Perspectives on Cybersecurity and Its Legal Implications
|
|
|
- Cynthia Casey
- 10 years ago
- Views:
Transcription
1 Survey Results 2015 Perspectives on Cybersecurity and Its Legal Implications a 2015 survey of corporate executives
2
3 The National Institute of Standards and Technology (NIST), a non-regulatory agency of the US Department of Commerce, released its cybersecurity framework in February 2014 to help regulators and businesses identify and mitigate cyber risks that could affect national and economic security. The need was urgent. According to the Ponemon Institute s 2014 Cost of Data Breach Study: Global Analysis, the total average cost per data breach for US businesses was in excess of $5.85 million. Unsure of Congress ability to respond quickly with effective legislation to address the myriad issues surrounding cybersecurity, companies are developing their own cyber risk management protocols. Survey Background and Participants In an effort to gauge industry concerns and measure corporate responses to these significant privacy and security threats, Mayer Brown conducted an informal survey of key executives and corporate counsel in 15 industry sectors between mid-november 2014 and mid-february The majority of the companies were from finance and financial institutions, professional services (law, medicine, accounting, architecture and design), utilities and energy (including extraction), health care and pharmaceuticals. While two-thirds (70%) of the respondents companies have a chief information officer (CIO) or both a CIO and a chief privacy officer, one-fifth (21%) of the companies had neither. Summary Analysis and Outlook Survey respondents overwhelmingly considered the disclosure of personally, identifiable information as the biggest cyberrelated threat to their companies (63%). Concern about interruption of business operations such as system sabotage ranked second (24%). Less than 10% of the respondents considered theft of trade secrets as the most serious threat. Most respondents (63%) considered cyber issues to be just one more cost of doing business or that these problems can be overcome. Well over half (57%) of the respondents estimated that litigation risk posed by cybersecurity issues has a relatively modest impact on their cybersecurity planning. For some, pessimism reigns. Around 29% of respondents have a negative outlook on cyber-related issues, believing that cybercrime will always be one step ahead of legislative protections and enforcement. The survey revealed that respondents concern about the adverse impact of regulatory enforcement appreciably affects their willingness to share incident information with the government. Liability protection is a critical component of a voluntary cyber information-sharing program. Without meaningful liability protection, companies will be hesitant to participate because any act or omission made by a participant based upon cyberthreat information received by that entity could subject it to liability. This concern may also explain why only 23% of respondents said that their company had built a close working relationship with either a government enforcement agency (FBI, US Secret Service) or a prosecutorial agency (DOJ or state attorneys general) on cyber issues. An equivalent percentage (23%) reported working closely with industry regulatory (FTC, FCC, FDIC, CFPB). Over 40% said no, they have no such relationship, while approximately 24% did not know. The survey showed that 84% of respondents expect clear national standards on data breach notification to emerge within the next five years. Smaller numbers expected national standards for securing personally identifiable information, investor disclosures and liability protection for information sharing. This may reflect a growing recognition in Congress that having 47 different reporting standards does not make sense. Given the number of breaches that have occurred in recent years, it makes sense to instead have a clear set of standards, not just for notification but for information security as well. Nearly 50% of respondents weren t sure if the NIST Cybersecurity Framework has been helpful to their company in managing cybersecurity risk. This may indicate that it is premature to judge the NIST Framework, or that companies are not sufficiently aware of how it is meant to be helpful. Mayer Brown has published an informative overview which can be found at: mayerbrown.com/the-nist-cybersecurity-framework-overview-and-potential-impacts/. mayer brown 1
