Overview
Results may vary depending on your particular facts and legal circumstances.
![]() |
Connell Foley LLP is proud to be designated an authorized Breach Coach® firm by NetDiligence®. |
From initial crisis response and regulatory compliance to litigation preparation and mitigation of future risk, Connell Foley LLP’s Cybersecurity, Incident Response, and Data Privacy team handles the full spectrum of complex issues related to a cyberattack. We bring more than 15 years of nationwide experience defending data breach litigation and regulatory enforcement actions to our representation of consumers and businesses victimized by cybercrime. Our clients include Fortune 100 corporations, start-ups, and privately held firms in various industries, including healthcare, retail, education, state and local government, transportation, manufacturing, professional services, and others. Connell Foley also helps clients manage cyber risk and ensure resiliency relevant to risk assessments, policies and procedures, incident response planning and exercises, security awareness training, third-party vendor management, and cyber insurance.
Connell Foley's Cybersecurity, Data Privacy and Incident Response Group offers the following:
- Artificial Intelligence (AI) Governance — Our team is dedicated to navigating the complex landscape of artificial intelligence in the legal sector. We provide comprehensive legal services to help clients harness the power of AI while ensuring compliance with evolving regulations and ethical standards. Our goal is to empower clients to innovate with confidence, leveraging AI to enhance their operations while maintaining the highest standards of legal and ethical integrity. Our team focuses on:
- Advising on federal and state AI regulations, including data privacy, algorithmic transparency, and anti-discrimination laws.
- Identifying and mitigating risks associated with AI deployment, such as bias, data security, and accuracy.
- Developing frameworks for the ethical use of AI, ensuring that AI applications align with professional responsibilities and client trust.
- Assisting in creating internal policies and guidelines for responsible AI use within organizations.
- Representing clients in disputes involving AI technologies, including issues of liability and intellectual property.
- Breach Response Services — In addition to offering a 24/7 Data Breach Response Hotline, Connell Foley serves as breach response counsel across various industries. We work with private companies, law firms and cyber liability insurance carriers on forensic investigations, breach notification, remediation, regulatory response and litigation. Our services include:
-
Conduct initial assessment and scoping of the data security issue, including digital forensics to contain, analyze, investigate, and remediate the incident.
-
Assess cybersecurity obligations at federal, state, and local levels, including consumer notification and regulatory requirements, as well as contractual obligations with vendors, customers, and third parties.
-
Draft and send consumer notification letters, along with regulatory and attorney general notification letters.
-
Facilitate consumer remediation services, such as credit monitoring and identity theft protection, if needed.
-
Coordinate crisis communication efforts in response to media inquiries and report to key stakeholders.
-
Report to local federal law enforcement (FBI, US Secret Service) and respond to inquiries from regulatory officials.
-
Defend against regulatory investigations, enforcement actions, and third-party litigation related to the breach.
-
Participate in Tabletop exercises to prepare for potential incidents and stay updated on developing cybersecurity legal and regulatory issues.
-
- Legal and Regulatory Compliance — We counsel leading companies in the United States on matters involving common law claims as well as the following federal and international laws:
- Computer Fraud and Abuse Act (CFAA)
- Stored Communications Act (SCA)
- Health Insurance Portability and Accountability Act (HIPAA)
- CAN-SPAM Act
- Federal Trade Commission Act
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- The Payment Card Industry Data Security Standard (PCI DSS)
- Children's Online Privacy Protection Act (COPPA)
- Representation in Court and other Proceedings — Clients throughout the country value our representation in federal and state courts and alternative dispute resolution forums, including defending against regulatory investigations and enforcement actions, and against third-party data breach-related litigation.
- Counsel on Social Media — In response to our clients’ developing needs and the impact of technology and data privacy across numerous industries, the Group also advises companies and professionals on social media. Teaming with Connell Foley’s Labor and Employment and Professional Liability Practice Groups, we provide risk management advice on social media in the workplace and counsel clients on implementing policies to protect their corporate social media assets. We regularly offer guidance to law firms and insurance and other industry professionals regarding the impact of social networking on their industries and in litigation.
Thought leaders in cybersecurity, our lawyers frequently speak at national conferences and publish on this evolving field. We monitor legal and regulatory developments and advise clients on the technological changes shaping their business. Karen Painter Randall, Chair of our Cybersecurity, Data Privacy and Incident Response Group, recently received a third American Bar Association presidential appointment to the ABA’s Cybersecurity Legal Task Force. She also founded and chairs the New Jersey State Bar Association’s Cybersecurity Legal Task Force. Most recently, she created and now chairs the first Cybersecurity Task Force in the southeast for the University Of South Carolina School Of Law.
In 2019, Connell Foley received a "Best Practices Award" from CIANJ for the firm's submission on the most important factors in responding to a ransomware attack. In addition, Karen Painter Randall was selected by NJBIZ as the only attorney among 34 honorees to receive an inaugural "NJ Digi-Tech Innovators Award;" she received the bi-annual award again in 2021.
