Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

12/5/2019
02:00 PM
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit

Assessments can be used against your company in court proceedings. Here's how to mitigate this potential risk.

SOC 2 audits and third-party technical assessments are useful tools for an organization to use in navigating the security risks it may face. But these security road maps also can provide direction to a plaintiff's counsel suing your organization in a later lawsuit related to a data breach. If the assessment describes your organization as being riddled with security vulnerabilities and, after the assessment, one of these unrepaired vulnerabilities is utilized to infiltrate your network, the assessment becomes proof that your organization knew about the risk and did not fix it.

On the flip side, engaging a third party to assess your security risk can also be used as a defense in court proceedings, showing that your organization engaged unbiased third parties to determine what risks it might face. In that way, an assessment can be a powerful tool in later court proceedings.

How do you mitigate against this potential future risk? Here are two strategies you can employ.

1. Think hard about who you're engaging and the services they provide.
In the last few years, there has been a proliferation of service providers claiming to offer technical security assessments. In determining who to hire, budget can't be your primary driver. Are your own customers requiring you to have a SOC 2 audit? Then you will need to engage a CPA firm that offers auditing services covering the Systems and Organizational Controls 2 (SOC 2) as put forward by the American Institute of Certified Accountants. Outside of a SOC 2, you may engage technical firms to perform assessments based on a variety of approaches, including the matrix from the National Institute of Standards and Technology.

But keep in mind that not all technical firms are created equal and that you need a reputable provider to put forward an assessment. Cheap sometimes means shoddy work. And if a service provider is looking for a later "up-sell" of services, be aware of that, too. Offering an array of services is not bad per se, but be cognizant of what could be motivating some of the findings. For instance, if the provider sells firewalls and suddenly your assessment comes back suggesting you need an upgrade, you may wonder whether the assessment was motivated by an unbiased opinion.

Create a list of questions to conduct diligence on providers and interview multiple providers. Develop a document trail of the process that went into engaging the audit team. This can be beneficial later to show your organization was thoughtful about security risk and wanted a truly unbiased opinion.

2. Arrange the engagement to protect the findings.
Attorneys have two special powers when it comes to confidentiality and protecting information. The first is the attorney-client privilege. Under the attorney-client privilege, communications between a lawyer and a client seeking and providing legal advice are protected from disclosure. The second is a nuanced doctrine called the work-product doctrine. Under this doctrine, a lawyer may engage a consulting expert to support the lawyer's legal work on behalf of a client. This too, in most cases, is considered confidential and privileged.

So, what does all this have to do with getting an assessment? Organizations are now hiring outside counsel to work with them on obtaining an assessment in order to shield assessments with confidentiality. The process works like this: An organization engages outside counsel to assist in reviewing the organization's cybersecurity risk. Outside counsel then engages the third-party assessment team to provide a technical assessment or SOC 2 to the lawyer. The engagement letter is set up so that the lawyer receives the technical assessment to support the lawyer's legal work. The lawyer and the client discuss the findings of the report together.

What does this do? It insulates, as best we can, the findings from being disclosed in a later lawsuit by using both the attorney-client privilege and the work-product doctrine. I've seen assessments come back with score cards of 35/100. The last thing any defendant in a data breach lawsuit needs is a 35/100 assessment scorecard blown up as an exhibit in front of a jury box, with an impassioned plaintiff's lawyer talking about how the company received a F on its assessment and did nothing to repair the risk before the breach occurred.

Without a lawyer, there is no privilege. Marking the document "confidential" and exchanging it may keep it confidential within your organization. But it won't protect the assessment from being disclosed to a plaintiff's lawyer in a later data breach lawsuit. The only way to try to do that is to work hard on the front end of obtaining assessments and have a lawyer involved in the process.

Related Content:

Beth Burgin Waller is a lawyer who knows how to navigate between the server room and the board room. As chair of the cybersecurity & data privacy practice at Woods Rogers, she advises clients on cybersecurity and on data privacy concerns. In this capacity, she ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Jmurphy116
50%
50%
Jmurphy116,
User Rank: Apprentice
12/17/2019 | 8:05:24 AM
Re: black magic
The article isnt telling companies to not fix their bad security practices, it is telling them how to have an honest assessment of their security with true confidentiality. If a company is afraid that any flaw found in an assessment can be brought out as Exhibit A in a lawsuit, they are far less likely to seek a high quality assessment. If a company knows that security company A is a top rated pentest company, and they will most likely find something significant to be addressed, but security company B is also "certified" from a check the box regulatory perspective but most likely wont find anything, AND they are concerned that any finding can be incorporated into a lawsuit, then what is the motivation to go with security company A? If however, the findings are truely confidential, as the process involved here outlines, than the company can go with the best to find all of its flaws and work on correcting them.
sgkmp
50%
50%
sgkmp,
User Rank: Apprentice
12/9/2019 | 12:03:51 PM
black magic
I'm appalled by this article. Instead of directing people with bad security practices to fix them, you are counselling them on how to hide their poor practices!!! Shameful.
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5524
PUBLISHED: 2020-02-21
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via UPnP function.
CVE-2020-5525
PUBLISHED: 2020-02-21
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via management screen.
CVE-2020-5533
PUBLISHED: 2020-02-21
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2020-5534
PUBLISHED: 2020-02-21
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.
CVE-2014-7914
PUBLISHED: 2020-02-21
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.