It’s every business owner’s nightmare. Should hackers gain access to your customers’ or employees’ sensitive data by causing a data breach, the very reputation of your company could be compromised. And lawsuits might soon follow.
No business owner wants to think about such a crisis, yet it’s imperative that you do. Suffering a data breach without an emergency response plan leaves you vulnerable to the damage of the attack itself and the potential fallout from your own panicked decisions.
Call your attorney
He or she should be able to advise you on the potential legal ramifications of the incident and what you should do or not do (or say) in response. Involve your attorney in creating your response plan, so all this won’t come out of the blue.
Engage a digital forensics investigator
Contact us for help identifying a forensic investigator that you can turn to in the event of a data breach. The preliminary goal will be to answer two fundamental questions: How were the systems breached? What data did the hackers access? Once these questions have been answered, experts can evaluate the extent of the damage.
Fortify your IT systems
While investigative and response procedures are underway, you must proactively prevent another breach and strengthen controls. Doing so will obviously involve changing passwords, but you may also need to add firewalls, create deeper layers of user authentication, or restrict some employees from certain systems.
No matter the company’s size, the communications goal following a data breach is essentially the same: Provide accurate information about the incident in a reasonably timely manner that preserves the trust of customers, employees, investors, creditors, and other stakeholders.
Note that “in a reasonably timely manner” doesn’t mean “immediately.” Often, it’s best to acknowledge an incident that occurred but hold off on a detailed statement until you know precisely what happened and can reassure those affected that you’re taking specific measures to control the damage.
Activate or adjust credit and IT monitoring services
You may want to initiate an early warning system against future breaches by setting up a credit monitoring service and periodically engaging an IT consultant to check your systems for unauthorized or suspicious activity. Of course, you don’t have to wait for a breach to do these things, but you could increase their intensity or frequency following an incident.
Data breaches are an inevitable risk of running a business in today’s networked, technology-driven world. Should this nightmare become a reality, a well-conceived emergency response plan can preserve your company’s goodwill and minimize the negative impact on profitability. We can help you budget for such a plan and establish internal controls to prevent and detect fraud related to (and not related to) data breaches.
At Abacus CPAs, our focus is you! We believe that our employees and clients deserve to interact in an environment that fosters growth, trust, and confidence. Our team focuses on tax, accounting, audit, and business consulting to partner with you and your business. Abacus professionals provide leadership by relentlessly pursuing the best guidance possible so those we serve can make smarter decisions.
You can learn more about the topic in this blog by contacting us. We are here and happy to help! Call us today at 417-823-7171, find us on Facebook, LinkedIn, and Twitter, or visit our website to learn more.
Abacus CPAs, LLC | Better Guidance. Smarter Decisions.