Data Breach Notification
,
Data Security
,
Governance & Risk Management
Blackbaud’s Attorneys Jon Olson and Ron Raether on Legal Risk, Trust and Recovery
After the immediate crisis passes, the legal and regulatory fallout of a breach begins. Lawsuits, regulatory scrutiny and reputational damage can unfold over years, often shaped by decisions made in the first hours after the incident.
See Also: Outcome-Driven Metrics Win Board Support
Such was the case for philanthropy software leader Blackbaud, which suffered a high-profile ransomware attack in 2020. In this Proof of Concept on “Anatomy of a Breach,” Blackbaud Chief Legal Officer Jon W. Olson and outside counsel Ron Raether explained why sustaining control in the aftermath of a breach requires disciplined communication, legal strategy and coordination across the business, cybersecurity and leadership teams.
“One of the things I found is that so much of what unfolds over the long endured period – the multiple years – are determined in the first few days. Even though the consequences unfold over time, the early framing decisions become anchors,” Olson said.
Those early choices influence regulatory posture, litigation strategy and how trust is preserved or rebuilt with customers, partners and authorities.
“To have credibility and legitimacy, we have to have a theme and a communication strategy that’s grounded in the facts and if those facts change and we have to pivot in ways that undermine the company’s credibility, that has long-term consequences,” said Raether, partner at Troutman Pepper Locke.
Olson and Raether joined Anna Delaney, ISMG’s executive director of productions, and Tom Field, ISMG’s senior vice president of editorial, to discuss:
- How early decisions shape years of legal and regulatory outcomes;
- Why credibility and communication define stakeholder trust;
- How organizations can sustain recovery through good governance and coordination.
Anatomy of a Breach Series
In this three-part series, ISMG asks security leaders and legal professionals to break down the key steps for breach readiness, incident response and remediation, and dealing with long-term legal and regulatory fallout. Episode 1 features experts on preparedness from Equifax and Rapid7. Episode 2 focuses on incident response.
About the Speakers
Olson is responsible for managing the Blackbaud’s legal activities, including SEC compliance, corporate transactions, enterprise governance and risk management, litigation and intellectual property matters. Prior to joining Blackbaud in September 2008, he was an attorney with Alcatel-Lucent and served in legal roles with MCI, Unisys and in private practice.
Raether leads the privacy and cyber team at Troutman Pepper and is a partner in the firm’s Consumer Financial Services Practice Group. He has helped companies navigate federal and state privacy laws for nearly 30 years. His understanding of technology – including his experience with data security, data privacy, patent, antitrust and licensing and contracts – allows him to be involved in legal issues that cross normal law firm boundaries.

