What do you do when a third-party vendor has a data breach and exposes your data? In this talk, discover what happened when a third-party vendor was extorted after a ransomware attack, exposing private company data.
1) Do you launch your Incident Response Plan?
Do you have an IR plan?
Have you tested it lately?
Does it cover a third-party data breach?
2) Do you call your Cyber Insurance carrier?
Do you have Cyber Insurance?
Do they cover this type of incident?
What does it cover?
Key takeaways:
* Review your IR plan. If you don’t have one, make one.
* Review your Cyber Insurance policy. What does it cover? If you don’t have cyber insurance, should you get it?
* Review your Risk Registry. Do you have third-party risk identified? If so, does it have the right priority?