


The cyber incident timeline is often delineated based on when things happen compared to discovering an incident – the Boom. The Left of Boom refers to everything before discovering the incident, and the Right of Boom describes everything after. Public consciousness of cyber attacks, guided by media coverage, focuses on the Right of Boom – things like the victim company’s response and communications and the impact on end customers and the company’s reputation. However, the preparation – all done Left of Boom – determines a company’s odds of successfully navigating a significant cyber incident. That preparation, unfortunately, is all too easy for in-house counsel to neglect.
The dedicated in-house cyber counsel role did not exist just a few years ago. Today it exists in a small number of very large corporations and security firms, but most in-house lawyers are only expected to weigh in on cybersecurity issues on an ad hoc basis. Cyber security is a secondary concern to their “real” job. What happens when in-house counsel’s first exposure to cyber security occurs during an incident? Faced with unfamiliar cyber/technical concepts, the temptation to defer to the “experts” can be overwhelming. The lawyer is merely an ancillary player, which does a great disservice to the corporate client. Fortunately, a preparation mindset can ensure sufficient work is done Left of Boom to substantially enhance the odds of successfully resolving a cyber incident.
Every business – big or small – will eventually face a cyber incident. And when it happens, there is no substitute for preparation. For a lawyer, preparation means thinking through the contingencies in advance and lining up internal and external resources. “Winging it” leads to bad outcomes. Weighing the risks of paying or not paying an extortion demand or whether to engage law enforcement should not be done for the first time during an incident. Similarly, selecting outside counsel, a forensic investigator, or a ransomware negotiator under duress is, at best, a gamble and an invitation to be taken advantage of. Fortunately, all of these things can be addressed in advance. In-house counsel can begin by meeting external resources, weighing whether to establish retainer agreements and considering the various legal issues that could arise. Is a third party involved? Is it a vendor? Customer? Does contract language compel certain actions during the incident response? Is there insurance coverage? Do regulators or anyone else need to be notified? Might there be media inquiries? Who are the internal decision-makers? Who will do the technical work? These are just a few basic questions to consider, and each question will lead to several others. Pair that with regular tabletop exercises, and eventually, a robust preparation cycle emerges.
" Asking questions even if they highlight ignorance on a topic is critical because those questions often spark insight among the technical team and pave the way for more open and honest collaboration "
It is easy for an attorney with no technical background to feel out of their depth during a cyber incident. But the cyber incident lawyer’s role is often to translate technical jargon into a non-technical message and convey legal and risk concerns in a manner that the technical experts can easily digest. Again, preparation is key to familiarity with terminology and core concepts.
In-house counsel is often uniquely positioned among the incident response team to see broadly across the enterprise risk landscape. This perspective is indispensable to successfully handling a cyber incident, and taking advantage of it requires putting aside anxiety and self-doubt at being the least technical person in the room. Even if in-house counsel is merely acquainted with the other incident response team members, minimal preparation can help overcome the initial reluctance to speak up. Asking questions, even if they highlight ignorance on a topic, is critical because those questions often spark insight among the technical team and pave the way for more open and honest collaboration. In-house counsel’s questions often clarify that even the most technical problems have non-technical impacts that must be factored into the solution. Perhaps most importantly, in-house counsel modeling an inquisitive mindset helps everyone think differently about the problem.
Preparation saves valuable time, fosters trust among internal and external resources, and helps minimize costs. It builds confidence and reduces panic. Business leaders derive great comfort from knowing their lawyers have already thought through contingencies and lined up resources. Perhaps most importantly, preparation enables adaptability in crisis. It’s imperative to remain flexible and adapt to the circumstances of the incident as they develop. Every incident holds countless unforeseen and often unforeseeable twists. In-house counsel must accept that some events are beyond their control and embrace a dynamic approach. Proper preparation provides a toolbox of options – a framework for response – and helps in-house counsel understand what is likely (and unlikely) to work in a given scenario. The old military maxim holds true for in-house counsel during a cyber incident – plans are worthless, but planning is everything.