Project Overview
The project consisted of building a Software-as-a-Service App, considered as one of the first known platforms of its kind dedicated to the discovery of sensitive information, data breach review, and building lists of affected individuals for data breach notification. The app is designed for service providers and law firms responding to data breaches in compliance with GDPR, FERPA, PCI, HIPAA, CCPA or other privacy laws or regulations.
It’s a cloud-based app that allows law firms, legal service providers, and incident response teams upload massive amounts of breached data for analysis. When the documents are uploaded, they are analyzed, PII is detected, and a report is generated. Users then have the ability to go through affected documents to look for affected individuals.
It comes with a sensitive information discovery capability to help teams respond faster, more accurately, and with less risk and resources than would otherwise be possible using traditional discovery approaches.
The app combines many new and existing discovery techniques into a unique workflow specifically designed to solve the problems discovering personally identifiable information (PII), protected health information (PHI), and student education records.
Industry
Cybersecurity / Legal & eDiscovery
Tech Stack
Team
Composition
Client Background
Industry leader specializes in Data Breach Response, PII & PHI Detection, Data Security, Sensitive Information Detection, Privacy, Data Subject Access Requests, Incident Response, Data Protection, GDPR, CCPA and Cybersecurity.
The Challenge
Business Challenges:
A Global cyber research firm predicts that cybercrime damages will cost the world $6 trillion annually by 2021, doubling from $3 trillion in 2015.
A couple of data breach & cybersecurity facts and figures for the year 2019 to 2021:
The Problem; users were forced to manually enter information found about affected individuals. They had no way of ensuring the data was accurate and no way to prevent duplicates, often relying on products such as Excel to hold the information.
Goals:
Mindful of the crippling cost and staggering volume of data breaches and cybersecurity events, the client’s ultimate goal was to:
The app processes electronically stored information using proprietary algorithms pre-trained for sensitive information detection and extraction that goes well beyond the capabilities of regular expressions.
The app’s reports are designed to help assess the impact of the breach before reviewing the data. Use the analytics to cull and organize documents in preparation for data mining affected individuals.
The app’s coding technology and workflow are designed to resolve the relationships between individuals and their elements found across multiple documents. Its ML model helps quickly extract, relate, and export a list of unique individuals.
Robust Upload: Upload or import from S3, Google Drive, Dropbox, Office 365, or SFTP
Defensible Processing: Process uploaded information using standard e-discovery methods
Active Lookahead: Actively associate individuals with documents as the system learns
Detect & Classify: Automatic PII/PHI detection using Machine Learning
Anomaly Detection: AI-based detection of data anomalies, such as typos in Social Security Number
Entity Relating: Link and relate entities to build lists of affected individuals/data subjects
MapAccel: Map spreadsheet columns to entities and import entities while reviewing documents
Entity Resolution: De-duplicate and normalize related entities, even with maiden/nicknames