NavigateLLC Logo

office (240) 475-3640
fax (888) 284-7309
toll-free (888) 284-7309

Information Protection, Privacy & Governance

NAVIGATE: EXECUTEExecution

With an information protection & privacy management plan in hand, your best option for implementing required change without burdening existing resources is through a partnership with a trusted third party.  Navigate LLC has the real-world experience and operational expertise to help you carry out the tasks needed to bring your company in line with customer expectations and legal requirements, while allowing you to focus on your core business objectives.  When it comes to ensuring that the increasingly important information protection & privacy needs of your organization are sufficiently addressed, Navigate LLC can lead the way.

Implementation Program Management

Focused and effective management is required to ensure the successful completion of your information protection & privacy plan – on-time and on-budget.  Navigate LLC can provide the resources required to lead your implementation efforts or to supplement existing staff. In either case, we form close partnerships with our clients for the purpose of facilitating knowledge transfer and fostering a sense of ownership by the stakeholders in order to help sustain the benefits of the program.

Policy Development

Policies and procedures are the cornerstone of any program and establish a framework for the information management operations of your company.  In order to be effective, however, policies and procedures must be easy to understand, actionable and well-communicated.  Your policies also create obligations for data management between you and your customers, employees, and partners.  Navigate LLC will work with you to review existing policies as well as create new information protection & privacy policies that will enhance existing operations rather than become a barrier to efficiency, or create data use conflicts within the organization.

Training

Training and education are often an overlooked aspect of an effective information protection & privacy program, yet they are critical to help employees develop a respectful understanding of their roles in recognizing and enforcing policies and procedures in their day-to-day jobs.  In some situations, training may even be required under law.  Navigate LLC can assist in the selection and deployment of the appropriate third party courseware, or develop customized training specific to your organization for delivery in an e-learning or classroom venue.

Communication Plans

A critical component to any comprehensive information protection & privacy program is communications.  Whether the communication plan is internal, focused on generating greater awareness of security risks and responsibilities among employees, an external plan targeting consumer awareness, or a crisis response plan designed to minimize reputational damage in the event of a breach, a strategic communication plan ensures accurate information is disseminated to the right audience.  Navigate LLC can create a comprehensive or targeted communications strategy, including the development of supporting materials, relevant to your organization’s needs.

Data Breach Incident Response Planning

Almost every state in the U.S. has a law dictating what you must do if certain personal information, including the information you’ve entrusted to outsourced vendors, is lost or stolen. In the age of ecommerce, those laws often apply nationwide, creating a complex – and often confusing – legal patchwork.  With the federal government and a number of international markets considering similar laws, it is imperative to keep current with your practices or risk falling afoul of regulators.

To help you do this, Navigate LLC will work with you to develop an incident action plan designed to ensure your organization is able to meet its legal obligations, while minimizing damage to brand reputation.  Navigate LLC will help you prepare in advance of an incident, and work with you throughout the cycle should it be necessary.  Elements typically addressed in an incident response plan include:

  • Identification of the incident response team;
  • Investigative plan to determine the root cause and extent of data loss and ensure the loss is stopped;
  • Templates for notification letters that may be required for individuals whose information was lost or stolen, as well as to notify the appropriate legal authorities;
  • Question and answer documents in preparation for response to notification letters;
  • A media response plan including press releases, spokesperson preparation, and question and answer training; and,
  • Identification and contracting with the relevant third party service providers (such as printers, mail houses, outside legal counsel and credit monitoring service companies) that will be needed to help your organization deliver on the steps in your response plan quickly.

Navigate LLC can work with your organization to create or review your incident response plan, facilitate practice walkthroughs of the plan and conduct annual tests of the plan.

Data Breach Incident Response Execution & Management

When a data breach occurs, a fast well-executed response is critical to minimize the damage. If your organization does not have an incident response plan, or has never been through a live data breach response, Navigate LLC can bring the required experience to efficiently manage your incident response effort in a manner that is defendable to regulators.  The result is that the costs you incur and reputational damage are limited.