Skip to main content
Paper Example Doctorate 1,304 words

Firm liability for data loss from cyberattacks and hacking incidents

Last reviewed: September 15, 2015 ~7 min read
Essay 1,304 words

¶ … Hacking and Firms' Obligations

In the United States, there is no a day that media have not reported about the cyberattacks and their consequent financial loss and misuse of corporate data. When the data warehouse of the Target and Home Depot was compromised by hackers, the issues became the front-page news. However, the companies invested millions of dollars' worth of financial and non-financial resources to protect their data, and despite these investments, hackers were able to penetrate the company database. By consequence, personal and financial data of customers and employees were compromised, and many people believed that firms should be held responsible for the data loss due to cyber-attacks. (Katten, 2015).

Objective of this paper is to discuss whether firms should be held liable for the loss sustained by employees, customers, and suppliers due to attack carried out by hackers.

Firm should be held Liable for Data Loss

This study argues that firms should be held responsible for the loss sustained by employees, customers and suppliers due to attack successfully carried out by hackers. Sterlicchi (2015) argues that firms are to be held responsible to the attack carried out by external penetrators. The author warned that a company's officers and directors can be held responsible by failing to protect customer and employees' data. Essentially, officers and directors ought to understand that it is their responsibilities to protect customers' data and prevent or manage cyber event in order to avoid the risks of being held liable.

Under different regulations in the United States, officers and directors are to implement controls and systems to manage the company data. If a company's officers and directors have breached their fiduciary duties, they can be exposed to lawsuits.

"Under the laws of various jurisdictions, the company might be liable for a variety of common law claims including negligence, strict liability for abnormally dangerous activities, and contract claims." (Finch, & Spiegel, 2014 p 352 -353).

Moreover, different rules and regulations have also been promulgated that obliged firms to carry out different security dimensions to protect the customer data. Rule 30 of the SEC (Securities & Exchange Commission) mandates investment companies, investment advisers and broke dealers to protect the confidential customer's data and information. The regulations maintain that organizations will be liable for the loss of data sustained by customers. Similar regulations are the Federal Privacy Laws that mandate all organizations to protect customers' data. The laws stipulate that firms should design their data warehouse to secure customer data and record against unauthorized access. The Gramm-Leach-Bliley Act stipulates that firms will face a sanction of $200,000 in case of accident of failure to protect customer data.

In the contemporary IT (information technology), organizations are responsible to use both the traditional and non-traditional security systems to protect the company data against the external attacks. Apart from protecting customer or employee data using sophisticated IT security, firms are required to use a comprehensive insurance policy to insure company data from the external intruders. It is essential to realize that data are the life blood of organizational competitive market advantages. (Sterlicchi, 2015). Thus, customer, employee, and suppliers' data are very important because of the private information held in the data. When employee or customers' data are compromised, the issue can expose customer and employee to greater risks because their data can be misused by unauthorized intruders. Thus, firm are responsible to carry out a comprehensive risk management policy to protect customer or employee data against external attacks.

Part II: Main facts to Support the Argument

Different organizations have faced lawsuits because of the data breach within their organizations. On November 24, 2014, employees' data of Sony Corporation were compromised by external penetrators, and 10 Sony employees filed the law suits on behalf of other 50,000 former and current Sony employees. The attack was carried out by North Korean penetrators that made 47,000 SSN (Social Security Numbers) as well as other identifiable information to be stolen. The lawsuit revealed Sony information security standards were below the industry standards. Although, Sony attempted to defend itself against the lawsuit, however, the company finally agreed to settle the affected employees. (Schwartz, 2015).

Similar case occur recently when a man files a lawsuit against the UC (University of California) Health Division at Los Angeles for failing to protect private information of patients. Typically, the data of 4.5 million patients have been comprised following the cyber-attack that happens in 2015. The cyber-attack has exposed the Social Security Numbers, health ID, medical records and other sensitive information of patients to the public. The lawsuit reveals that the attack is carried out because the UCLA does not implement adequate steps in order to safeguard the patient's information. (Daily Bruin, 2015).

When a hacker has penetrated the database of a company successfully, millions of sensitive customers' information will be stolen, which can expose customers to alleged frauds. When a SSN, credit card information and other personal information of customers and employees are in the hand of external penetrators, they can use the stolen information to carry out different activities such as obtain loan from banks, and use the credit card to commit frauds. Thus, there is no way companies will not held liable if customers or employees data are compromised. An organization that transforms its business from the traditional brick and mortal into online virtual business should use a comprehensive data protection strategy to protect their data from external penetrators. (Chartered Accountants, 2015).

Part III: Firm's Response to the Cyber-attack

Organizations should use different strategies to response to attacks. First, a firm that is a subject of cyber-attack should immediately consult a legal practitioner who has a comprehensive experience in the incident response policies. The lawyer should determine the strategy to proceed with the incident in order to minimize the legal liability. Moreover, a firm should carry out the incident response plan to mitigate the incidents. The strategy to be employed in mitigating the incident response plan is as follows:

Make initial assessment.

Communicating the incident.

Identify the severity of the damages.

Protect evidence.

Notifying external agencies.

Recover systems.

Compiling the incident documentation.

Assess incident costs and damage.

Review the response.

Implementing this strategy will assist the organization to minimize the financial loss that could have occurred after the incidents.

Part IV: Additional Measures to Limit Losses

273 Words Hidden · 79% Shown
Cite This Paper
PaperDue. (2015). Firm liability for data loss from cyberattacks and hacking incidents. PaperDue. https://www.paperdue.com/essay/analysis-of-it-hacking-and-firms-obligations-2155419

Always verify citation format against your institution’s current style guide requirements.