Got your Data in the Cloud? That’s nice.
August 8, 2018
But guess what: your liability and cyber exposure remain firmly planted on YOUR ground.
Your organization is responsible for safeguarding all data and information you collect from third parties. Using a cloud service to store your data does not transfer your liability in the event of a breach, and you can be held accountable.
Selecting the right cloud service provider can mean the difference between a lasting success or a costly failure. You need to ask the right questions and set the right requirements to ensure that your potential cloud provider increases your productivity, not your risks.
Before signing a contract, make sure it addresses the following:
- Is the provider obligated to replace your stored data if a disaster destroys their servers?
- Are there resources in place to back-up your data to ensure that there cannot be any permanent loss?
- Is the timeframe for the cloud provider to restore your data short enough for your business?
- Where is the data stored? While your provider may be headquartered in Canada, it could utilize server space in multiple countries. Depending on the location, this could mean reduced security standards.
- Is the process to transfer data from their servers back into your control well-defined, should your business relationship end for any number of reasons?
You are never done with cyber-security even once you complete your due diligence and select a cloud provider that you can entrust with your data. Despite your best efforts, you could still experience a breach.
How can Cyber Insurance help?
When you or your cloud provider has experienced a breach, time is of the essence. Many cyber insurers provide you with immediate access to a legal Breach Coach who manages your response and investigation process.
The right breach coach will help you start the response process under attorney-client privilege. This way, you can carefully prepare and control how information is released publicly. By engaging legal counsel specializing in data breaches, you are assured that you will be compliant with breach notification requirements.
PROLINK’s blog posts are general in nature. They do not take into account your personal objectives or financial situation and are not a substitute for professional advice. The specific terms of your policy will always apply. We bear no responsibility for the accuracy, legality, or timeliness of any external content.