Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCybersecurity News

Top 5 Fails from Companies Preparing for and Responding to a Data Breach

By Michael Bruemmer
November 8, 2016

Being adequately prepared to respond to a data breach is an ever-changing game – new threats are emerging, new regulations are being put into place and companies must regularly re-evaluate their response plans to ensure they are applicable to today’s threat landscape. Unfortunately, many companies are not reviewing and updating their plans frequently enough – in fact, only 25 percent of companies say they update their response plans once or twice a year. Not to mention that no matter how well prepared and updated a company’s plan is, an actual live breach response can present unforeseen challenges that cause companies to stumble.

At Experian Data Breach Resolution, we consistently see similar “fails” from companies across all industries during their planning and response to data breaches.

Failure to work with the proper external experts who can help you navigate the issue.

The team you surround yourself with during a data breach response is crucial to executing a smooth response which in turn can reduce the financial fallout and ensure the breach is contained quickly. This includes working with external experts in IT forensics, cyber insurance, legal counsel, communications and data breach resolution that will help companies follow best practices. But it’s not enough to simply have a list of experts to call on once a breach happens – these are experts you want to start building relationships with before a breach occurs so you can quickly and efficiently assemble the right people when necessary.

Failure to anticipate emerging threats that complicate breaches, such as ransomware.

The threat landscape is anything but stagnant – new threats are emerging constantly, and a one-size-fits-all response plan will not account for attackers’ latest techniques. One emerging threat that many companies have yet to plan for is ransomware. This attack can have a lasting impact on organizations, including malware left behind that could cause further damage down the road. When faced with a ransomware attack, organizations need to move quickly to respond to the attacker, as well as communicate with regulators regarding the incident. By accounting for and practicing a simulated response to a ransomware threat ahead of time, companies can decide under what circumstances they would pay a ransom and determine the best way to work with regulators to report an attack.

Failure to practice or incorporate “worst-case scenarios” in data breach preparedness plans

Practicing a data breach simulation is a well-known tactic to ensure data breach response plans are relevant. Unfortunately, only 55 percent of companies include a fire drill as a part of their data breach response practice. When they are completed, simulations are often conducted around a conference room table and follow a predictable cadence, which doesn’t pressure-test for real life circumstances. Instead, companies should include more difficult scenarios in their practicing, conduct fire drills at surprise times to see how the team adjusts, and conduct the drills in realistic settings that would mirror a real life breach response.

Failure to properly communicate while an issue is under investigation.

Many organizations are extremely cautious about how and when they communicate to the public that they have experienced a data breach. And rightly so – communicating too much information before all of the facts are known could lead to misspeaking about the breach or expose security weaknesses that other attackers could take advantage of before security practices are properly shored up. But waiting until a breach investigation is over, which can take weeks or months to complete, can leave customers, stakeholders and media without any official comment from the company to reassure them that the breach is known and an investigation is underway.

It’s important for companies to strike a balance for communicating about a breach investigation. Companies should talk about the steps they are taking to investigate the issue, but consider resisting sharing any hard numbers of consumers impacted or making any definitive statements. By communicating steps taken when an investigation has started but is not complete, companies can demonstrate that they are transparent and operating in the full interest of their customers.

Failure to engage all key audiences.

Lastly, for many companies, the first area of priority when communicating about a data breach are impacted customers. While this makes sense on the surface, there are other important groups – employees, partners, the customers’ customers – that also need to be properly and quickly informed to help protect brand reputation. The first step is to ensure you are accounting for all key audiences in your response plan, and tailoring the best way to communicate about a data breach to each impacted group. This could include packaging up specific guidance for individual audiences, sharing resources to help different audiences ask questions or receive updated information, and holding internal town halls to allow employees to voice their concerns directly.

The good news is companies don’t need to learn about these “fails” the hard way. By addressing these potential pitfalls in response plans, companies can work to get ahead of these issues.

 

More information on data breach preparedness and resources can be found at the Experian Data Breach Resolution website and the Experian Data Breach Resolution blog.

KEYWORDS: cyber risk mitigation cyber security investigation cybersecurity preparedness data breach data breach response

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Sec0416 data slide2 900px

Michael Bruemmer, CHC, CIPP/US, is Vice President with the Experian® Data Breach Resolution group. With more than 25 years in the industry, Bruemmer brings a wealth of knowledge related to business operations and development in the identity theft and fraud resolution space where he has educated businesses of all sizes and sectors through pre-breach and breach response planning and delivery, including notification, call center and identity protection services. Bruemmer currently resides on the Ponemon Responsible Information Management (RIM) Board, the Information Security Media Group (ISMG) Editorial Advisory Board and the International Association of Privacy Professionals (IAPP) Certification Advisory Board.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Business Risk of Data Breaches: Preparing Your C-Suite

    See More
  • Companies are Failing to Get Ahead of the GDPR

    Companies are Failing to Get Ahead of the GDPR

    See More
  • 3 Factors to Employee Data Loss Preparedness

    See More

Related Products

See More Products
  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Optimizing Social Media from a B2B Perspective

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing