CLS Blue Sky Blog

Skadden Discusses Cybersecurity and Incident Response During Coronavirus Pandemic

The spread of the novel coronavirus has upended Americans’ lives in a matter of months. While life outside has ground to a standstill in many regions of the country, much of corporate America is meeting the unique challenges posed by the current epidemic by adopting remote working technologies and practices. Companies, determined to sustain growth and add value, are adapting long-standing business practices to enable telecommuting and empower a new cyber workforce. For their part, workers are relying to an unprecedented degree on digital tools to keep them connected to coworkers and to do their jobs while staying safe at home.

As record numbers of Americans have begun to log in remotely each day, many for the first time, the number of cyber vulnerabilities facing companies has also increased. Unfortunately, malicious actors have spotted the opportunity, increasing both the frequency and complexity of their attacks. Media reports from the past week noted a wave of attacks on remote access tools relied upon by companies whose workforces have been forced to stay home in the midst of the epidemic. Other reports indicate malicious actors have also begun disguising phishing emails as coronavirus updates from health authorities, leveraging familiar attack vectors while capitalizing on individuals’ heightened fears regarding the pandemic.

Not only are well-known threats posed by phishing and ransomware exacerbated, but the unique cybersecurity challenges attendant to remote working in the current environment — the exponential growth of network access points, reliance on unsecured Wi-Fi networks and increased use of unpatched virtual private networks (VPNs) and devices — compound familiar cyber risks and increase the likelihood of a breach.

Much has been written about basic precautions that companies need to be taking to protect themselves from cyberattacks in the coming weeks and months. All companies should be working to develop and review systems, policies and procedures designed to secure their remote work spaces (e.g., multifactor authentication, VPN/remote access system patching, enhanced system monitoring, firewalls). Executives should aim to increase employees’ general awareness of IT support mechanisms in place to assist them while they work remotely and to alert them to specific anticipated issues, including, for example, the expected increase in phishing attempts and continued restrictions on the use of personal email and cloud storage services to conduct business. Also, management should test and, if necessary, increase the capacity of remote access solutions, and ensure that their business continuity plans are up-to-date.

Yet, beyond those precautions, companies must also consider how to ensure that IT security personnel are prepared to manage critical cybersecurity tasks — for example, log reviews, attack detection, and incident response and recovery — while working remotely.. For many companies, cybersecurity management plans still assume physical access to servers and network access points, and even where physical access is not a technical requirement, teams may be reliant on their ability to quickly assemble in war rooms to coordinate a response to an incident.

Identifying and responding to an incident while key security personnel are themselves dispersed and working remotely will pose unique challenges, particularly in the current environment where local shelter-in-place orders and health concerns could prevent key team members from convening to coordinate a response or from accessing key infrastructure. In the worst cases, IT professionals responsible for identifying and containing breaches may themselves end up locked out of the remote systems they are charged with defending. Without physical access to affected servers and backup systems, protocols for responding to infiltrations may no longer be valid, and forensic analyses to determine the scope and severity of a breach could prove difficult or impossible. In all cases, however, remote response teams will, in the absence of adequate planning, face a multitude of potential logistical hurdles in coordinating an effective response.

With forethought, however, management and security professionals can plan for and mitigate these increased risks. Companies should:

Some overseas regulators have expressed awareness of the extraordinary challenges facing corporations forced to urgently adopt dispersed work arrangements and arguably signaled their intent to be accommodating. For example, the U.K. regulator in charge of enforcing GDPR — the Information Commissioner’s Office — recently said: “We understand that resources, whether they are finances or people, might be diverted away from usual compliance or information governance work. We won’t penalise organisations that we know need to prioritise other areas or adapt their usual approach during this extraordinary period.”

Still, companies should understand that all existing statutes and regulations establishing cybersecurity requirements, including data breach notification laws, remain in place. Additionally, HIPAA remains in force for companies handling confidential medical information.

For companies operating in the United States, meeting data breach notice requirements is a challenge in ordinary times given the various state statutes’ short compliance windows. Delays stemming from the fact that key employees are working remotely and that vendors who often provide notice services may not be at full capacity underscore the need for companies to have well-rehearsed plans in place and react quickly to meet statutory obligations.

As companies transition to a remote workforce due to COVID-19, they are left exposed to new vulnerabilities that cyber attackers are poised to exploit. Now is the time for companies to reassess their incident response and business interruption plans to ensure they are ready for these new threats.

This post comes to us from Skadden, Arps, Slate, Meagher & Flom LLP. It is based on the firm’s memorandum, “Cybersecurity Challenges and Incident Response Preparedness During the Coronavirus Pandemic,” dated March 25, 2020, and available here.

Exit mobile version