Editor’s Note: Organizations relying on secrecy-based approaches to addressing potential cyber defense breaches may run afoul of the federal cybersecurity policies that are detailed in a growing number of regulatory and guidance documents. A more sophisticated approach to minimizing disclosure responsibilities by proactively managing cyber-risks is needed.
From: The Wall Street Journal
When Nationwide Mutual Insurance Co. discovered in October that a hacker had breached its systems and stolen personal details of roughly one million people, it put the internal probe in the hands of a law firm, rather than one of the forensic investigators typically retained for such incidents.