4 Full Survey Results Question 1: Does your organization have a Chief Privacy Officer ( CPO, or equivalent) or a Chief Information Officer ( CIO, orequivalent) who is accountable for developing, implementing and maintaining an organization-wide governance and privacy/cybersecurity program? 33% 37% 21% 4% 4% Chief Privacy Officer ( CPO or equivalent) Chief Information Officer ( CIO or equivalent) Both a CPO and a CIO Neither a CPO or a CIO Don t know the answer Question 2: How would you describe your outlook on cybersecurity issues? For this survey, cybersecurity issues could include breaches, attacks, denial of service, loss of data, and/or damage to cyber infrastructure. 27% 29% 36% 9% Optimistic, we re catching Pessimistic, the Neutral, cyber-related Don t know the answer up with or getting ahead problem(s) will always be issues are a cost of doing of the problem(s) one step ahead business 2 Perspectives on Cybersecurity and Its Legal Implications
5 Question 3: Which do you consider the biggest threat to your company? 4% Breach of confidential personally identifiable information 24% Theft of trade secrets Loss of availability or sabotage of systems 9% Don t know the answer 63% Question 4: Has the NIST Cybersecurity Framework been helpful to your company in managing cybersecurity risk? Yes No Don t know 36% 17% 47% mayer brown 3
6 Question 5: Has your company built a close working relationship with a government entity on cybersecurity issues (more than one answer could have been selected)? 20% 23% 41% Yes, a law enforcement agency (e.g., FBI, US Secret Service) Yes, an industry regulator (e.g., FTC, FCC, FDIC, CFPB) No 3% 7% 24% Yes, a prosecutorial agency (e.g., State AG, DOJ) Yes, an incident response agency (e.g., US-CERT) Don t know the answer Question 6: Which of the following percentage ranges best represents the estimated amount that litigation risk associated with cybersecurity issues influences your company s cybersecurity planning? 34% 23% 10% 6% 0% 0% - 20% 20% - 40% 40% - 60% 60% - 80% 80% - 100% *Don t know the answer - 27% 4 x Survey Results
7 Question 7: Does concern about regulatory enforcement actions or other adverse regulatory action impact your company s willingness to share incident information with the government? 14% 11% 27% 13% 4% 1 (no impact) (significant impact) *Don t know the answer - 30% Question 8: Do you expect clear national standards to emerge in the next five years in the following areas (more than one answer could have been selected)? Data breach notification Security of personally identifiable information Investor disclosures 84% 54% 41% Cybersecurity of third-party service providers Liability protection for information sharing 34% 30% mayer brown 5
8 Question 9: Has your company developed a global strategy to meet the differing cybersecurity and data privacy legal requirements of the countries in which you operate? Yes 46% No, we handle compliance on an individual country basis 27% Not applicable 17% Don t know the answer 10% Question 10: Does your company have a separate cyber insurance policy? Yes, for liability 27% Yes, for remediation costs Yes, for penalties or fines 7% 0% No, but considering in the next 12 months 14% No, but might down the road No interest 14% 4% *Don t know the answer - 33% 6 x Survey Results
9 Question 11: Does your organization have a written data protection plan? If so, how was the plan prepared (more than one answer could have been selected)? 30% 30% 49% We retained an outside IT expert or outside counsel to assist in preparing the plan We consulted the PCI, NIST and or ISO standards in preparing the plan Don t know the answer Question 12: If your company suspected that a cyber-related incident had occurred, which two external entities on the following list do you believe your company would contact first? IT security company Consulting firm with cybersecurity advisory Law firm Insurance company Law enforcement (any level) 19% 21% 28% 7% 13% 4%? Some other external entity not listed here *Don t know the answer 8% mayer brown 7
10
