|
|
|
|
Pivot Group Ends a Disgruntled Employee's Reign of Terror
- DYNAMICS
- Medium-Size Law Firm
- One Location
- Major Practice Areas = Corporate and Class Action Litigation
- Primarily a Windows Environment
- INFORMATION SECURITY ISSUES
- Disgruntled Employee
- Security Breach
- NO Protection of Confidential Information
- NO Back-Up and Recovery Plan
- NO IT Security Policies
- BUSINESS ISSUES
- Loss of Confidential Information
- NO System or Application Back-Ups
- Threat of Extortion
- Firm Liability and Reputation
- SECURITY SOLUTIONS
- Notify Appropriate Authorities
- Change All Access Controls
- Back-Up All Systems and Data
- Notify Clients
- Deploy Access Monitoring Tools
- Regular Assessments
- Develop and Enforce Access, Appropriate Use, and Incident Response Policies
- Deploy Automated, Secure Back-Up and Recovery Policies as well as Technologies
- Security Training and Education
- OUTCOME
- Firm was able to salvage all data. Provided enough evidence to issue a warrant for his arrest and pursue a civil lawsuit against the Disgruntled Employee.
- Firm implemented a proactive security program in order to mitigate future damages from security breaches in a more cost effective manner.
|
|
|