Cyberattack response
In an increasingly technology-driven world, cybersecurity stands as the cornerstone of digital resilience. In this programme, we will explore the full spectrum of cybersecurity, from prevention to response, while gaining both immediate, hands-on skills and a foresight for the future of cybersecurity. This programme brings together academic researchers and industrial experts, and thus provides a blend of lectures and use cases and practical testimonials.
Practical information:
Want to register?
- Prerequisites: no technical prior knowledge/background is needed
- Price: €250
In this session, we provide a comprehensive guide on effectively responding to cyber-attacks within the bounds of the law. The presentation explores the intricate web of legal considerations that accompany cyber incidents, delving into the realms of criminal law, data protection, privacy laws, and regulatory compliance together with all other possible side effects.
We begin by dissecting the anatomy of a cyber-attack through an incident response plan. A significant portion of the lecture is dedicated to the legal framework surrounding cyber-attacks. This includes an examination of data breach notification requirements, both domestically and internationally, as well as an exploration of the evolving landscape of cyber-related legislation. The discussion extends to the legal obligations imposed on organisations, shedding light on potential liabilities and consequences for non-compliance.
Furthermore, the lecture addresses, upon experiences learned, the critical role of digital forensics in incident response and legal proceedings. We gain an understanding of best practices for preserving electronic evidence, ensuring its admissibility in court, and collaborating with law enforcement agencies. The lecture also focuses on the post-incident phase, elucidating the legal aspects of breach disclosure, communication strategies, and managing reputational fallout. Practical guidance on engaging with regulatory bodies, law enforcement, and legal counsel is provided, offering a roadmap for a coordinated and lawful response to cyber incidents.
To conclude, we get a firsthand account from a company (TVH) that has experienced a cyberattack and that has been through the challenges of post-attack damage control.
This session is part of the series Cybersecurity excellence:
- Session 1: Tackling cybersecurity challenges: a complex security puzzle | 28 February 2024 - Vincent Naessens (KU Leuven)
- Session 2: ‘Privacy by design': a technical approach to privacy risk | 26 March 2024 - Kim Wuyts (PwC)
- Session 3: Efficient use of a 'network protocol analyzer' in cyber threats (workshop) | 24 April 2024 - Tom Cordemans (KU Leuven)
- Session 4: Hacking and protecting embedded devices (workshop) | 29 May 2024 - Jorn Lapon (KU Leuven)
- Session 5: EU cybersecurity standards and regulation for IoT ecosystems and Industrial Control Systems | 28 August 2024 - Vincent Naessens (KU Leuven)
- Session 6: Cyberattack response | 25 September 2024 - Tom Bauwens (Eubelius), Kalman Tiboldi (TVH)
- Session 7: Post-quantum cryptography | 23 October 2024 - Eric Michiels (IBM)
Related courses
Summer School on Security and Privacy in the Age of AI
Summerschool - Heverlee - KU Leuven, UGent, VUB, Imec