CIO
The Do's and Don'ts of Data Breaches
Here is a list of what companies should do and what they should avoid doing in the case of a data breach, besides putting a computer-emergency response team in place to react to such incidents
Cara Garretson (Network World)  19 June, 2007 14:42:16

Believe it or not, a data breach isn't the worst thing that could happen to your organization. Reacting poorly to the incident could be, however.

Experts agree every organization that stores personal or financial information about customers, partners or employees or that has intellectual property in electronic form should be considered a target — that's arguably just about every organization doing business. Instead of assuming data breaches happen only to large financial services companies or retailers, companies large and small in every industry should be prepared to react to help minimize damage and quickly restore customer confidence, they say.

"It makes all the difference in the world" if a company is prepared to respond to a data breach or other type of cyberintrusion, says Tom Bowers, managing director of Security Constructs, a security services firm based in the US.

Here is a list of what companies should do and what they should avoid doing in the case of a data breach, besides putting a computer-emergency response team in place to react to such incidents.

The list is compiled from interviews with consultants and security experts who have had to deal with these incidents or who have been called in to help companies immediately following an attack:

DO confirm and contain the problem.

This seems obvious, but in the stress and confusion of the moment, the importance of knowing exactly what happened can get lost. Once evidence of a potential data breach has been uncovered (customers complaining of fraud alerts on their credit cards, server logs showing unauthorized access to sensitive data, and so forth) security professionals should work with the IT team to determine whether a breach happened and how it happened, and to fix the weakness if possible.

"You need immediate containment; that's where the network and system folks jump in, and you need to let that team do its job," says Ed Zeitler, executive director of the International Information Systems Security Certification Consortium and former CISO of Charles Schwab.

DON'T contaminate the crime scene.

Decide whether the IT team can plug the security leak without modifying the computers from which the data was stolen; if not, call in security experts — preferably a company you have hired beforehand and have put on retainer to help in case of an incident. While this may delay reacting to an incident, it could help your company down the road.

"Often we see [an incident] could be an open-and-shut case, but the company muddied up the crime scene and so law enforcement won't achieve prosecution," says Bryan Sartin, vice president of investigative response with security services provider Cybertrust, which in May Verizon Business announced plans to acquire.

DO communicate with and rely on other departments.

You don't want legal counsel involved to the point that they are combing through log files, but security professionals who alert other key departments — legal, compliance, human resources, public relations, marketing and of course, the executive team — will put themselves on a better footing if they alert key departments in the breach's early stages, rather than at a point that could be construed as after-the-fact.

What's more, security professionals should rely on all these resources for help in the case of a breach. "The security person shouldn't feel they own the responsibility of what steps to take for the company; they should leverage resources and collaborate," says Randy Barr, CSO of WebEx, a conferencing and collaboration services provider that Cisco in March 2007 announced it plans to acquire. Because responding to a data breach is a multifaceted process that can include alerting customers, issuing press releases, dealing with regulators and possibly even litigation, security professionals should leverage the resources available to them, he says.

"Security is not 100 percent; you're in a race to protect yourself and your customer data. The biggest thing is not having to rely on your security program to address [all] the issues," Barr says.

DON'T go on the defensive.

"You need to keep an open mind," says an investigation manager with a US financial services company who has been called in to help his company's partners deal with security incidents, and who asked that his name and his company's name not be used. "A lot of times these guys are walking into a boardroom with the CEO, COO, CIO and head of IT, and all they're saying to themselves is, 'My job is going down the tubes,'" he says. "Go into it with an open attitude and spirit of cooperation, that's how you'll want to be perceived."

DO remember that it's not only your job that could be affected by a breach.

While some security professionals may believe it's best not to bother the executive team with details of an incident, those executives can be held accountable and therefore need to know what's happening. "While customers might be becoming a little more desensitized to data breaches [because they're in the news so often,] CIOs are becoming a lot more sensitized," says Security Constructs' Bowers, who previously was senior manager of information security with US-based Wyeth Pharmaceuticals. "That's what is driving money into security: More companies are saying we need to meet these privacy regulations because they could affect our stock price . . . and bonuses."

