The decision to escalate incidents to law enforcement is an area fraught with conflict. In your opinion, what are the pros and cons of law enforcement involvement? What resources and references can you cite to backup your assertions?
While escalating a situation to law enforcement is a touchy subject in a business setting, especially around cybersecurity issues, it is sometimes the correct choice depending on the organization’s capabilities. Involving law enforcement may lead to a more efficient and effective internal investigation into how it happened, information forensics, evidence collection and processing and the like, especially if the security team of an organization is unable to perform those tasks, or if they don’t have the required experience. It may be an embarrassment to the organization to have law enforcement do such a vital job for them, it is unfortunately sometimes a necessity. They can also help in handling the legal side of an attack, and help to investigate the parties involved, prosecute them, and ultimately make them pay for their illegal actions.
Involving law enforcement however, basically forced an organization to relinquish control of the situation to them. Information regarding the case may be withheld from members of the victim organization while investigations are ongoing, and vital components of a system or network may be confiscated for use as evidence, or investigative material, regardless of the important of that equipment. Not only this, but as stated before if the organization is medium or large, and quite well known, it will be a blow to their prestige, and may in fact invite more breach attempts upon them as a result.
While it is important to know when to involve law enforcement, it’s also important to be able to handle breaches and attacks as an organization rather then relying on law enforcement to take care of all post-attack investigations.
Source:
K, G. (2018, March 9). Data breach. whether or not to involve law enforcements ? LinkedIn. Retrieved September 20, 2022, from https://www.linkedin.com/pulse/data-breach-whether-involve-law-enforcements-guhan-k