What to do When the Worst Happens: Responding to a Cybersecurity Breach
November 21, 2018 —
Scott L. Satkin & J. Kyle Janecek – Newmeyer Dillion LLPCybersecurity is a growing concern for today's businesses. While it's always advisable to take whatever action possible to avoid a cybersecurity breach, no security measures can be one hundred percent perfect, and malicious actors are always innovating and trying to find new security flaws. The implementation of new technology brings with it new opportunities, but also potentially new vulnerabilities. And hackers have one major advantage – those working to defend against cyber-attacks have to try to find and fix every potential exploit, whereas those on the other side only need to find one. As demonstrated by recent high-profile breaches at Google and Facebook, even massive tech companies with access to vast financial resources and top engineering talent can still fall prey to cyber-attacks. Therefore, understanding how to respond to a breach is just as critical to a company's cybersecurity plan as attempting to prevent one. Below are a few solid tips on how to react when an organization's cybersecurity has been compromised.
Plan in Advance
The best response to a cybersecurity breach begins before the breach ever happens. A written incident response plan is of paramount importance. In the immediate aftermath of a cybersecurity breach, people will be scared and stressed. In those circumstances, they will be more likely to be able to respond effectively if there is a plan laid out for them and they have received training on how to follow that plan. Make sure that employees are trained on the parts of the plan that are relevant to them. Most may only need to know who to report to if they suspect a breach may have occurred, while those who will be involved in the breach response will need more in-depth training. The plan should also be updated regularly to account for staffing changes, new technology, and the evolving legal landscape. The law may also require a plan for responding to cybersecurity breaches, depending on the jurisdiction.
Call Your Lawyer- Early and Often
At the risk of sounding self-aggrandizing, attorneys are critical in responding to a cybersecurity breach. The most obvious reason is to advise clients on their legal obligations and potential liability – and this is indeed an important function. The patchwork of federal and state regulations governing cybersecurity is something laypeople – and even non-specialized attorneys – should navigate with caution. Of equal importance is the preservation of confidential communication under the attorney-client privilege. The presence of an attorney helps to improve the security of information surrounding the response to the breach because correspondence with that attorney is privileged, allowing candid evaluation of the breach. The ability to assert attorney-client privilege regarding an internal investigation and response can be quite useful in the event of a later external investigation or litigation.
To Disclose or Not to Disclose?
An important question that needs to be asked in the wake of a cybersecurity breach is whether the incident must be disclosed, and if so, when, how, and to whom should such disclosures be made? While many understandably wish that their mistakes and failures will never see the light of day, there are also many people who will want to know when a company's cybersecurity has been breached. Shareholders want to know – and may have a right to know – if such a breach has harmed the business. Consumers want to know if their personal information has been compromised so that they can protect against identity theft. Furthermore, state breach notification laws may mandate certain disclosures to consumers depending on facts surrounding the breach. Legal requirements from states, the federal government, and even foreign entities may also require companies to provide notices to one or more regulatory agencies.
An attorney can advise on whether a company is legally required to provide any notice in the aftermath of a data breach, but even though notice may not be a legal requirement in a particular set of circumstances, it may still be prudent to give it anyway. Google decided not to disclose the recent breach of data from its Google+ service to avoid a PR and regulatory backlash, but the fact that it had happened eventually leaked out anyway. Even though legal experts have opined in the aftermath that Google likely was not obligated to disclose the breach, the fact that it did not caused exactly what Google attempted to avoid, but with magnified effect. "Google Experiences Consumer Data Breach" may not have been a good headline, but "Google Hides Consumer Data Breach" was a worse one.
Remember: Protection Is Key
No company wants a cybersecurity breach, but past experience has increasingly demonstrated that this is not a question of "if" but rather one of "when" and "how bad." Planning ahead and knowing what to do when a data breach does happen can ensure that an organization bounces back from a breach as smoothly and painlessly as possible.
Scott Satkin and Kyle Janecek are associates in the Cybersecurity group of Newmeyer & Dillion. Focused on helping clients navigate the legal dispute implications of cybersecurity, they advise businesses on implementing and adopting proactive measures to prevent and neutralize cybersecurity threats. For questions on how they can help, contact Scott at scott.satkin@ndlf.com and Kyle at kyle.jancecek@ndlf.com.
