Is your crisis room prepared for anything that might happen?

Estimated reading time: 3 minutes

Summary

The year 2025 has just begun, and your crisis room is ready for anything, right? Yes? No?  

Well, if it isn't already – or doesn't exist – you can still include the acquisition of some resources in the emergency budget; after all, it's a "crisis room," and structuring your company's is very important. Hiring good training programs for crisis room members and secure incident management platforms, for example, should be seen as urgent actions.

So what is a crisis room? It's an emergency meeting held when a security incident occurs. And here we are specifically dealing with information security involving personal data.

The General Data Protection Law, Law 13.709/2018, does not require companies to maintain a crisis room or incident response committee within their structure. IT War RoomCall it whatever you want to call it, especially since its nature is ephemeral, but it is important to look carefully at Chapter VII of the LGPD.

This chapter discusses the security measures, best practices, and governance that corporations should adopt, such as reporting incidents to the National Data Protection Authority (ANPD), which must be done following technical criteria evaluated by the Data Protection Officer (DPO), especially regarding the timeframe and the quality of the personal data affected.

If a cyber incident occurs in a company, for example, and a IT War Room If the meeting is held without including the DPO, there is a risk of compromising this thorough technical assessment and even missing the deadline set by the Authority. 

It's common to convene crisis rooms restricted to IT and Legal managers, as well as the CEO and CFO – after all, someone needs to think about the finances.

But, regardless of the segment and size of each organization, it is essential that the crisis room includes someone who will analyze and be responsible for the following issues related to the incident, whether from internal staff or a contracted consultancy:

  • – Human Resources;
  • Legal;
  • – IT;
  • – DPO;
  • Press Office;
  • – Audit;
  • - Financial;
  • –Marketing;
  • – Business area(s) directly involved, if any.

And the DPO, in a crisis room, has fundamental responsibilities that only he, as the Data Protection Officer, can fulfill, such as: assessing whether the Information Security triad (CIA) has affected personal data; was the authenticity of the data maintained? Was there significant damage to the data? Was there technical mitigation? Are there operators involved? Are there sub-operators? And one of the most important: is it necessary to notify the ANPD (Brazilian National Data Protection Authority)?

Ultimately, it is essential that the members of a war room Be prepared because information security incidents happen and will continue to happen. They need to be able to fulfill their roles like a fire brigade.

To understand the importance of a crisis room, just like a fire brigade, one only needs to remember what happened at the Pequeno Príncipe Children's Hospital in Curitiba, Paraná, on the morning of October 31, 2023. reported by the hospital itself"The Hospital's Emergency Brigade's actions were once again crucial in the explosion. The team's quick response ensured that the flames did not spread. The Fire Department was called and by the time they arrived there was no longer any risk."

Ensuring the flames don't spread – that's what it's about.

About the Author

Meet the author of this article.

  • Certified EXIN DPO working in the educational field, specializing in Data Protection and Privacy, Process Management, BPM, ISO 27001 Information Security, ISO 9001 Quality Management, Postgraduate Professor in Digital Law. Specialist and postgraduate in Cybersecurity and Data Governance.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also