Skip to Main Content

Welcome to the 10th edition of our annual Data Security Incident Response Report!

04/23/2024 | 3 minute read

Posted in Data Security Incident Response

More than a decade ago, our team talked about how great it would be to share with our clients the data from the incidents we helped manage. At first, it was more of a marketing idea to demonstrate the depth of our experience. As the cybersecurity world around us matured, we learned that our clients were hungry for our data to help guide them when making decisions. Forensics firms were sharing data; however, not all incidents require digital forensics, and clients retain law firms for different reasons.

Some things have changed since we started creating this report – and other things not so much. Our first report (produced with a calculator and basic graphics) covered six areas using data from 200 incidents. We significantly expanded the data we tracked in subsequent years and continue to focus on the data points our clients find most important. Because the report was so widely read, we also expanded our coverage of privacy governance and litigation trends. In a short time, our team went from working on hundreds of incidents per year to working on well over 1,000.

In 2020, the Digital Assets and Data Management Practice Group was launched at BakerHostetler and we became the only law firm to prioritize “data” along with traditional practices. We have added features from our tech transaction, advertising/marketing and digital media, emerging technology, digital transformation, and information governance teams. This year, we cover hot topics that include web tracking, artificial intelligence, and FTC investigations.

While companies have matured when it comes to addressing cybersecurity, the same themes emerge when we compile our data each year. We need to continue to focus on the basics and accept that the more things change, the more things stay the same. Ten years ago, lost unencrypted backup tapes were the big incidents. Ransomware attacks hold that spot now. Phishing has remained constant over the past decade and comes in multiple flavors ranging from tricking individuals into executing malware on a device to fooling an employee into providing W-2s to a fraudster pretending to be a colleague (thankfully those have dramatically slowed) or providing access credentials. We also watched the rise of endpoint monitoring tools (important for both protection and forensic investigations). The tool a company is using is no longer the most important factor in selecting a forensic firm, because most firms are now “tool agnostic” – which was not the case several years ago. Today, we are seeing identity and access management controls become more important. And the multi-year trend of significant supply chain attacks continues (SolarWinds, Blackbaud, MOVEit, and now Change Healthcare).

One constant has been the incredible value of strong relationships across the incident response ecosystem – clients, insurance carriers, brokers, monitoring counsel, forensic firms, negotiation and ransom payment firms, mailing/call center vendors, file review firms, and restoration firms. The positive impact on the ultimate outcome from external firms that we have worked with on hundreds or thousands of incidents cannot be overstated, and we are grateful to have such strong partners.

We cannot thank you enough for the endorsements, recommendations, guidance, expertise, help, and camaraderie you have demonstrated. We are proud to continue to serve clients we first worked with when we could count the number of incidents handled on one hand. I am also tremendously proud of the incredibly diverse BakerHostetler team for their commitment to client service, for staying up to date on trends, and for spending their “free time” putting together this report.

We look forward to continuing to use the methods, strategies, and insights gained from helping to manage over 15,000 incidents to help clients manage risk and compliance challenges going forward.