Know the steps to report a security breach to the authorities and the issues you should consider.
endif; ?>When do you call the police? Find out in the third in a four-part series on the toughest security issues affecting the enterprise.
“If there’s an incident where no customer data was compromised, I’m not legally required to tell anybody,” says John Pescatore, vice president for Internet security at Gartner. “There’s a lot of reasons not to report, such as damage to the brand.”
Examing the CSO/CEO relationship
Only 25% of organizations that experienced computer intrusions in the past year reported them to law enforcement, according to the 2006 Computer Security Survey by the Computer Security Institute (CSI) and FBI, released last month. Respondents cited many reasons for not reporting, including negative publicity harming the company stock or image (48%) and giving competitors something to use to their advantage (36%). The percentage reporting intrusions is up 5% from the previous two annual studies, however.
Those reporting levels compare favorably to the findings of a separate 2005 FBI Computer Crime Survey, in which only 9% of organizations say they reported computer security incidents to law enforcement, believing the infractions were not illegal or there was little the authorities could or would do.
The FBI is working hard to dispel those notions through programs such as InfraGard, a public/private partnership for information sharing regarding critical infrastructure. FBI Special Agent Nenette Day is among those set to speak about partnering with law enforcement at The Security Standard event in Boston.
The government has many reasons for wanting more businesses to come forward to report security breaches, says Chris Geary, a supervisory special agent with the FBI Cyber Division Computer Intrusion Section in Pittsburgh. “The people who are being victimized are seeing the newest exploitations that are occurring. The more information we get, the more we’re able to anticipate future trends or exploitations,” he says. A security incident might appear to be small but could be related to another investigation. And the main goal is to catch the cyberculprit.
Robert Richardson, editorial director of CSI, says companies’ previous reluctance to talk to the FBI stemmed from fear of a big, theatrical event where black vans would swarm the parking lot and agents would wrap police tape around the building and shut it down. “Odds are people who work in your building will not even be aware the FBI is there,” he says.
The FBI doesn’t release information regarding its cases, according to Geary, but there’s a chance it could become public during a criminal prosecution.
It’s a good idea to have a reporting policy in place. Know in advance whom to call if you decide to bring in law enforcement, Pescatore recommends. Contact national authorities rather than local police unless you have reason to believe there’s a local person involved, such as a disgruntled employee. The FBI suggests calling the regional branch, but Pescatore advises contacting the joint Secret Service/FBI interagency task force on cybercrime.
“Make sure you have already started the process to inform your customers if it’s a customer data breach and make sure you’ve closed the hole. By reporting, you’re going to attract a lot of attention,” he says. “Inform your affected users they’re likely to see an increase in things like phishing attacks.”
Also, begin documenting everything you do to the affected systems and start a chain of custody for the evidence, Geary says. He suggests quantifying the losses your organization suffers as a result of the computer intrusion, such the time devoted to response and recovery and the cost of damaged equipment, as well as the value of data and revenue lost.
Keep in mind the authorities may need to remove your compromised systems, which can be disruptive to running your business. If the government tries to prosecute a hacker, your IT staff might spend a lot of time working with law enforcement, and your sensitive information could end up being part of a disclosure in a law trial, Pescatore points out.
When Boston College’s database for third-party fund-raising fell victim to a malware attack in 2005, the university used its own campus police force to investigate and then brought in the FBI after going public.
“Their criminal forensics teams do a great job, but it’s sad to say based on recent events that there isn’t any particular evidence that the government in general can protect the data any better than we can,” says David Escalante, director of computer security for Boston College.
Although there was no sign the 120,000 personal records contained in the database were compromised, the university decided to notify alumni just in case. “We tried very hard to get the information out to people as soon as we knew about it,” Escalante says. He recommends organizations take a personalized approach when notifying those affected by a security breach. “Something we did that in retrospect was highly effective, although it was painful, was to send everyone a personalized letter,” he says.
So, when should you go public on security breaches? Your company may be obligated to report certain types of breaches to comply with a litany of state privacy laws, or a report might be required for a cyberinsurance claim. If you’re not sure you have a worthy case, the FBI wants to be the judge. The threshold for monetary loss stemming from cybercrime is $5,000, a total that’s easily achieved in response and recovery.




