Cyber Incident and Data Breach Response and Management
For urgent assistance with a cyber incident or data breach, or to activate our Data Breach First Responder service, please contact:
Organisations today face a significantly expanded cyber threat landscape which can easily, and often unexpectedly, give rise to a cyber incident that affects their business and data processing activities. In addition to implementing security measures to protect their systems and data assets, organisations must also be ready to respond quickly and with appropriate actions to mitigate their risks and potential legal exposure. This requires robust preparation including the development of a data breach management plan and measures such as training on cyber incident response.
Drew & Napier’s Data Protection, Privacy & Cybersecurity Practice has supported numerous clients in preparing for, and responding to, cyber incidents and data breaches in Singapore, across Southeast Asia and globally. Our experience includes advising on data breach notification and information security requirements under the Personal Data Protection Act, Cybersecurity Act and sectoral laws and regulations relating to telecommunications and digital infrastructure, healthcare, finance and government (amongst others). We have advised on a wide variety of cyber incidents, some of which have involved the following:
- Phishing, ransomware and other malware
- Brute force attacks such as password spraying and credential stuffing
- Zero-day exploits and other software vulnerabilities
- Software defects and system misconfiguration
- Inadvertent disclosure or other mishandling of data
- Incidents relating to third-party service providers or third-party software
- Incidents relating to AI systems and services
The following sections detail key aspects of the services we provide.
Cyber Incident Response and Data Breach First Responder Service
A cyber incident typically results in a scramble by the affected organisation to quickly address the incident, mitigate its impact and limit its business, financial, legal and reputational impacts. When a cyber incident occurs, an organisation's immediate priorities are to establish what has happened, contain the incident to prevent (further) data loss and restore affected systems and data to full operational status. Organisations also need to determine what caused the incident and implement appropriate remedial measures.
While some aspects of cyber incident response are technical in nature, organisations often also face significant legal risks. These include regulatory exposure arising from laws which impose obligations relating to cybersecurity and/or data breach notification, as well as risks relating to legal obligations owed to business partners, suppliers, customers and other stakeholders (including employees). Our team is well-versed in advising on all legal aspects of cyber incident response and data breach management and includes professionals with extensive regulatory experience. Some of the areas we have assisted clients with include the following:
- Developing an effective cyber incident response strategy
- Assessing whether a cyber incident is a notifiable data breach under the Personal Data Protection Act or other applicable laws (within applicable time frames)
- Preparing notifications to regulatory authorities (including the Personal Data Protection Commission), SGX and other affected parties
- Ensuring appropriate steps are taken for preservation of critical information and preservation of legal privilege
- Engaging a cyber forensics consultant to support investigation of the cyber incident (with an appropriate scope under legal privilege)
- Assessing compliance with legal obligations relating to cybersecurity and the legal adequacy of remediation measures
- Ensuring public communications are properly framed in a manner that complies with legal requirements while minimising the organisation’s overall legal exposure
Data Breach First Response Service
To assist our clients in quickly and effectively responding to a data breach, we have developed a Data Breach First Responder service. This allows clients to appoint us as data breach counsel in advance so that we are ready for immediate activation upon the occurrence of a cyber incident.
In advance of an incident, we will:
- Be ready for activation: We pre-clear conflict checks so that our clients can instruct us immediately if a cyber incident occurs;
- Prepare your team: We provide a one-hour briefing for senior management, covering the key data breach management considerations to note in preparation for an incident; and
- Review your readiness: We familiarise ourselves with the organisation's existing data breach management plans and policies, in order to understand its processes and assess its current state of readiness.
Upon activation, we are ready to advise on every aspect of an organisation's data breach management and response, including to:
- Guide our clients on the immediate steps to be taken when a data breach occurs, including assisting with the appointment of the necessary digital forensics experts (if required);
- Provide an assessment of whether the data breach is notifiable to the relevant authorities and the affected data subjects under the law;
- Assist with preparation and submission of the necessary notifications to the relevant authorities (if required); and
- Advise on legal risks and potential legal liabilities relating to the data breach including, for example, communications with the affected data subjects and other regulators.
Please contact us using our details above for more information about signing up for our Data Breach First Responder service, or should you have any queries.
Data Breach Preparation and Management
With organisations of every size facing more frequent and sophisticated cyberattacks, it is increasingly necessary for organisations to actively review and enhance their data protection policies and data breach management plans, in order to reduce the likelihood of cyber incidents and minimise or mitigate their impact. In the event of a data breach, regulators will place significant scrutiny on the security arrangements that the organisation had put in place beforehand.
