Technology: Assessing the risks and obligations of network intrusions

How to know if you’re at risk for litigation and how to protect your company

Our first two articles discussed how to prevent and prepare for a network intrusion and what steps to take immediately upon discovering an intrusion to mitigate harm and re-secure your network. This article provides a framework for identifying and assessing the risks and obligations your company may face as a result of a network intrusion.

Companies may face three types of risks arising out of a network intrusion: legal risks, commercial risks and reputational risks. When your company discovers a network intrusion or other security breach, you should systematically identify, assess and address these risks and obligations so that you can minimize litigation, mitigate damage and protect your company's bottom line.

The legal risks and obligations a company may face as a result of a network intrusion arise from four sources:

  1. Federal or state statutes
  2. Regulations applicable to a particular sector or industry
  3. Contracts
  4. The common law

A number of federal laws impose reporting and other legal obligations, including:

  • The Sarbanes-Oxley Act, which requires that companies establish and report annually to the Securities and Exchange Commission (SEC) regarding their internal controls to ensure fair and accurate financial reporting, including data integrity and fraud prevention controls
  • Section 5 of the Federal Trade Commission Act, which prohibits unfair and deceptive trade practices, such as misrepresentations regarding data security
  • The Gramm-Leach-Bliley Act, which requires that any entity engaged in financial activities protect the security and confidentiality of customers' nonpublic personal information
  • The Health Insurance Portability and Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act), which requires that health care plans, providers, clearinghouses or any business associate of any of these comply with network security and breach notification requirements
  • The Fair & Accurate Credit Transactions Act (FACTA), which requires companies with consumer information to meet certain security standards in the disposal of such information
  • The SEC's cybersecurity disclosure guidance, which sets forth the disclosures publicly traded companies must make regarding cybersecurity risks and cyber incidents

Federal laws also impose data security and, in some cases, breach notification requirements on certain regulated industries including the nuclear energy industry; the maritime, aeronautical, and rail transportation industry; the chemical manufacturing industry; the telecommunications industry and any industry that may bring companies into contact with national defense information. Violations of these provisions can result in regulatory investigation, civil penalty, loss of government contracts and, in certain cases, criminal prosecution.

Nearly all 50 states have adopted breach notification laws requiring companies to notify individuals whose personal identifying information may have been exposed as the result of a network intrusion. State consumer protection laws also often offer a cause of action for litigants who allege harm resulting from a network intrusion.

Many contracts with vendors, customers or affiliates include data security or confidentiality clauses. Your company should review your contracts to determine which may potentially expose you to litigation and whether your company can take steps to mitigate this risk. Finally, common law theories such as implied contract, negligence and breach of fiduciary duty may also present a risk of litigation.

A company that suffers a network intrusion also must consider the risk the intrusion poses to its ongoing business. Increasingly, proprietary technology, information and other intellectual property are a company's most valuable assets. Companies may therefore suffer staggering commercial loss if, as the result of an intrusion, market competitors gain access to such technology and information. In such cases, companies should consider accelerating patent applications associated with such intellectual property and monitoring published patent applications for a period following the intrusion to detect any applications that appear to be based on information misappropriated during the intrusion. A similar strategy can be employed to protect trade secrets.

Reputational harm, though often hard to quantify, can pose the greatest threat to a company. Simply put, if your company's customers and business partners do not perceive your network to be secure, they may not want to entrust your company with their sensitive data. A victim company should assume that a breach will become public and prepare a communications strategy that addresses each of its important relationships and constituencies. Your company should prepare a communications strategy before it suffers an intrusion and should update the strategy as investigation of the intrusion and remediation of the network continue.

Page 2 of 2
About the Author
Todd Hinnen

Todd Hinnen

Todd Hinnen is a partner in Perkins Coie's Privacy & Security practice. Prior to joining Perkins Coie, Todd was the Acting Assistant Attorney General for National Security at the U.S. Department of Justice (DOJ), where he oversaw the Division's Internet and cybersecurity practices. Todd has also served as Chief Counsel to then-Senator Biden, Director for Combating Terrorism at the National Security Council, and a prosecutor in DOJ's Computer Crime & Intellectual Property Section.


About the Author
Michael Sussmann

Michael Sussmann

Michael Sussmann is a partner in Perkins Coie's Privacy & Security practice, where his practice covers Internet-related crimes, electronic surveillance, regulatory compliance, white collar defense, and national security and homeland security issues.  Prior to joining Perkins Coie, he held several positions within the U.S. Department of Justice, including serving as Senior Counsel in the Computer Crime & Intellectual Property Section.

Comments

InsideScoop Daily eNewsletter

InsideScoop delivers the latest-breaking news affecting in-house counsel. Get the latest business trends, current corporate litigation, labor developments, technology initiatives and more — FREE. Sign up now!

You have been subscribed! You will receive a confirmation email soon.

See the entire list of InsideCounsel eNewsletters.

Resource Library


7 Simple Strategies for Improving Legal Fee Budgeting Certainty

Understanding the legal fee budgeting paradigm and following seven simple strategies will help you control...

Complimentary White Paper: Best Practices for Meeting Critical eDiscovery Challenges

Packed with practical advice, this white paper discusses best practices for meeting eDiscovery challenges across...

Complimentary White Paper "Key Considerations for Collection Methodologies and Resources"

This white paper addresses the need for companies to reevaluate their current collection policies in...

Moving Matters In-House: How Technology Enables Legal In-Sourcing

Strategically shifting more matters to in-house counsel has proven to be an effective strategy to...

5 Ways to Promote Responsible Content Sharing

Find out five ways that organizations can promote responsible sharing of content among employees by...

Reducing the Costs of eDiscovery from Collection to Court!

Predictive coding is only one of many ways organizations can make eDiscovery faster, cheaper and...

Discovery Shifts to the Cloud

Adoption of Cloud computing continues to gain momentum. How can IT and Legal Teams avoid...

Lower Your Total Cost of Ownership

With the deployment of Proofpoint Enterprise Archive, organizations have realized significant cost savings in automating...

Health and Safety Risks of Counterfeits in the Global Supply...

This whitepaper underscores the prevalence of counterfeits within global supply chains across a number of...

Get the facts you need to Help Implement Sound Legal...

This whitepaper will examine the cases that are setting precedents. Download "Legal Hold and Self-Collection:...

View All »

Advertisement. Closing in 15 seconds.