Federal Guidelines for Responding to Cyberattacks - International Law Office

International Law Office

E-commerce - USA

Federal Guidelines for Responding to Cyberattacks

August 15 2002


"Internet Attacks on the Rise" reported on the dramatic increase in online attacks and the vulnerability of the Internet. In view of this situation, companies may wish to consider federal guidelines published in February this year, entitled “CIO Cyberthreat Response & Reporting Guidelines”, in assessing how to respond to a cyberattack. The better prepared an organization is to respond quickly and effectively to a cyberattack – be it an intrusion, virus, worm, denial of service or other attack – the better chance it has of minimizing the damage.

The 12-page guidelines were drafted by the Federal Bureau of Investigation (FBI) and the Secret Service in conjunction with private security experts brought together by CIO magazine, a trade publication for IT executives. The guidelines attempt to balance the government’s need for information in order to investigate attacks with the reluctance of commercial victims to publicize cyberattacks out of concern that they will scare away customers looking for secure transactions. The guidelines provide contact information and outline practices advocated by the FBI and the Secret Service. More specifically, the guidelines provide a framework and starting point for addressing a cyberattack by:

  • developing an incident response plan;

  • identifying the individuals and contact information necessary to implement the plan;

  • testing the plan and developing contingency plans;

  • determining what cybersecurity events to report to law enforcement agencies; and

  • determining when and how to report an incident.

The guidelines are a useful source in formulating a proactive and responsive strategy and collating contact information. Businesses should review them to determine whether they are appropriate for implementation given a company’s individual circumstances.


For further information on this topic please contact Alan Raul at Sidley Austin Brown & Wood LLP by telephone (+1 202 736 8477) or by fax (+1 202 736 8711) or by email (araul@sidley.com). The Sidley Austin Brown & Wood website can be accessed at www.sidley.com and the firm's CyberLaw website is located at www.sidley.com/cyberlaw.


Comment or question for author

ILO provides online commentaries as specialist Legal Newsletters. Written in collaboration with over 500 of the world's leading experts and covering more than 100 jurisdictions, it delivers individually requested information via email to an influential global audience of law firm partners and international corporate counsel. Please click here to register for the service.

The materials contained on this website are for general information purposes only and are subject to the disclaimer.

ILO is a premium online legal update service for major companies and law firms worldwide. In-house corporate counsel and other users of legal services, as well as law firm partners, qualify for a free subscription. Register at www.iloinfo.com.