Financial Poise
Cybersecurity practices for business

Cybersecurity Best Practices: Guidelines for Breach Prevention and Response

Creating a Culture of Cybersecurity

After collecting personal information, businesses must take ‘reasonable measures’ to safeguard it. Some states, such as Florida and Alabama, have this or similar requirements in their cybersecurity statutes. In 2023, the Federal Trade Commission (FTC) brought more than 90 cases against companies  for engaging in “unfair or deceptive cybersecurity practices.”

Putting Cybersecurity Safeguards Into Place

What exactly are reasonable cybersecurity measures? Fortunately, the FTC  provides some guidance on what these look like. The good news is that the most effective safeguards required by the FTC are easy to implement. By adhering to the following, your business should be able to adhere to cybersecurity best practices:

  1. Require all employees with access to personal information to use strong passwords.
  2. Restrict employee access to personal information on a ‘need-to-know’ basis.
  3. Train employees on cybersecurity best practices and precautionary measures, such as identifying and avoiding scams.
  4. Use multi-factor authentication.
  5. Update software and operating systems with the latest security patches.

Another aspect of reasonable cybersecurity pertains to vendors. Any vendor contracts should require the vendors to safeguard data, notify you of a data breach, and indemnify you for breach costs. You should review and renegotiate these contracts as necessary to follow the law.

Still, despite your best efforts at prevention, a data breach is virtually inevitable, which makes preparation and response all the more important.

Responding to a Data Breach

If your business has a data breach, you should consult legal counsel immediately. The breach triggers statutory and contractual legal requirements. Retaining legal counsel can offer attorney-client and work-product privilege benefits. These privileges can help you keep confidential communications and information concerning the breach. That way, data cannot be used against your business later or taken out of context in litigation.

A data breach at your business may trigger specific legal requirements:

  1. You must notify individuals whose personal information was compromised. This can get tricky as it requires the assistance of legal counsel and a forensic investigator. You must determine how many individuals were affected and where they live. Those answers will determine which laws apply and whether other parties must be notified of the breach.
  2. Depending on the size and scope of the breach, your business may need to notify your state’s attorney general and consumer reporting agencies.
  3. You must notify the appropriate credit card processors if the breach involves credit card data.
  4. If your company was a vendor for another company, you must notify your client.
  5. All notifications must be made within specified periods after the breach. Depending on which state’s law applies, they must contain specific information about the breach. Failing to follow notification laws can result in substantial financial penalties (e.g., up to $500,000 in Florida).
  6. If your business has cybersecurity insurance, the insurer should be notified as it is within the policy’s requirements.
  7. The vulnerability that allowed the data breach must be repaired so it can’t happen again. Cybersecurity law expects businesses to learn from their mistakes.

Can You Be Sued If Your Business Is Hacked?

You might wonder if a company can be sued over a data breach if nothing negative results from the breach like fraud or identity theft.

That’s a great question and one that courts nationwide are considering. The issue is standing. If there’s no harm, what’s the foul? In 2018, the US Supreme Court declined to hear a case that presented this question. So, it remains unanswered, at least on a national level. Some courts say the potential for identity theft is sufficient to maintain a lawsuit against the hacked company. Other courts disagree because there’s no showing of an injury, so there’s no reason to prosecute — at least not yet.

It’s Essential to Show You Followed Cybersecurity Best Practices

While a brighter cybersecurity future may be on the horizon, it is not a reality quite yet. Businesses still spend considerable time and money fighting lawsuits. The FTC has brought enforcement actions against businesses for having poor cybersecurity practices or for not taking reasonable cybersecurity measures. The regulators deem poor cybersecurity an unfair business practice, and they have ordered businesses to take specific corrective measures and adhere to extensive reporting requirements for up to 20 years.

Businesses seeking to avoid these burdens must demonstrate they practice reasonable cybersecurity measures. By doing so, they can better defend against lawsuits and satisfy regulatory inquiries stemming from the data breach.?

Cybersecurity law is complex. This article provides a broad overview, but it’s a good starting point for creating a legally compliant cybersecurity culture. With these pieces in place, your business can use cybersecurity best practices to minimize the chance of a data breach.


We think you’ll also like:

  1. Top 5 Areas in Tech Impacted By the Biden Administration and What It Means for Investors
  2. Cybersecurity Challenges for Boards of Directors
  3. How Threat-Savvy Companies Can Defend Against Data Breaches

[Editors’ Note: To learn more about this and related topics, you may want to attend the following on-demand webinars (which you can listen to at your leisure, and each includes a comprehensive customer PowerPoint about the topic):

  1. Blockchain and Smart Contracts
  2. Data Privacy Compliance
  3. Digital Assets as Collateral: UCC Article 12

This is an updated version of an article published September 14, 2018 and updated on November 24, 2020. This article was most recently updated by the Financial Poise Editors.]

©2024. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.

Share this page:

About Adam Brouillet

Adam Brouillet is a data privacy and cybersecurity attorney with Trenam Law in St. Petersburg, Florida. He advises clients on legal issues relating to information privacy, including cybersecurity standards, vendor contracts, insurance, business transactions, and data-breach response obligations. Adam also represents clients in commercial disputes in trial and appellate courts. Share this page:

Read Full Bio »