Skip to main content

News story

February 12, 2018

Cybercrime: Managing the legal issues for victims

Government statistics show that nearly seven out of 10 larger firms in the UK have been hit by a cyber-attack or a breach in the last year

It is not just the big names with an online presence being targeted by cybercrime. Increasingly smaller companies are finding themselves in the firing line, with nearly half of all UK businesses reporting at least one attack or breach.

Over 4 million individuals have also been victims of cybercrime, with 66% of cases resulting in a loss of money or goods.

Cyber Criminal

Cyber-attacks can cause havoc to a business. As well as raising questions about the security of IT systems, it also brings up many legal implications too. Just as it is a relatively new and constantly developing problem, it is also a relatively new and complex field requiring expert legal knowledge.

If your business has been the victim of a cyber-attack, you could face a number of repercussions that can affect your profits:

  • claims from customers who have suffered a financial loss as a result of the attack;
  • loss of client data;
  • disruptions of sales/staff work time; and
  • damaged reputation.

Business owners can also face claims from customers for breach of data protection. If your contracts with clients state your responsibility for data protection, you could have to deal with being held in breach of contract.

What responsibilities do businesses have regarding customer data?

Under the 1998 Data Protection Act (the DPA), organisations must take “appropriate technical and organisational measures” to protect personal data from unauthorised access or disclosure. However, as legal firms have discovered over the last few years, the DPA has some serious holes in it that are being exploited, leaving businesses reeling from the attack and subsequent fallout.

To shore up those holes, in May 2018, the EU’s General Data Protection Regulation (GDPR) will come into force. This will require all organisations to undertake data protection impact assessments for the riskiest uses of personal data.

It means that companies will need to ‘continuously’ identify risks that could put personal data at risk. Fines for any breach are expected to be significantly higher to a maximum of €20million or 4% of annual global turnover, whichever is higher. There will also be new legal obligations to report serious data security breaches and clearer guidelines on what data is regarded as ‘vulnerable’.

The government has already stated that this regulation will continue to be enforced after Brexit.

In the short-term

Investigation

Be prepared for an in-depth investigation into any cyber breach, so ensure you have a solid plan of action to cope. Our lawyers can help you to decide if the incident needs to be reported to the Information Commissioners Office (the ICO). Ensuring that breaches are reported sooner rather than later, and with full disclosure and details of preventative action initiated as a result, can mean the difference between a ‘lessons learned’ scenario or regulatory enforcement.

Dealing with claims

Seek legal advice around any liability claims arising from the cyber breach. This could include investigating the contractual position with any outsourced IT or virus protection providers to see if any losses can be recovered.

In the long-term

Risk assessment

Cyber security risks should be assessed, and a cyber security plan must be implemented. Because the threats to businesses are constantly changing, this needs to be reviewed to ensure you comply with legal obligations, giving customers and clients that all-important peace of mind that their data is safe.

Review and training

Your legal team can advise on any review of systems to protect your business from future attacks and training required to help staff respond effectively.

Prevention

Our lawyers can review your situation before you fall foul of an attack. They can check that your business complies with legal requirements and has the correct contracts, policies and procedures to protect it effectively.

Speak to data protection specialist Veronica Hartley today.

Note: This is not legal advice; it provides information of general interest about current legal issues.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • Double jeopardy of digital asset inheritance planning amid probate delays
    Hidden digital assets and mounting interest on inheritance tax bills are creating a costly double risk for families dealing with estates following the death of a loved one, as probate delays continue to impact thousands across England and Wales, addi


    Read more
  • Deal or no deal? Keeping negotiations on track
    How to keep commercial deals on track with Heads of Terms, NDAs and exclusivity, improving efficiency, reducing risk and avoiding delays.


    Read more
  • Rights and wrongs: How AI is reshaping Employment Tribunal claims
    AI may be a familiar presence in the workplace, but it’s now starting to appear somewhere less expected: the Employment Tribunal (ET). Grayson Stuckey explores this trend – and what it means for employers.


    Read more
  • Renters’ Rights Act: why process and paperwork matter more than ever for landlords
    The Renters’ Rights Act has now passed into law, marking one of the most significant shifts in the private rented sector in a generation. Most of the new measures will take effect in May 2026, with a national landlord database to follow later in th


    Read more
  • Understanding the Roles of Executors and Trustees
    When making a will, you place significant trust in those appointed to carry out your wishes. Executors and trustees are key roles, often held by the same people, but their responsibilities differ. Understanding these roles and their obligations helps


    Read more

What they say...

  • W Sandover, April 2026
    Boundary Wall dispute “Although (for complex, not relevant) reasons, this matter never reached the point of either negotiations or a court case, Barker Gillette staff provided us with excellent support. I would certainly go back to them in the

  • Client, April 2026
    Excellent suppy “Karen Cole supported me through a difficult time with warmth and professionalism. She made the entire process as smooth as possible, responding quickly to communication and giving clear advice. I would highly recommend Karen to

  • Client, April 2026
    So helpful! “Pippa Marshall listened and offered supportive, practical advice. She was very friendly, easy to talk to and did not pressure me to make any costly decisions during my free 30-minute consultation. I would definitely recommend Pippa

  • Nika Franke-Matthecka, April 2026
    “We had an excellent experience working with Michael Davies and his team on the sale of our property. They were efficient, knowledgeable, and highly diligent throughout the entire process. Communication was always prompt and clear, which made w

  • Paul Woodman, March 2026
    Will writing “Excellent service from start to finish. Efficient and good value. Charlotte was very professional, knowledgeable and understanding.”

Read more
Send this to a friend