Cybersecurity Risk: Trends, Preparedness, and Response
John Pavolotsky
Partner, Technology & Intellectual Property
Abstract
Data breaches, cyber incidents, and related litigation continue to challenge organizations across industries. In this video, John Pavolotsky discusses emerging cybersecurity trends, practical steps companies can take to reduce risk, and the importance of advance planning. He highlights key elements of an effective cybersecurity program, including risk assessments, incident response planning, insurance coverage, and coordinated communications strategies to help organizations respond effectively when an incident occurs.
Transcript
I'm John Pavolotsky. I'm a partner in the technology and IP group in the San Francisco office. I'm co-chair of our privacy, cyber, and AI practice.
In cybersecurity matters, we are seeing a number of trends. One, the pace of data breach litigation is not abating. Claims and litigation are still being brought, and that could be a function perhaps of the availability of AI tools and might be enabling some of these attacks. The cyber claims are typically covered by insurance.
We're noticing that many clients do have insurance, and so we will work with insurance carriers to help advise the companies in that.
Beyond that, there's certainly things that companies can do to help mitigate risk. These include having in place a robust and tested written information security program, doing an annual risk assessment, preferably by an external, credible third party to understand what data is being processed, how it's being protected, what the vulnerabilities are, and making sure that mitigation is in place to help limit risk.
If there has been a security incident, and bear in mind that a security incident is not necessarily a breach. A breach requires a legal determination, reviewing the various applicable state statutes on breach notification to determine whether or not there's been a breach. And then whether or not there's been a breach or if there has been, it may or may not be reportable or notifiable.
If a company is impacted or experiences an incident and there is not a plan to deal with it, then arguably it's already too late, possibly, to get it right. And so the advice here is to make sure that there is an incident response plan in place. That it is tested periodically, that a law firm is engaged before the incident happens, that there's insurance in place, and that there's also a forensics firm that is ready to do the investigation as soon as the incident happens.
And then making sure as well, and last but not least, that there is an internal and external communications plan to handle those first 24 to 48 hours of investigation.
So in short, if there's a cyber incident, there has to be work done in advance to get the best possible outcome.
Related Professionals
- Partner
