Many risk management functions are designed to protect their stakeholders’ information assets (including owners, creditors, investors, customers, and employees). Whether due to regulation, insurance requirements, fear of lawsuits, or just good business practice, organizations continue to evolve and invest in their breach response policies to help manage these risks to tolerable levels. Yet, despite these efforts and investments, data leakages and breaches occur.
Unfortunately, whether the source of the breach was an organization entrusted with the information or the individual’s unsophistication in protecting their data, the cost of personal identity theft continues to rise. According to a report co-sponsored by AARP and performed by Javelin Research, “American adults lost a total of $43 billion to identity fraud in 2023” (“Identity Fraud Cost Americans $23 Billion in 2023,” Christina Ianzito, AARP, https://tinyurl.com/mssy77nz). This does not include the non-financial, but still real, costs of mental anxieties, depression, and suicide resulting from being a victim of a personal data breach, which are discussed in another AARP report, “Blame and Shame in the Context of Financial Fraud” (https://tinyurl.com/256daeru). As a result, in their roles as trusted advisors, especially in providing for personal tax and financial planning services, CPAs will be called up to help their clients and employers protect and recover from the potential damage. They may also have to recover from the breach of their own information.
Practical Challenges
Much guidance, including newspapers, well-meaning blogs, and informative websites from vendors, exists to help individuals identify practices that could impact the probability of becoming a victim. Reliable preventive strategies are available from state attorneys general, federal agencies, and credit bureaus. The CPA Journal previously highlighted (Susan B. Anders, “IRS Tax Identity Theft and Fraud Resources,” The CPA Journal, December 2021, pp. 74–75) recommendations and tools from the IRS, including its identity theft central (https://www.irs.gov/identity-theft-central). The IRS Guide “Safeguarding Taxpayer Data: A Guide for Your Business” (https://www.irs.gov/pub/irs-pdf/p4557.pdf) is another excellent resource. (Note: CPAs’ professional and legal responsibilities to protect client data are beyond the scope of this article).
Unfortunately, many individuals (often in their role as consumers), whether due to ignorance or lack of resources, are unable to devote the resources (time and financial) to protect themselves adequately as to how they use and distribute their personal information. Some are faulted for lack of interest, diligence, or accountability, even though successful ongoing protection and monitoring may require dollar investments that they may not be able to afford. For others, understanding and trying to mitigate these risks is an enormous effort.
Many individuals remain frustrated that the source of data breaches often include parties which individuals had no idea were maintaining their information. For example, a data breach may lead to the dissemination of protected data from a third party, regardless of whether the individual was responsible for sharing the information with that third party, through no fault of the individual. In some cases, by the time the individual becomes aware of the breach, with or without appropriate notification from the third party, there may be little they can do.
Another complicating factor for individuals is the expanding variety of identity theft. Experian, one of the major credit reporting agencies, has identified 20 types of identity theft and fraud (https://tinyurl.com/ycb6u5yt). These range from well-known debit/credit card fraud to lesser-known others, such as medical fraud.
Learning from Organizations
Many individuals typically do not consider recovery strategies until their information is compromised. Although the risk of an actual loss cannot be totally eliminated, individuals can learn from the recovery preparation used by organizations. When an organization suffers a breach, the success of recovery relies significantly on the ability of the organization to prepare for such a breach. To do so requires that the organization develop, and periodically exercise, a plan for such an event. This is usually accomplished through the use of an incident response plan.
A previous column addressed the issues facing organizations and discussed a generic approach (See “Incident Responses to Cyber Attacks and Breaches: Considerations for Boards and Audit Committees,” May/June 2023, https://tinyurl.com/3ubawwnc). Key steps identified included placing incident response on the agenda; defining expectations and related responsibilities; knowing your data and what can be lost; understanding the impact of vendors; considering guidance, requirements, and expectations from insurance carriers; learning from other organizations; being prepared for media questions; and proper planning to reduce risk. Many of these actions can be adapted to help individuals recover from a personal breach. As with organizations, individuals may not have complete control over who maintains their data or prioritizes recovery strategies.
Individual Recovery Actions
Like businesses, individuals can better manage their response and minimize the impact of personal breaches by planning in advance and periodically testing recovery steps. Realistically, only some individuals will fully prepare. Although numerous articles exist that consumers could utilize, much of the guidance is incomplete or vendor-specific. Alternatively, federal agencies and state attorneys general publish reputable materials on the subject. The recovery guidance provided also identifies safeguarding practices that may increase the probability of encountering the problem. Ironically, as with their business counterparts, a significant part of individual recovery efforts will require many of the recommended safeguarding practices that should have already been implemented.
One admired source is the Federal Trade Commission’s (FTC) https://www.identitytheft.gov. Rather than provide generic advice, the interactive site enables an individual to develop a customized plan based on an actual event or an anticipated risk. The impacted individual marks statements relevant to the loss, and a recovery action plan is generated. Individuals can then create an account, enabling them to track progress and pre-fill letters and forms. Alternatively, users can browse the resources without going through the questionnaire. Key sections, each with sub-topics to guide the user, include what to do right away, what to do next, other possible steps, steps for specific accounts, and special forms of identity theft. Two reference sections provide sample letters to help resolve identity theft-related issues with third parties, including financial institutions, credit bureaus, and collection agencies. The other reference section discusses what to do if your information is lost or stolen.
A Strategy of Mitigation
Unfortunately, there are many sources of threats to nonpublic personal information and many ways that data can be breached and used improperly. One of the greatest fears related to personal identity and data theft is that the custodianship of an individual’s data does not reside with the individual themselves. For example, in one of the largest personal breaches, Equifax, a credit reporting organization, had the data of individuals even though the individuals had not contracted with Equifax directly. Information may have been shared with a trusted vendor or third party in other situations. Any personal recovery strategy begins with ensuring that the individual protects their personal data to the extent they can and what they have influence on to do so. Then, a recovery plan will be developed and implemented to mitigate and recover from the loss. Sometimes, even businesses do not complete these critical actions. Expecting individuals to do so may be unreasonable. Training, personal responsibility, and holding third parties accountable will remain key mitigating actions. But unfortunately, such actions will not be sufficient to reduce the occurrence of breaches.






























