Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

11/20/2018
02:20 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Consumers Are Forgiving After a Data Breach, but Companies Need To Respond Well

A solid response and reputation management program will go a long way in surviving a major breach.

After a major data breach, consumers are willing to forgive, but companies can only regain their trust if they are serious, communicate well, and implement real changes, say industry experts who focus on incident response and reputation management.

According to Chris Morris, principal of the Advisory Financial Services Cybersecurity & Privacy Practice at PwC US, although no one action will win back every customer, some measures are more likely to resonate. These include compensation for victims, a detailed explanation of what happened, and a clear description of the privacy policies in place.

"Consumers want businesses to be responsive, transparent, and take steps to ensure a breach does not happen again," Morris says.

In PwC's "Digital Trust Insights" survey, only about half of midsize and large businesses in important vertical sectors say they are building resilience to cyberattacks and other disruptive events to a large extent, Morris adds. And fewer than half say they are very comfortable their companies have adequately tested their resistance to cyberattacks.

As for reputation management, Morris views it as an important component of effective crisis management. For companies to emerge stronger from crisis, he says, they must take the following five steps:

  • Ground responses in the facts.
  • Establish governance and effective coordination via a cross-functional core team that combines PR/communications, legal, and key operational response functions.
  • Understand constituents and stakeholders, respond authentically, and know they will need to monitor each stakeholder for sentiment and may require a different engagement approach.
  • Dedicate energy during the crisis to "look around the corner" for both additional risks or opportunities.
  • Take action on what was learned.

Help on the Way
Some important help may be on the way for companies looking to step up their reputation management game.

Mark Goldman, strategic adviser of Atlanta-based Group Salus, says the company will be testing its new reputation management platform with beta customers during the first quarter of 2019.

The Salus platform, he says, will walk company executives through the five steps of response: assess, audit, plan, implement, and monitor.

"The assessment is not a pen test. It’s more of a look if you have the lines of communication open with all the stakeholders," Goldman explains. "We provide a template that people can walk through to audit their documents, develop a plan, and implement a plan for handling the media with the proper messaging. The platform will help companies decide who will say what and who will be authorized to speak to the press."

Pending successful beta tests, Salus should be readily available by the middle of 2019, he adds.

Related Content

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
NetCAT Vulnerability Is Out of the Bag
Dark Reading Staff 9/12/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16199
PUBLISHED: 2019-09-17
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.
CVE-2019-16391
PUBLISHED: 2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
CVE-2019-16392
PUBLISHED: 2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
CVE-2019-16393
PUBLISHED: 2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
CVE-2019-16394
PUBLISHED: 2019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.