Welcome to our 11th annual Data Security Incident Response Report!
Posted in Data Security Incident Response
The idea for this report came from spending time on-site with clients and watching them leverage not only their data but also our data — to predict outcomes and make decisions during a cybersecurity crisis response. It’s rewarding to see clients and third-party partners refer to the report during the year. A chief legal officer reassuring a board that the right vendors have been retained can go a long way, and when that executive can provide actual industry-specific averages for time to restore, ransom payment amounts, and number of individuals notified, the board gets even greater comfort and likely is better prepared to ask the questions necessary as part of its oversight responsibility.
It is hard to believe that it has been six years since we became (and remain) the only law firm to create a practice group — our Digital Assets and Data Management (DADM) Practice Group — dedicated to lifting data, technology, and innovation to the same level as traditional law firm practice groups to advise clients across the life cycle of data and technology. Building a convergence practice enabled us to more effectively help clients address enterprise risks and opportunities involving data, brand strategies, and innovation. Seeing how threat actors attack assets, regulators build enforcement priorities, private litigants choose whom to pursue and how to resolve claims, and entities build and market products and services allows our team to provide practical and actionable advice tailored to risk appetite and goals.
We are now building our group’s second five-year strategic plan, and our planning highlights the underlying challenge in this area: The more things change, the more they stay the same. Yes, there are definitely areas of rapid change. We see AI creating disruption, yet it has not shown up in a meaningful way in security incidents. Phishing was the leading underlying cause of incidents in our first report, 11 years ago (at 31%), and it is still near the top of the list this year (24%) (however, it has evolved — our report covers four different tactics). Phishing awareness training has not eradicated phishing as an effective attack vector, though there are definitely areas where the security industry has made progress. The industry supporting compromised entities has matured — as a result, we see shorter dwell time, shorter time to containment, faster completion of forensic investigations, lower cost for forensic investigations, shorter time to restoration after ransomware deployment, and declining ransom payment amounts. The combined efforts of carriers, brokers, law firms, forensic firms, restoration firms, ransom negotiation and payment facilitation firms, and law enforcement have yielded positive results.
An area where more help is warranted is post-data breach lawsuits and privacy lawsuits (especially ones exploiting old laws because those laws have minimum statutory damage components). After 15+ years of sensitive data being compromised, the records of most individuals have been involved 5, 10, or 50 times. Consequently, it is extremely rare to see actual fraud or loss connected to an incident. In the absence of harm, it is disappointing to see litigants capitalize on the uncertainty caused by old laws and inconsistent rulings for financial gain. The value of both precedent and the rule of law is immeasurable.
We hope you enjoy the report, and we invite you to reach out to any one of the DADM Practice Group’s members with questions or suggestions.

