Concept for - Cyber Incident Response: What Businesses Can Learn from the ASOS Cyber Attack

News of the recent cyber incident at ASOS has attracted significant media attention and highlights a reality that many organisations would rather avoid thinking about: when a cyber incident occurs, the quality of an organisation’s response can be just as important as the incident itself.

While no organisation can completely eliminate the risk of a cyber incident, a well-prepared and structured response can significantly reduce its legal, operational and reputational impact.

The First Few Hours Matter

When an incident occurs, there can be pressure from all sides to provide immediate answers. In practice, taking a step back and understanding what has happened is often more valuable than rushing into action.

In the immediate aftermath of a cyber incident, organisations are often under pressure to provide answers and minimise disruption. However, hasty reactions can create additional unnecessary risk and damage such as ineffective investigation, wasted resources and a misunderstanding of regulatory obligations.

Preparation can include implementing workable incident response procedures, identifying the individuals responsible for managing an incident (this should include IT, legal, your DPO, communications and senior management) and ensuring that key decisions are coordinated and documented.

Establish the Facts Before Making Decisions

One of the biggest challenges during the early stages of a cyber incident is investigation and establishing the facts. Organisations need to determine what happened, which systems have been affected, whether personal data is involved and the potential impact on the business and affected individuals.

The recent ASOS cyber incident illustrates this challenge. In its initial statement, ASOS advised that the incident involved “basic contact details”, but this position has since developed as the team has learned more about the event.

Proactive measures can assist businesses in promptly identifying impacted systems and data, such as up-to-date and well-managed records of processing activity.

We’ve seen organisations spend significant time and money pursuing the wrong line of investigation because early assumptions turned out to be incorrect. Taking the time to establish the facts can often avoid much larger problems later.

Assess Reporting and Notification Obligations Carefully

Organisations may have statutory obligations to notify the relevant data regulator and impacted data subjects, alongside a contractual duty to inform insurers or business partners following a cyber incident. Whether notification is required will depend on when the business became aware of the incident, the nature of the incident and the risks arising from it.

Premature reporting can result in unnecessary scrutiny, additional costs/resource and concern amongst customers and commercial partners. However, delaying or omitting notification where a statutory obligation exists can also create significant risks.

It is therefore important that notification decisions are made following a proper assessment of the facts and that internal procedures support escalation to the appropriate individuals to make this decision. A clear incident response process can help organisations identify and comply with reporting obligations within the required timescales.

Document Every Decision

Maintaining a clear audit trail throughout an incident response is essential. Organisations are under a legal duty to keep records of key decisions, investigations undertaken, advice received, communications issued and any remedial actions taken.

A comprehensive record can also assist with regulatory enquiries, insurance claims and any subsequent review of the incident.

Learn from the Incident

Finally, organisations should use cyber incidents as an opportunity to learn and improve. Once the immediate response to an incident has concluded, businesses should review their response to identify lessons learned, including what worked well and where improvements could be made. Policies, procedures and training should then be updated to reflect those findings.

Taking a proactive approach to continuous improvement can strengthen organisational resilience and reduce the impact of future incidents.

Conclusion

Overall, whilst the full impact of the ASOS cyber incident remains to be seen, it serves as an important reminder that a cyber incident can quickly affect customer trust, attract significant public attention and result in substantial commercial, operational and regulatory costs, including impacts on business and stock value. Remaining calm, following established procedures, understanding the facts, involving the right people, meeting reporting obligations, maintaining an audit trail and reviewing lessons learned are all key elements of an effective incident response. Together, these measures can help reduce unnecessary costs, limit disruption and minimise the wider impact of a cyber incident.

This article was co-written by Leanne Yendell, solicitor, and Lauren Yeo, trainee solicitor, in the Intellectual Property, Data Protection and Technology team.