top of page

Search Results

Search this site

174 results found with an empty search

  • Cost of a Data Breach for the Legal Department: Part 2

    February 27, 2019 Six months ago, we wrote about the prevalence and cost of data breaches and looked at some expensive examples of cyber-crime in the legal sector. We cited The World Economic Forum’s 2018 Global Risks Report which reported that in terms of likelihood, Cyber attacks and Data Fraud or Theft fell 3rd and 4th in international risks facing businesses, both rating at around 4 out of 5. This was alarming, although not particularly surprising, particularly within Corporate Legal Departments and Legal Operations. In 2018 Information Security stopped being a suggestion. Many companies are still adjusting to the compliance requirements and subsequent international impact of the General Data Protection Regulation (GDPR) which became enforceable on May 25th of this year, as well as the wave of data transparency and breach legislation across the US. In 2018, Information Security stopped being a suggestion. 16 years after California enacted the first mandatory breach notification law, all 50 U.S. states have now enacted their own breach notification laws. In addition, 2018 was a big year for regulatory oversight of Outsourcing Risk Management programs. From California’s Consumer Privacy Act (CCPA) and Colorado’s HB18-1128 to Nebraska’s LB 757 and Alabama’s SB 318v, regulators and legislators made it clear that not only were companies required to maintain reasonable security practices and procedures, but that they must also flow down those obligations to their vendors and third parties. And it seems to have worked! The 2019 Global Risks Report (GRR) reported that in terms of likelihood, Cyber attacks and Data Fraud or Theft fell to 4th and 5th in international risks facing businesses, both rating under 4, at about 3.75 out of 5 (a 25% reduction!). It’s encouraging to see progress, and we can expect data security will continue to improve as long as we continue to as well. One thing the GRR does not consider in detail is third-party contribution to risk, and when we look at a more third-party risk focused survey, the results are far less complimentary. 59% of respondents reported a third party data breach in 2018, a steady increase from past years (56% in 2017, 49% in 2016). So why is third party risk increasing? The problem isn’t that companies are just ignoring third party risk, it’s that many expect a one-size-fits-all solution to vendor assessment, selection, onboarding, and management. This leaves compliance managers and department leads with 400 question assessments that neither their vendors want to spend time completing nor do they want to spend time reviewing. As more regulations are passed and pressure on companies to show proof of third-party oversight, generalized solutions won’t work anymore. Clients and vendors are both quickly getting overwhelmed and as manpower is delegated away to deal with the management demands, things slip through the cracks. Wise companies recognize the costly inefficiency of this method and have recognized the value of delegating specialized Vendor and Third Party Risk Management resources to departments such as Legal Operations. And others are catching on - almost 60% of institutions said they expect to increase their enterprise risk management budgets during the next three years. How to select the risk third party risk management platform? We wrote a quick piece on what to look for in your IT and software vendors and what 6 questions to ask to ensure that your data will be secure. Find out more about Counself Risk here and about how Counself handles security internally here. To see a demo or for more information, contact us here.

  • Safer in the cloud or on the ground? The importance of vendor cloud security.

