When, Not If: California’s Mandatory Protocol for Data Breaches

Words are funny things.

If you are asked what your California firm will do IF your data is breached, then you’re tempted to say that the question doesn’t apply because your firm’s data will NEVER be breached. After all you have multiple security certifications, which means your data is 100% protected…right?

Google Gemini.

Tell that to Cushman & Wakefield, The Moody Bible Institute of Chicago, Station Casinos, UCLA Health, or any of a myriad of firms that reported data breaches in accordance with California law. Or better still, check with the companies that failed to report data breaches under California law.

But if you are asked what your California firm will do WHEN your data is breached, then you will be forced to develop an action plan. Which is a good thing.

Six items in your data breach action plan

The first thing in your action plan should hopefully be obvious: secure the breach! Revoke compromised access credentials. Preserve digital evidence for forensic investigation.

Second, determine the damage. Was any unencrypted personally identifiable information (PII) or protected health information (PHI) leaked? Or pretty much the same thing: were any decryption keys leaked with encrypted data?

Third, notify.

  • Under California SB 446, a firm must notify affected California residents within 30 calendar days of discovering or being alerted to the breach.
  • The notice must be in plain language, formatted for high visibility (at least 10-point font), and titled explicitly: “Notice of Data Breach.”
  • The notice must include five mandated headings:  What Happened⁠, What Information Was Involved⁠, What We Are Doing⁠, What You Can Do⁠, and For More Information⁠.
  • If certain PII is breached, you must offer at least 12 months of free identity theft prevention/mitigation services and provide instructions on how to enroll.
Google Gemini.

Fourth, notify. You’re not done notifying yet. If the breach affects more than 500 California residents, the firm must electronically submit a sample copy of the notification letter (with PII redacted) to the California Attorney General’s portal within 15 calendar days of notifying individuals.

Fifth, notify. If PHI was breached, add the California Department of Public Health (CDPH) to your notification list.

Sixth, notify. If you manage third party data, notify the data owner. (And the data owner will need to perform all the notifications above. The fun of third-party risk management.)

Can Bredemarket help you prepare your action plan?

Yes.

I’m not a lawyer.

But I am a writer.

And I write processes, including privacy processes.

Talk to me.

When, Not If, Your PII is Exposed

The best thing for all of us to do is just flat out assume that the personally identifiable information (PII) that companies collect from us WILL be compromised.

I’ve always assumed that Madison Square Garden and the New York Knicks LIKE celebrities. They get so much free publicity from them, after all.

But Madison Square Garden didn’t adequately protect celebrity PII.

“A criminal hacker collective called ShinyHunters recently published a slew of documents exposing the MSG database….ShinyHunters had demanded ransom to delete their data, but MSG apparently didn’t meet their terms.”

But then the celebrities found out what MSG was tracking about them.

“93 entries are marked as “LGBTQIA,” such as Ricky Martin, Phoebe Bridgers, and Geese’s Emily Green….

“The database also marks some entries with risk scores, often based on social media posts, a source told Wired. ‘It doesn’t have to be that serious. You could just be critical of the team or the place itself,’ the source said.”

This is what businesses like MSG fail to recognize. A data breach doesn’t only harm the victims. It also harms the organization itself because they’re perceived as a security risk. In the case of MSG they’re also perceived as nosy, even paranoid.

Google Gemini.

Which is one of the reasons why Bredemarket collects only the minimum necessary data on its Calendly form and other forms. I don’t ask for your sexual orientation or even your favorite sports team.

I don’t ask that much.

Business Concerns Always Override Technology Concerns

The Institute for Defense and Government Advancement (IDGA) recently released some survey results. Now I don’t want to simply reproduce the results; go here to download your own copy of the report.

But I do want to say this.

“A large number” of IDGA survey respondents expressed concern about “Interagency information sharing.”

  • This is NOT a technology concern. The technologies exist to enable information sharing. For example, one of Bredemarket’s clients recently made the technological changes necessary to allow an application, designed to interface to agency A, to instead interface to agency B.
  • No, this is a business concern—or in this case a governmental concern. A matter of setting up the processes to allow Bob from agency A to exchange data with Judy from agency B. Even though Bob thinks that Judy is a bozo, and vice versa.

And while we’re on the topic…

If you’re worried about Big Government (the FBI and the CIA and the BBC, BB King, and Doris Day) (or INTERPOL and Deutsche Bank, FBI and Scotland Yard) combining all their information to entrap you, your fears may be difficult to realize. Yes, there are cases in which the agencies share data. But there are also cases where they don’t, because it’s in an agency’s interest to keep its data to itself.

Agencies usually ask the question “How can I GET the data from the Bureau of Stuff?” They normally don’t ask the question “How can I GIVE my data to the Bureau of Stuff?”

And that’s why agencies run into problems sharing data.

Dig It.
Computer World.

(Past illustrations) Creating actionable information to document and expand a merged company’s combined market

(This past illustration describes something that I performed in my career, either for a Bredemarket client, for an employer, or as a volunteer. The entity for which I performed the work, or proposed to perform the work, is not listed for confidentiality reasons.)

By Lacrossewi – Own work, CC BY-SA 4.0, https://commons.wikimedia.org/w/index.php?curid=81149806

PROBLEM

After a merger of two companies, the combined company needed to know which customers used solutions from the combined company, which customers used competitor solutions, and which used both.

For example, a customer may use the combined company’s solution for one product line, but a competitor solution for another product line.

As the combined company introduced new products and entered new markets, this information was also required for the new product lines and markets.

SOLUTION

While others worked on front-end presentations of public portions of the data, I gathered the underlying data.

  • For multiple product lines, I recorded (when known/applicable) the type of customer (for example, a statewide government agency), current vendor, previous vendor, initial and extended contract value, product version, relevant statistics about the customer, and a designated reviewer for future quarterly updates.
  • The data was both stored separately for each product line and was also summarized.
  • Information was color-coded to highlight the combined company’s market position.
  • Data could be filtered as necessary (for example, only showing statewide government agencies).
  • The complete collection of highly sensitive data was tightly held.
  • Portions of the data were passed to selected subject matter experts on a quarterly basis for updating, allowing front-end presentations to be updated quarterly.
  • Additional information was gathered as new markets were entered and new products were launched.

RESULTS

The combined company had a better view of its positions in its various markets.

The resulting actionable information could be used to target specific customers and replace competitor products with the combined company’s products.