DATA DESTRUCTION 1. How long is data maintained? 2. How is the retention policy enforced? 3. Who can authorize the destruction? 4. Is the data securely destroyed to ensure it cannot be recovered? Is the data kept on physical devices or in the cloud? How is data wiped from those devices? 5. Is a log of data destruction maintained? 6. Are procedures in place for reporting and handling the accidental or unauthorized destruction of data? CONCLUSION Applying the Nebraska statutory requirements of the Security Act requires protecting data throughout its lifecycle. Security controls and their application is a multifaceted responsibility that spans people, process, and technology. By asking the right cybersecurity questions at each stage—creation, maintenance, use, archiving, and deletion—organizations can minimize risks and fulfill statutory, regulatory, and compliance obligations. A proactive approach to data security not only mitigates potential threats but also fosters a culture of accountability and resilience in the evolving digital landscape. Robert L. “Bob” Kardell is an attorney and partner at Baird Holm LLP in Omaha specializing in cyber-breach response, risk management, and fraud investigation. A former FBI special agent with 22 years of service, he is also a CPA, Certified Fraud Examiner, and Certified Information Systems Security Professional. You may reach him at (402) 636-8313 or bkardell@bairdholm.com. 1 Nebraska Legislature, LB1074, passed unanimously on April 11, 2024. 2 Neb. Rev. Stat. § 87-808, 2018. Accessed Oct. 8, 2025. https://nebraskalegislature.gov/FloorDocs/105/PDF/Slip/LB757.pdf. 3 Office of the Comptroller of the Currency, “OCC Assesses $60 Million Civil Money Penalty Against Morgan Stanley,” news release 2020-134, Oct. 8, 2020. Accessed Oct. 8, 2025. https://www.occ.gov/news-issuances/news-releases/2020/ nr-occ-2020-134.html. 4 Board of Governors of the Federal Reserve System, “Interagency Guidelines Establishing Information Security Standards,” accessed Oct. 8, 2025, https://www.federalreserve.gov/supervisionreg/interagencyguidelines.htm. TAKE US ANYWHERE! Scan to read the most recent publication. Stay up to date from your couch, office or even the moon! Place a 1” x 1” QR Code White on Black Here to the main website 24 Nebraska CPA
RkJQdWJsaXNoZXIy MTg3NDExNQ==