• Skip to primary navigation
  • Skip to main content
McKenna Storer

McKenna Storer

AV Rated Chicago Law Firm

  • Home
  • Insurance
    • Insurance Defense
    • Toxic Tort and Mass Tort Litigation
    • Construction Law
    • Commercial Transportation Law
    • Insurance Coverage
    • Professional Malpractice Defense
    • Medical Malpractice Defense
    • Legal Malpractice Defense
    • Appellate Practice
  • Business
    • Corporate Law & Commercial Litigation
    • Litigation Defense
    • SBA Lending
    • Commercial Real Estate
    • Appellate Practice
    • Health Care Law
    • Business Formation
    • Data Privacy and Cyber Liability
    • Employment Law
    • Employment Litigation
    • Workplace Harassment
  • Individual
    • Estate Planning
    • Wills and Trusts
    • Real Estate
    • Mediation Services
  • Banking Law
  • Our Attorneys
  • Our Firm
  • Blog
  • Contact Us
    • Chicago Office
    • Woodstock Office
  • Show Search
Hide Search

Three Ways Your Business May Respond to a Data Breach: FTC Issues Guidance for Data Privacy Breach Response

mckenna · November 28, 2016 ·

The Federal Trade Commission (FTC) recently released data breach response guidance for businesses.  Data security has become an increasingly important issue to businesses of all sizes, so the FTC has tried to provide guidance in this area.

The FTC’s “Data Breach Response: A Guide for Business” is its latest offering.  The FTC previously released two other guides, “Protecting Personal Information: A Guide for Business” and “Start with Security: A Guide for Business.” “Data Breach Response: A Guide for Business” focuses on three steps that a business should take:

  • Securing Operations
  • Fixing Vulnerabilities
  • Notifying Appropriate Parties

Securing Operations

The FTC guide recommends that a business first secure its operations to ensure that it isn’t a victim of multiple cybersecurity breaches.  Securing systems includes taking affected equipment offline and limiting access to physical areas related to the breach.  The FTC further recommends removing improperly posted information from the business’s own website and any other website.  Finally, the FTC cautions businesses not to destroy any forensic evidence.  All of this work should be performed by a team of experts, including a data forensics team and legal counsel.

Fixing Vulnerabilities

Following a data breach, the FTC recommends working with forensic experts to fix system vulnerabilities.  This work includes checking that encryption was enabled at the time of the breach, analyzing backup and/or preserved data, and checking network segmentation.  The business should also assess its relationship with service providers and review service providers’ access privileges to ensure that the service provider does not allow a breach.

Notifying Appropriate Parties

A business that is a victim of a data breach should also notify the appropriate parties.  Working with legal counsel to identify the appropriate parties is crucial.  The FTC first recommends notifying local law enforcement.  The business should also notify affected businesses and individuals. The FTC guide provides a sample letter for this purpose.  Additionally, if health information is involved, the business must comply with the FTC Health Breach Notification Rule and HIPAA Breach Notification Rule.

There are many questions surrounding how business can best respond to a data breach.  The FTC guide is a useful starting place, but the advice and guidance of experienced legal counsel can prove to be invaluable in answering many of those questions.  If you need additional guidance regarding the data breach notification response of your business, or for guidance and legal advice about privacy and data security matters, please contact Tim Hayes at McKenna Storer.

Privacy and Data Security Litigation

About mckenna

McKenna Storer is a corporate law firm that provides a full spectrum of legal services for businesses and individuals. More than half of our lawyers have received positive peer review ratings from Martindale Hubbell, including 10 individual Preeminent AV ratings.
McKenna Storer has been serving its clients for more than 66 years. We are open and available for consultations at both our Chicago and Woodstock locations. Please follow us on or our LinkedIn, Twitter or Facebook pages.

Chicago Office
McKenna, Storer
33 N. LaSalle, Suite 1400
Chicago, Illinois 60602
312.558.3900
312.558.8348
Mo,Tu,We,Th,Fr 8:30 am – 5:00 pm
Woodstock Office
McKenna, Storer
1060 Lake Avenue
Woodstock, Illinois 60098
815.334.9690
815.334.9697
Mo,Tu,We,Th 8:30 am – 5:00 pm

  • Home
  • Insurance
  • Business
  • Individual
  • Banking Law
  • Our Attorneys
  • Our Firm
  • Blog
  • Contact Us