Wait on That Present: Firms Face Difficult Season With Holiday Hackers
Speed is critical for law firms in the cyber incident response business, but the holidays can present some unique challenges to attorneys and clients alike as they attempt to combat opportunistic hackers.
December 03, 2019 at 09:30 AM
4 minute read
While everyone else is hanging their stockings by the chimney with care this Christmas, response teams at law firms across the country may be busy checking their emails and voice messages for news of an errant cyber incident.
Many of those practices have been developed to respond to a breach, ransomware or other intrusion at the drop of a hat, 365 days a year. Holidays, however, may be like red meat to bad actors looking to capitalize on corporate vacations and an influx of financial (aka shopping) activity, all the while posing some unique logistical challenges to the attorneys tasked with responding.
"Holidays tend to be the biggest time [for cyber incidents] because the thinking is that the security teams are not at their computers — they are home. IT people aren't there to see weird stuff happening," said Christopher Ballod, a partner with Lewis Brisbois Bisgaard & Smith.
He noted there tends to be a big spike in cyber incidents in the week leading up to Christmas, which then trails off as the calendar approaches New Year's Day (even hackers need vacations).
What this means for privacy and cybersecurity teams varies from law firm to law firm. Ballod, for instance, indicated that Lewis Brisbois tends to beef up the number of responders on call over the holidays.
The resources that are needed run the gamut from bodies monitoring inquiries that come in over email or telephone lines to people who can run the necessary conflict check required before a lawyer can officially take on the case.
"It's like an arms race with incident response. If you can't respond in 15 minutes with 'conflicts are clear and we're ready to jump on a call,' you're really not that helpful to the people who are in crisis," Ballod said.
Still, rapid-response time isn't exactly an alien concept to law firms. DLA Piper, for example, has two attorneys on call every weekend to handle any cyber incidents that clients may bring to their doorstep.
Jim Harper, co-chairman of the firm's global cybersecurity practice, doesn't expect to make any changes in anticipation of the holiday season.
To be sure, not all firms are anticipating a bundle of yuletide cyber fires.
Christopher Hart, co-chairman of the privacy and cybersecurity group at Foley Hoag, has noticed an uptick in the number of incidents that tend to occur this time of year, but indicated that he would be surprised to receive any calls over the Christmas holiday since most clients will be away from their desks.
Those absences can make it difficult to organize an effective and quick response even if a cyber incident is brought to the attention of an attorney. For example, while many organizations may have put a breach response plan in place, Hart has yet to see one that specifically accounts for the holidays and the ensuing absence of key decision-makers.
"It is harder. … Clients themselves want to take their own vacations," Hart said.
It's not just the corporate vice presidents who may be off singing Christmas carols in parts unknown. Other key partners that law firms may rely on in the aftermath of a cyber incident—vendors such as forensics companies—may be experiencing their own holiday-related slowdowns.
"When they try and get the resources they need, sometimes that just isn't available to them. So it's really a ballet that we have to orchestrate all while staying completely calm for the client," Ballod of Lewis Brisbois said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllLaw Firms Mentioned
Trending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250