FTC Issues Data Breach Guide for Businesses, Confirming Uninsured Breach Response Will be Costly
Time 2 Minute Read

As reported in the Privacy & Information Security Law blog, on October 25, 2016, the Federal Trade Commission released a guide for businesses on how to handle and respond to data breaches (the “Guide”). The 16-page guide details steps businesses should take once they become aware of a potential breach. The guide also underscores the need for cyber-specific insurance to help offset potentially significant response costs.

The Guide lists several actions for a business to take if it suspects or confirms it has experienced a data breach. These include securing operations, fixing vulnerabilities and notifying appropriate parties. According to the Guide, businesses should consider “assembl[ing] a team of experts to conduct a comprehensive breach response,” including independent forensic investigators and outside legal counsel.

The Guide also emphasizes the importance of breach notification and stresses that notification should be made to individuals, other affected businesses, regulators and law enforcement, taking into account all applicable state data breach notification laws and federal regulations (e.g., the HIPAA Breach Notification Rule or the Gramm-Leach-Bliley Act). The Guide also highlights the need for expedient notification to allow affected parties to take steps to protect their information as soon as possible, and provides a model breach notification letter.

Finally, the Guide serves as yet another reminder to businesses to ensure that their cybersecurity programs include both adequate cybersecurity safeguards and appropriate insurance coverages, including first-party and third-party cyber/crime insurance coverages. Failure to maintain either component may hinder an appropriate cyber response as well as limit or preclude coverage for any resulting cyber losses and expenses.

  • Partner

    Mike is a Legal 500 and Chambers USA-ranked lawyer with more than 25 years of experience litigating insurance disputes and advising clients on insurance coverage matters.

    Mike Levine is a partner in the firm’s Washington, DC ...

You May Also Be Interested In

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page