Cybersecurity and AI Law Report: Jon Wilson Discusses State Scrutiny of Data Breach Responses
Shook Privacy and Cybersecurity Senior Counsel Jon Wilson was quoted in the Cybersecurity and AI Law Report article “State Cybersecurity Laws: Steps to Address Regulators’ Priorities,” which looks at how state officials are pressing companies for more detail after data breaches and other security incidents.
The article focuses on the questions companies are receiving after breach notifications, including inquiries about incident response plans, data retention and minimization, access controls, vendor management and resilience planning.
Wilson said incident response plans should include customer support, vendor coordination and regulator communications. He also noted that regulators are increasingly questioning whether companies need to retain certain datasets and expect disposal when there is no remaining business or legal purpose.
Wilson also addressed vendor and access-management issues, including the importance of focused data inventories, controls on who can add programs to company systems, regular vendor contract reviews and stronger monitoring of third-party relationships. He also noted that companies should plan for vendor failure when a supplier suffers an incident or becomes an attack conduit.