Digital forensics
The first move in any response is to contain and investigate — gathering as much evidence as the environment will yield. We engage Australia's leading digital forensic investigators from a pre-negotiated panel and move quickly to leverage that expertise.
Our practitioners have analysed hundreds of forensic reports and guided investigators to ensure their efforts align to business outcomes and legal-risk mitigation. Once the investigators complete their work, we use their reporting to build a roadmap to resolution.
Working group
While investigators are working, we rapidly establish rapport with your internal technology and business teams and prepare them for the action that's coming. A working group is stood up to own each stage of the response, with clear lines of communication end to end.
Once established, that working group can lead efforts for the remainder of the response — including discovery of at-risk data, containment and mitigation, and external engagement.
External communications
Regulators, customers and the public are just some of the stakeholders in a cyber incident. We shape communications that are proportionate and informative — effective at mitigating future harm to affected parties while managing the risk of future claims. We guide you through that balancing act with a steady hand.
Mandatory reporting timeframes apply under the Privacy Act 1988 (Cth) and a handful of other instruments. We keep that clock visible and proactively co-ordinate the response, including advice to directors and parties with a common interest as circumstances require.
Data Mapping
Often referred to as an organisation's crown jewels, we help you comprehensively identify where your most sensitive data resides on the network. We critically analyse data flows to flag where sensitive data may be residing in places it shouldn't.
This step can be undertaken prior to an incident as a preventative measure, or run concurrently with the digital forensic investigation once an incident is underway.
Map the exposure
Once we understand where sensitive data lives — and combine that with insight from the forensic investigation — we begin to build a picture of the risk the incident poses. We identify the fastest route to assess data risk, either working outward from your sensitive data or following the evidence of the intrusion to see how close an attacker came to exposing it.
Where sensitive data has been exposed, we rapidly build a comprehensive list of affected individuals to enable notification or remedial action. In appropriate cases this is done programmatically with modern data-science techniques — saving hundreds of hours of manual work.
Eligible Data Breach Assessment
Notification call
As lawyers and technologists, we analyse the facts of the incident and determine notification requirements under the Privacy Act 1988 (Cth), state-based legislation, and any organisation-specific laws that may compel notification.
The output is a defensible Eligible Data Breach Assessment, which is our advice on whether the incident meets the threshold for notification based on a risk assessment of the likelihood of harm. Get this right and the rest of the response falls into place.
Notification campaign
If notification is appropriate we produce the form of notification and run the campaign. Our approach strikes the right balance between legal compliance, helpfulness to impacted individuals, and protection of your organisation's interests. We handle foreign-jurisdiction notification through our international network where needed.
Notification is always a difficult step for an impacted organisation. With the right approach you minimise disruption to the business and present professionally to customers, regulators and the people whose data was touched.
Hardening and remediation
Cyber incidents often occur because of unforeseen vulnerabilities in the makeup of an organisation's digital infrastructure. Once identified, we recommend new or replacement technology systems to remedy those vulnerabilities and improve digital processes.
We go a step further than a typical law firm or IT consultancy — combining both disciplines to give you practical advice on mitigating the risk of future incidents, not just a post-mortem dressed up as a report.
Regulatory close-out
If regulators or third parties need to be engaged, it's important to have the best representation possible to safeguard your organisation's business interests. Combining a solid understanding of the technology with current and emerging jurisprudence, we successfully defend clients from regulatory investigation and legal claims arising out of cyber incidents.
The exit state is the one we started with in mind — a defensible posture, documented, and ready to stand in front of the OAIC, your insurer, or the public.