32
DATA BREACHES What’s Your Plan? PREPARED BY

DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

  • Upload
    others

  • View
    8

  • Download
    0

Embed Size (px)

Citation preview

Page 1: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

DATA BREACHESWhat’s Your Plan?

PREPARED BY

Page 2: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control
Page 3: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

NO ONE IS SAFE

Page 4: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

IT’S NOT IF THERE IS GOING TO BE A DATA BREACH

It’saquestionof

Page 5: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

92%oforganizationsbreachedsuffercommercialconsequencesTargetincurredover$290millioninbreachexpenses,ofwhichinsuranceonlycovered31%

64%ofconsumerssurveyedworldwidesaytheyareunlikelytoshopordobusinessagainwithacompanythathadexperiencedabreachwherefinancialinformationwasstolen

Page 6: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Communicationsiscriticaltosuccessfullymanagingadatabreach

• Thekeyismanagingtheresponse• Knowwhatyou’regoingtosay

Delaying,hiding,concealinginformationaboutcustomersisnotviewedfavourably

Page 7: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Today’srealityinanonlineworldcanwreakhavoconabrand,whichiswhyspeed,honestyandhavingaplanyoucanexecute,areallcentraltoaneffectivecrisiscommunicationsresponse.Evenonestatementtakenoutofcontextormadebyanemployeecanhaveadevastatingimpactonabrand’sbottomline.

Page 8: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

JULY 2016:

Over1,000 USlocationsimpacted– morethan3.4timesthenumberoflocationsfirstannouncedinthefallof2015.Customerdata,includingcardholdernames,creditordebitcardnumbers,cardholderverificationvalues,andservicecodesstolen.

Page 9: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

LackofcommunicationfrustratesOhiocreditunion:

Wedon'tknowhowlargeorsmalltheproblemis.Wendy'sisnotprovidingthatinformationfastenough,whichistypicalinthesebreaches.

- GretchenBartholomew,directorofoperations,Kemba FinancialCreditUnion

Page 10: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Targetwasavictimofoneofthemostwidespreaddatabreachesinhistory.MalwarefromthelaptopofanHVACcontractormadeitswayontoTarget’smaincomputernetwork.Throughthethird-partyvendor,hackerswereabletoaccessTarget’sdatabase.Morethan40million Targetcustomershadtheirdebitandcreditcardrecordsstolen.70millionpeople hadtheiremailandmailingaddressestaken

Page 11: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Concernedconsumersfacedpoorcustomerservicewhencallingorsearchingformoreinformationregardingthebreachafterthenewsinitiallybroke.

• Quarterlyprofitsdroppedby46%asthehithappenedduring2013Xmasholidays

• Target’sCEOresigned• Breachcoststodate:$290millionUSD

Page 12: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• IttookTarget22daysfromitsbreach’soccurrenceforittoreportitpublicly

• IttookWendy’s51daystoreportitpublicly• Targettook19daysfromitsfirstannouncementtoconfirmpublicly

ithadremovedthemalwareandstopthebreach• IttookWendy’s143daystomakethesameannouncement

Page 13: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Veridian CreditUnionhasfiledaclassactionlawsuitagainstWendy'sTheclassactionclaimsWendy'sfailedtopreventthebreachbyupdatingitsPOSsystems

Despitethegrowingthreatofcomputersystemintrusion,Wendy'ssystematicallyfailedtocomplywithindustrystandardsandprotectpaymentcardandcustomerdata.

Page 14: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Veridian claimssecuritysystemswereoutdated,creditcardinformationwasn'tdeletedwhenitwassupposedtobe,antivirussoftwarewasn'tregularlyupdated,firewallsweren'tmaintained,andaccesstonetworkandcreditcarddatawasn'tmonitored.

Page 15: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Franchisorsneedtolearnhowtoeffectivelycommunicatedatabreaches

• Lettingconsumersknowaboutabreachearlyoncanhelppreventdamagetoafranchise’sreputation

• Asuccessfulcrisiscommunicationsresponseforfranchisesrelaystherightkeymessagestoallstakeholdersasquicklyaspossible

Page 16: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

How can you apply best practices to protect your franchise from a data breach or cyber crisis?

