Help and advice for damage limitation
A listed law firm has recently hit the headlines for being the victim of a cyber-attack which saw the loss of some of its client data. The firm dealt with the breach quickly and effectively and credited its security controls for limiting its impact. The situation the firm found itself in is far from an isolated instance – indeed the statistics paint a shocking picture. According to recent research, up to 88% of UK companies have suffered data breaches in the last year and Hiscox claims that every 19 seconds, a small business in the UK is successfully hacked!
The pandemic has only intensified the problem. The unprecedented digital migration of services and goods, with many companies moving online for the first time, under major time pressure and the huge trend of working and learning from home (something which looks set to continue at a higher level than pre-pandemic) means cybercrime is at an all-time high.
But before you despair, we can learn valuable lessons from this recent attack. With clear processes and open, transparent communication, you can limit the reputational and financial damage to your business and minimise any regulatory consequences. Whilst a data breach may not always involve personal data, failure to look after the personal data that you’ve been entrusted with in accordance with the requirements of data protection law, will see you facing scrutiny and potential penalties from the Information Commissioner’s Office (ICO).
Some practical tips to manage a data breach
If your data has been breached, the most effective and efficient way of dealing with the situation is to follow a plan or checklist that addresses the following questions:
- What type of breach was it (i.e., what data was leaked or hacked) and how did it occur?
- Did the breach involve personal data and/or commercially confidential data?
- Did the data belong to your organisation only or does the breach also affect your customers and/or suppliers?
- What systems, applications, locations or transactions were involved?
- What are the potential ramifications?
- Commercial: does the leak have a commercial effect? Does it have implications for an ongoing transaction or funding round for example?
- Legal (non-regulatory): does the leak potentially indicate a breach of your confidentiality obligations?
- Regulatory:
- if personal data is involved, what is your organisation’s role with respect to that personal data (i.e. are you a Controller or a Processor) and what obligations flow from that?
- If your organisation conducts any kind of regulated work (such as financial services), what obligations do you have?
- Operational:
- Do any IT systems or applications need to be quarantined?
- Do you need to switch to a business continuity or disaster recovery plan?
Once you have ascertained the scope and severity of the event, it is important to communicate effectively with the relevant stakeholders. There is a balance to be struck between communicating quickly and communicating in detail and you must consider what you are trying to achieve with each item of communication. Be aware that, though you may feel under time pressure, if you publicly announce information that later turns out to be incorrect or incomplete, you may inadvertently give the impression that you are not handling the situation well. Better to investigate carefully and then release information rather than risk damaging your reputation further.
So, first you need to communicate within your organisation. Having clear, agreed protocols will make this easier. Constitute a working group whose responsibility it is to respond to data breach incidents and manage the dissemination of information. Remember, a blanket announcement to the entire business is unlikely to be appropriate but determining what information needs to be shared with each of your employees is something that you can do to a great extent before any incident occurs.
Your team also needs to ascertain what external stakeholders or agencies need to be told. These could include customers, investors, third-party suppliers or vendors so it is important that you look carefully at all your business relationships and processes to understand fully the potential risk of an attack. In our experience, organisations that undertake this exercise often discover things about their business, such as historical suppliers that they were unaware they were still using, so it is a worthwhile process anyway. Depending on the incident or your business, you may also have to inform the ICO or the media. Your plan should specify whose role this is.
Examples of how our lawyers have helped clients deal with data breaches
Our lawyers have a lot of experience in this field and have helped many businesses deal with complex and potentially very damaging situations. Because our lawyers work closely with the companies they support, they are on hand to react quickly, decisively and of course lawfully. The following are examples of situations that our TLD lawyers have encountered which demonstrate the complexities that can arise from data breaches and the benefit of clarity, transparency and decisive action:
- It is worth remembering that most data breaches do not arise from malicious attacks. Human error is the most frequent cause of a data breach and is the reason why regular staff training is key. One of our lawyers had experience of a breach that occurred because settings segregating customer access weren’t reapplied after an update of the business’ online service. Even though the mistake was corrected within minutes, the breach required management in accordance with GDPR requirements and the provision of transparent and detailed logs to the Data Protection Officer so that an assessment could be made as to whether the breach was reportable.
- Our lawyers have also dealt with breaches that have not been initially recognised because they have been reported via chat bot or by email to a sales team email address. Having guided the business through dealing with the breach, we have then helped update policies and procedures and delivered training to minimise the risks of further occurrences.
- Recently, a TLD lawyer helped a technology client (a SaaS provider) manage a data leak relating to a third-party provider of an “add-on” product. In this instance, there was a possibility of financial information being disclosed and the decision was made to delay notification until it was ascertained whether this was the case or not. As it turned out, only a small batch of personal email addresses was released and no public announcement needed to be made – only the relevant data controller had to be notified.
- Our clients have also benefitted from the value that a lawyer can bring to negotiations. One of our lawyers recently challenged a claim for damages, recognising that no real damage had been sustained and ultimately saved his client from settling an unnecessary claim.
How can The Legal Director help you?
Effective planning and robust processes help enormously in mitigation and containment of any data breach incident, and we can ensure you do this properly. Working closely in your business, we can help you identify the group of stakeholders whose responsibility it is to deal with a breach and set out specific areas of responsibility and decision-making for each stakeholder. We can create or revise your data breach processes and procedures and prepare training for staff to help them recognise a breach and understand their responsibilities. It is imperative that everyone within your organisation knows the importance of cyber security and the protocols to follow in the event of an incident. Our lawyers are adept at communicating this information effectively and engagingly and can help you produce clear guidance for your staff. Graphics or flowcharts illustrating who to notify in a breach situation is a good example of this.
We can also help you maintain and update your policies and procedures, mandating regular testing of the plan and gathering feedback from stakeholders. In the event of an attack, we can support you with any compliance issues or legal obligations and can help satisfy the requirements of Data Protection Officers and the ICO. Should a dispute arise from a breach, we will put the weight of our experience and expertise into fighting your corner.
A data breach can happen to any organisation, but those who are well prepared will likely emerge from a breach with their reputation intact and that can only be good for business. If you would like us to support your company with cyber security or data breach management, or would just like a conversation about how we can help, please do get in touch on 020 3056 8538 or info@thelegaldirector.co.uk for an informal chat.
Related Posts
-
Are you planning to sell your business or looking for funding? Our lawyers can help you to manage your legal affairs on a flexible, part-time basis.

