Cyber and Employment Law - Lexology
We have seen an increase in the number and sophistication of threat actors carrying out ransomware attacks against companies. Frequently these involve exfiltration of employee personal data, such as the content of HR personnel files, with a threat to post sensitive employee details on the dark web unless the ransom is paid. HR data can be particularly vulnerable, sensitive and appealing to attackers.
During our Data Protection & Cyber Conference on 10 November 2022, we talked through some of the key practical and legal issues which arise from an HR perspective in relation to cyber breaches as follows:
Pre-breach
- Staff training and awareness: The workforce plays a key role in preventing and identifying attacks. John Edwards, the UK Information Commissioner, has recently stated “the biggest cyber risk businesses face is not from hackers outside of their company but from complacency within their company”. The most important step that an employer can take in relation to its workforce is to train staff to be vigilant to cyber risks and to identify and report cyber breaches promptly.
- Mapping HR data: Understanding the company’s framework for storing and processing employee data is vital. A central part of this analysis is how long HR records are retained and whether these periods are appropriate based on the employer’s processing purposes.
- Monitoring: Tools that involve the monitoring of employee activity must comply with applicable laws and related guidance for...
Read Full Story: https://news.google.com/__i/rss/rd/articles/CBMiU2h0dHBzOi8vd3d3LmxleG9sb2d5L...