Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

11/20/2018
02:20 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Consumers Are Forgiving After a Data Breach, but Companies Need To Respond Well

A solid response and reputation management program will go a long way in surviving a major breach.

After a major data breach, consumers are willing to forgive, but companies can only regain their trust if they are serious, communicate well, and implement real changes, say industry experts who focus on incident response and reputation management.

According to Chris Morris, principal of the Advisory Financial Services Cybersecurity & Privacy Practice at PwC US, although no one action will win back every customer, some measures are more likely to resonate. These include compensation for victims, a detailed explanation of what happened, and a clear description of the privacy policies in place.

"Consumers want businesses to be responsive, transparent, and take steps to ensure a breach does not happen again," Morris says.

In PwC's "Digital Trust Insights" survey, only about half of midsize and large businesses in important vertical sectors say they are building resilience to cyberattacks and other disruptive events to a large extent, Morris adds. And fewer than half say they are very comfortable their companies have adequately tested their resistance to cyberattacks.

As for reputation management, Morris views it as an important component of effective crisis management. For companies to emerge stronger from crisis, he says, they must take the following five steps:

  • Ground responses in the facts.
  • Establish governance and effective coordination via a cross-functional core team that combines PR/communications, legal, and key operational response functions.
  • Understand constituents and stakeholders, respond authentically, and know they will need to monitor each stakeholder for sentiment and may require a different engagement approach.
  • Dedicate energy during the crisis to "look around the corner" for both additional risks or opportunities.
  • Take action on what was learned.

Help on the Way
Some important help may be on the way for companies looking to step up their reputation management game.

Mark Goldman, strategic adviser of Atlanta-based Group Salus, says the company will be testing its new reputation management platform with beta customers during the first quarter of 2019.

The Salus platform, he says, will walk company executives through the five steps of response: assess, audit, plan, implement, and monitor.

"The assessment is not a pen test. It’s more of a look if you have the lines of communication open with all the stakeholders," Goldman explains. "We provide a template that people can walk through to audit their documents, develop a plan, and implement a plan for handling the media with the proper messaging. The platform will help companies decide who will say what and who will be authorized to speak to the press."

Pending successful beta tests, Salus should be readily available by the middle of 2019, he adds.

Related Content

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6852
PUBLISHED: 2019-11-20
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP har...
CVE-2019-6853
PUBLISHED: 2019-11-20
A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server.
CVE-2013-2092
PUBLISHED: 2019-11-20
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
CVE-2013-2093
PUBLISHED: 2019-11-20
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
CVE-2015-3166
PUBLISHED: 2019-11-20
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as d...