Exploring Legal Landmines in Incident Response with Thomas Ritter

  Рет қаралды 12

Exploring Information Security

Exploring Information Security

Күн бұрын

Summary:
In this episode of Exploring Information Security, host Timothy De Block sits down with Thomas Ritter, a seasoned attorney specializing in cybersecurity and privacy law, to discuss the often-overlooked legal complexities surrounding incident response (IR). From breach terminology to ransomware negotiations, Ritter shares insights from his years of experience navigating legal pitfalls that can arise when responding to security incidents.
Key Takeaways:

Understanding "Incident" vs. "Breach": Ritter emphasizes the importance of careful communication within an organization during a security incident. Misusing legally significant terms, like "breach," can lead to premature obligations, such as breach notifications, which may have serious consequences for an organization.

Attorney-Client Privilege in IR: External counsel's role can extend attorney-client privilege over critical aspects of IR, including the involvement of forensic specialists. This protection can prove essential if an incident escalates into litigation.

Ransomware Negotiation Nuances: With ransomware incidents on the rise, Ritter provides a detailed look at the negotiation process, advising organizations to work with professional negotiators. He recounts instances where attackers leveraged knowledge of clients' cyber insurance coverage to increase ransom demands.

Tabletop Exercises for IR Preparedness: Ritter highlights the value of tabletop exercises, especially involving executive leadership. He notes that regular, comprehensive drills help organizations refine incident response policies and minimize legal exposure during actual incidents.

Navigating Class Action Exposure: As data breaches often trigger class action lawsuits, organizations must take steps to prepare, including consulting legal professionals to reduce risk through privilege-protected documentation.
Resources Mentioned:

International Association of Privacy Professionals (IAPP) (iapp.org/) : A valuable source for privacy and security trends.

Cybersecurity Law Report (www.cslawrepor...) : An in-depth publication on current legal issues in cybersecurity.

Ritter Gallagher Blog (www.rittergall...) : Thomas Ritter’s firm provides regular insights on emerging legal topics in cybersecurity.
About Our Guest:
Thomas Ritter is a cybersecurity and privacy attorney at Ritter Gallagher, where he focuses on helping organizations navigate the legal landscape of security incidents and data breaches. For more information, or to get in touch, visit RitterGallagher.com (rittergallaghe...) or email Thomas directly at thomas@rittergallagher.com.
Contact Information:
Leave a comment below or reach out via the contact form (www.exploresec...) on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn ( / timothy-deblock ) .
Check out our services page (www.exploresec...) and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed (www.timothydebl...) ] [iTunes (itunes.apple.c...) ] [LinkedIn ( / timothy-deblock ) ]

Пікірлер
The Stuxnet Story: What REALLY happened at Natanz
37:38
OTbase
Рет қаралды 196 М.
Classical Liberalism Seminar - Victor Hansen - November 7, 2024
1:35:28
Stanford Classical Liberalism Initiative
Рет қаралды 9 М.
The Ultimate Sausage Prank! Watch Their Reactions 😂🌭 #Unexpected
00:17
La La Life Shorts
Рет қаралды 7 МЛН
бабл ти гель для душа // Eva mash
01:00
EVA mash
Рет қаралды 9 МЛН
Think Fast, Talk Smart: Communication Techniques
58:20
Stanford Graduate School of Business
Рет қаралды 42 МЛН
The Tong Wars of New York's Chinatown (Part 3) | The China History Podcast | Ep. 173
41:35
How to Get a Private Phone, Number, and Cellular Data
10:00
Mental Outlaw
Рет қаралды 1,1 МЛН
Andrew Scheps & Fab Dupont discuss mixing with headphones
18:45
Gain SOC Experience with LetsDefend
8:16
MyDFIR
Рет қаралды 5 М.