Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Incident Response Plans and Tabletop Exercises May Be A Waste of Time

By Larry Gagnon
November 01, 2022

Suppose you have invested considerable time and money creating an Incident Response Plan (IRP) and delivering annual Tabletop Exercises (TTE) within your organization in the hopes that these efforts will drive an efficient and effective response when a breach occurs. If that is the entirety of your response strategy, you are going to be disappointed. Developing and delivering an IRP or TTE to improve the effectiveness of your incident response approach, in isolation, does not work. If your incident response preparation activity does not include some fundamental tactical actions, when the time comes and your house is on fire, your breach response will fail to meet your expectations, I promise.

In my 23 years of delivering incident response and digital forensics services to companies I've become fairly adept at predicting how an incident response engagement will go, based on the first 10 minutes of an initial call with a client. Some clients are well prepared and able to chug through the incident process with our team and get back to routine operations in a couple of days. Other, less prepared clients are in for a painful experience that could drag on, consuming resources and dollars for more than two or three weeks. It is entirely how those clients prepared for the incident that makes the difference.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

The Bankruptcy Hotline Image

Recent cases of importance to your practice.

Use of Deferred Prosecution Agreements In White Collar Investigations Image

This article discusses the practical and policy reasons for the use of DPAs and NPAs in white-collar criminal investigations, and considers the NDAA's new reporting provision and its relationship with other efforts to enhance transparency in DOJ decision-making.

How AI Has Affected PR Image

When we consider how the use of AI affects legal PR and communications, we have to look at it as an industrywide global phenomenon. A recent online conference provided an overview of the latest AI trends in public relations, and specifically, the impact of AI on communications. Here are some of the key points and takeaways from several of the speakers, who provided current best practices, tips, concerns and case studies.

The DOJ's New Parameters for Evaluating Corporate Compliance Programs Image

The parameters set forth in the DOJ's memorandum have implications not only for the government's evaluation of compliance programs in the context of criminal charging decisions, but also for how defense counsel structure their conference-room advocacy seeking declinations or lesser sanctions in both criminal and civil investigations.