Data breaches and cyber incidents can happen to any law firm. When an incident occurs, the actions taken during the first 72 hours can significantly affect the consequences for the firm, its clients and its regulatory position.
Following the first webinar in this three-part series, “Can We Use AI Safely in Law Firms? Data Protection, Compliance and Practical Guidance”, data protection expert and Spencer West Partner Kristy Gouldsmith returns to explain what firms should do immediately after discovering a suspected breach.
This practical session will explore how to assess and contain an incident, determine whether it must be reported to the Information Commissioner’s Office, decide if the affected individuals need to be told and preserve evidence for an internal investigation.
Kristy will also consider how firms should communicate with clients, employees and other affected parties without making the situation worse. She will explain the importance of clear responsibilities, accurate decision records and having an effective breach-response plan in place.
Key takeaways:
• The immediate actions firms should take after discovering a suspected breach.
• How to determine whether an incident is reportable to the ICO.
• How to decide what to tell the affected individuals
• Understanding the relevant reporting requirements and timescales.
• Common mistakes firms make when responding to a breach.
• Managing communications with clients, employees and other affected parties.
• Conducting an internal investigation and preserving evidence.
• Recording decisions and allocating responsibilities.
• Creating and testing an effective breach-response plan.
Delegates will leave with practical guidance to help their firm respond confidently while reducing legal, regulatory and reputational risk.
They will also have the opportunity to ask Kristy questions during a live Q&A session at the end of the webinar.