Matthew Pokarier - Incident Response: What Security Teams Need to Know (legal one)

Focus: • Legal obligations during and after a cyber incident • Breach notification timing, evidence preservation, and legal professional privilege - including when privilege applies (and when it doesn’t) • Common mistakes that increase regulatory exposure • Legal risks of ransom payments (sanctions, terrorism financing, AML laws) and how these interact with conflicting disclosure laws and regulator expectations Abstract: When a cyber incident occurs, the first 24-72 hours determine both the legal exposure and the quality of recovery. This session distils what security teams must get right (fast) and provides practical guidance on actions that can be implemented immediately. The session will cover the triggers and sequencing of legal obligations from discovery to containment, clarify when and how to notify affected parties and regulators, outline the mechanics of preserving evidence and explain how to structure workstreams to maximise legal professional privilege (and avoid pitfalls). We’ll also cover the evolving rules of engagement on ransom-related risks, including sanctions, terrorism financing, and AML exposure, and Australia’s mandatory ransomware payment reporting regime and show how these elements interact with disclosure expectations from regulators and boards. Delegates will leave with an incident checklist, an awareness of legal privilege and board ready talking points. Learning outcomes: Attendees will gain an understanding of: • The mandatory steps to take within the first 72 hours of a cyber incident and the information to produce at each step • Preserving evidence without impeding the response to a cyber incident and how to structure legal engagement to maximise privilege where it applies while avoiding common pitfalls • Ransom risk – how to assess sanctions and AML exposure, recognise what can and can’t be negotiated and how to comply with Australia’s ransomware payment reporting rules • How to navigate differing regulator expectations