More Posts

We are pleased to announce the release of the first BakerHostetler Data Security Incident Response Report, which provides insights generated from the review of more than 200 incidents that our law firm advised on in 2014. It looks at the nature of the threats faced by companies, as well as detection and response trends, and the consequences that follow. The report shows that human error was the number one cause of data security incidents we worked on last year, with employee negligence responsible for incidents 36% of the time. Other leading causes were theft by outsiders (22%), theft by insiders (16%), malware (16%) and phishing attacks (14%). The full report can be found here.

The report also makes clear that no industry is immune from threats to its sensitive information. Industries represented in the report include education, financial services, retail, insurance, technology, entertainment, hospitality and, in particular, healthcare sectors. While healthcare topped the chart of industries affected, that is due in part to strict data breach notification laws that all healthcare providers must follow.

It is important for companies to understand that data security is not just an issue for retailers, financial firms and hospitals. Incidents do not only occur at businesses that have payment card data or protected health information. Privacy and data security issues are firmly entrenched as a significant public and regulatory concern and a risk that executive leadership and boards of directors must confront.

Rapid Response is Critical

Our report shows that incidents were self-detected 64% of the time. Of the incidents reported by a third party, 27 % were due to theft. A quick response to an incident is important for several reasons, including creating the opportunity to stop an attack in its early stages before sensitive data is accessed, preserving available forensic data to enable a precise determination of what occurred, and generating affirmative evidence to help the company respond in a way that protects  affected  individuals and minimizes potential financial and reputational consequences.

Detection Times Must be Shortened