# When not if: why a data breach response plan is more important now than ever
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-06-29
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Data Breach Response: Preventing vs. Responding
Meta Description: Learn why responding effectively to data breaches is crucial for organisations, as outlined by security expert Paul Balkwell.
URL: https://financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-everhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/program-code-on-a-monitorfkj4vhwu-1736838258381-compressed.jpg)

There was a point, a few years ago, when the language among security professionals evolved from talking about how organisations should prevent data breaches to how they should respond when a breach inevitably does happen. The necessity of that shift is underlined by [a recent report](https://www.securelink.com/research-reports/a-crisis-in-third-party-remote-access-security/) from SecureLink and the Ponemon Institute, which shows that half of organisations have been breached by a third party in the last 12 months.

According to Paul Balkwell, Vice President – International at ZIX \| AppRiver, such alarming stats don’t mean that organisations should give up on preventing breaches, far from it.

“The report shows that a number of breaches can be attributed to outsourcing business functions to third-party vendors,” says Balkwell. “While that seems like an easy win for businesses, there’s a cost and a very real threat to granting third parties [access into your internal](https://www.financedigest.com/auditors-could-have-unfettered-access-to-internal-business-processes-to-avoid-another-carillion.html "Auditors could have unfettered access to internal business processes to avoid another Carillion") systems and networks.”

“That’s true of many [aspects](https://www.financedigest.com/addressing-the-human-aspects-of-business-transformation.html "Addressing the human aspects of business transformation") of business,” he adds. “A short-term cost-cutting measure can end up costing the [organisation if it results in a data](https://www.financedigest.com/avoiding-a-big-data-car-crash-how-to-organise-your-data-to-detect-fraudulent-claims.html "Avoiding a big data car crash: How to organise your data to detect fraudulent claims") breach.”

Balkwell also points out that this is especially true when it comes to [implementing security](https://www.financedigest.com/how-cloud-is-driving-forward-implementation-of-zero-trust-security.html "How Cloud is Driving Forward Implementation of Zero Trust Security") measures.

“No organisation should simply trust the default [security measures that come with the products and services](https://www.financedigest.com/wrapping-financial-services-in-a-security-blanket.html "Wrapping Financial Services in a Security Blanket") they use,” he says. “They should also make use of third party security firms that offer 24/7 support, offer [threat detection and response](https://www.financedigest.com/forescout-and-fireeye-expand-partnership-enabling-faster-response-to-cybersecurity-threats.html "FORESCOUT AND FIREEYE EXPAND PARTNERSHIP, ENABLING FASTER RESPONSE TO CYBERSECURITY THREATS"), secure backups, and keep you compliant with regulations.”

Even with all of that in place, a [data breach](https://www.financedigest.com/5-simple-ways-to-prevent-a-data-breach-from-putting-your-accountancy-practice-out-of-business.html "5 Simple ways to prevent a data breach from putting your accountancy practice out of business") response plan is still critical.

“The first [step in such a plan is to have a data breach](https://www.financedigest.com/10-steps-to-stop-lateral-movement-in-data-breaches.html "10 Steps to Stop Lateral Movement in Data Breaches") response team in place,” says Balkwell. “The [team should be drawn from departments across the organisation](https://www.financedigest.com/most-sales-and-marketing-teams-struggle-to-activate-data-in-their-organisation-according-to-new-international-study.html "Most Sales and Marketing teams struggle to activate data in their organisation, according to new international study"), including customer care, executive leaders, IT, and HR. This team should also include external partners (if you don’t have them internally) such as [legal counsel](https://www.financedigest.com/imf-general-legal-counsel-sean-hagan-to-retire.html "IMF General Legal Counsel Sean Hagan to Retire"), communications, forensics, and your technology providers. Everyone in this team should be aware of what responsibilities they have when it [comes to responding to a data](https://www.financedigest.com/real-time-connect-nyc-where-adtech-leaders-come-together-to-redefine-data-strategies.html "Real-Time Connect (NYC): Where AdTech leaders come together to redefine data strategies") breach”.

Once the team is together, simulating different event [scenarios will assist the team to work together to execute the planned](https://www.financedigest.com/data-analytics-scenario-planning-and-the-finance-department.html "Data analytics, scenario planning, and the finance department") response.

