3 New Responsibilities Legal IT Departments Face Because of Cyber Threats
IT departments in law firms must go beyond just having a continuity strategy in place to tackle IT downtime and cybersecurity.
February 12, 2018 at 08:00 AM
6 minute read
The legal industry has sensitive data in constant use, both for case proceedings and daily practice management, and for this reason their IT departments are often at the center of technology evolution. While this can be a good thing, it also means that law firms are particularly susceptible to cybersecurity incidents, since cybercriminals have increasingly come to view the legal industry as a big payout for cyberattacks.
IT departments in law firms must go beyond just having a continuity strategy in place to tackle IT downtime and cybersecurity. They must also be equipped to prove its effectiveness to their clients, auditors, and other stakeholders. The external and internal pressures of risk management have led to, and will continue to foster, a monumental shift within legal IT departments. Here are three new responsibilities that have arisen within IT teams, and what they mean to the future of legal practice.
1. Firms Must Integrate Cybersecurity Functions with IT Disaster Recovery Functions
Business continuity demands are becoming more similar than different from each other, since a cyberattack now tends to have the same impacts on IT availability and client reputation as a weather disaster. The rapid growth in cyber incidents means that the likelihood of a breach is now greater. This is why firms must formally begin considering security incidents as “disasters,” and IT teams must widen their perspective of what can take their business offline.
The realms of cybersecurity and IT disaster recovery (DR) have several similarities. Security professionals have long been known for their quick responsiveness to breach incidents and DR professionals are dedicated in their event reaction to avoiding data loss. The two groups, while historically in silos from each other, have a shared goal in meeting availability demands, and companies in many industries have noticed this commonality as a strength in building IT resiliency. We're seeing the lines of specialty blurred more and more, as the two groups are being asked to work together.
Proper risk mitigation demands a two-pronged approach: a balance of preventative and restorative measures.
It's a hard reality, but firm leadership must recognize that no matter the amount of money invested in cyber threat prevention, all it takes is one wrong click to invite an intrusion. For this reason, a restorative approach—i.e. a robust DR plan—must take equal precedence, if not more. And yet, it's the restorative aspects that are often lacking within law firms.
Disaster Recovery-as-a-Service (DRaaS) has long been used to solve for downtime and data loss. In these recent years, this solution has also emerged as a great way to achieve holistic IT availability, especially with cybersecurity and DR practices merged into a single plan. Since DRaaS has an established reputation as enabling a quick response to a variety of events, it's becoming increasingly popular among law firms.
2. Firms' IT Teams Are Now Responsible for Vendor Management
One growing trend that is affecting all legal departments is the use of third parties. The pay-as-you-go-for-what-you-use model of service for outsourced entities means that firms gain flexibility and a helping hand to tackle the challenges of the future. For IT departments, the biggest trend of outsourcing is that of the data center, since cloud computing has made it possible to offload this management to a third party. Since they no longer need to dedicate extensive resources to maintaining IT infrastructure, IT departments have now freed up bandwidth to refocus efforts on more pressing projects.
The problem with outsourcing is that, if not kept in check, third-party vendors could pose a major cybersecurity risk, since they're basically an extension of your firm and your firm's data. For this reason, many IT teams are being held responsible to manage the relationships between these vendors and ensure all IT systems, both on the firm's end and the vendor's end, are up to snuff.
3. To Truly Secure Technology, Firms Must Address Generational Gaps
Pat O'Day, CTO of Bluelock, predicts that the majority of cybersecurity incidents in 2018 will be a result of poorly-maintained legacy IT systems or poorly-implemented modern IT systems—a result of generational differences within IT teams.
As O'Day states, “Legacy in-house technology may not be up-to-par to compete against faster, more modern solutions. If this infrastructure is managed by an IT group entrenched in a traditional way of doing things, it could mean slower adaptation to emerging cybersecurity threats. Conversely, modern IT tools are often implemented and managed by a younger group that may never have experienced the full impact of an actual breach. Here, unfamiliarity on both sides is driving inadequate solutions.”
A disconnect in understanding and lack of communication creates the recipe for a security breach. When new technologies are implemented, how will they affect clients? If two law firms use Dropbox or Google Docs to share information on a mutual client, does the client know? What security risks could this pose? Adopting new technologies with the interest of greater convenience and winning a case may not always be the best choice in the long term.
The older generation must educate the younger generation of what can happen when technology goes wrong, since the younger generation may not have experience with breaches. Likewise, the younger generation must educate the older generation of what technologies exist that could drive efficiency. Then, the two groups must examine the pros and cons of new technology together, sharing with their unique perspectives. This cooperation will help IT teams agree upon the best course of action, which is the ticket to successful risk management.
Jeff Ton is executive vice president of product and service development for Bluelock where he is responsible for driving the company's product strategy and service vision and strategy. Ton has over 30 years of experience in business and information technology and previously served as CIO for Goodwill Industries of Central Indiana and Lauth Property Group.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Lawyer’s Resolutions: Focusing on 2025
- 2Houston Judge Exonerated on Appeal, Public Reprimand Vacated
- 3Bar Report - Dec. 30
- 4Employment Law Developments to Expect From the Second Trump Administration
- 5How I Made Law Firm Leadership: 'It’s Imperative That You Never Stop Learning,' Says Ian Ribald of Ballard Spahr
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250