What Should You Do After The Breach?
Written by Evan SchumanThere is no shortage of advice on ways to try and prevent a data breach. But if it happens to you, do you have a plan of precisely what to do after the fact? Very few retailers do. Lots of complicating factors exist, such as the probability that the breach will be discovered many months after it ended, plus the fact that the bad guys will almost certainly have radically altered the logs. But the essential issue is that you have an urgent need to do several things immediately.
First, you have two competing Number One priorities: Stop the current attack (if it’s still going on) and prevent a new one; and keep systems fully functional so that sales are in no way impacted. Those two priorities don’t play well with each other, and that’s what we’re exploring in our Guest Column this week on the new McAfee security blog. Conflicts aside, there is a logical sequence of events that retailers need to follow the instant a breach is discovered.
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
