Skip to main content

Cybersecurity for small business: Understanding the NIST Cybersecurity Framework

Andrew Smith, Director, FTC Bureau of Consumer Protection
The FTC hosted roundtables across the country asking small business owners how we can help you address the challenges of cybersecurity. Based on your feedback, we designed to-the-point tips now available at ftc.gov/cybersecurity . Last week we kicked off a 12-part every-Friday Business Blog series with cybersecurity basics . Today’s topic: what you need to know about the NIST Cybersecurity Framework . One thing business owners told us at those...

FTC and New York AG miffed by overbiffing

Lesley Fair
If you aren’t familiar with the word “overbiffing,” there’s no need to add it to your vocabulary. But if you know what overbiffing is and engage in it, a case just filed by the FTC and the New York Attorney General suggests now would be an excellent time to cut it out. Overbiffing is the practice of debt collectors tricking consumers into paying more than their “Balance In Full,” sometimes abbreviated as BIF. The FTC and the New York AG charge...

Listen in on how sellers pitched business “coaching” services

Lesley Fair
One of the Utah-based defendants’ corporate names was Vision Solution Marketing, but you need to hear their sales pitch to get a sense of how they peddled their big-money “business coaching” services to consumers. In addition to imposing multi-million dollar judgments, FTC settlements ban the defendants for life from selling business coaching or development services. But you really should listen to these phone calls. The FTC filed suit in May...

The “law” of averages: FTC challenges SoFi’s student loan refinancing claims

Lesley Fair
Imagine a baseball scout is taking a look at a prospect. On paper, the slugger’s batting average seems impressive. But now imagine that, unbeknownst to the scout, those stats left out all the times the batter struck out. It’s an unrealistic hypothetical, of course, but it illustrates the principle that in compiling averages, removing certain categories of data can skew the results. The FTC’s action against California-based SoFi for allegedly...

Control no longer controlling for HSR reporting of not-for-profit combinations

Premerger Notification Office Staff
The PNO routinely provides informal guidance on Hart-Scott-Rodino reporting obligations that arise when combining not-for-profit entities, typically in the context of hospital combinations. In the past, much of this guidance focused on whether the combination resulted in a change of "control" of the board of directors of one or more of the combining entities. This was because those seeking guidance described hospital combinations primarily in...

Cybersecurity for small business: Cybersecurity basics

Andrew Smith, Director, FTC Bureau of Consumer Protection
As a small business owner, you know that cyber criminals will steal data any place they can find it, whether it’s from a global giant or a Main Street store. So where can you find just-the-facts security advice tailored to your needs? At ftc.gov/cybersecurity . The FTC has boiled it down to a dozen need-to-know topics for small businesses and we’ll address one each week in the Business Blog. First up: Cybersecurity Basics , which sets the stage...

Share cybersecurity resources with non-profits in your community

Rosario Méndez
Do you work for a non-profit? Or maybe you’re on the board of a charity or active in a professional or service organization in your community. If so, you know the group collects all sorts of private information, including details about members or people you serve and financial information related to donors. Your own personal information, too, is probably in the group’s records of employees and volunteers. Cyber criminals would love to get their...

PrivacyCon 2019: Mark your calendar

Lesley Fair
Take out your scheduler now and block out Thursday, June 27, 2019 . That’s the date of the FTC’s fourth annual PrivacyCon and you’ll want to be in on the action. PrivacyCon brings together internationally renowned privacy and security experts to discuss their recent research. PrivacyCon encourages productive cross-talk among gurus in related fields and helps FTC staff stay in the loop on the latest. If you’re interested in presenting at...

Three films not on our Top 10 list

Lesley Fair
In the annals of film, Citizen Kane , The Godfather , and Casablanca are among our top picks. But don’t expect our list to include TBX-FREE, Eupepsia Thin, or Prolongz, dissolving strips of film the FTC says California-based Redwood Scientific deceptively advertised for smoking cessation, weight loss, and male sexual performance. According to the 16-count complaint, the defendants could fill a multiplex with other misleading practices: deceptive...

Happy 20th birthday, COPPA

Peder Magee
October 20, 2018, marked 20 years since Congress passed the Children’s Online Privacy Protection Act . Many of the kids the law was originally designed to protect are now parents themselves. Looking back on two decades of COPPA, here are our five key takeaways. The FTC continues to be committed to rigorous COPPA enforcement. At the direction of Congress, the FTC issued the COPPA Rule in 2000. Since then, we’ve brought 28 cases to enforce the Rule...