What to do When the Worst Happens: Responding to a Cybersecurity Breach
November 21, 2018 —
Scott L. Satkin & J. Kyle Janecek – Newmeyer Dillion LLPCybersecurity is a growing concern for today's businesses. While it's always advisable to take whatever action possible to avoid a cybersecurity breach, no security measures can be one hundred percent perfect, and malicious actors are always innovating and trying to find new security flaws. The implementation of new technology brings with it new opportunities, but also potentially new vulnerabilities. And hackers have one major advantage – those working to defend against cyber-attacks have to try to find and fix every potential exploit, whereas those on the other side only need to find one. As demonstrated by recent high-profile breaches at Google and Facebook, even massive tech companies with access to vast financial resources and top engineering talent can still fall prey to cyber-attacks. Therefore, understanding how to respond to a breach is just as critical to a company's cybersecurity plan as attempting to prevent one. Below are a few solid tips on how to react when an organization's cybersecurity has been compromised.
Plan in Advance
The best response to a cybersecurity breach begins before the breach ever happens. A written incident response plan is of paramount importance. In the immediate aftermath of a cybersecurity breach, people will be scared and stressed. In those circumstances, they will be more likely to be able to respond effectively if there is a plan laid out for them and they have received training on how to follow that plan. Make sure that employees are trained on the parts of the plan that are relevant to them. Most may only need to know who to report to if they suspect a breach may have occurred, while those who will be involved in the breach response will need more in-depth training. The plan should also be updated regularly to account for staffing changes, new technology, and the evolving legal landscape. The law may also require a plan for responding to cybersecurity breaches, depending on the jurisdiction.
Call Your Lawyer- Early and Often
At the risk of sounding self-aggrandizing, attorneys are critical in responding to a cybersecurity breach. The most obvious reason is to advise clients on their legal obligations and potential liability – and this is indeed an important function. The patchwork of federal and state regulations governing cybersecurity is something laypeople – and even non-specialized attorneys – should navigate with caution. Of equal importance is the preservation of confidential communication under the attorney-client privilege. The presence of an attorney helps to improve the security of information surrounding the response to the breach because correspondence with that attorney is privileged, allowing candid evaluation of the breach. The ability to assert attorney-client privilege regarding an internal investigation and response can be quite useful in the event of a later external investigation or litigation.
To Disclose or Not to Disclose?
An important question that needs to be asked in the wake of a cybersecurity breach is whether the incident must be disclosed, and if so, when, how, and to whom should such disclosures be made? While many understandably wish that their mistakes and failures will never see the light of day, there are also many people who will want to know when a company's cybersecurity has been breached. Shareholders want to know – and may have a right to know – if such a breach has harmed the business. Consumers want to know if their personal information has been compromised so that they can protect against identity theft. Furthermore, state breach notification laws may mandate certain disclosures to consumers depending on facts surrounding the breach. Legal requirements from states, the federal government, and even foreign entities may also require companies to provide notices to one or more regulatory agencies.
An attorney can advise on whether a company is legally required to provide any notice in the aftermath of a data breach, but even though notice may not be a legal requirement in a particular set of circumstances, it may still be prudent to give it anyway. Google decided not to disclose the recent breach of data from its Google+ service to avoid a PR and regulatory backlash, but the fact that it had happened eventually leaked out anyway. Even though legal experts have opined in the aftermath that Google likely was not obligated to disclose the breach, the fact that it did not caused exactly what Google attempted to avoid, but with magnified effect. "Google Experiences Consumer Data Breach" may not have been a good headline, but "Google Hides Consumer Data Breach" was a worse one.
Remember: Protection Is Key
No company wants a cybersecurity breach, but past experience has increasingly demonstrated that this is not a question of "if" but rather one of "when" and "how bad." Planning ahead and knowing what to do when a data breach does happen can ensure that an organization bounces back from a breach as smoothly and painlessly as possible.
