Take out your pencils, everyone, and take this pop quiz:

Select the answer that does not complete the phrase “_______ means never having to say you’re sorry”:

  1. Love (as in the most famous line from the movie Love Story)
  2. Management (as exemplified by a line from the movie Office Space:  “I have people skills; I am good at dealing with people; can’t you understand that? What the hell is wrong with you people?”
  3. Public office (as evidenced by incidents involving politicians that are too numerous mention)
  4. Experiencing a security breach (as in Kevin Mandia’s keynote at RSA Conference 2014, in which he said that cybercrime is “the only crime I can think of where you have to apologize for being a victim”)

If you answered “4” – I’m sorry (see what I did there?).

To be fair, if your organization has followed the letter and spirit of compliance requirements … if your organization has made deliberate decisions about what security-related risks to accept, assign, and mitigate … if your organization would not be embarrassed by questions about whether or not it had exercised a standard of due care in protecting the information of its customers, after a breach occurs … then I agree with Kevin Mandia. We all understand the fundamental asymmetry of security: the defenders need to be successful one hundred percent of the time, while the attackers need to be successful only once.

Sadly, it seems that most of the time organizations experiencing security breaches have not done all the right things. My blogs on incidents involving LinkedIn and eHarmony, Yahoo!, Evernote, Onity, Barnes & Noble, South Caroline Department of Revenue, TD Bank, The Works Bakery Café, Apple, Briar Group and Snapchat – to name just a few – all illustrate organizations that were not compliant, ignored risk, or arguably did not uphold a reasonable standard of due care.

Even if your organization has done all the right things and still been breached, however, you still have to communicate to your customers about an awkward and unpleasant topic. And there are still certain things they want to know: What happened? Who is accountable? What steps are being taken to prevent it from happening again? How will I be made whole?

Based on some ideas developed in my blog on When Security Breaches Hit Close to Home: M.J. O’Connor’s (9 January 2014), I am proposing the following Incident Response Communications Report Card:

Incident Response report card Derek Brink Aberdeen

Incident Response report card Derek Brink Aberdeen

Or perhaps it should be called an Incident Response Communications Checklist – in reality, it’s both:

  • When it’s used to develop IR communications, it’s a checklist
  • When it’s used to evaluate IR communications, it’s a report card

In future blogs, I plan to apply this framework to actual incident response communications, and give a letter grade – what fun! I also plan to make another entry in my Screwtape CISO series – based on the version of this checklist that the general counsel, marketing and public relations people in your organization would be more likely to recommend.

For today, however, class is dismissed.