11 About Mayer Brown Mayer Brown is a global legal services provider advising clients across the Americas, Asia and Europe. Our geographic strength means we can offer local market knowledge combined with global reach. We are noted for our commitment to client service and our ability to assist clients with their most complex and demanding legal and business challenges worldwide. We serve many of the world s largest companies, including a significant proportion of the Fortune 100, FTSE 100, DAX and Hang Seng Index companies and more than half of the world s largest banks. We provide legal services in areas such as banking and finance; corporate and securities; litigation and dispute resolution; antitrust and competition; US Supreme Court and appellate matters; employment and benefits; environmental; financial services regulatory and enforcement; government and global trade; intellectual property; real estate; tax; restructuring, bankruptcy and insolvency; and wealth management. Please visit for comprehensive contact information for all Mayer Brown offices. Mayer Brown is a global legal services provider comprising legal practices that are separate entities (the Mayer Brown Practices ). The Mayer Brown Practices are: Mayer Brown LLP and Mayer Brown Europe-Brussels LLP, both limited liability partnerships established in Illinois USA; Mayer Brown International LLP, a limited liability partnership incorporated in England and Wales (authorized and regulated by the Solicitors Regulation Authority and registered in England and Wales number OC ); Mayer Brown, a SELAS established in France; Mayer Brown JSM, a Hong Kong partnership and its associated legal practices in Asia; and Tauil & Chequer Advogados, a Brazilian law partnership with which Mayer Brown is associated. Mayer Brown Consulting (Singapore) Pte. Ltd and its subsidiary, which are affiliated with Mayer Brown, provide customs and trade advisory and consultancy services, not legal services. Mayer Brown and the Mayer Brown logo are the trademarks of the Mayer Brown Practices in their respective jurisdictions The Mayer Brown Practices. All rights reserved. Attorney advertising
12 Americas Asia Europe
Corporate Perspectives On Cybersecurity: A Survey Of Execs
Portfolio Media. Inc. 860 Broadway, 6th Floor New York, NY 10003 www.law360.com Phone: +1 646 783 7100 Fax: +1 646 783 7161 [email protected] Corporate Perspectives On Cybersecurity: A Survey
Spring 2015 reforms: the new DC flexibilities
Spring 2015 reforms: the new DC flexibilities THE REFORMS AT A GLANCE y Until April 2015, members usually faced serious tax penalties if they did not spend at least 75% of their DC pots on an annuity meeting
Addressing UBTI Concerns in Capital Call Subscription Credit Facilities
Legal Update November 2012 Addressing UBTI Concerns in Capital Call Subscription Credit Facilities A subscription credit facility (a Facility), also frequently referred to as a capital call facility, is
New York State Department of Financial Services Proposes a BitLicense Regulatory Framework for Virtual Currency Businesses
Legal Update August 6, 2014 New York State Department of Financial Services Proposes a BitLicense Regulatory Framework for Virtual Currency Businesses The New York State Department of Financial Services
IRS Issues Revised Guidance on Form W-2 Reporting Requirements for Costs of Employer Group Health Coverage
Legal Update January 23, 2012 IRS Issues Revised Guidance on Form W-2 Reporting Requirements for The Patient Protection and Affordable Care Act of 2010 (PPACA) requires employers to report the aggregate
Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates
Legal Update February 11, 2013 Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates On January 17, 2013, the Department of Health
Intellectual Property & Data Protection 2015: Legal developments you need to know about
Intellectual Property & Data Protection 2015: Legal developments you need to know about Welcome This is a short guide to some of the key legal developments for intellectual property and data protection
TERMINATION PAYMENTS AND INTERNATIONALLY MOBILE EMPLOYEES
Article A similar version of this article first appeared in tax Journal, 18 November 2013 TERMINATION PAYMENTS AND INTERNATIONALLY By James Hill Speed Read: The taxation of termination payments paid to
Information Disclosure on the Securities Market
3 Legal Update Banking & Finance Construction & Engineering Corporate & Securities Vietnam 06 July 2012 Information Disclosure on the Securities Market Summary On 5 April 2012, the Ministry of Finance
Major Changes Introduced by the New Companies Ordinance Private and Public Companies 1
Major s Introduced by the New Companies Ordinance Private and Public Companies 1 1. Abolition of Memorandum of Association Memorandum of Association is abolished for all local companies. Current provisions
Trends in Data Breach and CybersecurityRegulation, Legislation and Litigation. Part I
Trends in Data Breach and CybersecurityRegulation, Legislation and Litigation Part I March 20, 2014 Speakers John J. Sullivan, Partner, rejoined Mayer Brown after serving as General Counsel at the US Department
Good faith is there a new implied duty in English contract law?
