
Looking Left of Boom
A New Approach to Preventing Fraud After Cyber Incidents
At the recent Midyear Meeting of the Coalition Against Insurance Fraud in New Orleans, Resolute Strategic Services Founder and Managing Partner Dave Smolensky challenged attendees to rethink how organizations define success following a cyber incident.
For years, cyber incident preparedness has focused almost exclusively on the organization itself. Incident response plans, tabletop exercises and recovery strategies are typically designed around restoring operations, satisfying regulatory requirements, protecting the organization’s reputation and minimizing business disruption.
While those objectives are important, they often overlook a critical question. What about the people whose information was compromised?
When a cyber incident occurs, customers, clients, patients, employees, vendors and other third parties can face years of potential fraud, identity theft and financial disruption. Yet during the planning process, organizations rarely spend meaningful time discussing how to reduce the impact on those individuals before an incident ever occurs.
During his presentation, Smolensky encouraged attendees to shift their thinking further “left of boom” by identifying proactive opportunities to reduce consumer harm before a cyber event takes place.
One of the most effective strategies is also one of the simplest. Organizations should take a hard look at the data they maintain and ask a fundamental question – Do we still need it?
Many organizations retain years, and sometimes decades, of sensitive information that no longer serves a legitimate business purpose. Customer records, former employee files, outdated vendor information and other historical data often remain stored simply because no one has made a decision to remove it.
The reality is data cannot be compromised if it no longer exists.
By conducting regular data audits, implementing data retention policies and securely disposing of unnecessary information, organizations can significantly reduce the amount of sensitive data available to threat actors. In many cases, these efforts may have a greater impact on protecting individuals than any notification letter or credit monitoring service offered after an incident occurs.
“The best way to protect someone’s information is to not have it in the first place,” Smolensky told attendees.
The presentation also highlighted the growing intersection between cyber incidents and fraud, noting that stolen information can create opportunities for tax fraud, medical identity theft, financial fraud, synthetic identity schemes and other forms of victimization long after an organization has restored its systems.
As organizations continue investing in cybersecurity, incident response planning and business continuity, Resolute Strategic Services believes the conversation must expand beyond organizational recovery alone.
Success should not be measured solely by how quickly systems are restored or how effectively a crisis is managed. Success should also be measured by how well organizations protect the people who trusted them with their information in the first place.
By incorporating data minimization, retention reviews and stakeholder-focused planning into cyber preparedness efforts today, organizations can take meaningful steps to reduce fraud opportunities tomorrow.