Email

rdd@dijuliolaw.com

Monday - Sunday

9:00am - 6:30pm

Cybersecurity Incident Response

Cybersecurity & Data Privacy Law

Data Breach & Incident Response Attorney — Los Angeles

The first forty-eight hours after a security incident determine your notification exposure, your privilege position, and what a regulator will later conclude about your response.

The Short Answer

When must a California business notify people of a data breach?

Under Civil Code section 1798.82, a business must notify California residents in the most expedient time possible and without unreasonable delay when unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. If more than 500 Californians are notified in a single breach, a sample copy of the notice must also be submitted to the California Attorney General.

Cybersecurity & Data Privacy Law

Directing a Breach Response Under California Law

Incident response is a legal process supported by technical work, not the reverse. Counsel directs the forensic investigation so that findings are developed under privilege where available, establishes what categories of data were actually affected, determines which notification obligations are triggered in which jurisdictions, and manages communications with insurers, regulators, and affected parties.

California's statute is precise about what counts. Notification turns on unencrypted personal information as defined by statute, on acquisition rather than mere access in some circumstances, and on specific content requirements for the notice itself. Over-notifying creates unnecessary litigation exposure; under-notifying creates regulatory and statutory exposure. The distinction requires knowing what the forensics actually established, not what they initially suggested.

Post-incident, the same facts frequently generate follow-on claims: statutory claims under California's privacy laws, contractual claims from business customers under data protection addenda, and vendor claims where a third party caused the incident. Those are handled through privacy and cybersecurity litigation, informed by the record built during response.

Office

330 North Brand Boulevard, Suite 1280
Glendale, California 91203

Courts

Los Angeles County Superior Court, including the Glendale and Stanley Mosk courthouses.

Focus

Breach response, California privacy compliance, privacy litigation, and intellectual property disputes.

What We Handle

Incident Response Matters We Handle

For California businesses, professional practices, and organizations handling personal information.

Privileged Investigation

Retaining and directing forensic vendors under counsel so investigative findings are developed within privilege to the extent California and federal law permit.

Notification Analysis

Determining whether statutory triggers are met, which states and regulators are implicated, and what the notice must contain and when it must issue.

Regulator Communications

Submissions to the California Attorney General, responses to inquiries from the California Privacy Protection Agency, and coordination with other state regulators.

Vendor & Contract Claims

Pursuing or defending claims against processors and service providers under data protection addenda, indemnity clauses, and security commitments.

Insurance Coordination

Timely notice to cyber carriers, panel counsel and vendor approval requirements, and preserving coverage for response costs and defense.

Post-Incident Remediation

Contract, policy, and vendor management changes that reduce recurrence and demonstrate a reasonable security program if the incident is later examined.

Situations We See

Incidents That Reach Our Office

Composite examples drawn from the kinds of matters this practice handles. They illustrate common fact patterns and are not descriptions of specific client cases or predictions of any result.

01

The Business Email Compromise

A finance mailbox is compromised and a fraudulent wire is sent. Beyond recovering the funds, the exposure is the mailbox contents: whether personal information sitting in years of email was accessible determines the notification analysis.

02

The Vendor's Breach

A payroll or IT vendor suffers an incident affecting a Los Angeles company's employee data. Notification obligations generally run to the business, while the recovery runs against the vendor under the contract.

03

The Ransomware Decision

Systems are encrypted and data is exfiltrated. Whether to pay, what was actually taken, what must be notified, and what to tell customers are legal decisions with regulatory and litigation consequences.

When to Get Advice

When to Call About an Incident

  • You have detected unauthorized access, encryption of systems, or data exfiltration.
  • A vendor has reported an incident affecting your data.
  • A forensic firm has been engaged without counsel directing the work.
  • You are unsure whether the incident triggers California notification duties.
  • A regulator or attorney general has made an inquiry.
  • Affected individuals or business customers have begun making demands.
Practical Next Steps

What to Do First

  1. Preserve and contain

    Preserve logs and images before remediation overwrites them. Containment and evidence preservation are not in conflict if sequenced correctly.

  2. Engage counsel before forensics

    Retaining the forensic vendor through counsel is what supports a privilege position. Reversing the order afterward is generally not possible.

  3. Notice the carrier immediately

    Cyber policies impose short notice periods and vendor approval requirements. Late notice or unapproved vendors can jeopardize coverage.

Common Questions

Cybersecurity Incident Response — Questions California Clients Ask

What California businesses ask in the first days after a security incident.

What are a California business's legal obligations after a data breach?

California law (Civil Code §1798.82) requires businesses to notify affected California residents within a reasonable time after discovering a breach of certain categories of personal information. Depending on the nature of the breach and the information involved, federal notifications (e.g., HIPAA, FTC) and notifications to the California Attorney General may also be required.

What is the California Consumer Privacy Act (CCPA) and how does it relate to breach response?

The CCPA (as amended by the CPRA) gives California residents rights over their personal information and imposes obligations on covered businesses regarding data collection, use, and disclosure. Businesses that fail to implement reasonable security measures and suffer a breach exposing personal information may be subject to statutory damages of $100–$750 per consumer per incident under the CCPA's private right of action.

What should a business do immediately after discovering a cybersecurity incident?

Immediate steps include containing the incident to prevent further damage, preserving logs and forensic evidence, notifying legal counsel, evaluating notification obligations and their deadlines, retaining a qualified incident response firm, and reviewing applicable cyber insurance coverage. Prompt coordination between legal, technical, and executive stakeholders is critical.

What is attorney-client privilege in the context of a cyber incident investigation?

Engaging an attorney to direct the cybersecurity investigation and incident response can allow communications and investigative findings to be protected by attorney-client privilege. Retaining technical forensic experts through legal counsel — rather than directly — can help preserve these protections and reduce the risk that investigation findings become discoverable in subsequent litigation.

What cyber insurance coverage should California businesses carry?

Cyber liability policies typically cover first-party costs (breach notification, forensic investigation, business interruption, ransomware response) and third-party claims (lawsuits by affected individuals or regulatory actions). Coverage terms, exclusions, and sublimits vary significantly by policy. An attorney can help evaluate coverage and maximize recovery following an incident.

What are ransomware-related legal considerations for California businesses?

Ransomware raises legal questions around whether payment is permitted under OFAC sanctions regulations, whether the incident triggers data breach notification obligations, and how to preserve forensic evidence while managing business continuity pressures. Legal counsel should be involved before any ransom payment is made or refused.

Can a business be held liable if it is hacked?

Yes. Businesses that fail to implement reasonable security measures can face liability under the CCPA, common law negligence, or breach of contract theories if a cybersecurity incident results in the compromise of customer, employee, or third-party personal information. The reasonableness standard considers the nature of the data held and accepted industry security practices.

What is CCPA/CPRA compliance and how does it reduce legal risk?

Compliance with the CCPA and CPRA (including having an updated privacy policy, honoring consumer rights requests, limiting data collection, implementing data security measures, and executing required vendor contracts) can reduce the risk of regulatory action and class litigation following a breach, and demonstrates that the business took reasonable steps to protect personal information.

DiJulio Law Group

Talk to a Data Privacy Attorney

If an incident is in progress, the sequence of the next few decisions matters more than any of them individually. Call the office directly.