Steady Counsel
At A Time Of Confusion & Uncertainty
The threat posed to organizations of all types and sizes from data breaches and other cybersecurity events is unprecedented and, by all accounts, only set to increase. Whether the threat emanates from a for-profit hacking group engaged in ransomware activity or a nation-state actor seeking valuable intelligence, the threat vectors come from practically all sides. The reality is that “it is a question of when, not if,” a particular company or other organization will experience an incident. From smaller breaches to ones of great proportions, such as AT&T’s data breach that resulted in “nearly all” customers’ data being disclosed.
Once hit with a data breach or cybersecurity event, the fallout to a business can be immense, not only in terms of regulatory and legal expenses but also reputationally. The legal dynamics of data breach compliance are complex and overwhelming due to the need to comply with patchwork breach notification regimes on the state level (such as the CCPA as amended by the CPRA), federal level (such as HIPAA), and international regulatory authorities (such as the GDPR). Though the legal frameworks are criticized, failure to comply with relevant legal obligations in the event of an incident or data breach can result in hefty fines. Further, strategically protecting the organization, including the attorney-client privilege, is critical. For example, maintaining the confidentiality of subject matter experts’ analysis of security posture pre-breach and the extent of the incident can be pivotal in limiting the cost of a cyber incident, including as it relates to post-breach private action.
At RICHT, we focus on helping clients navigate the confusing web of laws that come into play in a data breach or cyber event, stressing mitigation and protecting client interests. Specifically, our services include pre-planning such as tabletop exercises (TTXs) and counseling clients in real-time experiencing a breach with technical experts under our RICHT&Co. offering.
Our Data Breach & Incident Response Services
Preparedness & Prevention
Incident Response Plans
Regulatory Investigations
Vendor Risk
Breach Notification Compliance
Cyber Insurance Review