


I recently heard a prediction that by 2023 a cyber breach would occur every eleven seconds! I do not know if this has come to fruition over half-way through 2023, but as a law firm Director, with responsibility for managing e-discovery and document review services for our clients, this does not surprise me, and it also alarms me. It makes me realize the importance of law firms’ diligent attention to cyber security issues in order to build and maintain trust with clients.
Protecting Sensitive Client Information in Discovery
You might be wondering, why is cyber security such a big deal for a law firm? Well, law firms come into possession of a lot of client files when representing companies in litigation or other capacities. Those files may contain sensitive information, like personally identifiable information (PII), company trade secrets, and even personal health information (PHI). Inadvertent disclosure of this information can be extremely damaging and costly and may also violate certain laws. As recently as June 2023, an attorney was sanctioned by a Court in Nevada for, among other violations, failing to redact personally identifiable information (multiple birth dates and the name of a minor child) in public court filings. The attorney was fined $3,000 for this redaction failure (see Davis v. Clark Cnty. Sch. Dist., 2:11-cv-01896-JAD-NJK (D. Nev. June 16, 2023)).
When it comes to protecting sensitive information, the requirements are pretty straightforward, given the various–and evolving-federal, state, and even international, laws that address data protection requirements. In the e-discovery context, this presents a requirement for the law firm handling the e-discovery–or directing an e-discovery vendor-to ensure sensitive information is identified and redacted. It is important to leverage technology that can help identify various forms of PII and PHI and redact it, thereby ensuring against sanctions and properly protecting client information.
Raising awareness among law firm attorneys regarding the need to identify and redact sensitive client information is key. Drafting e-discovery review protocols that include directions on how to handle sensitive information and having process checks to confirm that sensitive information is redacted prior to production ensure client data is properly protected.
A New Law Firm Role
But e-discovery is not the only area in which a law firm encounters cyber security challenges. Law firms routinely receive sensitive client information related to, say, mergers and acquisitions. As you have probably read, the holding of sensitive information by their law firms is something to which General Counsel are keenly attuned. As a result, law firms find themselves routinely responding to security questionnaires from clients conducting due diligence to be sure their company information is properly secured in the law firm environment. This focus on security requirements by clients has led to new technology, new certifications, and a new function in the law firm.
Indeed, law firms are hiring cyber security professionals to help with managing client cyber security requirements. These are positions that did not exist a dozen years ago. A recent google search showed 13,000 legal cyber security jobs posted on LinkedIn. These law firm cyber security team members use various, often cutting-edge, technologies (representing new law firm spend) to monitor data flow into, within, and out of the law firm as part of the vigilant effort to protect against cyber breaches and maintain the security of client files.
“A law firm that is aware and proactive about cyber security can build trust with their clients and differentiate themselves from competitors.”
Law firms proactively addressing cyber security may also be relying more heavily on the information governance professional to oversee the intake, secure storage, secure access, and proper disposition of client files. This administrative role is key to a law firm’s proactive cyber security program.
A Law Firm Cyber Security Awareness Team
Having cyber professionals and a strong information governance program is not enough, however. Many law firms have received certifications and regularly undergo security audits to comply with external security certifications and client mandates. Often, as a requirement for maintaining these security credentials, a Cyber Security Committee is formed to routinely review information security data and address security compliance within the law firm. They may also develop protocols around security issues, such as those for data encryption and remote work.
Training is always an opportunity, but in the cyber security context, it is a requirement. Educating employees to raise awareness of various scams and ‘phishing’ attempts that might result in a cyber breach is critical, as is monitoring participation in the training. This is true for any business in the 21st century, not just law firms.
The cyber security team is also involved in vetting other technology solutions being introduced to the law firm. For example, as I evaluate any technology platform, a part of the due diligence that must be conducted before bringing the technology into the firm – whether it is behind our firewall or in the cloud – is the security evaluation. This includes understanding a myriad of information that is all directed at ensuring our data, and by extension our client’s data, is secured.
Law Firm Services Related to Cyber Security
Of course, cyber security concerns and processes are not unique to law firms. Our clients face similar challenges and requirements around cyber security. Those needs present an opportunity to the law firm. At a recent meeting of some of my law firm peers, nearly everyone in the room was working on a data breach review for a client. This means firms are able to leverage their expertise in e-discovery to assist clients in identifying sensitive information exfiltrated during a breach. These data breach reviews are often very time-sensitive due to the various notification laws in place and require a rapid response time, e-discovery processes, technology, and expertise, in conjunction with lawyer expertise regarding data breach notification laws and negotiation with breach offenders, provide law firms with a unique opportunity to help clients in these unfortunate situations.
Data breach review is not, of course, the only opportunity. It is not uncommon for law firms to offer entire practice advisory services around cyber security. Such legal services might include offering legal guidance on a company’s data privacy compliance efforts, negotiating various vendor contracts to ensure security and privacy considerations are addressed favorably for the client, maintaining awareness of various national and international privacy laws, helping craft privacy and security policies, and cyber incident response planning.
While cyber security presents varied challenges and certain requirements for law firms, it is also another opportunity for law firms and their clients to collaborate. A law firm that is aware and proactive about cyber security, as described above, can build trust with their clients and differentiate themselves from competitors. A win-win for all.