General Counsel, Heads of Legal and Heads of compliance play a critical role when there’s a cybersecurity issue. Along with the communications professionals, these roles ensure that the Board is well positioned to make the best decision by providing independent counsel on the implications of those decisions.
The three phases of cybeesecurity (before, during, after) require different inputs from an organisation’s most senior lawyers and risk managers. Now that cyber risk is ranked as the number one risk to business, this needs to be high on the agenda of the GC/compliance team.
In our experience, the best thing to do is get broadly ready for how you’ll respond to a cyber issue, and then tailor your advice to the specifics of the incident.
General Counsel, Heads of Legal and Heads of compliance play a critical role when there’s a cybersecurity issue. Along with the communications professionals, these roles ensure that the Board is well positioned to make the best decision by providing independent counsel on the implications of those decisions.
The three phases of cybeesecurity (before, during, after) require different inputs from an organisation’s most senior lawyers and risk managers. Now that cyber risk is ranked as the number one risk to business, this needs to be high on the agenda of the GC/compliance team.
In our experience, the best thing to do is get broadly ready for how you’ll respond to a cyber issue, and then tailor your advice to the specifics of the incident.
Understanding the particular compliance aspects that relate to data and your organisation and industry will help inform which products and services to purchase. Understanding how the products and services work will allow you to decide if they fit with those requirements e.g. where are servers hosted? How is data stored? In our experience, lawyers can add a huge deal to the selection of the right cybersecurity product or service as long as they are brought in early in the process.
The roles of compliance and legal will also help to inform your scenario plans. A dry run of a cybersecurity incident will throw up the kinds of challenges and tensions you are likely to encounter when the issue arises in real life. There will always be a healthy, natural tension between compliance and communications but it is best to know where this lies ahead of an incident.n
If a cyber incident affects your organisation, then you’ll need to be at the heart of decisions that are made which will have regulatory and other implications.
You’re best positioned to know what has to be reported and when and to whom. You’ll also be able to counsel on the courses of action available. The work done in this stage is often the bedrock of your recovery from the incident.
Regulators wants to know that you did the best you could given the circumstances – so making the right moves at this stage is essential.
Cyber incidents have a long tail and stakeholders have long memories. Some organisations have adopted a ‘lessons learned’ approach to their own data breaches and used it to lead their markets.
What will your recovery plan be? Compliance will take you only so far – how will you thrive post-incident?
How will the legal team and compliance work to drive the organisation forward?
Secure email (SMAIL) for small and medium-sized organisations is now a reality. Communicate with confidence: use SMAIL.
Make sure that scammers are locked out of your main digital asset: your website. Find, Fix & Secure with SiteFix.
Using Digital ID means your clients and customers know who they’re dealing with every time. Transact with confidence.
Secure your website – and show the world that it’s secure. Use our certificate services for SMEs.
Our full suite which covers code protection, GDPR tracking, threat monitoring, and network security.
We provide products for start-ups and smaller accountants, insurers and retailers, medium-sized law firms and financial services companies, for schools and biotechs.
We’re trusted to solve cyber-security for major organisations across the public, insurance, financial services, legal, pharmaceutical and accountancy sectors.
We provide products for start-ups and smaller accountants, insurers and retailers, medium-sized law firms and financial services companies, for schools and biotechs.
We’re trusted to solve cyber-security for major organisations across the public, insurance, financial services, legal, pharmaceutical and accountancy sectors.
Doddie Weir (1970-2022)
|