Page 17: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

STEP 1: COMMUNICATE THE PROBLEM

Yourcrisiscommunicationsteam’sfirstpriorityistocommunicatedirectlywithyouraffectedstakeholdersassoonaspossible.• Takecontrolofthestory• Behonestandtothepoint• Letyouractionsandwordsshowhowdeeplyyoucareandare

takingthesituationseriously• Makesureyourcommunicationsanswersthemainquestions

Page 18: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Sayhowthebreach:

§ affectsthoseimpacted§ whattheyshoulddotoimmediatelyprotectthemselvesand…§ whereandwhenyouwillprovideanotherupdate

COMMUNICATE

Page 19: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

STEP 2: RELEASE YOUR OFFICIAL STATEMENT

• Draftanofficialstatementandpublishittoyourcrisiscommunicationshomebase

• Createalinktothisstatementfromyourwebsite’shomepage• Tellyourstory.Ifthemediawillbereportingonthis,thengive

themthe(true)storytouse.Thisisagoodwaytomakesureyoubecomethenarrativeofyourowncrisis

Page 20: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Beashonest,transparentandcompassionateasyouwereinyourdirectcommunicationswithyouraffectedstakeholders.Focusonbuildingandstrengtheningyourrelationships

• Clearlystatewhattherepercussionsare,whatyouhavedoneandwhatyouwillbedoingtomanagethiscrisisandprotectthosewhoseconfidentialinformationhasbeenbreached

Page 21: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Answerallforeseeablequestions– andcomebackandupdatethisstatementasmorequestionsgetanswered

• Titlethisstatementwithatitlethatwillrankwellforthekeywordspeoplewillusetosearchformoreinformation

• Provideacontactformediainquiries

Page 22: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

STEP 3: MAKE SURE YOUR SOCIAL MEDIA TEAM IS READY

• Linktoyourofficialstatementfromyoursocialmediaaccounts• Monitorsocialmedia.peoplewillbegoingtoyourplatformsto:

§ Lookforinformation§ Askquestions§ Expresstheirupsetanddisappointment

Page 23: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Yoursocialmediateamneedstobearmedwith:

• Clearmessagingforproperresponse• Informationonwheretosendspecificinquiriesthatneedtobe

redirected• Aresponseflowcharttohelpthemanswerthetoughquestions,

suchaswhentorespond,andwhentoescalateaspecificcasetothecrisisteam

Page 24: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

STEP 4: MONITOR YOUR ONLINE REPUTATION

Page 25: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

Ifthehackhasgarneredenoughattentionmediaandbloggerswillreportit.Thesearticleswillbeindexedinthesearchengines,whichmeansthatyouwillwantto:

• Makesureyourcommunicationsarehelpingtoshapethenarrativeofthiscrisis

• Dowhatyoucantomakesuretheserankedarticlesarenotgoingtooverpoweryourownonlinepresenceandrankings

Page 26: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

SUMMARY

• Communicate,communicate,communicate• Nosuchthingastoomuchinformation• Haveamediarelationsstrategy• Supportbrandtorebuildtrust• Demonstrateopenness• Commitmenttocustomers• Cybercrisiscanbecomeacrisisoftrustandloyaltyifswift

communicationsaren’tused

Page 27: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

THE 3Rs

Page 28: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

RESPONSIBILITY

• Takeresponsibilityforsolvingthedatabreach• Youractionswillreinforceyourwordsanddemonstrateyour

honestyandcommitment• Keyelementisyourdeterminationtoaddressandsolvetheissue,

notnecessarilyacceptingresponsibilityfortheunderlyingcause

Page 29: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

REGRET

• Evenifitisnotyourfault,expressregretthattheproblemhasdeveloped.Thiscanbeachievedwithoutsacrificinganylegalrights

Page 30: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

RESPONSE

• Timingisextremelyimportant• Youremployees,media,customersandthegeneralpublicmust

knowyouaretakingstepstodealwiththeissueandworkinghardtoensureitwillnotberepeated

Page 31: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

PREPARE FOR THE WORST – HOPE FOR THE BEST

• Alwaysplanforincidentresponse.Yourplanshouldincludedetection,responseandescalation,engaginglawenforcementasappropriate,preservationofevidence,compliancewithregulationsandcontractualagreements,customerandmedianotificationandpublicrelations.

Page 32: DATA BREACHES What’s Your Plan? · Your crisis communications team’s first priority is to communicate directly with your affected stakeholders as soon as possible. • Take control

• Aprofessionalcrisiscommunicationsplanwillestablishabestpracticesprotocoltofollowandhelpmanagethecrucialearlydaysofacrisis

• Aplanwillprovetobeaninvaluableresourceforfranchisesthatmaybeoperatingwithoutoneinplacetoday,whichwouldbesimilartodrivingwithoutinsurance

• Holdamockcrisistoensureeveryoneisawareoftheirresponsibilitiesandtoseeareasthatneedtobeimproved