Legal Update July 2013 Good faith is there a new implied duty in English contract law? Background English law does not currently recognise a universal implied duty on contracting parties to perform their
China s New Trademark Law Introduces Key Changes
Legal Update Intellectual Property Mainland China 13 September 2013 China s New Trademark Law Introduces Key Changes The PRC government passed a decision to amend the PRC Trademark Law on 30 August 2013.
A Quick Start Guide to EMIR: What you need to do and when
Legal Update January 2013 A Quick Start Guide to EMIR: What you need to do and when On 19 December 2012 the Commission adopted the majority of the subordinate legislation necessary to implement Regulation
Crossing Borders New Guidance on the Transfer of Personal Data outside Hong Kong
Legal Update Privacy & Security Hong Kong 20 January 2015 Crossing Borders New Guidance on the Transfer of Personal Data outside Hong Kong Section 33 of the Hong Kong Personal Data (Privacy) Ordinance
Vietnam s Insurance Market: An Overview January 2014
Legal Update Insurance Vietnam 29 January 2014 Vietnam s Insurance Market: An Overview January 2014 1. Introduction Vietnam started liberalising its insurance market by allowing foreign insurers to participate
Capital Commitment Subscription Facilities and the Proposed Liquidity Coverage Ratio
Legal Update December 20, 2013 Capital Commitment Subscription Facilities and the Proposed Liquidity Coverage Ratio On November 29, 2013, the Board of Governors of the Federal Reserve System (FRB), the
Rare Bird Sightings: Recent Developments Address Distressed Obligation Issues Faced by REMICs
Article Rare Bird Sightings: Recent Developments Address Distressed Obligation Issues Faced by REMICs By Russell Nance, Erin Gladney and Mark Leeds For more than 30 years, tax practitioners working with
Financial Institutions and Cloud Computing What s on the Horizon
Financial Institutions and Cloud Computing What s on the Horizon Rebecca Eisner Partner - Chicago +1 312 701 8577 [email protected] Mark Prinsley Partner - London +44 203 130 3900 [email protected]
Beginner s Glossary to Fund Finance
Article Beginner s Glossary to Fund Finance By Kristin M. Rylko, 1 Zachary K. Barnett 2 and Mark C. Dempsey 3 Kristin M. Rylko Chicago +1 312 701 7613 [email protected] Zachary K. Barnett Chicago +1
Technological Evolution
Technological Evolution The Impact of Social Media, Big Data and Privacy on Business Consumer Privacy & Big Data Advice, Regulatory and Resulting Litigation Denise Banks Chief Privacy Officer BMO Financial
Insolvency Litigation and Related
Insolvency Litigation and Related Strategic t Concerns US, European and Asian Considerations David Allen Partner London Jean Marie Atamian Partner New York Jan Kraayvanger Partner Frankfurt +44 20 3130
Negotiating ERP Implementation Agreements for Success
Negotiating ERP Implementation Agreements for Success Paul Chandler 312 701 8499 [email protected] Paul Roy 312 701 7370 [email protected] Business & Technology Sourcing Practice "An excellent
Equity Incentive Plans Extending US- and UK-based Plans Across the Pond
Equity Incentive Plans Extending US- and UK-based Plans Across the Pond Andrew Stanger Partner +44 20 3130 3934 [email protected] James C. Williams Partner +1 312 701 8139 [email protected]
Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re
Cyber Risk: Global Warning? by Cinzia Altomare, Gen Re Global Warning It is a matter of time before there is a major cyber attackon the global financial system and the public needs to invest heavily in
Lawyers and Social Media: The Legal Ethics of Tweeting, Facebooking and Blogging
Lawyers and Social Media: The Legal Ethics of Tweeting, Facebooking and Blogging Anthony Diana, Partner 212 506 2542 [email protected] Michael Lackey, Partner 202 263 3224 [email protected] Mayer
Contracting for Cloud Computing
Contracting for Cloud Computing Geofrey L Master Mayer Brown JSM Partner +852 2843 4320 [email protected] April 5th 2011 Mayer Brown is a global legal services organization comprising legal
Cybersecurity and Data Breach: Mitigating Risk and How Government Policymakers Approach These Critical Issues
Cybersecurity and Data Breach: Mitigating Risk and How Government Policymakers Approach These Critical Issues Todd Bertoson Daniel Gibb Erin Sheppard Principal Senior Managing Associate Counsel [email protected]
US Bank Regulators Propose Net Stable Funding Ratio Rule to Enhance Financial System Resiliency
Legal Update May 5, 2016 US Bank Regulators Propose Net Stable Funding Ratio Rule to Enhance Financial System Resiliency The Federal Deposit Insurance Corporation (FDIC), Office of the Comptroller of the
German Insolvency Law is geared towards liquidation of the debtor insolvency plan procedures are only applied in exceptional cases.
