Be Forthcoming
The question isn't whether a breach will happen, but when it will happen. Since it's impossible to know when an adversary will attack, it's wise to plan for the event in any case. A forensic examination can reveal what happened and how, although most organizations lack the resources they need to perform effective forensic work. From reputational and cultural perspectives it's imperative that employees and customers be notified about a breach in a timely manner and informed about what the company is doing to address it, even though the details of the breach may remain unknown for weeks or months.
"The biggest mistake companies make when something happens is to delay communication until they think they have the whole picture, thus reducing their user's or employee's ability to protect themselves because they're not aware of what's going on," Jacob West said. "The longer you wait to admit a problem, the more it appears you're trying to cover something up."
(Image: Unsplash via Pixabay)