“While there may be some technical work that needs to be done in the event of a breach, the real emphasis should be on communication,” he adds. “Internally, everyone within the organisation should have an accurate idea of what caused the breach and what [steps are being taken to minimise the damage and secure customer](https://www.financedigest.com/uk-banks-and-insurers-told-to-step-up-help-for-struggling-customers.html "UK banks and insurers told to step up help for struggling customers") records. While employees may not talk to the press, they will talk among themselves as well as to [friends and family](https://www.financedigest.com/generation-y-relying-on-friends-and-family-to-pay-their-energy-bills.html "Generation Y relying on friends and family to pay their energy bills"). If they have a clear idea of what’s going on, they can help create a sense of calm and avert unnecessary panic”.

According to Balkwell, it’s also important that organisations include communication with [regulators and legal authorities in their breach response plans](https://www.financedigest.com/uk-energy-regulator-drops-plan-to-ring-fence-customers-cash.html "UK energy regulator drops plan to ring fence customers’ cash").

“There are a couple of [important reasons](https://www.financedigest.com/despite-the-headwinds-investors-have-important-reasons-to-be-cheerful.html "DESPITE THE HEADWINDS, INVESTORS HAVE IMPORTANT REASONS TO BE CHEERFUL") for this,” he says. “First, it is increasingly a legal [requirement — thanks to legislation such as GDPR](https://www.financedigest.com/how-automation-can-help-the-financial-sector-meet-gdpr-requirements.html "How automation can help the financial sector meet GDPR requirements") — that organisations inform authorities of breaches. Secondly, having a good [relationship with regulators and legal authorities means that they can guide the organization and its impacted customers on whether they need](https://www.financedigest.com/why-finance-teams-need-to-go-beyond-numbers-to-an-active-relationship-with-data.html "Why finance teams need to go beyond numbers to an active relationship with data ") to take any additional steps to those already being undertaken”.

Perhaps the most important part of the response plan, however, is [customer communication](https://www.financedigest.com/bnp-paribas-personal-finance-streamlines-customer-communications-with-opentext.html "BNP Paribas Personal Finance streamlines customer communications with OpenText").

“Security breaches that compromise customer data almost always [negatively affect customer confidence](https://www.tcs.com/blogs/from-cyber-security-to-cyber-customer-experience),” says Balkwell. “In order to regain that confidence, it’s [vital that organisations](https://www.financedigest.com/why-an-orchestrated-digital-identity-strategy-is-vital-for-financial-organisations-in-fighting-fraud.html "Why an orchestrated digital identity strategy is vital for financial organisations in fighting fraud") get information out as quickly as possible — either as reassurance or as notification that their personal information has been breached, and what they should do about it No matter who it’s addressed to, this communication should be calm, informative, and factual.”

**Stay safe and refine**

Ultimately, an [organisation’s data](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") breach response plan should allow it to go into ‘safe’ mode in the event of a breach. This, in turn, should allow it to run system [checks to identify the breach](https://www.financedigest.com/check-please-adding-up-the-costs-of-a-financial-data-breach.html "Check, Please! Adding up the Costs of a Financial Data Breach"), alert a task team and communicate to affected parties, service teams, the information regulator, and media accordingly.

“In order for this to happen, Balwell says, “it’s vital that the [plan is repeatedly tested](https://www.financedigest.com/planning-to-move-to-the-low-carbon-economy-how-banks-can-plan-today-for-new-stress-tests-arriving-soon-2.html "Planning to move to the low carbon economy: How Banks can plan today for new stress tests arriving soon") and refined. This not only stops people getting complacent, it helps [keep the plan](https://www.financedigest.com/e-on-casts-doubt-on-german-plan-to-keep-nuclear-plants-on-standby.html "E.ON casts doubt on German plan to keep nuclear plants on standby") fresh in the face of new threats and employee turnover”.

“Backing up regularly and securely is also critical to breach recovery,” he concludes Your backup provider should be able to [address the unique needs](https://www.financedigest.com/if-the-nation-backs-fintech-we-need-to-address-a-few-things.html "If the nation backs FinTech, we need to address a few things") of laws such as GDPR and any others that impact the jurisdiction you operate in. This includes, but is not limited to, its choice of [data centre](https://www.financedigest.com/keysource-awarded-major-contract-to-design-nationwide-network-of-data-centres-throughout-china.html "KEYSOURCE AWARDED MAJOR CONTRACT TO DESIGN  NATIONWIDE NETWORK OF DATA CENTRES THROUGHOUT CHINA"), data encryption, at-rest and in-transit rules, and the ability to purge backups. Additionally, adopting a backup provider shouldn’t impact on your [organisation’s](https://www.financedigest.com/how-giving-insights-into-card-spend-can-help-organisations-to-manage-their-business.html "How giving insights into card spend can help organisations to manage their business") ability to do business”.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

