Balancing Containment and Notification: Being Practical When Handling a Data Breach

When a company suffers a data breach—or fears that it has suffered a breach—teams often go into panic mode. When the dust settles, work divides into two camps: those focused on business continuity and containment, and those focused on determining if the organization has any breach notice obligations under relevant laws.

Often, these goals can be in conflict—or at least resources to achieve these goals can conflict. Different teams work on different sides of the issue. Internal resources are stretched. Outside resources overlap. What can a company do? First, recognize that both goals are important and deserve resources. Second, account for both goals throughout the breach “process.” The following are some concrete steps companies—and their breach crisis teams—can take:

  • Before the incident: Everyone knows about creating an incident plan, and giving it a test run. But what about taking steps to understand your business realities and needs? Being prepared and ready to address a breach, if it arises, hinges on a good understanding of the types of information you have, where you have it, and with whom that information is shared. It is never too soon to start on this work, and keeping that information up-to-date can be a life saver if a breach arises.
  • Digging in—investigating an incident : This is where the work of the two goals, containment and determining notification obligations, can come into the most conflict. Obviously you will need to contain and control the incident. You will want to take steps like investigating the nature of the incident and getting the right team–with the right background—on hand. But you will also want to know some very specific facts for the lawyers who are determining whether notification is necessary. This includes understanding if there was a compromise to the information and if the information itself triggered breach notice laws (social security numbers, medical information, usernames and passwords, etc.).
  • Notification : If you determine that notification is necessary, containment should not leave the scene. Will your notice impact any ongoing investigations? Will you tip off a bad actor? These are things that should be taken into account as you draft your notifications, and as you potentially work with law enforcement pursuing said bad actors.
  • Post -notification: Once your notice goes out, you are not finished. The containment team will want to look at what lessons can be learned for next time—if there is a next time. The legal side of the house will be thinking about potential post-notice inquiries, whether they come from regulators, the press, or impacted individuals.

Regardless of whether your incident involves an aggressive bad actor bent on destroying your company or gives rise to a duty to notify, your team should ensure that it is taking appropriate steps to both contain and assess legal risks. The tips above are aimed at helping you get there.

Liisa Thomas, Esq.
Partner at Winston& Strawn LLP

Liisa will speak more on data breaches at the ISACA’s CSX 2015 cyber security conference in Washington, DC, 19-21 October 2015.

Note: This post is the third in a series of Cybersecurity Awareness Month blog posts. To learn more on the cyber security resources ISACA is offering this month, click here.

[ISACA Now Blog]

Your Not-So-Typical Cybersecurity Awareness Tips

“We tend to focus on the shiny technology when, in fact, actually, humans are the weak link in cybersecurity.”
— Michael Daniel, cybersecurity coordinator, Executive Office of the President

As a nation, the US will be recognizing cybersecurity awareness throughout the month of October. The Department of Homeland Security and likely every vendor that sells cybersecurity products or services will be sounding the ‘awareness alarm’, offering tips and tricks for users in an effort to promote safer online practices and better cyber hygiene.

But for those of us in the cybersecurity profession, awareness should not stop at educating users. As leaders in our field, the term must invoke a determination to address a workforce in crisis.

No one can truly understand what we are facing as a profession unless they are actually in the profession. Security managers are struggling to find qualified staff to run the security operations center; system administrators are bustling to keep pace with patching demands; incident responders are trying to catch a breath in between back-to-back breach timelines.

In recent years, it has been said that we are suffering from a ‘human capital crisis,’ a term recognized by both lawmakers and leaders in the public and private sectors. The very core of this crisis is characterized by a widening gap between supply and demand for workers. The(ISC)2 2015 Global Information Security Workforce Study (GISWS) forecasts that this workforce gap will only continue to widen and will reach 1.5 million professionals worldwide by 2020 due to the insufficient pool of qualified candidates.

Among U.S. federal government GISWS survey respondents, 60% said that they do not have enough personnel to meet the demands of their mission, and that this is one of the key factors working against them. While both public and private sectors have dedicated significant resources to programs in an effort to fix this problem, we have found no silver bullets. As it goes, practitioners in this field are working in an environment with the odds stacked against them – and with very little relief in sight.

During the month of October, I would like to challenge those in our field to promote a different type of awareness. My challenge is for us to pull together and inspire whomever we come in contact with to consider a career in cybersecurity.

The impact of growing the cybersecurity workforce with trained and skilled personnel will be far reaching, and will ultimately benefit the users at the central focus of this month’sNational Cyber Security Awareness Month activities.

