Attorney General Ken Paxton has launched a major initiative to crack down on companies who sell solar panel systems and are engaging in fraudulent and deceptive practices.
As part of the initiative, Attorney General Paxton has issued Civil Investigative Demands (“CIDs”) to a number of companies such as Freedom Forever, LLC. (“Freedom Solar”), SunRun, Inc. (“Sunrun”), Lone Star Solar Services LLC (“Lone Star Solar”), and CAM Solar Inc. (“CAM Solar”). Collectively, there are over 100 complaints that have been filed with the OAG against these companies, along with thousands more online.
The companies are largely being investigated for violations of the Deceptive Trade Practices-Consumer Protection Act. Some of the companies’ actions being investigated involve misrepresentations regarding savings for consumers on their energy bills, the efficacy of their solar panel systems, equipment…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
