With Remote Working, Legal Departments May Be Addressing Cybersecurity on Multiple Fronts
The prevalence of remote working could be changing the way that some corporate legal departments and their organizations think about cybersecurity, but that also means reevaluating privacy and data protection risks as well.
June 17, 2020 at 03:20 PM
3 minute read
While remote working certainly isn't a novel phenomenon, the COVID-19 pandemic caused the scale of workers conducting business from home to build sizably, a trend that may not even completely reverse itself once shutdowns have lifted. The implication for corporate legal departments likely won't be a complete cybersecurity overhaul, but instead a very deliberate reexamination of how they are protecting their networks and evaluating data privacy risks.
Ken Jenkins, principal and founder of the cybersecurity solutions provider EmberSec, had previously told Corporate Counsel that one of his clients had begun to focus more on securing the organization's endpoints than the corporate office. But such an undertaking is also not without its complications.
"The threat obviously is that your corporate enterprise still has solutions that need to be secure and while you are in transition and trying to figure that out, your attack surface remains, right?" Jenkins said.
Of course, just how far along a given company is in that transition will likely vary from organization to organization. But Christopher Ballod, vice chairman of the data privacy and cybersecurity practice at Lewis Brisbois Bisgaard & Smith, noted that while the gradual shift to remote working predates COVID-19, many corporate legal departments and businesses were likely not prepared for huge portions of the enterprise to swing in that direction all at once.
For many organizations, the overall urgency of the requisite cybersecurity adjustments can become a question of risk, balancing not only the health of the network but repercussions stemming from data privacy laws such as the General Data Protection Regulation or the California Consumer Privacy Act.
Ballod explained that corporate legal departments are emphasizing those risks even as some companies continue to prioritize business continuity. "So I'm seeing that people have sounded the alert or at least are aware that, 'Look, if our data goes out the door, we have legal obligations, potential liability and brand dilution and other risks,'" Ballod said.
Those considerations may continue to present themselves as companies mull new security measures to put into place around remote working. Dyann Heward-Mills, CEO of the data protection office HewardMills, indicated that it would be wise for organizations to perform data risk assessments around new security technologies or processes being implemented.
The object is to document the process in the event that it falls under regulatory scrutiny. "If there is a failure somewhere or an incident or a breach, at least there is the audit trail in evidence that the risks were properly assessed, they were documented, they were escalated and mitigated," Heward-Mills said.
But what systems specifically might corporate legal departments be looking at to help drive security in the age of remote working? Christopher Zegers, director of consulting services, legal at Ivionics, said that legal departments who have embraced document management systems are in a much better position than those where attaching files to email is still the practice in vogue.
He argued that having a central data location as opposed to employees saving a document to their personal drive or email accounts can prevent sensitive data from circulating and duplicating. But many legal departments may have some work yet to do in that area.
"There's still a lot out there that haven't gotten there yet," Zegers said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllPorsche's Venture Capital Arm Adds General Counsel From Clifford Chance
How a 200,000-Worker Global Enterprise Took Down the Silos and Made ESG Its Mission
4 minute readCorporate Counsel's 2024 Award Winners Performed Legal Wizardry, Gave a Hand Up to Others
'We’re Here to Empower People to Make Good Decisions': Why Compliance Chiefs Must Learn to Think Like a Businessperson
Law Firms Mentioned
Trending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250