Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis...

6
#ACICyber 15 th Advanced Global Legal & Compliance Forum on Cyber Security & Data Privacy and Protection J. Andrew Valentine Verizon RISK Team Cyber Security Preparedness: Best Practices for Data Breach Incident Response Teams With a Focus on Preemptive Measures to Take and Rehabilitating Your Image Christopher T. Pierson, Ph.D., J.D. Viewpost EVP, General Counsel & Chief Security Officer Korin Neff Wyndham SVP, Corporate Compliance Officer January 15-16, 2015 Tweeting about this conference?

Transcript of Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis...

Page 1: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

15th Advanced Global Legal & Compliance Forum on Cyber Security & Data Privacy and Protection

J. Andrew Valentine

Verizon

RISK Team

Cyber Security Preparedness: Best Practices for

Data Breach Incident Response Teams With a Focus on Preemptive Measures to Take and

Rehabilitating Your Image

Christopher T. Pierson, Ph.D., J.D.

Viewpost

EVP, General Counsel & Chief Security Officer

Korin Neff

Wyndham

SVP, Corporate Compliance Officer

January 15-16, 2015

Tweeting about this conference?

Page 2: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

Agenda

• Incident preparedness • Proactive crisis communications training

• Risk assessments and vulnerability audits

• The cyber defense response team • Managing the crisis through comprehensive communications

•Post-incident recovery • Reputation management

• Public relations and impact assessments

• Stakeholder communications, and more

The opinions contained herein do not reflect the opinions and beliefs of the author’s employers or associated agencies. All content contained herein is for informational purposes only and may not reflect the most current legal developments. The content is not offered as legal or any other advice on any particular matter.

Page 3: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

Incident preparedness

•Plan A / Plan B

• “Awesome”

Page 4: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

Cyber Defense Team

•Controlling the Incident • Internally and Externally

• Working with Partners (CPO, GC, CCO/CRO, CISO, CIO, Externals)

•Controlling the Chaos • Table Top Exercises

• Flows, Roles & Responsibilities

•One Source of Truth • InfoSec messaging, research, facts

• Handling all tasks execution

• Internal messaging & communications

• Incident Documentation and tracking

Page 5: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

Post-incident recovery

•Notification • Consumers, Agencies, Law Enforcement

• Stakeholders

•Crisis Management • Media, Shareholders, Employees and Customers

•Remediation • Up the Ladder Reporting

• Technical and Administrative Enhancements

• Lessons Learned

•Additional Matters for Consideration • Insurance Coverage

Page 6: Cyber Security Preparedness · #ACICyber Agenda •Incident preparedness •Proactive crisis communications training •Risk assessments and vulnerability audits •The cyber defense

#ACICyber

Contact Us

J. Andrew Valentine

Verizon

RISK Team

[email protected]

Korin Neff

Wyndham

SVP, Corporate Compliance Officer

[email protected]

Christopher T. Pierson, Ph.D., J.D.

Viewpost

EVP, General Counsel & Chief Security Officer

[email protected]