About Newmeyer & Dillion
For more than 30 years, Newmeyer & Dillion has delivered creative and outstanding legal solutions and trial results for a wide array of clients. With over 70 attorneys practicing in all aspects of cybersecurity, business, employment, real estate, construction and insurance law, Newmeyer & Dillion delivers legal services tailored to meet each client's needs. Headquartered in Newport Beach, California, with offices in Walnut Creek, California and Las Vegas, Nevada, Newmeyer & Dillion attorneys are recognized by The Best Lawyers in America© and Super Lawyers as top tier and some of the best lawyers in California, and have been given Martindale-Hubbell Peer Review's AV Preeminent® highest rating. For additional information, call 949.854.7000 or visit www.ndlf.com.
Read the court decisionRead the full story...Reprinted courtesy of
Performing Work with a Suspended CSLB License Costs Big: Subcontractor Faces $18,000,000 Disgorgement
September 17, 2015 —
Steven M. Cvitanovic & David A. Harris – Haight Brown & Bonesteel LLPIn what could lead to a draconian result, the Court of Appeal for the First Appellate District held that a contractor who performs work without a valid license can be required to disgorge all payments received, even if the contractor perfectly performed its work. The case, Judicial Council of California v. Jacobs Facilities, Inc. (Ct. of Appeal, 1st App. Dis., Div. One, A140890, A141393), involved an $18,000,000 contract between Jacobs Facilities, Inc. (“Jacobs Facilities”) and the Judicial Council of California (“Judicial Council”). In April 2006, Jacobs Facilities, a wholly owned subsidiary of Jacobs Engineering Group, Inc. (“Jacobs Engineering”) entered into a three year contract with the Judicial Counsel to maintain 121 courthouses and other judicial branch buildings throughout Southern California (the “Contract”). Jacobs Facilities contracted to provide maintenance and oversight services, while retaining subcontractors to perform the actual maintenance and repair work.
In December 2006, as part of a corporate reorganization, Jacobs Engineering started winding up Jacobs Facilities and transferred its employees to Jacobs Engineering and then subsequently to another wholly owned subsidiary called Jacobs Project Management Co. (“Jacobs Management”). The work that was performed by Jacobs Facilities was taken over by Jacobs Management. As part of the windup, Jacobs Facilities’ Contractor’s State License Board license was allowed to lapse and the license expired by operation of law in November 2008. Although Jacobs Management was now performing the work, it was not added as a party to the contract. Although it appears Judicial Council was aware of the corporate changes, it was not until November 2009 that the parties assigned the contract to Jacobs Management.
Reprinted courtesy of
Steven M. Cvitanovic, Haight Brown & Bonesteel LLP and
David A. Harris, Haight Brown & Bonesteel LLP
Mr. Cvitanovic may be contacted at scvitanovic@hbblaw.com
Mr. Harris may be contacted at dharris@hbblaw.com
Read the court decisionRead the full story...Reprinted courtesy of
Former Zurich Executive to Head Willis North America Construction Insurance Group
March 01, 2012 —
CDJ STAFFInsurance Journal reports that Sean McGroarty will be directing surety operations for their construction practice in North America. Previously, Mr. McGroarty was the senior vice president and head of international surety with Zurich Financial Services. He has also worked for Liberty Mutual Group and the St. Paul Companies.
Mr. McGroarty will be leading a team of professionals offering brokerage services for contract and commercial surety.
Read the full story…
Read the court decisionRead the full story...Reprinted courtesy of
The Legal Landscape
June 17, 2024 —
David McMillin - Construction ExecutiveThe construction industry continues to change as new technologies reshape jobsites and new generations of leaders rethink the way companies should operate. But one piece of the puzzle remains very much the same: Everyone needs a good lawyer.
According to the most recent edition of the Arcadis Construction Disputes Report, the average value of a dispute in the industry has soared to $42.8 million—a 42% year-over-year increase between 2021 and 2022. And based on how busy the attorneys at
Construction Executive’s 2024 Top 50 Construction Law Firmshave been this year, there is no sign of legal issues becoming less important to builders and contractors.
Every construction leader wants to spend more time and energy doing what they do best—building projects safely, efficiently and profitably—and less time thinking about the things that might land them in court. How can you best avoid big disputes bound for mediation, arbitration or litigation? What emerging rules and regulations should be on your radar as you develop strategies for success?
