Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

11/20/2018
02:20 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Consumers Are Forgiving After a Data Breach, but Companies Need To Respond Well

A solid response and reputation management program will go a long way in surviving a major breach.

After a major data breach, consumers are willing to forgive, but companies can only regain their trust if they are serious, communicate well, and implement real changes, say industry experts who focus on incident response and reputation management.

According to Chris Morris, principal of the Advisory Financial Services Cybersecurity & Privacy Practice at PwC US, although no one action will win back every customer, some measures are more likely to resonate. These include compensation for victims, a detailed explanation of what happened, and a clear description of the privacy policies in place.

"Consumers want businesses to be responsive, transparent, and take steps to ensure a breach does not happen again," Morris says.

In PwC's "Digital Trust Insights" survey, only about half of midsize and large businesses in important vertical sectors say they are building resilience to cyberattacks and other disruptive events to a large extent, Morris adds. And fewer than half say they are very comfortable their companies have adequately tested their resistance to cyberattacks.

As for reputation management, Morris views it as an important component of effective crisis management. For companies to emerge stronger from crisis, he says, they must take the following five steps:

  • Ground responses in the facts.
  • Establish governance and effective coordination via a cross-functional core team that combines PR/communications, legal, and key operational response functions.
  • Understand constituents and stakeholders, respond authentically, and know they will need to monitor each stakeholder for sentiment and may require a different engagement approach.
  • Dedicate energy during the crisis to "look around the corner" for both additional risks or opportunities.
  • Take action on what was learned.

Help on the Way
Some important help may be on the way for companies looking to step up their reputation management game.

Mark Goldman, strategic adviser of Atlanta-based Group Salus, says the company will be testing its new reputation management platform with beta customers during the first quarter of 2019.

The Salus platform, he says, will walk company executives through the five steps of response: assess, audit, plan, implement, and monitor.

"The assessment is not a pen test. It’s more of a look if you have the lines of communication open with all the stakeholders," Goldman explains. "We provide a template that people can walk through to audit their documents, develop a plan, and implement a plan for handling the media with the proper messaging. The platform will help companies decide who will say what and who will be authorized to speak to the press."

Pending successful beta tests, Salus should be readily available by the middle of 2019, he adds.

Related Content

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19668
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to preve...
CVE-2019-12882
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2017-6363
PUBLISHED: 2020-02-27
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for...
CVE-2017-6371
PUBLISHED: 2020-02-27
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.
CVE-2017-5861
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000020. Reason: This candidate is a reservation duplicate of CVE-2017-1000020. Notes: All CVE users should reference CVE-2017-1000020 instead of this candidate. All references and descriptions in this candidate have been removed to...