Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Videos
    4. How do EU companies respond to ransomware attacks?

      Videos

    How do EU companies respond to ransomware attacks?

    Oct 16, 2023

    LinkedInX (Twitter)EmailCopy URL

    By Jason Kravitz and Jenny Holmes

    Guest Louise Mehl of Implement Consulting Group joins A Little Privacy, Please!® hosts Jason Kravitz and Jenny Holmes to discuss the contrasting responses of EU and U.S. companies to ransomware attacks.

    Our next guest on A Little Privacy, Please! is Louise Mehl, a partner with Implement Consulting Group in Copenhagen, Demark. A self-proclaimed privacy nerd at heart, Louise helps companies develop ambitious data protection and cyber and information security programs.

    Watch this episode of A Little Privacy, Please!

    Ransomware attacks are an all-too-common scenario for companies in the U.S. Are ransomware attacks as prevalent in the EU?

    Absolutely. Ransomware attacks are a concern in the EU.

    Just last month in Denmark, in the Northern Jutland, a targeted attack on five schools in Denmark compromised sensitive personal data. The compromised data included evaluations of children’s mental health (e.g., learning disabilities), employee information, and communications between teachers, parents, and kids. The attacks were discovered a month before disclosure to the public. The schools were embarrassed about the attacks and delayed their response, potentially making the damage even bigger.

    When we have a client that’s hit with a ransomware attack, the starting point for us is assembling a team comprised of legal counsel, key decisionmakers within the company (i.e., IT,  chief technology officer), and forensic investigation teams. And if the company is lucky enough to have a cyber insurance policy, we will also involve the insurer in the process. How is a ransomware attack addressed in the E.U.?

    It’s rare to have cyber insurance in the EU because it tends to be very expensive, and you won’t find many insurance companies willing to insure cyberattacks.

    When facing a ransomware attack involving personal data a common initial step is to notify the data protection authorities and, of course, law enforcement as to act in accordance with both GDPR and other regulations.

    What are the timelines for breach notification in the EU? I believe they’re much stricter in the EU?

    They absolutely are. If it involves personal data, we have the General Data Protection Regulation’s (GDPR’s) seventy-two (72) hour notification. We also have the coming Directive on Security of Network and Information Systems (NIS) 2 cybersecurity framework, which mandates twenty-four (24) hours for notification, so we are looking into very strict notification timelines.

    On the contrary, if you don’t have the critical infrastructure, if it does not involve personal data, then the outcome is somewhat how you described—you would call local law enforcement, you would get into investigations. Of course, the pressure is always on if you are losing confidential and important data.

    It seems there’s a fundamental difference between the U.S., where the emphasis is on getting more information before the notification, and the EU, where the notification comes first, and the information is investigated second.

    It depends; if it's an attack of a certain size and amount of data, you make that assessment before notifying the authorities. But you should be able to make that within the first 72 hours.

    Switching gears just a little. I know you’re very passionate about fighting for the privacy of children. Can you talk about some of the causes you’ve supported?

    It is a cause very close to my heart. I have three children of my own.

    I conduct free workshops with parents, schools, and various volunteer organizations to educate them about social media safety. I want to raise awareness about the challenges children face online, the potential risk of interacting with online predators, and the impact of sharing personal information, including photos and videos. I see that adults, parents in general, often give up on digital and social media because they don’t understand it, don’t want to interfere, or are just not present on the same platforms as the children. I try to empower adults with knowledge and strategies to protect children.

    A Little Privacy, Please!

    Practices

    Cybersecurity & Privacy

    Insights And Happenings

    • Video

      Data protection laws in Canada

      Cybersecurity & Privacy
      Jan 22, 2024
    • Video

      Data Protection Laws in Mexico

      Cybersecurity & Privacy
      Nov 6, 2023
    • Article

      Five steps for responding to a cyber breach

      Oct 26, 2023
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved