Privacy expert Rebecca Herold talks with Tom Field about data breach response plans. Herold: Most organizations still do not have a documented privacy breach response plan. She says many organizations make insensitive statements that downplay the risk results and in such a way that it makes customers and consumers angry. 40 U.S. state-level laws, including the District of Columbia, have specific notification laws in place, including how quickly notification notices must be made, and how quickly they can notify affected individuals. The second major hole is not knowing the legal requirements for the breach notices.”]
Source: https://www.bankinfosecurity.com/data-breach-response-tips-to-protect-your-institution-a-670

