Reputation Management

BCLP
Contact

The reputational injury following a data breach can be severe.  Indeed, reputational injury – including lost customers – often surpasses legal liability.

Effective management of the reputational impact of a data security incident requires a proactive and reactive strategy.  The proactive strategy assumes that the organization will control when, and what, information will be conveyed to the public, media, and impacted consumers.  For many organizations the proactive strategy that they choose is to wait until their investigation of an incident is complete so that they can provide the public with the most accurate and meaningful information.

The reactive strategy anticipates that the public may be alerted to a possible security incident at a time when the organization may not have full or complete information.  The reactive strategy must carefully balance responding to requests from the public for details that may not be known to the organization.  While the pressure to provide information can be significant, providing inaccurate, incomplete, or preliminary information can confuse consumers, increase the likelihood of legal liability, and, in the long run, lead to worse reputational injury.  Due to the complexities involved, many companies retain third party communications, public relations, or reputational consultants to help manage reputational impact.

75%

Percentage of people that reported that they “trusted” family owned businesses.1

65%

Percentage of consumers in one study which reported that they lost trust in an organization that experienced a data breach.2

31%

Percentage of consumers in one study that discontinued a relationship with an organization that experienced a data breach.3

$149 - $2,000,000

Range of money spent on public relations and other crisis services costs following a data breach.4


What to think about when retaining a consultant to help manage the reputational impact of a security incident:

  1. Has the consultant dealt with data breaches in the past? If so, was the strategy advocated by the consultant effective in controlling the reputational impact and quantity of media exposure?
  2. Has the consultant dealt with data breaches in the industry in which you operate?
  3. What was the most publicized breach that they handled? (Remember that high publicity does not necessarily signify an effective reputation-management strategy).
  4. What other breach-related services do they provide? If reputation-management is not the main focus of the consultant, is their practice sufficiently specialized in that area?
  5. What is the consultant’s general approach to responding to media inquiries about a security incident when a forensic investigation is not complete?

1. 2017 Edelman Trust Barometer, Special Report: Family Business, https://www.edelman.com/trust2017/family-business-trust/.

2. Ponemon Institute & Centrify, The Impact of Data Breaches on Reputation & Share Value, 12 (May 2017), https://www.centrify.com/media/4737054/ponemon_data_breach_impact_study.pdf.

3. Id.

4. Net Diligence, 2017 Cyber Claims Study, 8 (2017), https://netdiligence.com/wp-content/uploads/2017/10/2017-NetDiligence-Claims-Study_Public-Edition.pdf.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© BCLP | Attorney Advertising

Written by:

BCLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

BCLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide