What In-House Lawyers Can Learn From the Cyberattack on DLA Piper
Threats of a cyberattack are very real, as proven time and time again, most recently with this week's ransomware attack at DLA Piper.Attorneys…
July 05, 2017 at 07:32 AM
4 minute read
The original version of this story was published on Law.com
Threats of a cyberattack are very real, as proven time and time again, most recently with this week's ransomware attack at DLA Piper.
Attorneys who work on cybersecurity and as well as experts in the field acknowledged the severity of this week's breach and said that in-house lawyers need to be more cautious than ever about securing their information. That includes the data companies share with vendors and outside counsel.
Larry Ponemon is chairman and founder of research think tank the Ponemon Institute, which specializes in data protection. He has worked with DLA Piper as a consultant in the past and considers its data privacy and security measures to be “very good.”
“From my experience, it's an excellent firm with reasonable due diligence procedures,” Ponemon said. “This tells me … this could happen to anyone.”
A DLA Piper spokesman did not immediately respond for comment but in a June 27 statement, the firm said it was working closely with leading external forensic experts and relevant authorities, including the FBI and the U.K.'s National Crime Agency. “We are working to bring our systems safely back online,” the statement said.
Ponemon did not comment directly on DLA Piper's breach but said in general that in-house counsel and law firms need to encrypt all email communications whenever possible. He recommended avoiding email attachments for documents with sensitive data. Instead, he suggested, they should use data sharing document tools. “The ones that are free are not very secure,” he warned, adding that those that cost money are usually more effective.
A report released this week by IT security provider LogicForce found 40 percent of law firms were breached in 2016 without knowing it.
John Sweeney, president of LogicForce, called this number “scary,” and said firms and in-house lawyers “have to take into consideration the fact that lawyers have an ethical obligation to protect a client's data.”
On the other hand, he believes firms are trying. “I don't think there's a law firm that doesn't have policies in place and isn't training their people,” he said.
Sweeney recommends that in-house counsel have a solid auditing process in place for their law firms—in which they ask tough questions to keep them accountable. “If you're not doing the right things, shame on you,” Sweeney said. “If I'm the CEO of IBM and I entrust IP for Watson to a big or small IP firm, think about if it got stolen what the impact would be. These are very serious issues.”
Sweeney knows that no company or law firm is immune to cyber threats, but said that “law firms have to realize they are in the IT management business whether they want to be or not.” He said because firms are holding onto companies' trade secrets, intellectual property or even M&A activity dealings, “law firms are definitely a highly targeted industry.”
Behnam Dayanim, a partner with Paul Hastings, advised that in-house counsel monitor vendors and law firms with which they share information. But he said there is some leeway: They should prioritize how sensitive the data is that they are sharing with each firm and audit accordingly.
Collin Hite, an attorney at Hirschler Fleischer, said these types of conversations about cyber risk assessments need to occur “at least yearly.”
“This is not a 'fix what you need, put it on a shelf and forget it' scenario,” Hite noted. “It needs to be reviewed, tested, updated on a regular basis.”
Having the best technology isn't a foolproof plan, though. Employees need to be properly trained, according to Hite.
“Make sure your law firm is keeping up, because as we've seen this week, the criminals are using new vectors of attack. You can have the best software, the best information security officer, but if an employee clicks on a phishing email, all bets are off,” he said.
He added: “It doesn't matter if it's a multinational Am Law 50 firm or a five-person boutique down the street. If you're not viewing the situation from a holistic risk management viewpoint, you're missing the boat.”
Contact Stephanie Forshee at [email protected]
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllFatal Shooting of CEO Sets Off Scramble to Reassess Executive Security
5 minute readBen & Jerry’s Accuses Corporate Parent of ‘Silencing’ Support for Palestinian Rights
3 minute readShareholder Activists Poised to Pounce in 2025. Is Your Board Ready?
Regulatory Upheaval Is Coming. How Businesses Prepare and Respond Will Separate Winners and Losers
Trending Stories
- 1'Largest Retail Data Breach in History'? Hot Topic and Affiliated Brands Sued for Alleged Failure to Prevent Data Breach Linked to Snowflake Software
- 2Former President of New York State Bar, and the New York Bar Foundation, Dies As He Entered 70th Year as Attorney
- 3Legal Advocates in Uproar Upon Release of Footage Showing CO's Beat Black Inmate Before His Death
- 4Longtime Baker & Hostetler Partner, Former White House Counsel David Rivkin Dies at 68
- 5Court System Seeks Public Comment on E-Filing for Annual Report
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250