GC of eHarmony Ronald Sarian Battles Cyberattacks With Knowledge, Careful Planning
Sarian emphasized that keeping up with the latest in cybersecurity can make all the difference in stopping the next attack.
December 04, 2017 at 02:59 PM
4 minute read
It's often said that there are two types of companies: those that know they've been hacked and those that simply haven't realized it yet. Essentially, no company is immune from the risk of some kind of cybersecurity incident. And depending on the way a company handles breach response and messaging post-breach, recent incidents at companies such as Equifax Inc. and Uber Technologies Inc. highlight that the repercussions can be massive.
So how are in-house counsel handling this responsibility?
For eHarmony Inc. vice president and general counsel Ronald Sarian, a major part of the strategy is staying in the know about what types of attacks other companies are experiencing. Sarian, who joined the dating site as its legal boss in 2013, said on a panel on the first day of ALM's 2017 cyberSecure conference in New York City that this constant reading on latest developments actually thwarted a phishing attack at eHarmony.
|
➤➤ Sign up here for Inside Track, Law.com's new briefing on in-house lawyering.
About two years ago, Sarian said, scammers went after Snapchat by impersonating the tech company's chief executive officer and asking those in the payroll department for personal employee information. Sarian read about the successful attack and advised eHarmony colleagues to watch out for a similar incident.
The next day, according to Sarian, eHarmony's accounting department was targeted by an identical phishing attack in which scammers pretending to be eHarmony CEO Neil Clark Warren requested W-2s for salary review. But because of Sarian's warning, the accounting employees knew not to respond, he said.
Even more important, he added, is really knowing those in a company's IT department. With a background as a litigator, Sarian explained that he made a point when he moved in-house at eHarmony to sit down with the company's tech team and develop relationships with them. “They need to be comfortable when they're talking to you so that if they have anything that's even suspicious, they [aren't] scared of you and you don't want to be scared of them either,” Sarian said. “You want to be on the same wavelength.”
And then there's employee onboarding and offboarding, Sarian said. New employees should know, for instance, about what to look for, what to open and what not to open, he said. And when someone is leaving the company, he noted, it's important to have a system in place that immediately shuts off access to company systems and devices.
“You don't want a disgruntled employee coming in and trying to mess you up,” Sarian said. “Not giving them any advance notice that they're being terminated is a little bit harsh, but that's the only way to do it in the tech business, really. You just can't tell someone in advance, because they're going to start plotting against you, perhaps, and you're going to have some trouble.”
Just as important as incident prevention is reacting to incidents that occur, Sarian said, because having a good cyber response plan in place can go a long way in protecting a company's reputation.
“The first thing you have to do is figure out what the hell hit you … and then you make a disclosure to all your customers,” he said.
It's true that getting to the bottom of these incidents takes time, and quickly releasing inaccurate information and then later having to make corrections can damage a company's reputation, he explained, but sitting on a breach or trying to hide it will only make things worse when the information inevitably comes out.
“How you handle it after [an incident] occurs has a lot to do with how hard it's going to hit your company,” said Sarian.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllHealth Care Giants Sue FTC, Allege Lina Khan Using Loaded Process to Vilify Pharmacy Benefit Managers
3 minute readPorsche's Venture Capital Arm Adds General Counsel From Clifford Chance
How a 200,000-Worker Global Enterprise Took Down the Silos and Made ESG Its Mission
4 minute readCorporate Counsel's 2024 Award Winners Performed Legal Wizardry, Gave a Hand Up to Others
Trending Stories
- 1First California Zantac Jury Ends in Mistrial
- 2Democrats Give Up Circuit Court Picks for Trial Judges in Reported Deal with GOP
- 3Trump Taps Former Fla. Attorney General for AG
- 4Newsom Names Two Judges to Appellate Courts in San Francisco, Orange County
- 5Biden Has Few Ways to Protect His Environmental Legacy, Say Lawyers, Advocates
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250