Professional Liability Insurance SimplifiedKeeping Your Insurance Simple & Effective
Have Questions? Need Help? Call Us! 1-877-569-4111

Creating A Data Breach Response Plan

November 16, 2017

 

        While lawyers must make reasonable efforts to guard against exposure of client information due to cyber security breaches, most tech experts agree that there is no way to completely keep ahead of cybercriminals, and that, eventually, every firm will be hacked at some point. Consequently, no cybersecurity framework is complete without some sort of breach response plan. A handy way to build such a plan is to create procedures to address each of five categories of response: Identify, Protect, Detect, Respond, and Recover.

Identify

  • Identify one person in the firm who is designated to take the lead on any cyber security breach response, so that all information will be collected and handled centrally.
  • Install virus detection software on all of your systems and devices and regularly check for alerts. Consider subscribing to security services provided by your ISP or web host supplier.
  • Set up a process to notify all system users in the event of a breach. Remember that these notifications might need to be made outside of normal business hours.

Protect

  • Create procedures that can isolate compromised devices or your network from further infiltration. This may include removing devices from network connections, or physically securing mobile devices, free-standing back up drives, or other storage devices. Note, though, that most experts advise against shutting down systems completely as a defense lest you compromise forensic investigation later regarding the source and extent of the attack.
  • Contact a security consultant for guidance about how to proceed to protect data.
  • Change passwords for all systems and devices on which you need to continue to work.

Detect

  • Investigate to determine the extent of the breach, including what data may have been compromised. This may require consultation with a technology expert.

Respond

  • Notify your professional liability insurance carrier of the breach as soon as possible. Your policy may provide coverage for hiring an attorney or outside technology consultant to help you minimize potential damage and to comply with legal requirements.
  • Review and comply with required actions under applicable state or federal data breach laws. Almost every state has laws establishing required notification procedures in the event of data breaches. Remember that, depending upon your clients and the type of data involved, you may be covered by more than one states’ laws and rules.
  • Determine what, if any, disclosure needs to be made, to whom, and in what timeframe. Not all breaches will trigger disclosure requirements under data breach laws, but lawyers need to consider ethical obligations as well regarding keeping the client informed of any significant developments affecting your representation of them. It’s best to get guidance from outside legal counsel or your insurance provider.

Recover

  • With the help of your tech advisors, recover what data you can, not only the data that was breached, but data about the hack itself, so that cyber security can be improved moving forward.

Protexure Lawyers /// Professional Liability Made Easy

“I found the Protexure representatives to be extremely professional, knowledgeable, and courteous. They found similar coverage for me for a substantial amount less than I had been paying. I have been pleased with Protexure’s service and would recommend it highly.”

- David M. Lipschutz, Esquire

Receiving a quote from Protexure Lawyers is made super easy by the quick response time of their team. The renewal process is different from what I have ever seen, they offer a mostly filled out application which made the process even easier for me!

- Eric Schwab - Woodbridge, NJ

It was a pleasure working with you, - you gave me the most competitive price, quick turn around and good follow-up.

- Howard S. Kavenow

My account representative was very helpful in assisting me to complete my application. He made me feel like my questions and my business were a priority to him.

- Kim Davis

When faced with a substantial increase from our existing malpractice carrier, we received the name Protexure Lawyers from a referral. On contact, they were not only very prompt in processing our application, but also responded to several coverage questions we had. So far, the service has been excellent.

- Law Office of Shriver, O'Neill & Thompson

Mr. Dixon contacted me many months ago and I told him I renew my policy in September and that it would be helpful to contact me in July or August of this year. He did that; he was very patient with me and assisted me with the application process. He was extremely prompt in replying to my inquiries. I had been with the same company for many years so I was reluctant to leave them. He made the transition quite simple. I am fortunate that he was the salesman who contacted me.

- Robert Lewin

Thanks. You guys got my business because (a) your price was great, and (b) you were responsive and on top of things (a number of insurers surprisingly were not).

- Scott Maxwell

I first came in contact with Ryan on a cold call. Usually I am dismissive of these types of calls, but Ryan was brief and to the point - no hard sell or over promising. In the end, I received a less expensive policy than others I researched. I guess not all cold calls are a bad thing.

- Steve Hunter

Ryan offered to compare my current insurance with what he and his company could offer. I took him up on this, and gave him my pertinent information. I did my own research, and discovered that his quote was lower and the carrier had an A rating. I contacted my existing agent to see if she could match the quote. I had been her customer for a number of years and thought that was fair. She was unable to match Ryan's offer.

- Steve Hunter

I discussed some minor differences in the policies with my account representative, and throughout the process, he was easy to reach and called me back promptly. I value this a great deal. In the end, it was clear to me that I would receive a less expensive policy than I currently have, with the same coverage and excellent customer service.

- Steve Hunter

Copyright © 2018 All Rights Reserved

Have A Question?

We are here to help! Fill out the form below and we will get back to you shortly.

You have Successfully Submitted your question!