because protections may be lax.

So how do businesses of all sizes go about data breach prevention and cyber security? Here are seven tips to strengthen your business against a data breach.

1. Train employees and users on data breach prevention

Human error is often to blame for most breaches. The easiest way for a hacker to invade your network is by preying on an employee who doesn’t recognize the risk. Whether through a malware email attachment, or by downloading a document from an unreliable resource, there is a wide variety of easy phishing attempts that can lead to a data breach. The key to prevention is teaching your employees how to avoid making these common mistakes. Also, include a technology protocol section in your employee handbook where your team can easily access it. This section should cover proper steps to take to protect your technology, especially anything that could be considered a trade secret, or private customer/client information and data.

2. Store customer data in an encrypted database

Another tip for data breach prevention is to use a secure database and encrypt any items containing customer/client information or trade secrets. The encryption process converts that information or data into a code, which then works to prevent unauthorized access. A common example of this process is the one used when you make an online purchase. Once you enter your payment information onto an ecommerce website and it has been approved, your information is encrypted before it is stored on the website. When you later go back to the website to make another purchase from your account, your information is ready to use.

3. Improve cybersecurity with two-factor authentication

Two-factor authentication adds an extra layer of protection to logging into a website. After a user inputs the required login and password, an extra step is initiated to ask the user for another piece of information that only he or she would have. For example, a text message with a one-time code may be sent to the user’s phone, which is tied to the account. Two-factor authentication is very important for data breach prevention if your business has devices that go in and out of the office, such as tablets or laptops, making sure they are secure in the event they become lost or stolen.

4. Malware detection software on both servers and workstations

Each workstation inside your business, as well any servers, need to have malware detection software installed to help with data breach prevention. The detection software prevents malware from being installed. Malware can be hidden in a variety of formats, the detection software helps scan each item to ensure its safety. There are a variety of different software packages available for businesses, depending on the level of security needed.

5. Perform regular vulnerability checks

It’s critical that you perform regular vulnerability checks to minimize the risk and prevent data breaches. For example, it’s important that firewall configurations be reviewed regularly with penetration testing, to make sure only trusted networks are given access. Software updates may also vary with your malware protection software. There are programs that can run regular checks, or you can look to a third-party IT company for assistance. It’s also important that you continue to test and train employees through phishing emails to ensure they stay vigilant.

6. Require frequent remote data backups

Whether routinely completed on the cloud or on an external hard drive, remote data backups ensure that your data is stored securely. A routine backup allows you to have a reference point if your data is breached in the future. Most backup providers allow you to pick the frequency of the backup, time of day it occurs, and what level of information detail you would like to store.

7. Have a disaster plan ready in case of a data breach

Protecting your business against a data breach is an ongoing process. Under the Michigan Identity Theft Protection Act, in the event of a data breach that is likely to cause harm or result in identify theft, a business must provide a notice of the security breach to each affected Michigan resident, customers and vendors affected by the breach, as well as consumer reporting agencies. Keep in mind, the notifications must be precise and meet certain statutory requirements.

Unfortunately, even with planning, a cyberattack can still happen. Be prepared by having a disaster plan ready, and be sure to include the proper steps for employees to take both during and after an attack. Review the plan as an internal team frequently to ensure that everyone has a clear understanding of timelines and responsibilities. Time is of the essence during a data breach, and having a disaster plan prepared will make that stressful time more efficient.

To learn more, contact an attorney at Fraser Trebilcock at 517.482.5800 or by clicking here to fill out this form on our website.


business-legal-checklist

Business Legal Compliance Checklist

A critical overview of laws and regulations governing businesses of all sizes.

Download the Checklist