U.S. Circuit Court of Appeals ruled that the Federal Trade Commission has authority to regulate infosec breaches. The court ruled that it’s OK for the FTC to find businesses at fault for data breaches and tie them up with consent decrees that force them to submit to third-party security assessments every two years for 20 years. It’s still unknown what impact the ruling will have on the fervor with which the FTC goes after breached companies, says Jason Straight, senior vice president and chief privacy officer.”]

