Cybersecurity & Data Protection
Security obligations, written down and testable.
Counselize advises on the privacy and information-security requirements that apply to a business, the written program a regulator expects to see, and what has to happen in the first days of an incident.
Security is a legal obligation before it is a technical one. Most regimes do not ask whether a company is secure, which is not a question anyone can answer. They ask whether it maintains a written information security program, whether that program follows from a risk assessment, whether a named person is accountable for it, and whether it is tested. A company can be well defended and still fail an examination for having none of that on paper.
Which rules apply turns on what the business does and whose data it holds. Financial institutions face the Gramm-Leach-Bliley Safeguards Rule, and companies regulated in New York face the Department of Financial Services cybersecurity regulation, with its multi-factor authentication, asset inventory, testing, and senior-officer certification requirements. State consumer privacy laws now reach most businesses of any size through thresholds on revenue and volume of personal data, carrying rights of access, deletion, and opt-out along with obligations on sensitive data and targeted advertising.
A great deal of this lives in contracts rather than in policies. Data processing agreements, security exhibits and audit rights, breach-notification timelines negotiated with vendors, and the third-party risk program that reviews them are where the obligations are actually created and where they are most often breached. A vendor's failure is generally still the client's notification obligation.
Incident response is the part that cannot be improvised. Notification deadlines run in days, they differ by state and by regulator, and they start before the technical picture is complete. Counselize prepares the plan while there is time, advises during the event on what is reportable and to whom, and handles the notifications and regulator communications that follow.
Scope