Recognizing that immediate action and crisis management are crucial in the event of a breach, Connell Foley's Cybersecurity, Data Privacy and Incident Response team is available to assist businesses 24 hours a day, 7 days a week:
Phone: 973.840.2500
Email: breachresponse@connellfoley.com
Experience
Experience
Recent Representative Incident Response Matters (investigation, containment/eradication, assessment, notification, remediation):
Results may vary depending on your particular facts and legal circumstances.
- Insider Wrongdoing: Served as breach response counsel for client related to insider wrongdoing involving unauthorized access to the personally identifiable information of co-workers’ payroll information.
- Website Compromise: Served as breach response counsel for client regarding unauthorized access to client’s website involving the inadvertent disclosure of customer’s personally identifiable information including credit card/payment information.
- Insider Wrongdoing: Served as breach response counsel for client regarding inadvertent disclosure of customers’ banking information requiring notification and regulatory evaluation under Gramm Leach Bliley Act.
- Social Engineering: Served as breach response counsel to provider of MRO whose employee responded Reply All to a phishing email purporting to be from the CEO, sending the companies’ W2's for all U.S.-based employees for the past two years.
- Insider Wrongdoing: Served as breach response counsel for client related to insider wrongdoing involving the theft of employee personnel files containing personally identifiable information, including Social Security numbers, bank account numbers/PINS and protected health information.
- Business Email Compromise: Represented professional clients in external system breaches involving phishing emails wherein funds were fraudulently wired.
- Theft of School Files: Represented school district regarding theft of student IEPs from employee’s vehicle, and advised them regarding notification and privacy implications under FERPA.
- Technical Support Compromise: Served as breach response counsel to accounting firm involving a “Microsoft Premium Technical Support” compromising the tax returns of its clients.
- Social Engineering/Ransomware: Served as breach response counsel to a school district infected with malware indicative of two banking Trojans, Emotet and Trickbot wherein the credentials of its employees who entered them into financial institution website or other similar website were compromised. Followed by ransomware attack.
- Ransomware: Served as breach response counsel to law firm who was the victim of a ransomware attack (Ryuk), and worked with forensics and bitcoin broker to pay ransom, obtain the decryption key for the return of data and restore.
- Social Engineering: Represented law firm wherein a third party gained unauthorized access to email account, and advised regarding obligations under applicable state statute and requirements as bankruptcy trustee.
- Social Engineering: Served as breach response counsel to accounting firm involving a third party gaining unauthorized access to email account and firm’s portal storing confidential client information.
- HIPAA: Represented physical therapist facility related to former employees downloading client email list prior to departure to advise on applicable state statute and HIPAA requirements.
- HIPAA: Represented third-party organization that uses data analytics to promote patient safety and quality healthcare to advise them on potential HIPAA violation associated with information provided from a covered entity.
- Social Engineering: Represented service provider to insurance carriers in connection with processing premium payments under their Pay-As-You-Go workers compensation policy involved in a phishing attack, which resulted in unauthorized access to information contained within an employee’s email account. Data mining services were deployed.
News & Insights
News
Events
Publications
Blog
Blog Posts
- Legal Blogs and Updates, 05.23.2023
- Legal Blogs and Updates, 03.17.2023
- Legal Blogs and Updates, 08.18.2022
- Legal Blogs and Updates, 10.07.2021
- Legal Blogs and Updates, 08.04.2021
- Legal Blogs and Updates, 07.07.2021
- Legal Blogs and Updates, 05.13.2021
- Legal Blogs and Updates, 03.23.2021
- Legal Blogs and Updates, 03.27.2020
- Legal Blogs and Updates, 03.26.2020
- Legal Blogs and Updates, 09.13.2019
- Legal Blogs and Updates, 08.05.2019
- Legal Blogs and Updates, 07.29.2019
- Legal Blogs and Updates, 07.18.2019
- Legal Blogs and Updates, 01.07.2019
- Legal Blogs and Updates, 07.09.2018
- Legal Blogs and Updates, 06.01.2018
- Legal Blogs and Updates, 05.25.2018
- Legal Blogs and Updates, 05.21.2018
- Legal Blogs and Updates, 04.30.2018
- Legal Blogs and Updates, 12.04.2017
- Legal Blogs and Updates, 11.13.2017
- Legal Blogs and Updates, 09.18.2017
- Legal Blogs and Updates, 08.22.2017
- Legal Blogs and Updates, 07.20.2017
- Legal Blogs and Updates, 07.10.2017
- Legal Blogs and Updates, 06.30.2017
- Legal Blogs and Updates, 05.12.2017
- Legal Blogs and Updates, 05.01.2017
- Legal Blogs and Updates, 03.15.2017
- Legal Blogs and Updates, 01.24.2017
- Legal Blogs and Updates, 12.21.2016
- Legal Blogs and Updates, 04.28.2015
- Legal Blogs and Updates, 04.15.2015
- Legal Blogs and Updates, 03.19.2015
- Legal Blogs and Updates, 02.28.2015
- Legal Blogs and Updates, 02.23.2015
- Legal Blogs and Updates, 02.18.2015
- Legal Blogs and Updates, 02.09.2015
- Legal Blogs and Updates, 02.04.2015
- Legal Blogs and Updates, 01.30.2015
- Legal Blogs and Updates, 01.20.2015
- Legal Blogs and Updates, 01.12.2015