German Insolvency Law is geared towards liquidation of the debtor insolvency plan procedures are only applied in exceptional cases. German Insolvency Law German insolvency law is governed by a comprehensive
Guide on How to Invest in Real Estate in Hong Kong
Guide on How to Invest in Real Estate in Hong Kong Mayer Brown JSM... 9 times a winner of Real Estate Law Firm of the Year, by Asian Legal Business Awards Table of Content 1. How are ownership rights
FINRA Publishes its 2015 Report on Cybersecurity Practices
Securities Litigation & Enforcement Client Service Group and Data Privacy & Security Team To: Our Clients and Friends February 12, 2015 FINRA Publishes its 2015 Report on Cybersecurity Practices On February
Guide to Discrimination Law in the PRC
Guide to Discrimination Law in the PRC 1 General Introduction 2 Discrimination Against Women 3 Disability Discrimination 6 Discrimination Against Carriers of Epidemic Pathogens General Introduction There
Cyber Risks in the Boardroom
Cyber Risks in the Boardroom Managing Business, Legal and Reputational Risks Perspectives for Directors and Executive Officers Preparing Your Company to Identify, Mitigate and Respond to Risks in a Changing
Mitigating and managing cyber risk: ten issues to consider
Mitigating and managing cyber risk: ten issues to consider The board of directors is responsible for managing and mitigating risk exposure. A recent study conducted by the Ponemon Institute 1 revealed
Authorisation and Restriction: Interplay and other Strategic Considerations
Authorisation and Restriction: Interplay and other Strategic Considerations Informa Conference on REACH Montfort, Jean-Philippe Partner +32 (0)2 551 5970 [email protected] Brussels, 5 March 2012
Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements
Insurance Considerations Related to Data Security and Breach in Outsourcing Agreements Greater New York Chapter Association of Corporate Counsel November 19, 2015 Stephen D. Becker, Executive Vice President
Cyber Insurance Presentation
Cyber Insurance Presentation Presentation Outline Introduction General overview of Insurance About us Cyber loss statistics Cyber Insurance product coverage Loss examples Q & A About Us A- Rated reinsurance
Guide to Investing in Real Estate in the PRC
Guide to Investing in Real Estate in the PRC China Business Law Award Winner: Construction & Real Estate China Business Law Journal (2013) Asia Law Firm of the Year (Transactions) Global PERE Awards (2013)
Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission. June 25, 2015
Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission June 25, 2015 1 Your Panelists Kenneth L. Chernof Partner, Litigation, Arnold & Porter LLP Nicholas
Bloomberg BNA Professional Learning Legal Course Catalog OnDemand Programs
Bloomberg BNA Professional Learning Legal Course Catalog OnDemand Programs *This is a sample course catalog. BBNA is in the process of moving all of our recorded content on to our new platform. Not all
Managing Cyber Security as a Business Risk: Cyber Insurance in the Digital Age
Managing Cyber Security as a Business Risk: Cyber Insurance in the Digital Age Sponsored by Experian Data Breach Resolution Independently conducted by Ponemon Institute LLC Publication Date: August 2013
Cloud Computing: A Primer on Legal Issues, Including Privacy and Data Security Concerns. Privacy and Information Management Practice / Washington, DC
Cloud Computing: A Primer on Legal Issues, Including Privacy and Data Security Concerns Privacy and Information Management Practice / Washington, DC Disclaimer THIS PRESENTATION IS TO ASSIST IN A GENERAL
Cyber and Data Security. Proposal form
Cyber and Data Security Proposal form This proposal form must be completed and signed by a principal, director or a partner of the proposed insured. Cover and Quotation requirements Please indicate which
The Legal Pitfalls of Failing to Develop Secure Cloud Services
SESSION ID: CSV-R03 The Legal Pitfalls of Failing to Develop Secure Cloud Services Cristin Goodwin Senior Attorney, Trustworthy Computing & Regulatory Affairs Microsoft Corporation Edward McNicholas Global
Third Annual Study: Is Your Company Ready for a Big Data Breach?