    September 13, 2018 For legal professionals, moving to the cloud has lowered costs, increased operational efficiency, and expanded security control. For others, the increasing number of cyber breaches is a clear warning against becoming easy targets for hackers. In any case, the legal sector is a warehouse of sensitive and confidential data and necessary steps need to be taken to reduce risk, whether data is digital or physical. For offices that still operate primarily in hard-copy, there are well-known and widespread risks, from documents being left out and taken home, to faxes and scans sent to the wrong recipient. In a study done on 5 major industries, including the financial and governmental sectors, the combined percentage of data breaches due to physical loss, stationary device loss, and unintended disclosure ranged from 18.6% to 44.7%. Back in 2012, a survey done by Legal IT Professionals asking respondents whether they were willing to move key applications to the cloud showed that most responded with “overwhelming skepticism” with an almost-even split with 45% for and 46% against. In a more recent survey done by the International Legal Technology Association (ILTA) in 2017 however, the conversation seems to have changed from “maybe we will” to “when we will.” It reports that those surveyed predict that the adoption of cloud-based solutions is steadily increasing, rising from 51% in 2016 to 63% in 2017. Even for those whose primary networks are not cloud-based, it’s hard to find an organization that doesn’t employ cloud technology in some way, whether it’s using Dropbox to share files, or Office 365 to correspond with colleagues and clients. “54% of law departments specifically highlight the importance of external data security practices for their vendors.” The trend seems to be catching on in the legal industry, despite plenty of hesitance from law departments and law firms combined. The biggest concerns are regarding information security, which is understandable, considering the sobering statistics being reported. 1,579 data breaches were reported in 2017, at least 2.8 billion records were exposed in 2017 and 2018 alone, and $3.62 million averaged as the total cost of a data breach in 2017. The CLOC reported that 66% of legal organizations stated that internal data security was a growing focus with 54% of law departments specifically highlighting the importance of external data security practices for their vendors. However, there is growing agreement that storing data on the cloud is better than on the ground. “Using the cloud is safe, as long as legal organizations do their due diligence.” Storing information in the cloud is a risk mitigator for protecting against natural disasters, with backups enabling system restores within minutes. Decreasing need for in-house servers and secondary datacenters, companies and firms can reduce hardware costs and better plan for disaster recovery. Not to mention the increased security measures cloud-based systems enforce, from role-based access control to multi-factor authentication to compliance reports and logs. There’s no question that cloud-based applications also improve efficiency and increase productivity, enabling attorneys and employees to work from anywhere and through various devices. Many state bar associations (such as Massachusetts and California), have concluded that using the cloud is safe, as long as legal organizations do their due diligence. Due Diligence is the key to how you can protect yourself. With increasing pressure on the legal industry to do all they can to protect their information, law departments and firms alike, everyone really, needs to carefully select and thoroughly vet their third-party cloud providers and vendors to ensure they can provide proof that they process, and store data using best practices and hold verifiable certifications and accreditations. Wise companies and firms must turn to their technology partners and ensure that vendors’ information security policies and processes align with their own security and compliance objectives as well as those of their clients and partners. No one can afford to assume their third-party providers have information security considerations in mind and data protection policies and procedures in place. Any vendor can claim to have secure environments to host data (and many do), but most lack verification. Why? Because it’s a lengthy and costly process to alter operations processes, achieve genuine certifications, and be recognized for it. But that’s not your concern – if vendors are handling your sensitive and critical information, you should insist on proof of compliance and specify security requirements in your vendor selection process. “Wise companies and firms must ensure that vendors’ information security policies and processes align with their own security and compliance objectives.” One trusted and rigorous certification is the ISO 27001:2013 standard designed for organizations in any industry but is particularly pertinent for SaaS vendors, especially those which operate in the cloud. It not only ensures that information is secured from a technical and organizational perspective, it requires guidelines and processes for managing risk and implementing controls that continuously test compliance. ISO 27001 requires management to systematically assess security risks and impacts, design, and implement controls to address potential vulnerabilities and to review and revise controls over time. Furthermore, verified certifications can only be attained through a rigorous 3 step auditing process performed over several months and re-verified annually by third-party accredited certification bodies recognized by government-authorized parties. Unfortunately, most vendors, particularly in the United States have not gone through the certification process and will often refer their prospects and clients to their cloud-service providers’ certifications, such as Microsoft or Amazon. This is highly misleading and risky, as those service providers only ensure the security of their own infrastructure, platforms, and software. Vendor software and data are not in the cloud-service providers’ ISO scopes. That’s why it is of the utmost importance to make sure your technology vendors carry their own certifications. So how can you tell? Start by asking all of your vendors these questions: Do you carry any security certifications, such as ISO 27001, and who is your certification body? What are your company-specific policies and procedures on information security? How often do you perform security risk assessments to identify and measure risks, and do you keep a log of security and risk incidents? What are your organization’s internal policies regarding user access and account security? How do you encrypt data at rest and in transit, and what kinds of controls and processes are in place for intrusion detection, monitoring, and threat detection? How often are vulnerability scans and penetration tests performed? How do you store and what is your retention policy regarding client data? How do you securely and permanently delete client data? Do you enforce your third-party partners and contractors to follow the same security and risk compliance measures, and how often are reviews of these contracts and partners performed?

