If we need to do a data breach notification...

Preemptively, I'd like to flag that we should connect around strategy if it's appropriate for all WordFly-based orgs to reach out to our patrons about the ransomware data breach.

I have absolutely nothing deeper than that to say yet, but it occurred to me earlier today that, should we need to do this, a good number of tri-state area people may suddenly be on the receiving end of dozens of alarming notifications and make the issue feel even larger. A coordinated notification may be a better approach.

Should today's Town Hall reveal that we ought to pursue this, we'll spin up an initial Zoom or something along those lines.

Please go ahead and use this thread to note ideas or even just interest.

CC: to the NJ folks, and

Parents
  • Post-call and post-debrief with colleague, my takeaway is that we need to see the written materials that are forthcoming from WordFly as well as initiate internal conversations about liability ramifications and customer service intentions. This suggests to me that a call for us is likely useful, so that, at the very least, we have a general awareness of how many of us have decided to alert patrons. I'll identify a time and a Zoom for the second half of the week so we'll have a bit of time for internal conversations.

    Counterpoints/ideas welcome. I know how to facilitate spaces, but am unversed in cybersecurity response.

  • Very happy to participate in a call. Is anyone notifying legal counsel or insurance providers? 

Reply Children
No Data