Apart from advising on cyber incident response, we have also advised many clients on data breach preparation and management. This includes areas such as the following:
- Developing and/or reviewing a data breach management plan to ensure that it appropriately addresses legal requirements under applicable laws and regulations
- Preparing and/or reviewing data protection-related policies, practices and contracts (for example, relating to outsourcing of data processing or IT services) to ensure appropriate security measures are incorporated
- Advising on legal issues relating to (or arising from) cybersecurity audits and other security assessments
- Conducting data protection training, incident simulations and other data breach preparedness exercises
In conjunction with the above, the Drew Data Protection & Cybersecurity Academy also delivers specialised training for clients and assists them in developing and implementing organisational strategies, structures, policies and processes relating to data protection and cybersecurity.
Cyber Incidents relating to Digital Infrastructure, AI and Other Regulated Sectors
Our expertise in advising on cyber incidents cuts across all the areas of law, including the following (for more information, please visit our Telecommunications, Media and Technology practice page or our Artificial Intelligence and Digital Trust practice page):
- Cybersecurity of Critical Information Infrastructure: We have advised clients on the regulatory framework under the Cybersecurity Act 2018 for the protection of Critical Information Infrastructure, including cybersecurity risk management, incident reporting, cybersecurity audits and exercises. We have also advised on the licensing regime for cybersecurity service providers, including providers of penetration testing and managed security operations centre monitoring services, ongoing compliance and regulatory engagement.
- Telecommunications and Digital Infrastructure: We have advised clients on security and data protection issues relating to telecommunication networks and services, including the emerging regulatory framework for foundational digital infrastructure services and data centre operations under the draft Digital Infrastructure Bill. This includes advising major cloud service providers and data centre operators on the proposed major FDI licence regime for specified foundational digital infrastructure services, and on the DC licence regime applicable to qualifying data centres. We have also advised on the proposed licensing obligations on operational resilience, business continuity, incident-reporting, sustainability and energy-efficiency. Apart from advising on regulatory obligations, we have assisted clients with pre-legislative regulatory engagement, including submissions on the draft Digital Infrastructure Bill and engagement with IMDA and other relevant agencies.
- Artificial intelligence (AI): We have advised clients on security and data protection issues relating to the use of AI systems and services, including data breach notification obligations under the Personal Data Protection Act. Where AI is involved, we tap on members from our Artificial Intelligence and Digital Trust practice to develop an incident response and business continuity strategy, advise on reporting obligations (whether to regulators, affected individuals or the general public) as well as advise on potential allocation of liability under statute, tort and contract law. This is because incidents involving the use of AI may involve issues beyond the leakage of personal data, such as the loss of a company's confidential data, allegations of bias or discrimination, erroneous outputs that were relied upon by the company, or being suddenly cut off from access to AI models, compute or other products/services contractually provided for due to changes in export control laws, to name a few. We have also advised parties across the AI value chain, from model developers and platform providers (which host the models), all the way to deployers of AI systems, on a variety of operational issues arising from their use of AI, and are thus familiar with the technology and industry developments, and can work directly with your technical teams as well to manage the situation.
- Healthcare, Financial services and other regulated sectors: Sectoral laws and regulations often impose additional legal obligations relating to cybersecurity and data breach notification. We have advised clients in many regulated sectors on data protection and cybersecurity obligations under applicable laws, such as major public healthcare institutions, banks and other financial institutions.
Cross-Border and Global Cyber Incidents
As more countries in Southeast Asia and across the world develop laws relating to the protection of personal data and/or cybersecurity, organisations are facing an increasingly complex web of applicable legal frameworks that require close attention in multiple jurisdictions. Different reporting thresholds and timelines may apply, legal concepts and liability exposure may differ, and the scope of legal privilege may not be uniform. A legal strategy that may be helpful to an organisation in one jurisdiction may nonetheless negatively impact the organisation's position in another.
We have advised clients in many cross-border cyber incidents including incidents in Singapore that have affected personal data obtained from other jurisdictions (which required coordination with data breach counsel in those jurisdictions), as well as incidents in other jurisdictions that affected data obtained from Singapore data subjects. Where required, we ensure that a consistent approach is adopted, particularly with respect to the conduct of the forensic investigation into an incident and consistent reporting across the relevant jurisdictions.
With the establishment of Drew Network Asia in 2020, we can effectively support clients in cyber incidents (or as part of our Data Breach First Responder service) across Southeast Asia and beyond. We have worked with (and instructed on behalf of our clients) law firms in Drew Network Asia, as well as other firms whom we have worked with in many other jurisdictions on data protection and cyber incident response matters.