Lawsuit raises new questions about legal responsibility for cybersecurity breaches

An upcoming lawsuit in which a US casino operator will seek damages from its cybersecurity contractor adds a new layer to the data breach 'blame game'.
Prefer the Global Legal Post on Google

Fer Gregory

When a company suffers a data breach, who foots the bill? A lawsuit filed against Chicago-based cybersecurity firm Trustwave by Las Vegas-based casino operator Affinity Gaming is offering a possible new answer to that question. In 2014, Affinity hired Trustwave to investigate and remedy a breach of the casino's data security systems that compromised the credit card information of around 300,000 customers. Trustwave handled the breach, giving Affinity's security system the all-clear. However, the casino later discovered a second breach during Trustwave's investigation that the cybersecurity firm failed to detect, and is now suing the company for allegedly misrepresenting its ability to protect Affinity's data. While responsibility for customer data has generally been the domain of businesses, the landmark case could set a precedent under which companies can seek damages from their cybersecurity provider when their data defences fail.

'Woefully inadequate'

According to Affinity's complaint against Trustwave, lodged in late December, the measures used by the cybersecurity firm to diagnose and remedy the original data breach proved 'woefully inadequate' when the second breach occurred. The complaint argues that Trustwave 'knew (or recklessly disregarded)' that examining only a small subset of Affinity's data systems would leave an incomplete picture of how and where the breach occurred. One of Trustwave's key competitors, Mandiant, also alerted Affinity to the fact that the malware responsible for the breach has never been fully removed from Affinity's system, despite reports to the contrary submitted by Trustwave to the Payment Card Industry authority. A forensic report from Mandiant concluded that the second breach 'occurred on a continuous basis both before and after Trustwave claimed that the data breach had been contained'.

Mounting costs

As a result of the breach, Affinity was required to pay for a second PCI forensics report conducted by Mandiant, as well as additional assessments that allowed banks to reissue credit cards. Affinity is now seeking at least $100,000 in damages from Trustwave, having already reportedly used $1.2m of a $5m cybersecurity insurance policy to settle expenses related to the breach. Trustwave has denied any wrongdoing and indicated that it plans to 'vigorously defend' the allegations in court. Sources: The Hill, Financial Times, Ars Technica

Email your news and story ideas to: [email protected]

Top