адвокат, юрист
A cyber incident at a company is not only an IT problem: it brings legal obligations, the risk of criminal liability and claims from customers. Attorney Vitalii Petryk explains what a company must do, and in what order, during the first hours and weeks after a breach is discovered.
Key points
The first hour determines the scale of the losses and the quality of the future evidence base – every action counts.
The obligations depend on the type of incident and the status of the company, but several requirements are common.
Notifying regulators. If the leak concerns personal data, the company must notify the Ukrainian Parliament Commissioner for Human Rights. Critical infrastructure operators must also notify the State Cyber Protection Centre under the Law on the Basic Principles of Cyber Security of Ukraine.
Notifying customers and partners. If third party data has been compromised, those persons must be informed within a reasonable time – delay may become grounds for damages claims.
Reporting to law enforcement. A criminal report to the police or directly to the cyber police (cyberpolice.gov.ua) records the offence, triggers investigative measures and provides the basis for action against the attacker.
An internal investigation without a lawyer carries a risk: the material gathered may be held inadmissible in court or in criminal proceedings.
Criminal liability threatens not only the attackers but, in certain situations, the company as well.
Attackers may be prosecuted for unauthorised interference with computer systems (Article 361 of the Criminal Code), distribution of malicious software (Article 361-1) and unauthorised collection or distribution of personal data (Article 182).
The company or its officers may be liable if they deliberately or negligently failed to implement statutory protection measures, concealed the incident from regulators or affected persons, or destroyed evidence or obstructed the investigation.
Must customers be notified of a leak of their data?
Yes, if customers personal data has been compromised. The timing and procedure depend on the circumstances, but unjustified delay may give rise to claims. Consult a lawyer to determine the scope and deadline for notification.
What does reporting to the cyber police achieve?
It opens criminal proceedings, giving investigators powers to identify the attacker and seize evidence. It is also a necessary document for insurance settlement and certain regulatory procedures.
Can the IT contractor be held liable if the breach resulted from its negligence?
Yes, if the contract provides relevant warranties or you can prove that the contractor acts or omissions caused the vulnerability. Prospects depend on the contract terms and the evidence.
What if the attacker demands a ransom (ransomware)?
Do not pay without consulting a lawyer and cyber security specialists. Payment does not guarantee restored access and may complicate dealings with the insurer and law enforcement. The priority is isolating the system and engaging specialists.
How can we protect against a repeat incident from a legal standpoint?
Once the consequences are dealt with, run a legal audit of contracts with IT suppliers, update the internal information security policy and verify compliance with personal data protection law.
Has your company suffered a cyber incident and needs legal help?
Attorney Vitalii Petryk provides legal assistance in cybercrime cases, business protection during cyber incidents and criminal proceedings in the IT field.
This article is informational and is not legal advice. To assess your specific situation, contact an attorney.
Залиште номер, і я зателефоную вам протягом 50 секунд.
Ваш номер не передається третім особам
Або зателефонуйте самі: +38 (096) 878-07-36

Pingback: Liability for a personal data leak | Attorney Petryk