DO be honest in communicating with the public, customers, employees and partners.

How a company alerts people to a breach is the first step in rebuilding their confidence in the organization. Without giving away too many details, offer an honest assessment of what happened. If the company has no reason to believe the stolen data has been used by the criminal, state that, too.

DON'T go public until you know what happened.

If a company has to change its story about what happened — a la TJX — their credibility is instantly eroded. "You can cause panic sometimes," says the investigation manager. "TJX released information that wasn't necessarily true [about the extent of stolen information and when it was compromised] and caused the people who were working on that case trying to identify the extent of the breach to be sidetracked trying to answer the feeding frenzy in the media," he says.

"They did exactly the wrong thing."

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Newsletters
Sign up for our CIO newsletters!
Syndicate content

URL
www.kyoceramita.com.au

Call us on
Australia: 1800 339 003
New Zealand: 0508 596 2732

Email us
marketing@kyoceramita.com.au

Did you realise that the cost or running a laser printer over its lifetime is likely to exceed the original purchase price by several times? To compare your current printer's running costwith a Kyocera printer, select the TCO Calculator

Total Cost of Ownership (TCO)
Kyocera Saves... Try our Saving Estimator now
Calculate Now

Testimonials

 

Wondering how to improve your business with UC on an IP Network?

Join Computerworld's Live Webinar where we will address the move many companies are making towards IP based voice services (SIP trunking, VoIP) and look at how they are using a single connection for data and voice rather than separate lines. Learn about the latest in IP networks and how it can help your organisation.

Wednesday 25th November 2009, Time 10.30 am EST (Sydney, Australia) Screening at your desk

Register now

  • +

    CA brings SOA security to open source JBoss 09 February, 2010 10:08:00

    More commercial options for widely-used app server
    CA has announced its SiteMinder and SOA Security Manager products are now available for the open source JBoss middleware platform.
  • +

    Indian pleads guilty in overseas stock hacking scheme 08 February, 2010 07:50:00

    The group of hackers compromised brokerage accounts, then pumped up the prices of stocks
    An Indian national pleaded guilty Friday to conspiracy and aggravated identity-theft charges related to an international fraud scheme to hack into online brokerage accounts in the U.S. and use them to manipulate stock prices, the U.S. Department of Justice said.
  • +

    E-mail scam steals €3 million in carbon credits 05 February, 2010 06:47:00

    The phishing scheme resulted in losses of up to €3 million from companies
    A clever phishing scheme launched last week may have stolen more than €3 million (US$4.1 million) worth of carbon emission permits from companies.
  • +

    Windows 7 Tips: Best Security Features 04 February, 2010 04:52:00

    IT can specify which applications can run on employees' desktops
    For both enterprises and consumers, one of the big draws of Windows 7 has been its tighter security features.
  • +

    Twitter forces password reset to protect some accounts 04 February, 2010 05:48:00

    The company has discovered that log-in information has been stolen in compromised torrent file-sharing sites
    Twitter required some users to reset their passwords on Tuesday after discovering that their log-in information may have been harvested via security-compromised torrent Web sites, the company said.

Upcoming Industry Events
  • No upcoming events available
Whitepaper

Operational Responsiveness: An independent thought leader view

Operational responsiveness is the ability of processes and systems to respond in real-time to changing conditions and customer interactions, enabling business leaders to capitalise on opportunities, drive greater efficiencies, and reduce risk. Read on for more.

CIO Industry Insight Podcast #6: Brenton Smith, Managing Director, CA (ANZ)
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper
Securing People and Information: How to Protect Against Today’s Web-based Threats

This white paper explores the benefits of an Application Delivery Network, highlighting the ability to protect your users and applications and still deliver outstanding application performance with confidence, consistency and cost-effectiveness across your distributed network.

Read Whitepaper

Brought to you by