What are the critical steps that legal departments must take during the first 24 hours of cybersecurity incident response?
Contact external legal counsel
For more significant cyber-attacks, one of the first steps that an organization should take, during the first 24 hours, is to engage their external cybersecurity counsel to advise on incident response strategy and to maximize the privilege that can be asserted over communications and documents relating to the incident.
Outside counsel can guide you through every step of the process, helping your organization define and implement the various workstreams, timing, and risk considerations appropriate for the particular incident. The Hogan Lovells global incident response team has accumulated extensive experience across thousands of incidents, and can bring invaluable foresight that will help your organization avoid costly mistakes. It is vital to engage experienced external counsel to guide you through this critical 24-hour period and beyond. (And later in the process, outside counsel can help you identify contractual and legal notification obligations that may have been triggered by the incident and prepare notifications to regulators, customers, and individuals.)
Launch a privileged forensic investigation
Once a cybersecurity incident has been detected, it is important to quickly learn about what happened, where it came from, and the extent of compromise, while also confirming that the incident is contained, the attacker is eradicated, and damage is mitigated.
For more significant incidents, your outside counsel should quickly engage third-party cybersecurity experts to conduct a forensic investigation under privilege. Having the investigation directed by external legal counsel will help to bolster claims that forensic findings, reports, and communications related to the incident are protected by the attorney-client privilege and work product doctrine, which will be critical if the incident results in litigation and also may be helpful for regulatory enforcement.
Assess insurance coverage
Cybersecurity incidents can be costly and some insurers require that you notify them of incidents quickly. Your organization will want to quickly identify any possible insurance policies that may provide coverage. Counsel can help you assess your policy and, if applicable coverage exists, notify your insurer of a potential incident. Throughout incident response, your insurer may request certain information, and external legal counsel can help you present the incident accurately in a way that minimizes exclusions.
Develop a communications strategy
Perhaps a cybersecurity incident has brought a business function to a screeching halt and your customers are asking questions. Or perhaps a threat actor has identified your organization as its victim or publicly leaked your data online. In these and many other scenarios, you will want to quickly develop a public relations and communications strategy to address inquiries from customers, employees, the media, and other interested parties. External legal counsel can help you do so in a way that addresses these parties’ concerns while helping you avoid making statements that could increase the risk of litigation or regulatory enforcement actions down the line.
Consider engaging a negotiation vendor
In the event of a ransom demand, you may want to consider engaging a specialized negotiation firm. Even if you do not want to pay, you should discuss options with outside counsel, as often the negotiation process can be a useful way to gain information or delay destructive actions by the threat actor.
Consider contacting law enforcement
Consider contacting law enforcement to gain intelligence about your attacker. In the case of ransomware, it can be especially helpful to contact law enforcement, as the large ransomware gangs typically have the full attention of dedicated law enforcement teams who can provide significant information and recommendations, and, in rare cases, can sometimes even assist in retrieving stolen data or cryptocurrency, or providing decryption tools. In cases where an organization is considering paying a ransom, it is even more important, as working with law enforcement can mitigate risk that you may be paying a sanctioned party. In some cases, insurers may also require that the incident be reported, and regulators and consumers tend to regard this positively.
So how can your organization best prepare to execute these steps when an incident occurs?
BE PREPARED. You can take steps today that will pay off down the road.