Skip to main content

Practice area 03

Data Security and Breach Response

The first hours of an incident decide most of what follows. Whether the notification clocks have started, who is authorised to speak, and whether the investigation is privileged are questions best answered before the call comes, not during it.

Frameworks in scope

  • GDPR Article 33 and 34
  • HIPAA Breach Notification Rule
  • US state breach statutes
  • NIST CSF
  • ISO/IEC 27001
Schedule a Consultation
03.1

Incident response planning

A plan is only useful if the people named in it know they are named in it. We write plans that are short, role-based, and specific about the decisions that must be made under time pressure, then rehearse them with the people who will have to make those decisions at an inconvenient hour.

  • Response plan with defined severity levels, decision authority, and escalation paths.
  • Notification analysis prepared in advance: which regimes apply, which clocks run from discovery, and who must be told.
  • Communication templates for regulators, affected individuals, customers, insurers and employees.
  • Tabletop exercises using scenarios drawn from your own architecture and vendor relationships.
  • Preserved routes to privilege, so investigation work is structured properly from the first hour.
03.2

Breach investigation

When something has happened, the priority is an accurate account of what was accessed, whose data it concerned, and what the law requires as a result. We coordinate the investigation as counsel, working with your security team and forensic vendors, and keep the legal analysis moving in parallel with containment rather than after it.

  • Scoping and evidence preservation, coordinated with internal security and external forensics.
  • A running determination of whether the event meets the notification threshold in each applicable jurisdiction.
  • Notification drafting and filing within statutory deadlines, including regulator portals and individual notices.
  • Regulator correspondence and follow-up inquiries, handled by counsel.
  • A post-incident report that records both the facts and the corrective actions taken.
03.3

Security audits and safeguards review

Security obligations in privacy law are written in terms of appropriateness, which means they are judged against your circumstances after the fact. We assess your administrative, physical and technical safeguards against the standard that would actually be applied to you, and produce a record of the reasoning behind each decision, including the risks you consciously accepted.

03.4

Policy development

Access control, encryption, retention and disposal, vendor security, acceptable use, and device standards all need to exist in writing and match what is deployed. We draft policies that reflect your environment rather than an imported template, and keep the set small enough that people can find the rule that applies to them.

What you receive

Work product, dated and defensible.

Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.

  • Incident response plan with roles and severity criteria
  • Jurisdictional notification matrix and clock analysis
  • Regulator, individual and customer notification templates
  • Tabletop exercise and written findings
  • Safeguards assessment against applicable security rules
  • Post-incident report and corrective action plan

How the engagement runs

Four stages, agreed before we start.

  1. 01

    Prepare

    Build the plan, agree decision authority, and rehearse it with the people who will run it.

  2. 02

    Contain

    On notification of an event, stand up the response, preserve evidence, and start the legal analysis immediately.

  3. 03

    Determine

    Establish scope and affected populations, and apply each jurisdiction’s threshold to the facts as they firm up.

  4. 04

    Notify and close

    File and send within the deadlines, handle follow-up inquiries, and record the corrective actions.

Common questions

Asked before most engagements.

Do we have to notify every time something goes wrong?

No. Most regimes set a threshold, and many events fall below it. The mistake is deciding that informally. We document the analysis so that a decision not to notify is a defensible conclusion rather than an omission.

Our vendor was breached, not us. Is that our problem?

Usually, yes. Where the data is yours, the obligation to notify typically remains yours, whatever your contract says about responsibility between the parties. That is why the vendor terms and the response plan need to be written together.

Can you work with our existing security team and forensics firm?

That is the normal arrangement. We do not replace your security function. We direct the legal side of the investigation, protect privilege where it is available, and take the notification decisions off the team that is trying to contain the incident.

Decide the hard questions before the incident.

If your plan has never been rehearsed, or does not exist yet, a consultation is the fastest way to find out what it is missing.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now