When should companies go public following a security breach?
Marne Gordan · Computer Fraud & Security · 2006
Should security breaches be kept under wraps? The guidelines for reporting security breaches are still not clear-cut, but organizations should use a common law liability approach to guide them in the right direction. In the past, companies chose between prosecution and fixing a breach. But fixing a compromise often meant destroying evidence. In America, 23 states have data notification laws regarding security breaches, and another 12 have legislation on the way. Different member states in Europe have different approaches to notifying customers. Notification of affected customers should be another part of incident response. If an organization resides in a member state that is not subject to a specific notification law, they should adhere to common law liability – taking each incident on a case-by-case basis. But is it always in the corporation's interest to notify customers of a breach as the hostile publicity can make a dent in the share price and as a result adversely affect shareholders? Also, if customers are being informed of every breach, trust may decrease in the company. Data theft has become a fact of everyday life. Businesses, non-profits, and government agencies have all experienced serious information security breaches that have put at risk the data of millions of individuals. Some attacks have been intricate electronic exploits targeting specific databases, while others have been simple thefts of hardware containing sensitive data. Attackers themselves range from disgruntled teens experimenting with hacking tools to sophisticated organized crime rings that seek out financial institutions, health care organizations, data aggregators, and government agencies, all of which process and store highly confidential information in aggregate. Such data represents a gold mine for ID thieves. In many cases, consumers may choose whether or not to disclose personal information to these organizations – they may decide against doing business with certain companies if it involves the disclosure of personal information. They do not always have that luxury, however, when dealing with government agencies. In fact, individuals may or may not know that a government entity is in possession of their personal information; they have no input into its protection, and often little recourse after a security incident. Given that, the question now becomes, when should an organization notify consumers of a breach in its data security?