  • Cost of a Data Breach for the Legal Department: Part 1

    August 9, 2018 In January 2018, The World Economic Forum published its Global Risks Report, finding that in terms of likelihood, Cyberattacks and Data Fraud or Theft fell 3rd and 4th in international risks facing businesses, both rating at around 4 out of 5 in corporate risk levels. Extreme Weather Events and Natural Disasters were the only two ahead on the list, but unlike environmental risks, technological ones can practically be managed and mitigated. The latest gold mine for hackers. The legal industry has particularly seen a stark increase in data breaches as cybercriminals realize the value of information they can tap into and how easy it often is to access. The industry has even been labeled “the latest gold mine for hackers.” This is because of the value of information circulated in the legal industry, and the easy access to client networks through firm networks. This can prove to be extremely damaging and the financial impact can compound into hundreds of millions of dollars, taking into account equipment replacement, regulatory fines, and lost business among other consequences. Third party involvement in a breach increases the cost. The Ponemon Institute's annual Cost of a Data Breach Study reported earlier this month that on average, the cost of a breach of at least 1,000 lost or stolen records rose a quarter of a million dollars, from $3.62M to $3.86M. Third party involvement in a breach increases the cost. If a third party caused the data breach, the cost increased by more than $13 per compromised record for an adjusted average cost of $161, up from $148 per record. Very few organizations can handle such costs, with major data breaches estimated to have average costs of $39 million -$350 million depending on the amount of data breached and the rate at which it was contained. For smaller organizations, a data breach can easily put them out of business. Devastating consequences. Let’s look at two examples of data breaches that had devastating consequences: In 2010, hackers instigated a massive attack on Canadian law firms, companies, and the government, successfully penetrating at least seven firms, including prominent firms Stikeman Elliot and Blake, Cassels & Graydon, in search of exclusive information on a takeover of the Potash Corporation. Daniel Tobok, who investigated these wide-spread attacks, stated that the attack was not only “very sophisticated and highly targeted” but that “nobody knew the severity of the issue or what was happening.” Not only were companies and firms targeted, but the cyber attack’s success in penetrating the Canadian government’s computers shut down all internet connections to the Finance Dept and Treasury Board and divisions of the Dept of National Defense, and almost a year later, all three departments still didn’t have full internet access. The consequent shut down of the deal cost nearly $40 Billion in the loss of the deal alone, with millions more in lost business and data. Even more infamous was the attack on Mossack Fonseca, the fourth largest offshore law firm, when more than 2.6 terabytes of information was stolen and nearly 11.5 million documents were leaked. An estimated $135 billion was wiped off of the value of nearly 400 companies after what was dubbed The Panama Papers incident, not to mention the massive fines and closures the firm faced. The information leaked led to numerous investigations, high-profile resignations, police raids and arrests, protests, and national legal reforms, amongst other consequences. According to Hannes Wagner of Milan’s Bocconi University, the financial hits to companies following the Panama Papers represents “the largest [overall] loss in history” following a data breach. Too many organizations are still employing a reactive stance than a proactive one. Despite more awareness of the prevalence and reality of attacks, too many organizations are still employing a reactive stance than a proactive one. For law departments and firms especially, it is too little, too late to ask for security certifications from technology vendors when a breach has already taken place. Cybersecurity consideration and preparedness must be sought and enforced from the onset, built into law department and firm technology acquisition processes and centralized in the same way other vendors due diligence processes are performed. Use ISO 27001 Certified, fully secure Counself Risk platform to send Due Diligence Requests to your vendors, create and circulate intelligent Forms that streamline the data collection process for you and your vendors, and maintain full audit histories and access security restrictions for ease of monitoring and maintenance. Please contact us here for more information.

  • InfiniGlobe Named Mitratech Certified Partner

    “Today, the role of the legal department is expanding across the organization,” said Mark Delgado, General Manager, EMEA & APAC, Mitratech.“Given that recent shift, it’s more important than ever that the right technology is in place. We look forward to working with InfiniGlobe to ensure client success.” As a Mitratech Certified Partner, InfiniGlobe is committed to assisting clients with new implementations, helping them understand and realize the benefits of their system, and advising others on how to advance and enhance existing solutions. The company’s experienced teams offer a broad range of matter management implementation and customization services, including project management, process analysis and system design, as well as data conversion, report writing, end-user training, and continued support. View the official press release here. About Mitratech Mitratech is a market-leading provider of legal, compliance and risk software solutions for more than 1,200 organizations of all sizes across the globe, representing almost 40 percent of the Fortune 500, and over 500,000 users in over 160 countries. Mitratech’s portfolio of enterprise legal and risk management software includes: legal matter management, spend management, eBilling, legal hold, contracts management, risk management, policy management, audit management and health & safety management. To learn more, visit mitratech.com. About InfiniGlobe InfiniGlobe LLC is a software technology and consulting company headquartered in Newport Beach, California, offering a broad range of professional services and software solutions for the legal industry. With decades of experience working in legal technologies and a prominent reputation of consistently and passionately helping clients solve their problems, the InfiniGlobe team enables Corporate Legal Departments and Law Firms alike to overcome the challenges and complexities of technology through simple, intuitive design solutions. At InfiniGlobe, we don’t believe in the finite – in what just works; we believe in the infinite – in purpose, collaboration, and achievement. To learn more, please visit infiniglobe.com.

bottom of page