Scott Satkin and Kyle Janecek are associates in the Cybersecurity group of Newmeyer & Dillion. Focused on helping clients navigate the legal dispute implications of cybersecurity, they advise businesses on implementing and adopting proactive measures to prevent and neutralize cybersecurity threats. For questions on how they can help, contact Scott at scott.satkin@ndlf.com and Kyle at kyle.jancecek@ndlf.com.
About Newmeyer & Dillion
For more than 30 years, Newmeyer & Dillion has delivered creative and outstanding legal solutions and trial results for a wide array of clients. With over 70 attorneys practicing in all aspects of cybersecurity, business, employment, real estate, construction and insurance law, Newmeyer & Dillion delivers legal services tailored to meet each client's needs. Headquartered in Newport Beach, California, with offices in Walnut Creek, California and Las Vegas, Nevada, Newmeyer & Dillion attorneys are recognized by The Best Lawyers in America© and Super Lawyers as top tier and some of the best lawyers in California, and have been given Martindale-Hubbell Peer Review's AV Preeminent® highest rating. For additional information, call 949.854.7000 or visit www.ndlf.com.
Read the court decisionRead the full story...Reprinted courtesy of
Virginia Chinese Drywall and pollution exclusion
May 27, 2011 —
CDCoverage.comIn Nationwide Mut. Ins. Co. v. The Overlook, LLC, No. 4:10cv69 (E.D. Va. May 13, 2011), homeowner Edmonds sued insured developer/general contractor Overlook seeking damages resulting from defective Chinese drywall installed in Edmonds’ home. Overlook’s CGL insurer Nationwide defended Overlook under a reservation of rights and filed a declaratory judgment action. The federal district trial court granted Nationwide’s motion for summary judgment.
Read the full story…
Reprinted courtesy of CDCoverage.com
Read the court decisionRead the full story...Reprinted courtesy of
New Mexico Holds One-Sided Dispute Resolution Provisions Are Unenforceable
November 05, 2024 —
Bill Wilson - Construction Law ZoneDispute resolution provisions that grant one party the unilateral right to choose either litigation or arbitration to resolve disputes are common in the construction industry. The main difference between the two forums is that courts are more likely to strictly enforce contract terms as written as well as the applicable law, while arbitrators make decisions on more equitable considerations, untethered to the contract terms and—to some degree—the law. The party with the sole discretion to select the dispute resolution procedure can select the process most beneficial to its interests based on the nature of the dispute, regardless of who brings the claims. In Atlas Electrical Construction, Inc. v. Flintco, LLC, 550 P.3d 881 (N.M. Ct. App. 2024), the Court of Appeals of New Mexico recently held that an arbitration provision in a subcontract, under which the contractor retained the exclusive right to choose whether disputes arising under the subcontract were litigated in court or arbitrated was unreasonably one-sided, substantively unconscionable, and unenforceable.
The Atlas Electrical case involved two sophisticated entities with equal bargaining strength to negotiate the terms of a subcontract. The parties agreed to a subcontract provision which provided in the relevant part:
In the event [contractor] and [subcontractor] cannot resolve the dispute through direct discussions or mediation … then the dispute shall, at the sole discretion of [contractor], be decided either by submission to (a) arbitration … or (b) litigation …
Read the court decisionRead the full story...Reprinted courtesy of
Bill Wilson, Robinson & Cole LLPMr. Wilson may be contacted at
wwilson@rc.com
Massive Danish Hospital Project Avoids Fire Protection Failures with Imerso Construction AI
December 23, 2023 —
Aarni Heiskanen - AEC BusinessEnsuring regulatory compliance of firewall constructions is getting a high-tech boost. Over the past 16 months, the construction team responsible for the iconic new Nyt Hospital Nordsjælland near Copenhagen used Imerso construction AI technology to achieve remarkable results. By using Imerso, the team enhanced work productivity while preventing costs and delays worth €5.2 million during the construction of the superstructure.
Inspired by this success, the team led by Project Manager Anders Kaas has since been eager to explore the potential of the technology in other areas. The opportunity arose to address a topic that has traditionally posed significant challenges and expenses in numerous construction projects – ensuring regulatory compliance of fire barriers and firewall constructions.
