It’s six pm on a Friday night. Your phone rings. It’s your client’s general counsel. The company was hacked. Systems are offline, and the full extent of the compromise is unknown. The company holds a lot of confidential and personal information it needs to access to maintain operations and services. What do they do?
Unfortunately, this is a scene that more and more companies are experiencing each day. For organizations, it’s “when” you will experience a cybersecurity incident, not “if”. Technology, including rapid advancements in AI, makes it easier for bad actors to infiltrate systems, trick users, and do it faster.
For cyber incident response, the best offence is a good defence. It's important to take certain steps long before an incident ever arises. A well-organized response can be the difference maker and help make a difficult situation more manageable.
The starting point is an incident response plan (IRP). An IRP is developed by identifying the information and systems that have value to your organization, the incidents you may face, and the organization’s best people to be on an incident response team. Organizations with a dedicated plan can avoid having to say “what do we do next?” These plans should be comprehensive, address each stage of an incident, and set out players who will form the core “incident response team”, including internal stakeholders from key departments (leadership, IT and security, human resources, legal, public relations and communications) and delineate responsibilities.
The incident response plan also sets out the external support an organization can rely upon to navigate the crisis. One key tool is cyber insurance. In addition to the usual financial losses that an insurance policy covers, cyber insurance policies give clients access to more resources that can help them get through a breach.
If there’s an incident, insurers may have specific requirements, including notification. An incident response plan should consider those requirements and any needed approvals from an insurer in advance before retaining external support. Your incident response plan, your cyber insurance policy, and any other key documents (contact lists, inventory of contracts) should be stored securely on your system and in a secondary offline location to ensure access when your systems are down.
Your breach coach is one of the key resources to navigate a crisis. These are external counsel with expertise in navigating incident response. One benefit to using a lawyer as a coach is that it is more likely that privilege may attach, which is helpful in any subsequent litigation. Your first call should be to legal counsel, in the hopes of attaching privilege in executing the IRP.
The breach coach guides the organization through the entire cyber incident lifecycle, including liaising with the forensic/incident response teams, coordinating with crisis communications personnel, managing communications with the threat actor, law enforcement, and insurance, guiding and supporting the organization’s leadership throughout the crisis, and managing any required notifications because of legal or contractual obligations.
The next call (or your first if you do not have a breach coach selected in advance) should be to your cyber insurer. The insurance provider may require immediate contact if you want to be able to make a claim on your insurance policy. Data breaches are costly ventures beyond just the costs of the resources needed to deal with the actual incident. A data breach would involve costs to fix the breach and may expose the organization to litigation. Some of the items a cyber risk policy covers could include expenses related to the breach (cyber coach, legal counsel, notification costs, fines, costs to restore systems), ransomware payments, and other liabilities. Some insurers require that counsel and other vendors are selected from their pre-approved panel. Notifying your insurance provider at the earliest opportunity helps you maximize any coverage or reimbursements.
Engaging an external ransom negotiator may also be a decision which requires insurer authorization. These teams can help an organization preserve critical data points as they work to contain an incident and restore systems.
Organizations should also coordinate with their breach coach to track business impact and recovery costs from the start of an incident. Your breach coach also helps assess whether any notification thresholds are met—triggered by law or contracts. If the incident impacts individuals located in another jurisdiction, breach counsel may need to coordinate with firms in other locations to assess any notification obligations. Again, in insured cases, these vendors should be preapproved.
Work with your breach coach should start before an incident. Rachel Schechter, legal counsel and breach coach, stresses this importance. “For many organizations, the relentless pace of change in the privacy and cybersecurity space can be intimidating. It is imperative that organizations stay proactive and review incident response plans and strategies at regular intervals to ensure it is up to date, compliant with privacy and industry-specific requirements, and that they know when and who to call when they experience an incident so they can mitigate risk to the greatest extent possible,” she says.
Organizations need to practice their incident response (often referred to as tabletop exercises) and evaluate what actions can be taken now to improve cybersecurity readiness and posture.
These simulations can help organizations strategize recovery procedures and identify items of pre-agreement to minimize real-time decision making. They can also help you identify areas where additional training may be necessary to help every member of an organization understand their responsibilities in the event of an incident. Human error is a cause or contributing factor in most cyber incidents, and social engineering and phishing schemes are growing increasingly sophisticated.
Regular review of cyber insurance policies and incident response plans also ensures that the organization is staying on top of any policy requirements and best practices. While regular software and firmware updates, patching, enforcing multi-factor authentication, and security awareness training are all best practice, for example, they may also be conditions of coverage at designated intervals.