FTC Released a Guide Data Breach Response- A Guide for Business (April 2019)

Data Breach Response: A Guide for Business

April 2019

The Federal Trade Commission (“FTC”) released a guide Data Breach Response: A Guide for Business, which outlines essential steps businesses should take immediately after discovering a data breach involving personal information. Here's a summary of the key points:

Immediate Actions

  1. Secure Operations.

    • Quickly secure systems and fix vulnerabilities to prevent further breaches.

    • Assemble a breach response team, including forensics, legal, and IT experts.

  2. Investigate the Breach.

  3. Hire independent forensics investigators to determine the breach's source and scope.

  4. Consult legal counsel to understand applicable laws and obligations.

  5. Take affected systems offline without turning off machines until forensics arrive.

  6. Update credentials and passwords to prevent unauthorized access.

  7. Eliminate improperly posted personal information from your website and contact search engines to prevent caching.

  8. Record the investigation process and avoid destroying any evidence.

  9. Contain Data Loss.

  10. Remove Exposed Information.

  11. Document Everything.

Fix Vulnerabilities

  • Review access privileges for service providers and ensure they implement necessary security measures.

  • Evaluate network segmentation and make adjustments to enhance security.

Communication Strategy

  • Develop a comprehensive communication plan for stakeholders, ensuring transparency without compromising the investigation.

  • Prepare clear FAQs for affected individuals to alleviate concerns.

Notification Requirements

  1. Notify Law Enforcement.

    • Report the breach to local authorities, including the FBI if needed.

  2. Understand Legal Obligations.

  3. Familiarize yourself with state and federal breach notification laws.

  4. If health information is involved, adhere to specific regulations like HIPAA.

  5. Inform individuals whose data was compromised, including details about the breach and steps they can take to protect themselves.

  6. Consider offering credit monitoring services.

  7. Notify Affected Parties.

Post-Notification Guidance

  • Advise affected individuals on how to recover from identity theft, including contacting credit bureaus and the FTC.

This guide emphasizes the importance of swift action, effective communication, and adherence to legal obligations to mitigate the impact of a data breach on consumers and the business itself.

 

For more information, see here:  https://www.ftc.gov/tips-advice/business-center/guidance/data-breach-response-guide-business

 

These materials were obtained directly from the Federal Government public websites and are posted here for your review and reference only.  No Claim to Original U.S. Government Works.  These may not be the most recent versions.  The U.S. Government may have more current information.  We make no guarantees or warranties about the accuracy or completeness of this information, or the information linked to.  Please check the linked sources directly.