How can we promote such awareness? I, for one, intend to promote careers in cybersecurity whenever I get the chance to address students and their parents such as later this month when speaking to MITRE employees as part of (ISC)2 Foundation’s Safe and Secure Online program. Here are some suggestions for my cybersecurity colleagues and others as you go about your day-to-day activities during the month of October:

  • Look for opportunities to speak with children about cybersecurity. Check out your neighborhood school’s calendar of events to identify career days and rally your colleagues to get involved.
  • Educate yourself on the many scholarship opportunities for those seeking careers in this field and encourage students entering college to apply.
  • Know a veteran who is transitioning to civilian life? Provide him/her with information about the many programs that assist with cybersecurity career training and support.
  • Your friends who are either unhappy in their current role or temporarily out of a job might see cybersecurity as a chance to transition onto a rewarding career path. Not sure how to get them started? Find an (ISC)2 member or contact us directly.
  • Are you a member of (ISC)²? If so, you can volunteer to teach parents, children, teachers and seniors about online safety through the (ISC)2 Foundation’s Safe and Secure Online program, which also offers an opportunity to pique student interest in a cybersecurity career at a young age.
  • Feed a student’s interest in cybersecurity by guiding them to one of the many cyber camps, challenges and competitions within our community.

Certainly, the goal of cybersecurity awareness is to inspire users to maintain a daily regimen of sound cyber practices. Let’s not stop at ‘shiny technology’. Instead, let’s get the message out that fortifying the workforce is essential in establishing and maintaining a safe and secure cyber world.

Dan Waddell, CISSP, CAP, PMP, (ISC)2 managing director, North America Region and director of U.S. Government Affairs, was lead author of this peer-reviewed post.

[InfoSecurity Magazine]

Is the Internet of Things safe? New ISACA Survey Shows Significant Perception Gap

As global use of connected devices–including those used for life-saving purposes—grows, a new survey from ISACA shows that there is a significant confidence gap between consumers and cybersecurity and IT professionals. In fact, while 64% of US consumers say they are confident they can control information conveyed through Internet of Things (IoT) devices, 78% of professionals say security standards are insufficient.

According to ISACA’s 2015 IT Risk/Reward Barometer, the number one IoT-related security concern for enterprises is data leakage. Nearly half of the more than 7,000 global professionals surveyed think their IT department is not aware of all of the organization’s connected devices (e.g., connected thermostats, TVs, fire alarms), yet 73% believe the likelihood of being hacked through an IoT device is medium or high. All while 72% say that IoT device manufacturers do not implement sufficient security.

It is clear that further education and awareness efforts are needed. Now. The number of B2B IoT devices is expected to grow from 1.2 billion connected devices in 2015 to 5.4 billion in 2020. That is a lot of important personal and confidential data being shared, transported and used by often unknown entities.

On the flip side, there is a significant business risk if organizations do not embrace IoT. They may lag behind competitors and upstarts, and risk losing revenue and reputation. In addition, enterprises do gain value from IoT. Specifically, global survey respondents reported that the greatest benefits of using IoT are:
* Greater accessibility to information (44%)
* Greater efficiency (35%)
* Improved services (34%)
* Increased employee productivity (25%)
* Increased customer satisfaction (23%)

The key is to balance risk with benefits, and I encourage professionals and consumers to safely embrace IoT devices. To help do this, ensure all devices are updated regularly with security upgrades, take cyber security training, be wary about information shared and stay alert for unusual behavior at all times. The future is bright. Or at least that’s what my connected watch tells me.

Rob Clyde, CISM
International Vice President and Board Director, ISACA
Managing Director, Clyde Consulting LLC

Note: ISACA’s annual IT Risk/Reward Barometer is a global indicator of trust and attitudes. The 2015 study is based on polling of 7,016 ISACA members in 140 countries and additional surveys among 1,227 consumers in the US, 1,025 consumers in the UK, 1,060 consumers in Australia, 1,027 consumers in India and 1,057 consumers in Mexico. To see the full results, visitwww.isaca.org/risk-reward-barometer.

[ISACA Now Blog]

National Cybersecurity Awareness Month: YOU Have the Power to Change Cybersecurity

National Cybersecurity Awareness Month in October is the perfect time to reflect on what you’re doing to overcome the cybersecurity skills shortage. That’s right – you – personally. According to Dr. Jane LeClair, COO for the National Cybersecurity Institute at Excelsior College, the cybersecurity skills shortage is everyone’s problem, and we all have a responsibility to meet this need.

