thecybersecurityreview

CYBERSECURITY REVIEW8 SEPT- NOV 2023The cyber incident timeline is often delineated based on when things happen compared to the discovery of an incident ­ the Boom. Left of Boom refers to everything before discovery of the incident and Right of Boom describes everything after. Public consciousness of cyber attacks, guided by media coverage, focuses on Right of Boom ­ things like the victim company's response and communications along with the impact to end customers and the company's reputation. It is, however, the preparation ­ all done Left of Boom ­ that determines a company's odds of successfully navigating a significant cyber incident. That preparation, unfortunately, is all too easy for in-house counsel to neglect.The dedicated in-house cyber counsel role did not exist just a few years ago. Today it exists in a small number of very large corporations and security firms, but most in-house lawyers are only expected to weigh in on cyber security issues on an ad hoc basis. Cyber security is a secondary concern to their "real" job. What happens, then, when in-house counsel's first exposure to cyber security occurs during an incident? Faced with unfamiliar cyber/technical concepts, the temptation to defer to the "experts" can be overwhelming. The result is that the lawyer is merely an ancillary player which does a great disservice to the corporate client. Fortunately, a preparation mindset can ensure sufficient work is done Left of Boom to substantially enhance the odds of successful resolution of a cyber incident.Every business ­ big or small ­ will eventually face a cyber incident. And when it happens there is no substitute for preparation. For a lawyer, preparation means thinking through the contingencies in advance and lining up internal and external resources. "Winging it" leads to bad outcomes. Weighing the risks of paying or not paying an extortion demand or whether to engage law enforcement should not be done for the first time during an incident. Similarly, selecting outside counsel, a forensic investigator, or ransomware negotiator under duress is at best a gamble and an invitation to be taken advantage of. Fortunately, all of these things can be addressed in advance. In-house counsel can begin by meeting external resources, weighing whether to establish retainer agreements, and thinking through the various legal issues that could arise. Is a third-party involved? Is it a vendor? Customer? Does contract language compel certain action during incident response? Is there insurance coverage? Do regulators or anyone else need to be notified? Might there be media inquiries? Who are the internal decision-makers? Who will do the technical work? These are just a few of the basic questions to consider and each question will lead to several others. Pair that with regular tabletop exercises and eventually a robust preparation cycle emerges. LEFT OF BOOM - IN-HOUSE COUNSEL'S ROLE By Josh Cook, Chief Counsel, US Privacy & Cybersecurity, John HancockIN MY OPINIONJosh Cook
< Page 7 | Page 9 >