Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Digital Evidence

Data Breach Response Plan

Many companies have a technical playbook and assume it is their breach plan. The gap tends to appear once systems are back online and someone asks who has to be told, by when, and in what words.

Reviewed

01 GUIDE

Data Breach Response Plan: what usually happens

The legal layer of the plan

A technical playbook explains how to detect, contain, and recover. A data breach response plan also needs a path for deciding whether personal information was affected, who makes the legal determination that notice is required, and how that determination is recorded. A matrix of the notice regimes that could realistically apply, organized by data type and by where affected people live, saves a great deal of research during an incident. Pre-approved templates for individual notices and regulator correspondence help, provided someone checks them against the actual facts before anything goes out. The plan should also say how and when the cyber insurer is told, since late notice can affect coverage.

Some regulators expect one to exist

For certain businesses a written plan is not optional. New York's financial regulator requires the companies it supervises to maintain a written incident response plan, federal health information security rules require covered health care organizations to have security incident procedures, and contracts with larger customers frequently require a plan as a condition of doing business. In those settings the plan is something a regulator or customer may ask to see, and its absence, or a plan that was plainly never used, can become part of the story after an incident. Even where nothing requires one, a company that had a plan and followed it is usually better placed to explain its decisions.

Keeping it current

Plans age quickly. Acquisitions bring in new systems and new data, vendors change, and the people named in the document move on. A short annual review confirming names, contact paths, insurer requirements, and the notice matrix catches most of the drift, and a change in the law is a reason to revisit sooner. We are often asked to review an existing plan rather than write a new one. When we do, we read it alongside the company's actual data map, contracts, and insurance policy, and we flag the places where the document assumes facts that are no longer true.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

03 CASE RESULTS

Matters we have handled

Prior results do not guarantee a similar outcome.

05 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

06 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about data breach response plan and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.