Third Annual Study: Is Your Company Ready for a Big Data Breach? Sponsored by Experian Data Breach Resolution Independently conducted by Ponemon Institute LLC Publication Date: October 2015 Ponemon Institute
Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd
Data breach, cyber and privacy risks Brian Wright Lloyd Wright Consultants Ltd Contents Data definitions and facts Understanding how a breach occurs How insurance can help to manage potential exposures
Restructuring, Bankruptcy & Insolvency in Asia
Restructuring, Bankruptcy & Insolvency in Asia Mayer Brown JSM has one of the most respected Restructuring, Bankruptcy & Insolvency teams in Asia, and is one of only a few law firms in the region with
What are you trying to secure against Cyber Attack?
Cybersecurity Legal Landscape Bonnie Harrington Executive Counsel EHS and Product Safety & Cybersecurity GE Energy Management Imagination at work. What are you trying to secure against Cyber Attack? Personally
MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS
MANAGING Cybersecurity Risk AND DISCLOSURE OBLIGATIONS RRD Donnelley SEC Hot Topics Institute May 21, 2014 1 MANAGING CYBERSECURITY RISK AND DISCLOSURE OBLIGATIONS Patrick J. Schultheis Partner Wilson
Competitive Intelligence Acquisition and Reverse Engineering
Competitive Intelligence Acquisition and Reverse Engineering Pitfalls and Best Practices in the US, the UK and Germany Richard M. Assmus Andrea C. Hutchison Dr. Ulrich Worm May 20, 2010 Sangeeta Puran
A Brief Legal Guide to Investing in Real Estate in the US
A Brief Legal Guide to Investing in Real Estate in the US chicago Contents 1. What makes the property market in the United States popular for investment? 1 2. What is the process for a foreign investor
The German Pension System. An Overview
Established more than 100 years ago the German Pension System often perceived as an old-fashioned dinosaur has been subject to a number of reforms to make it fit for the challenges of the future. The German
Leveraging Supply Chain Finance to Optimize Value
Leveraging Supply Chain Finance to Optimize Value Brad Peterson +1 312 701 8568 [email protected] Massimo Capretta +1 312 701 8152 [email protected] David A. Ciancuillo +1 312 701 7258 [email protected]
RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION
RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION October 23, 2015 THREAT ENVIRONMENT Growing incentive for insiders to abuse access to sensitive data for financial gain Disgruntled current and former
The promise and pitfalls of cyber insurance January 2016
www.pwc.com/us/insurance The promise and pitfalls of cyber insurance January 2016 2 top issues The promise and pitfalls of cyber insurance Cyber insurance is a potentially huge but still largely untapped
The Cloud and Cross-Border Risks - Singapore
The Cloud and Cross-Border Risks - Singapore February 2011 What is the objective of the paper? Macquarie Telecom has commissioned this paper by international law firm Freshfields Bruckhaus Deringer in
Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor
Cyber Risks Management Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor 1 Contents Corporate Assets Data Breach Costs Time from Earliest Evidence of Compromise to Discovery of Compromise The Data Protection
