{"id":307,"date":"2020-01-21T10:24:05","date_gmt":"2020-01-21T15:24:05","guid":{"rendered":"https:\/\/pbacyber.com\/?p=307"},"modified":"2020-01-21T12:59:01","modified_gmt":"2020-01-21T17:59:01","slug":"an-approach-to-discharging-the-duty-of-reasonable-care-in-data-breach-matters","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2020\/01\/21\/an-approach-to-discharging-the-duty-of-reasonable-care-in-data-breach-matters\/","title":{"rendered":"An Approach to Discharging the Duty of \u201cReasonable Care\u201d in Data Breach Matters"},"content":{"rendered":"<p>By Joseph Decker and Brett Creasy, CCE, CISSP, <a href=\"https:\/\/www.bit-x-bit.com\/index.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">bit-x-bit LLC<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>When a company is targeted and a data breach results, the exposure can be staggering.\u00a0 To take the most extreme example, Equifax\u2019s Jan. 13, 2020 settlement of a 2017 class action data breach lawsuit, regarding a breach incident that affected approximately 147 million people, involves payments of potentially $380,500,000 into a fund for credit monitoring, plus an additional $125,000,000 for out of pocket losses, and potentially $2 billion more if all class members sign up for the monitoring. That is the largest class action data breach settlement to date. What did Equifax allegedly do wrong? According to news reports, Equifax delayed for two months in patching a known vulnerability in one of its website tools, a vulnerability that was used by hackers to exfiltrate the consumers\u2019 data.<\/p>\n<p>&nbsp;<\/p>\n<p>In July 2019, Capital One was sued by a putative class, alleging that Capital One failed to exercise reasonable care in securing and safeguarding consumers\u2019 sensitive personal information, misconfigured its firewall, and failed to take \u201cadequate and reasonable measures to ensure its data systems were protected.\u201d What did Capital One allegedly do wrong? Capital One allegedly failed to properly configure a firewall.<\/p>\n<p>&nbsp;<\/p>\n<p>Plaintiffs in the Capital One suit asserted common law legal theories which are typical of data breach lawsuits: breach of contract; negligence \u2014 duty to exercise reasonable care; negligence <em>per se<\/em> based on FTC Section 5, as interpreted, prohibiting failure to adequately protect PII.<\/p>\n<p>&nbsp;<\/p>\n<p>But is it fair for companies to face huge exposures if they fail to protect what cybersecurity experts acknowledge as \u201cunprotectable?\u201d Experts appear to agree that no one can completely secure the data in their custody, and that a data breach is not a matter of \u201cif,\u201d but \u201cwhen.\u201d\u00a0 The \u201cstandard of care\u201d for legal purposes cannot be perfection. But companies argue that they are being held to a \u201cperfection\u201d standard, made worse by the fact that the reasonableness of their data security measures is judged with the benefit of 20\/20 hindsight.<\/p>\n<p>&nbsp;<\/p>\n<p>How does a business discharge a legal duty to take reasonable measures to safeguard its customers\u2019 data \u201creasonably,\u201d and be able to defend its reasonableness in court?\u00a0 One of the best ways to demonstrate \u201creasonableness,\u201d is for a company to refer to the requirements of a security standard \u201cyardstick\u201d which defines what are \u201creasonable measures,\u201d and demonstrate that it implemented those measures.<\/p>\n<p>&nbsp;<\/p>\n<p>There are many security standards, some more complex than others. The sheer complexity of some of the standards may deter companies from starting the process, or from implementing the standards in an organized fashion. The National Institute of Standards and Technology (NIST) publishes numerous standards for both the government and large companies, and NIST also publishes standards for small businesses. The core NIST standards \u2014 \u201c<em>identify, protect, detect, respond and recover<\/em>\u201d \u2014 are well known, but their implementation, and the NIST guidance, can be complex.<\/p>\n<p>&nbsp;<\/p>\n<p>Most companies would do well to start with a set of standards that are easier to understand and implement. One example of a comprehensive set of security controls that are simpler to understand and implement can be found in the publications of the Center for Internet Security (CIS). The CIS controls can be mapped to the NIST framework, but in easily understandable ways. For example, the CIS breaks down the 20 NIST control groups into just three implementation groups, which are designed to help businesses of different sizes evaluate where to start the journey of improving their security posture. Implementation group one (IG1) is designed for businesses that have limited resources to implement the subcontrols \u2014 your typical small business. Implementation group two (IG2) is focused on a typical mid-sized business which has moderate resources available to it, such as a full time IT person, an IT budget, etc. \u00a0Implementation group three (IG3) is the final group. IG3 is geared toward mature organizations that have considerable resources available \u2014 an entire IT department, likely a separate IT security group, and the budget to back those departments up. In other words, IG3 is for the mature organizations that may be looking at the NIST CSF or ISO requirements and are just looking for a no-nonsense approach in order to be well on their way to adhering to those larger frameworks.<\/p>\n<p>&nbsp;<\/p>\n<p>Not surprisingly then, the CIS controls that are recommended for IG1 start with subcontrols such as \u201cimplement a security awareness program,\u201d \u201cdesignate management personnel to support incident handling\u201d and \u201cencrypt mobile device data.\u201d \u00a0These are controls that any business can adopt with minimal outside help or out-of-pocket costs. A helpful tool to see what controls to focus on first, based on the implementation groups, is even supplied freely on the <a href=\"https:\/\/www.cisecurity.org\/controls\/cis-controls-implementation-groups\/\">CIS website<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>Although no set of controls are one hundred percent effective, implementing just the first five CIS controls has been proven to stop <em>85%<\/em> of real-world attacks. That number jumped to <em>97%<\/em> once all twenty controls are implemented, making a solid argument that the company which adopts the controls as part of the organization\u2019s security program has acted \u201creasonably,\u201d thus placing it in a more defensible legal position should a data breach occur.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><a href=\"https:\/\/www.bit-x-bit.com\/ManagementTeam.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Joseph Decker<\/a> is vice president and general counsel at bit-x-bit, where he consults with clients and counsel on a wide variety of computer forensics, incident response and e-discovery matters. He also directs bit-x-bit\u2019s use of data analytics in e-discovery, developing strategies and overseeing the implementation of data analytics.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.bit-x-bit.com\/ManagementTeam.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Brett Creasy<\/a> is the president and director of digital forensics at bit-x-bit, where he directs the company\u2019s overall operations in digital forensics, e-discovery, cybersecurity and incident response.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Joseph Decker and Brett Creasy, CCE, CISSP, bit-x-bit LLC &nbsp; When a company is targeted and a data breach results, the exposure can be staggering.\u00a0 To take the most extreme example, Equifax\u2019s Jan. 13, 2020 settlement of a 2017 class action data breach lawsuit, regarding a breach incident that affected approximately 147 million people, <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2020\/01\/21\/an-approach-to-discharging-the-duty-of-reasonable-care-in-data-breach-matters\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,10],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/307"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=307"}],"version-history":[{"count":10,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/307\/revisions"}],"predecessor-version":[{"id":317,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/307\/revisions\/317"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}