Establish a strategy for security breach notification


Even if your organisation takes every possible precaution to protect its data, a security breach is often inevitable. What do you do if it happens? Mike Mullins offers some pointers for notifying those affected.

News broke recently about one of the largest known security breaches at a university. A database break-in at the University of California, Los Angeles has reportedly exposed the private information of about 800,000 people.

While this is the latest in a long line of similar stories, don't let the huge number of potential victims sway your attention. When it comes to security breaches, it's important to remember that old adage about quality vs. quantity.

Data breaches aren't just about a hacker breaking into a network and stealing information. In fact, they come in all shapes and sizes:

  • A data breach can occur with a lost or stolen laptop that has someone's social security number.
  • A data breach can occur with a lost BlackBerry that has personal information about employees or customers.
  • A data breach can occur with a fax that includes financial information that's thrown away instead of shredded.

In other words, a data breach can happen any time an unauthorised individual has access to sensitive or private information. It's important to remember that a variety of factors can lead to this exposure.

Regardless of size, every network will experience some form of data breach at some point. And users are becoming increasingly more savvy about identity theft and sensitive to the long-term damage it can cause to their finances.

So when the inevitable data breach happens, what do you do? Establishing notification procedures in advance will help you better deal with the problem when it occurs. Planning now will help mitigate the damage from a customer/employee relationship standpoint later -- and it's the right thing to do.

When a data breach occurs, you obviously need to notify those affected. You definitely do not want to tell people that someone accessed their personal information in an e-mail. Users could easily mistake such an e-mail as a phishing attempt and delete it without reading it.

While this is the electronic age, there's a better method for delivering the bad news -- snail mail. The postal service will ensure delivery to the person -- and usually even if they've moved to another address.

Deciding how to notify people is the easy part -- deciding what should go in that notification can be a lot trickier. First of all, describe what happened.

Don't give out information that could compromise the investigation, but do tell people in nontechnical terms how it happened as well as what information the breach exposed or lost. Tell them what your organisation is doing to remedy the situation, and make sure you include contact information.

If identify theft is a possibility, explain how they can try to protect themselves. Tell people how to contact the credit reporting agencies to put a fraud alert on their accounts.

In addition, the Identity Theft Resource Center is an excellent source of information. Include a link to the Web site in your correspondence, and encourage people to take active steps to protect their financial information.

If law enforcement is involved in the case, provide the contact information for the officer working the case, as well as the case report number. This is information people may need to repair credit or obtain a job if they become a victim due to the breach.

Finally, if the breach is wide enough, contact the credit reporting agencies first to determine whether identify theft is taking place as a result of the breach. If you uncover evidence of identify theft, offer some form of credit monitoring service in the notification. This could mitigate the damage done to both the individual and your company.

Final thoughts
While your organisation should take every security precaution to protect its data, a security breach is often inevitable. Too much information stored in too many places provides too much temptation.

Losing control of someone's personal, privacy, or financial information can put your company at risk in many ways. How you handle the loss after the fact will speak volumes to your employees and customers (both current and future). Developing some simple procedures before a loss occurs and implementing them when it happens can go a long way to mitigating the damage.

TechRepublic is the online community and information resource for all IT professionals, from support staff to executives. We offer in-depth technical articles written for IT professionals by IT professionals. In addition to articles on everything from Windows to e-mail to firewalls, we offer IT industry analysis, downloads, management tips, discussion forums, and e-newsletters.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

10 minutes ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

28 minutes ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

2 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

12 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

12 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

13 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

13 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

13 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

14 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

14 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

14 hours ago by Beta on Regional review highlights NBN, mobile

michael kors outlet http://www.michael-kors-discount.com/#5923

14 hours ago by michael kors bag on Best iPhone travel apps

Hey butterflyeffecs and lex, Sorry you're not fans of this piece. But you're dead right in that it is the thoughts and experience of a se...

14 hours ago by LHopewell on Android fragmentation steers Vic Health

teen cams
http://www.aloe-vera.cz handjob

14 hours ago by MyncWenry on Fusion-io ioDrive (80GB)

We have fashional replica bags designer .Replica luxury bags sale here are perfect compromise of quality and price. The replica handbags ...

15 hours ago by Machelle on Telecom NZ CEO Paul Reynolds to leave

It's not a question of whether anyone at HSU would know how to do this, but whether they would have connections with people who could. T...

15 hours ago by meski on CT, phone clone

Fred, I can tell you what the difference between FTTN and FTTH is. FTTH means we will be developing technology and services that we sell ...

15 hours ago by andye on NBN FUD: will Abbott ever learn?

You are 100% right – Abbott is a paragon of tenacity. Now if he could only try that hard to get Malcolm Turnbull's phone number, we co...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Very interesting to hear Ben and thanks for providing some real-world examples. I suspect the NBN has actually improved things for a grea...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

Hi Geoff, my opening paragraph simply suggests that the leader of the opposition party would rightfully be turning to his communications ...

15 hours ago by braue on NBN FUD: will Abbott ever learn?

This story has been voted 12000 times in the last 24 hours!

18 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar