ZeroHour
CyberScooppublished ()ingested @HowellONeill

3 Strategies For Addressing Sensitive Legal Cybersecurity Issues

criticalExploit / PoC exploited in the wildimportance 60
Full article705 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

In this op-ed, two expert attorneys gives some advice on how to keep cyber risks from turning into legal risks.

(Getty Images)

Three years after enacting one of the most exacting cybersecurity regulations in the United States, the New York State Department of Financial Services (NYDFS) recently filed its first cybersecurity enforcement action. This enforcement action shows the importance of mitigating legal risks when addressing cybersecurity risks.

NYDFS alleged that First American Financial, one of the country’s largest providers of title insurance, failed to properly address a known security vulnerability on its website that allowed millions of documents containing consumers’ nonpublic information to be exposed.

After the vulnerability surfaced in a penetration test, First American misclassified the vulnerability as “low,” failed to investigate the vulnerability in the timeframe set by the company’s cybersecurity policy, as well as the scope of documents that were exposed, and neglected to heed the recommendations of its in-house cybersecurity team.

The timing of the NYDFS’s inaugural enforcement action shows that cybersecurity remains a key priority for government agencies, even during the COVID-19 pandemic. Private litigants are increasingly prosecuting cybersecurity claims, too. While we await the results of the NYDFS’s hearing, three key lessons can be learned:

 Involve outside counsel when sensitive cybersecurity issues arise. The NYDFS’s charges detail First American’s employees’ internal confusion and disagreements about how to address the vulnerability. Outside counsel can coordinate a response and minimize the chance that employees will arrive at conflicting conclusions about a security vulnerability. Outside counsel can establish a privileged channel for communications, which will reduce the likelihood of unflattering documents relating to a data incident becoming evidence in a legal proceeding. Organizations should retain competent cybersecurity counsel before cybersecurity issues arise.

 Second, use outside cybersecurity experts. Under the direction of outside counsel, cybersecurity experts should be brought in to provide a detached, objective assessment of sensitive technical issues. These experts will lessen the possibility that an organization’s employees will have disputes on how to respond to a cybersecurity issue. From the perspective of employees, these disputes can destroy morale. From the perspective of government agencies and litigation adversaries, these disputes can often be looked at maliciously, compounding the problem brought on by a cybersecurity failure.

 Third, remain vigilant against evolving risks. In April, the NYDFS issued guidance urging vigilance against heightened pandemic-related risks stemming from increasing remote work arrangements, phishing and fraud, and outside vendors. Organizations should periodically review their cybersecurity programs to ensure they mitigate new risks and follow evolving best practices.

Charles J. Nerko and Daniella Casseres are principal attorneys at Offit Kurman, P.A. The authors can be reached at [email protected] and [email protected].

More Scoops

Former President Donald Trump gives a speech on tax reform at the Heritage Foundation’s President’s Club Meeting at a hotel in Washington, DC, on October 17, 2017. (MANDEL NGAN/AFP via Getty Images)

An opportunity for Trump’s deregulation journey: Cybersecurity harmonization

The incoming administration should lean into its efficiency push by taking on the patchwork system of cyber regulations.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cybersecurity-lawyers-nydfs-charles-nerko-daniella-casseres/