Reporting data breaches
Tracey Caldwell · Computer Fraud & Security · 2012
The number of data breaches continues to grow and so too do requirements to report data breaches to the authorities. Yet many organisations, while spending small fortunes on securing their systems, do not have a plan for reporting data breaches. The US Privacy Rights Clearing House tracked 535 breaches involving 30.4 million sensitive records in 2011. This brings the total reported records breached in the US since 2005 to 543 million – and many states do not require companies to report data breaches to a central clearing house. Data breaches are a fact of life and companies need to spend as much effort on planning how to handle reporting them efficiently as they do on prevention. The number of data breaches continues to grow and so too do requirements to report data breaches to the authorities. Yet many organisations spend thousands on securing their systems but do not have a plan for reporting data breaches. Tracey Caldwell reports on the changing legislation around data breach reporting internationally, why some companies are still reluctant to report data breaches and how incident management plans should include details of who will take responsibility, what type of incident needs to be reported, how it should be reported and to whom.