As Cyber Attacks Proliferate, New Roundtable Promotes Women's Leadership in Cybersecurity
Bess Hinson of Nelson Mullins started the Atlanta Women in Cybersecurity Roundtable to encourage female leadership in the fast-growing field.
October 05, 2017 at 04:20 PM
7 minute read
Bess Hinson became a data privacy lawyer because she was concerned about the way in which people's data is being disseminated. Now, she has started the Atlanta Women in Cybersecurity Roundtable to help women advance in the fast-growing field.
“There is a tremendous opportunity for women to get involved,” said Hinson, an associate in the privacy and information security practice at Nelson, Mullins, Riley & Scarborough.
As cyber-attacks proliferate and intensify in severity—notably Equifax's announcement September 7 that hackers had accessed social security numbers and other personal and financial information from 145.5 million consumers—there is a growing shortage of executives qualified to handle business's data breach prevention and response activities.
Women make up only about 10 percent of the cybersecurity workforce, according to Cybersecurity Ventures and other trade groups. Hinson said this “disheartening” statistic was a major reason she started ATLWIC. The invitation-only group, whose members are women in charge of cybersecurity operations at their companies, will meet quarterly for lunch and discussion.
The first meeting late last month attracted 25 executives from Atlanta companies, including SunTrust, UPS, Cox Enterprises, Worldpay, Global Payments, Gwinnett Medical Center, Porsche Cars North America, Graphic Packaging and CareerBuilder. Hinson said the same number have already signed up for the next meeting.
The participants' titles vary, but they include chief information security officer, chief privacy officer, and general counsel, among others. About 60 percent of the group are lawyers, Hinson said.
To facilitate the free flow of information, all the participants sign an agreement that what's talked about at the roundtable stays at the roundtable.
Hinson hopes the luncheons will create an environment that encourages members to share ideas, educate each other and promote women's advancement in the rapidly growing cybersecurity field.
The Girl Scouts have announced they will start awarding cybersecurity badges next year, so Hinson invited the Girl Scouts of Greater Atlanta's CEO, Amy Dosik, to speak at the first roundtable. To earn a cybersecurity badge, young scouts will learn how computers and viruses work, how cyberhacks happen, and how to avoid hoaxes and scams.
The discussion topic at the first ATLWIC meeting was how a chief information security officer (CISO) works with in-house counsel to protect data and combat threats, Hinson said. The CISO is quickly becoming a permanent fixture at larger companies. About half of large companies had CISOs in 2016, and that's already increased to 65 percent, according to ISACA, an international professional association focused on IT governance.
Hinson said meeting participants also debated where companies are best off locating their cybersecurity department—under the purview of the GC, the CEO, or somewhere else?
“This really matters. If you don't have the right oversight, you may not get the [intrusion] report in a timely manner and find out about the issues,” she said.
For effective cybersecurity, people must communicate across all departments—the C-suite, IT, compliance, legal, the marketing department and areas that handle customer data, such as a financial institution's commercial loan department, she said.
“Information is everywhere about your customers, so you have to work together,” Hinson said.
Delivering Bad News
While being a female cybersecurity leader offers plenty of opportunity, it can be taxing in a predominantly male environment, Hinson said.
“One of the goals of the roundtable is to provide support,” she explained. “You may be the only one in the room delivering news to your company that they don't want to hear—and you have to deliver that as a female, which can present some challenges.”
The bad news could be a breach—or, more often—that the company needs to spend a lot more money on cybersecurity.
“It's not news that people necessarily want to hear—that their business isn't good enough in this area, they haven't taken sufficient precautions, and they need to come up with money to make it better,” she said.
The cost of setting up a cybersecurity infrastructure “is almost equivalent, if not worse,” to the budget increases companies had to make when they started setting up IT departments with the advent of computers, Hinson added.
“A lot of companies have not budgeted for cybersecurity,” Hinson said. “They may have cyber-liability insurance, but they're not thinking about hiring a cybersecurity officer to fully vet the vendors they are employing to assess threats and address gaps in security.”
Many of these vendors are forensic experts who are former NSA or military officers, she added. “A lot of that crowd is male.”
Companies often use lawyers, whether in-house or outside counsel, like Hinson, to oversee these vendors and make sure they are complying with legal and regulatory requirements. This also allows for attorney-client privilege, Hinson said.
At least 60 percent of Hinson's practice is breach response cases, but increasingly she's working with companies on the front end to build a strong threat-hunting program. In the event of a breach, a company's ability to show it has taken appropriate precautions to prevent hacks can be a mitigating factor in any ensuing litigation or government investigations.
“Every company is going to be breached,” Hinson added.
Brave New World
Hinson, 33, was in college when Facebook launched, and through her twenties she witnessed the proliferation of people sharing information via social media.
“The 'Brave New World' aspect captured my imagination, the way all this information could be collected about us online—much more than ever before—and be used for discriminatory purposes,” she said. “It got me thinking about what companies do with information, why they collect it and how we can protect ourselves.”
Initially, Hinson thought she would become a civil rights lawyer for cyberspace. While at the University of Michigan Law School, she interned at the Justice Department's civil rights division and at the Southern Poverty Law Center. But her focus shifted to the companies using the data.
“I think one of the reasons I love this practice so much is I truly feel I am helping our businesses and protecting our consumers,” she said. “Data is money these days.”
Hinson joined King & Spalding in 2013 following a federal clerkship. “I was very adamant about my interest in data security,” she said, noting that it was after the Target breach but before the Home Depot breach.
There Hinson worked on breach cases and class action defense with Phyllis Sumner, who heads King & Spalding's data security and privacy practice. (Sumner is representing Equifax in its data breach. Sumner also represented Home Depot in settlements to consumers over its 2014 data breach exposing up to 56 million card numbers.)
Even then, the concept of data breach litigation was fairly new, Hinson said. There were fewer law firms and partners who really focused on this area or paid it much attention, other than touting their experience with the Fair Credit Reporting Act—a law enacted in 1970 that governs credit reporting agencies and how they use consumer credit data.
Hackers are more sophisticated now, she said, and their intrusions go way beyond “point-of-sale breaches,” detecting data from cards as they're swiped, as in the Target case.
“Hackers are several steps ahead. I think breaches go undetected for longer,” she said.
In 2015, Hinson moved to Nelson Mullins to build her own data privacy and security practice. She was attracted to the firm because its rates and fees are more competitive for all different size companies, she said.
“Data security is an issue for the Fortune 50, but it's also the local juice shop or the government agency that collects our water payments,” she said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View All'Strategy, Brains, Creativity and Passion' Drive Lori Cohen of Greenberg Traurig
Hall Booth Smith Founder Uses Down Time to Pen Fictional Tales of Murder
4 minute readTrending Stories
- 1'Politically Destabilizing': Trump Lawyers Say NY Criminal Case Must be Dismissed
- 2DLA Piper Sued by 2 Houston Companies, Alleging a 'Fake Lawyer' Represented Them in Argentina
- 3Critical Mass With Law.com’s Amanda Bronstad: Schools Score Again in Suits Against Social Media, Johnson & Johnson Subsidiary Seeks Sanctions Over Andy Birchfield’s Deposition
- 4Southern District Refuses to Grant Summary Judgment Due to Lack of Documentary Evidence Demonstrating that Insured's Misrepresentations Were Material
- 5People in the News—Nov. 20, 2024—Rawle & Henderson, Panitch Schwarze
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250