Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

DSK Bank
Dimitar Mutafchiev, Data Protection Officer / Head of Data Protection Section
Data Breach Management


So - what can we do to address this?
Well – if you have asked yourself that question for the first time now and you are not in charge of a data processing related company, that has been established last week – you are probably going to have pretty unpleasant experience both short and long term. In the past 10 years, managers around the globe had plenty of opportunities to conclude that the situation that we are now in is coming for sure – boom in data collection and processing across the board, regulatory changes aimed to address that by enhancing security and data protection by implementing more stringent rules to comply with, rapid and sustainable long-term increase in cyber-attacks related risks, several high-profile cases of cyber-attacks in different sectors, which resulted in multimillion loses and deterioration of consumer trust. So, let’s explore the world in which managers saw the signs and took actions.
BASE LINE
The basic design, around which the overall data breach incident response philosophy should be built, is the idea that crisis, by definition, happens as a surprise. So lengthy and heavy procedures and complicated decision-making algorithms are not a good idea. It is better to purposefully increase the level of management and employee awareness and understanding on topics such as information security, data protection and regulatory framework, in which the company operates. Тhis can be achieved through advanced training programs and continuous communication that this is a priority.
My opinion is that you need an initial response action list that can fit into one page and with enough flexibility to account the variables. It is also critical to identify the people, who have the talent and knowledge to manage the crisis, and include them into first responders’ team.
A few examples, that need to be predefined, that I consider rudimental for successful crisis management – clear and fast reporting lines so the people that need to know – knows; small knowledgeable and talented management team that is capable to draft initial action plan in
short notice and have the authority to execute it; introduce communication tools so everyone in the team receives prompt information updates and are in line with overall development; keep the action plan simple and focused on the immediate threat; begin investigating the possible scenarios on where the breach came from and how it is affecting core operational capabilities of the company; keep a log of the events; know your supervisory and statutory obligations in order to prepare a proper communication – to authorities, internally to management and employees and external – to customers, press and if needed - shareholders;
The first 24 hours is a game of priorities.
As mentioned above, the initial surprise should be substitute in timely manner with rational assessment and analysis.
In my opinion the first two vectors, that should be inspected, are: is it an outside attack or an inside job and then to determine the scope.
If it is the first option then the most important question is: “Is it still ongoing? Are they now in our network/resources?” This is crucial for several reasons - if the illegal access is not over yet, you cannot trust your internal systems, which requires the inclusion of external resources for crisis management and also you may want to shut down parts or the whole system in order to avoid further damage. This can cause chaos within the organization and can heavily deteriorate the operations, which ultimately will lead to loses - so it’s kind of a last resort.
The internal attack or inside job is more welcome scenario due to the fact that if handled right it is more likely to close the case fast, with relatively low levels of damage and public focus. It is rare for employees to just want to hurt the company - in most cases such actions are justified by monetary incentive a.k.a. blackmail.
-
In order to be successful and effective in crisis management you need a tailored approach, which takes advantage of organization's strengths, while mitigating the adverse effects of the known weaker links
The next big topic is how the event affects core operational capabilities of the company. If it doesn't - great. But if there is disruption, it is very important to create the necessary organization in order to respond and to strengthen communication channels - for example, if you cannot serve customers in physical offices, it is a good idea to provide additional staff for call centers and to try to compensate for the extra load to digital channels. You may also have to adopt temporary “war-time” customer service procedures because the “peace-time” one could be impossible to follow.
Next is the initial game plan – high level tasks that aim to manage the crisis and/or to obtain additional information and facts on the origins and root causes. Short deadlines will help to keep the plan operative in nature and will enhanced the information flow among stakeholders, which will lead to coordinated efforts within the different domains of the organization.
At this stage you should start preparing for regulatory communication. First of all, the circle of mandatory regulators and supervisors, that need to be notified, should be clear before the data breach. Typically, this includes sector supervisor authority /National bank, financial commission or other regulating legislative body/, law enforcement authorities /preferably cyber-crime units/ and the Data protection authority /DPA/, if you fall under GDPR scope. The latter implies taking additional step, namely a risk assessment on the impact of the breach to the rights and freedoms of natural persons involved, based on which management can take an informed decision on whether there is an obligatory requirement to notify the DPA. Data breach management under GDPR is a universe of its own and this article is not enough to develop the topic in appropriate detail, so I laid down only the basics.
Based on the results of the above listed measures and in compliance with management decisions on how to manage the crisis, by the end of the first 24 hours you should be ready with initial PR and communication plan. /this is given only if the breach is not already public knowledge - for example data dump on file exchange website/ Тhe earlier a plan is prepared and approved, the more time you will have to communicate it internally to managers and employees, conduct training if necessary, evaluate feedback, make changes if needed, arrange media coverage, etc.
In conclusion, there is no one-size-fits-all solution for data breach management that you can read in a book or methodology and simply effortlessly apply. In order to be successful and effective in crisis management you need a tailored approach, which takes advantage of organization's strengths, while mitigating the adverse effects of the known weaker links. Тhe possible attack vectors, the specifics of different companies, the various regulatory and supervisory regimes and requirements, the business considerations makes it hard to plan in detail so it is better to create a flexible framework, which takes into account the main domains and considerations and leave the rest to the talent of the team to demonstrate their problem solving capabilities.

