Cyber War Games: Data Breach at Ground Zero
Association of Corporate Counsel – Annual Meeting
November 10, 2015 at 4:00 pm
Columbia, South Carolina
Players:
- Narrator/CEO – Robert Sumner, Moore & Van Allen
- In-house Counsel – Robert Wilson, CSC
- Insurance Broker – Brian Warszona, Willis of Illinois (Chicago)
- Outside Counsel – Karin McGinnis, Moore & Van Allen
- IT Professional – Mark Lester, South Carolina Ports Authority
- Computer ForensicsProfessional – Serge Jorgenson, Sylint Group
*Contact information below at the end of the outline *
- Introduction (Robert Sumner)
- Introduce the scenario
- Explain the goal
- Introduce the players
- Voting(Robert Sumner)
- Poll Everywhere
- Text vote
- Real-time reporting
- Announce results
- Initial Meeting (Robert Wilson and Robert Sumner)
- Between CEO and Corporate Counsel
- How did the breach occur?
- How were we notified?
- Chief Information Security Officer (CISO)
- Data Breach Plan
- Cyber-Insurance
- Information Technology & Computer Forensics
- Information Technology (Mark Lester)
- Detection
- Analysis
- Containment
- Eradication
- Recovery
- Post-incident activities
- Insurance Broker(Brian Warszona)
- Data Breach Coach
- Notice to Carrier
- Choose Vendors
- Outside Legal Counsel
- Forensic Investigation Firm
- Notification and Call Center
- Public Relations Firm / Media
- Keep broker up-to-date
- Setbacks or delays that broker can assist
- Interpretation of policy by carrier
- Outside Counsel(KarinMcGinnis)
- Legal Landscape
- Overview of laws and guidelines governing data breach
- Data Breach
- Definition of Personal Information
- Internal Notification
- Investigation Scope and Coordination
- Treatment of Investigation Communications and Documentation
- Immediate Information Collection
- Containing the Breach
- Official Notifications
- Other Notifications
- Outside Computer Forensics(Serge Jorgenson)
- What is the Scope?
- What is the state of the Evidence?
- What Tools are available?
- What is the Timeline?
- How much does this Cost?
- What are the Outcomes?
- Data Breach Notification – Outside Counsel(Karin McGinnis)
- Identify state laws in play – states where victims reside
- Confirm deadlines for notification
- Notice to state attorneys general, consumer protection, etc.
- Data breach notification company
- Letters
- Emails
- Call center
- Consider hiring a data breach notification company
- Prospective actions(Robert Wilson and Karin McGinnis)
- Public relations
- Need to protect customers
- Need identify potential risks
- Security/Identity Monitoring
- Wrap-up (Everyone)
- Final thoughts
- Words of warning
- Lessons learned
- Questions
Contributors:
Brian Warszona
Assistant Vice President
Willis of Illinois (Chicago)
312-288-7850
Mr. Warszona is a Cyber and E&O broker for large organizations with responsibilities of negotiating terms and conditions, limits, placing coverage, and post placement handling including incident/breach organization for clients.
______
Mark Alan Lester
Information Security Manager
South Carolina Ports Authority
843-724-4057
Mr. Lester is the Information Security Manager, charged with building the Information Security Framework that provides prevention, detection, response and recovery, and measurement of items related to the confidentiality, integrity, and availability of the information created, changed, or used to accomplish the mission of the SC Ports Authority.
______
Robert Wilson, Esq.
Principal: Attorney, Mergers & Acquisitions and Global Alliances
CSC (Computer Sciences Corporation)
803-528-4007
Mr. Wilson the primary in-house attorney supporting over $1 billion annually in global M&A activity as well as corporate governance and global commercial transactions, alliances, and joint ventures.
______
Serge Jorgensen
Founding Partner, Chief Technology Officer
Sylint Group
941-951-6015
Mr. Jorgensen and his team manage incident responses and security architecture for international companies and government entities.
______
Karin M. McGinnis, Esq.
Member
Moore & Van Allen, PLLC
704-331-1078
Ms. McGinnis is the co-head of Moore & Van Allen’s Privacy and Data Security group and has handled a wide range of employment, privacy and data-security matters. She has successfully litigated a variety of issues on employers’ behalves in federal and state court, and in arbitration.
______
Robert E. Sumner, IV, Esq.
Member
Moore & Van Allen, PLLC
843-579-7018
Mr.Sumner is the Litigation Team Leader for the Charleston Office for Moore & Van Allen and a member of the firm’s Privacy and Data Security practice group. Mr. Sumner has handled a wide range of privacy and data-security matters in litigation and pre-litigation settings. Mr. Sumner’s litigation practice includes filing and defending wide ranging commercial litigation matters in state and federal courts across the country.
______