Home
published on 10 March 2020 | reading approx. time 3 minutes
The role of a security officer, or the role of key central security technicians and the team responsible for data protection is generally already understaffed and not sufficiently staffed. What does a failure of one of these central functions mean for a company?
One might think that, due to the distribution of tasks within an IT team, one could do without these central security and data protection roles for a certain time. After all, the substitution plan usually ensures the loss of a functionary. But as Murphy's law says, it does not stop at one disaster. And it is precisely these central roles in the company that often have a little distributed knowledge of the security and protection mechanisms within and in relation to third parties in the company. If partial or complete failures are to be expected, emergency operation must be ensured here as well. Here, concrete preparations must be made for three phases:
In the following, we would like to provide valuable information on how the company should behave.
Depending on the size of a company, the above roles vary in content and capacity. In quite a few companies, the roles are implemented on a part-time basis. In corporate groups, there may also be several distributed responsibilities, which in turn does not facilitate a uniform and centralized guarantee of tasks.
In concrete terms, this means that within the preparatory phase, the partial or complete loss of these roles must also be included in the risk assessment. If this has not been the case so far, the risk analysis should be extended or corrected by these dimensions.
It follows from this that, if the risk assessment is adjusted, the emergency plans existing in the company will also take adequate account of a partial or complete failure of these roles, or an adjustment will also be necessary here.
In concrete terms, this means in any case:
Depending on the tasks of the above roles in an emergency (including loss of representation) and in combination with a security or data protection incident, this means further:
If the company lacks the capacity and know-how for the preparation phase or for representation, it is recommended to involve the Rödl & Partner crisis team.
If, according to definition, an emergency or crisis arises from preparations and one or more functionaries and representatives are affected, measures are initiated in line with the defined emergency plans.
Depending on the extent of the loss of the functionaries and their representatives, the crisis management team must make decisions on a case-by-case basis. These could be:
Here too, multiple emergencies could threaten the ability of the crisis team to perform its tasks.
It can be assumed that, in the context of the loss of functionaries and representation, some monitoring and control tasks were no longer implemented. It is therefore necessary to
Since the resources within the functionaries are usually not abundant, the question of the involvement of third parties arises. In this case it is also advisable to involve the Rödl & Partner crisis team.
Coronavirus: What you need to know
Frank Reutter
Partner
Send inquiry