Read the court decisionRead the full story...Reprinted courtesy of
Aarni Heiskanen, AEC BusinessMr. Heiskanen may be contacted at
aec-business@aepartners.fi
Freddie Mac Eases Mortgage Rules to Limit Putbacks
May 13, 2014 —
Clea Benson and Jody Shenn - BloombergFreddie Mac, which along with Fannie Mae has forced home lenders to buy back tens of billions of dollars of flawed mortgages, said the companies are loosening rules that made banks more cautious about extending credit.
The government-backed companies will expand the pool of loans that become exempt from putback requests, Freddie Mac (FMCC) said in a memo to lenders today. Under the new rules, loans will typically be spared from such demands if borrowers make 34 of their first 36 scheduled monthly payments. Previously, borrowers needed to avoid delinquency for the first three years.
Ms. Benson may be contacted at cbenson20@bloomberg.net; Ms. Shenn may be contacted at jshenn@bloomberg.net
Read the court decisionRead the full story...Reprinted courtesy of
Clea Benson and Jody Shenn, Bloomberg
Denial of Coverage For Bodily Injury After Policy Period Does Not Violate Public Policy
May 12, 2016 —
Tred R. Eyerly – Insurance Law HawaiiThe Rhode Island Supreme Court agreed that the insurer had no coverage obligations for bodily injury occurring after the policy had been canceled. Hoesen v. Lloyd's of London, 2016 R.I. LEXIS 41 (R.I. March 24, 2016).
The plaintiff, Mark Van Hoesen, was seriously injured on July 23, 2012, when he fell from a deck of his house. He sued his contractor, Brian Leonard, alleging that the deck had been negligently constructed. Lloyd's, Leonard's insurer, was later named as a defendant. Lloyd's admitted it issued the policy to Leonard, but it was cancelled on August 29, 2007. Even if it had not been canceled, the policy had expired long before the injuries alleged in plaintiff's complaint occurred.
Read the court decisionRead the full story...Reprinted courtesy of
Tred R. Eyerly, Insurance Law HawaiiMr. Eyerly may be contacted at
te@hawaiilawyer.com
New Jersey Judge Found Mortgage Lender Liable When Borrower Couldn’t Pay
August 06, 2014 —
Beverley BevenFlorez-CDJ STAFFAccording to the New Jersey Law Journal, Freedom Mortgage Corporation has to pay treble damages and legal fees after Bergen County Superior Court Judge Gerald Escala found the company “liable under New Jersey’s Consumer Fraud Act for providing a home refinance loan to a 70-year-old borrower it should have known would be unable to make the payments.”
“Escala further ruled that Freedom Mortgage must hold off on obtaining a foreclosure judgment for a year to allow an opportunity for borrower Mamie Major to look for someone to buy the property or to obtain refinancing elsewhere,” the New Jersey Law Journal reported.
Read the court decisionRead the full story...Reprinted courtesy of
Resilience: Transforming the Energy Sector – Navigating Land Issues in Solar and Storage Projects | Episode 3 (11.14.24)
December 17, 2024 —
Pillsbury's Construction & Real Estate Law Team - Gravel2Gavel Construction & Real Estate Law BlogIn the latest
episode of the Resilience podcast, colleague
Shellka Arora-Cox and Laura Pagliarulo, CEO and founder of SolaREIT, get down to the nitty-gritty in a discussion of the interplay of solar power capacity, generation and land use.
(Editor’s note: The following transcript has been edited for clarity.)
Welcome to Resilience, the vodcast where we talk about the most pressing challenges and the biggest opportunities in the energy sector. I’m your host, Shellka Arora-Cox, a partner at Pillsbury Winthrop Shaw Pittman. I’m thrilled to have Laura Pagliarulo, the CEO and founder of SolaREIT, with me today.
Read the court decisionRead the full story...Reprinted courtesy of
Pillsbury's Construction & Real Estate Law Team