Dr. LeClair believes that in order to shore up the workforce, it’s essential to broaden the pool of candidates beyond typical populations (such as the military and IT). Dr. LeClair sees cybersecurity awareness – both its impact on our daily lives and as a career opportunity – as the perfect vehicle to achieve this.

So, rather than providing courses only to people who are pursuing a formal cybersecurity education and are on a professional track, the NCI offers both career-oriented education AND informal awareness courses and content.

By combining public awareness of cybersecurity issues with career-oriented education, the NCI is hoping to attract as many people as possible to the field. Through robust (often free) courses, such as “Introduction to Cybersecurity,” monthly webcasts and a daily blog, they are hoping to give people a voice to discuss issues that are important to them and an outlet for increasing their knowledge. Dr. LeClair challenges, “If cybersecurity is so vital in our daily lives, shouldn’t we all be doing everything we can to help?”

She states, “People can get complacent, so it’s important that we keep cybersecurity in front of them and keep it fresh. We know people are interested in these issues, and the informal learning piece helps them continue to learn as the industry changes.”

NCI’s ultimate goal is to teach people to like cybersecurity, whether they go on to pursue a career or just have their cybersecurity consciousness elevated. Dr. LeClair asserts, “Cybersecurity is a lifelong, daily learning opportunity. We want people to develop a personal enjoyment and passion for it in order to be strong, lifelong learners.”

The NCI is tackling the issue both from the bottom up and the top down. Through their MBA cybersecurity program, they aim to raise awareness at a managerial level. Dr. LeClair believes organizations have a deep need to realize how important cybersecurity is and that if management embraces the message, it will trickle down to all employees.

These programs are gaining a lot of traction, and Dr. LeClair knows they’re on to something. So, they’ve ramped up their National Cybersecurity Awareness Month efforts this year:

  • Offer daily podcasts.
  • Post a different game every day.
  • Offer a free, live event on cyber law and cyber insurance.
  • Post one case study per week that people can use within their organizations to get discussions going about cybersecurity.

It’s easy to think that by avoiding those links that could crash your company’s network and not falling for those emails from Nigerian princes, you’re doing enough. But what if we all had cybersecurity awareness ingrained in us? What if children began learning about cybersecurity as a career option early in school? What if cybersecurity education was accessible to ALL people, rather than just an elite group already on the path to a lifelong cybersecurity career? We could actually improve the global cybersecurity situation.  For more information on the GAP, please visit https://www.isc2.org/global-academic-program/default.aspx or send an email to academic@isc2.org.

[(ISC)² Blog]

Cybersecurity Information Sharing Act Still Awaits Action in US Senate

Because October is National Cyber Security Awareness Month, conventional wisdom holds that the US Senate will consider cybersecurity information sharing legislation that was introduced in the spring. The Senate, however, has yet to schedule a formal vote on the Cybersecurity Information Sharing Act (CISA) (S. 754).

The proposed legislation aims to defend against cyberattacks through the creation of a framework for the voluntary sharing of cyberthreat information between private entities and the federal government. Companies may share threat indicators and defensive measures with the government, but they must institute appropriate security controls and remove personal information. Liability protection is available for companies choosing to share information, provided they implement the proper controls.

During his State of the Union address earlier this year, US President Barack Obama urged Congress to pass legislation focused on cybersecurity, including the sharing of information. The US House of Representatives passed two similar bills on information sharing in April: the Protecting Cyber Networks Act (PCNA) (H.R. 1560) and the National Cybersecurity Protection Advancement Act (NCPA) (H.R. 1731). One of the key differences in the House bills is that the NCPA Act only authorizes sharing with the Department of Homeland Security, while the PCNA provides companies the flexibility to choose to share cyber threat indicators or defensive measures with a number of different government agencies.

Before a conference committee can convene and iron out differences between the House and Senate versions, the Senate must act. Media reports that the Senate will likely consider the legislation after they return from a brief recess the second or third week in October, but no firm plans have been announced. According to published media reports, the Senate is working to limit amendments in order to fast-track debate on the proposed legislation.

There is a deep divide on whether the CISA legislation should be passed. Some businesses and industries welcome the information sharing and liability protections the Act would provide. Privacy advocates, however, warn that the Act would put individuals’ private information in the hands of the US government.

Montana Williams
Sr. Manager of Cybersecurity Practices, ISACA

[ISACA Now Blog]

English
Exit mobile version