While legal issues will never disappear, listening to what some of the best construction lawyers in the country—all members of 2024 Top 50 Construction Law Firms—are thinking about offers a helpful perspective on future-proofing your business against risk, liability and worse.
Reprinted courtesy of
David McMillin, Construction Executive, a publication of Associated Builders and Contractors. All rights reserved.
Read the court decisionRead the full story...Reprinted courtesy of
White and Williams Ranked in Top Tiers of "Best Law Firms"
November 08, 2021 —
White and Williams LLPWhite and Williams has achieved national recognition from U.S. News and World Report as a "Best Law Firm" in the practice areas of Insurance Law, Bankruptcy and Creditor Debtor Rights / Insolvency and Reorganization Law and Media Law. Our Boston, Delaware, New Jersey, New York City and Philadelphia offices have also been recognized in their respective metropolitan regions in several practice areas.
National Tier 1
Insurance Law
National Tier 2
Bankruptcy and Creditor Debtor Rights / Insolvency and Reorganization Law
National Tier 3
Media Law
Metropolitan Tier 1
Boston
Insurance Law
Litigation - Insurance
Read the court decisionRead the full story...Reprinted courtesy of
White and Williams LLP
New LG Headquarters Project Challenged because of Height
January 24, 2014 —
Beverley BevenFlorez-CDJ STAFFThe new LG headquarters project in Englewood Cliffs, New Jersey, has been challenged by various environmental groups because of what the groups see “as a blight on the Hudson River landscape,” according to the New York Times. The problem isn’t the building itself, but the proposed height of the tower: LG “plans to construct eight stories, 143 feet total, in an area previously zoned for a maximum of 35 feet. The height restriction was first lifted through a variance, which has been challenged in State Superior Court in one of two lawsuits filed to protect the view. Subsequently the land was rezoned to allow for a taller building.”
Robert F. Kennedy Jr., the Natural Resources Defense Council, and a New Jersey conservation group are continuing to fight against the removal of the height restriction. “This is like if somebody tried to build a high-rise next to Yellowstone,” Mr. Kennedy said in an interview with the New York Times. “It’s a national issue.”
However, there is also local support for this project, “which LG has said will be environmentally sensitive and produce jobs,” reported the New York Times.
Read the court decisionRead the full story...Reprinted courtesy of
Employee or Independent Contractor? New Administrator’s Interpretation Issued by Department of Labor Provides Guidance
August 04, 2015 —
Tanya Salgado – White and Williams LLPThe question of whether a worker should be classified as an independent contractor or an employee is fraught with confusion and misunderstanding for many businesses. Compounding the problem is the fact that there are a number of different tests used to determine employee status, which vary by jurisdiction and by the particular law in question. For example, the Internal Revenue Service uses the common law rules which focus on the degree of control and independence exercised by the worker. In contrast, the United States Department of Labor uses the “economic realities” test which focuses on whether the worker is economically dependent on the employer.
In an effort to help combat the confusion over proper worker classification, the United States Department of Labor (DOL) has issued a new Administrator’s Interpretation that provides a detailed explanation of the test used by the DOL to determine if a worker has been misclassified as an independent contractor. The DOL enforces the Fair Labor Standards Act (FLSA), which mandates that employees (but not independent contractors) be paid minimum wage and overtime. When a business misclassifies non-exempt workers as independent contractors, and those workers are not paid the minimum hourly wage for their labor, or are not paid overtime when they work more than 40 hours in a workweek, this violates the FLSA.
Read the court decisionRead the full story...Reprinted courtesy of
Tanya Salgado, White and Williams LLPMs. Salgado may be contacted at
salgadot@whiteandwilliams.com
Charlotte, NC Homebuilder Accused of Bilking Money from Buyers
April 01, 2015 —
Beverley BevenFlorez-CDJ STAFFThe Charlotte Observer reported that a homebuilder couple “was arrested Tuesday on charges alleging that they kept more than $600,000 three families paid them to build Lake Wylie homes that were never completed.”
Robert Scott Kuhlkin and wife, Sherry Lynn Kuhlkin “accepted $189,000 from one family, $239,000 from another family, and $233,000 from a third family to build houses, 16th Circuit assistant solicitor Matthew Hogge said in court, but instead they ‘took the money for themselves.’”
The alleged victims told the court that the homes had defects or were left unfinished.
Read the court decisionRead the full story...Reprinted courtesy of