Transforming Law Firm Culture to Ensure Information Security
Changing the culture of law firms when it comes to information security has less to do with age and generational differences and more to do with acknowledging and accepting the current environment.
January 17, 2019 at 07:00 AM
5 minute read
Lawyers handle some of the most sensitive documents and communications imaginable, and yet law firm culture does not adapt well to the rapid changes in technology that define the world today. American law is built on precedent, where wisdom finds roots in stare decisis, so by nature, the mindset of lawyers is to embrace history for guidance and resist change. But those days are gone. It is time for law firms to transform their culture to ensure information security in a modern age.
Attorneys born prior to 1967 grew up in a time when the words Internet and Internet Protocol (IP) did not exist. Theirs was a paper world driven manually via word processors, copy machines and faxes. They dictated letters and legal briefs that were transcribed by legal secretaries and word processing departments. Documents were hole-punched and fastened into folders and stored in fire-proof metal file cabinets located non-securely throughout the office. Closed files were boxed up and manually delivered to closed storage facilities in some warehouse.
Over the last two decades, everything has changed for lawyers and their firms. The internet, email, smartphones, text messages, and other electronic communications now demand our attention. Ethical requirements and government regulations demand that sensitive information be protected from breaches (hacks) and inadvertent electronic disclosure. Changing the culture of law firms when it comes to information security has less to do with age and generational differences and more to do with acknowledging and accepting the current environment.
In the 2019 world, 6.2 billion people have internet access and two-thirds of the world have mobile-phone connections. Trillions of dollars are transferred online daily, from Swift transfers to PayPal and bitcoin and bank card information being omnipresent. Virtually all confidential client information is stored on hard drives or in clouds and communicated digitally via emails, flash drives, and numerous sharing protocols like Dropbox and Google Docs. As protectors of a free society's confidences, secrets, and intellectual properties, it is time for law firm culture to be transformed so that all lawyers become the technology leaders of the future
Generational differences aside, the ABA, state bar associations, and governmental agencies today demand that all attorneys become knowledgeable in protecting sensitive information. Stare decisis-thinking does not apply to communications in a modern age. Law firms of all sizes must recognize their risks and commit to understanding new and developing technology, as they inexorably impact every aspect of legal business today. No client relation can exist without it. And no law firm can allow itself to be viewed as a dinosaur from a past era.
The drums are beating loudly, by now all lawyers should know that ABA's Rule 1.1 requires a lawyer to be knowledgeable, competent, thorough, and prepared as to cases undertaken. Comment 6 obligates a lawyer “to keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology, engage in continuing study and education and comply with all continuing legal education requirements to which the lawyer is subject.” Today, over 30 state bar associations have adopted similar requirements, but bar mandate requirements should not drive a law firm's commitment to protect data, firms must incorporate technology competence and information security as part of their brands.
Every week a new data breach impacting millions of users hits the headlines. Facebook's quagmire with Cambridge Analytica on the 2016 elections, Marriott's acquisition of an elite hotel chain whose database came with an undetected mega-virus, and all the retail outlets (Macys, Kmart, Sears, Best Buy, Sax Fifth Avenue) that were viciously hacked in 2018 put law firm clients at the beachhead of the info security battlefield. But how can these companies feel secure in addressing their risks when their legal professionals are viewed as outdated dinosaurs?
To reach the same page as their clients, law firms and lawyers must embrace technology. A culture of minimal adequacy is not the way to forge the future and instill confidence. Though not required by any ABA ethical rules, encryption, differential sharing, differential access, color-coded privilege protection, cradle-to-grave monitoring of private and privileged information all must be incorporated into the fabric of every law firm.
Law firms need holistic security protocols and mindsets addressing security at every level. In a global world connected by the WWW, clients everywhere are using technology to provide products and services worldwide. And law firms are increasingly communicating with clients, experts, freelancers, virtual offices, and employees on an international stage.
The New Year has just arrived. Why not make your number one New Year's resolution the transformation of your law firm's culture to ensure the highest possible level of technological competence and information security?
Christopher C. Combs is the CEO of WindTalker, Inc., the developers of Distributed Sharing software that protects, redacts, and safely shares sensitive and privileged content for the lifecycle of the document. WindTalker's patented technology provides one central place to manage document, data and content security. The company was founded in 2016 and is based in Atlanta, Georgia. Michael Lester is the CTO for WindTalker, Inc. Mike has worked in the Information Systems industry for over 20 years as a consultant, instructor, and author. He has written books and courses on Information Security, Digital Forensics, Encryption, and Penetration Testing, and has taught courses in almost every state in the US, often at military bases.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250