Corporate Counsel
  • Home
  • News
  • Surveys
  • Resources
  • Lawjobs
  • Advertise
  • Subscribe
  • Bookstore
  • Contact

Topics » IP Insider | Labor & Employment | From the Experts | On the Job | Moves | DC Watch | International

Home > Survey of GCs Sees Cybersecurity Risk, Anxiety

Font Size: increase font decrease font

Survey of GCs Sees Cybersecurity Risk, Anxiety

By Sue Reisinger Contact All Articles 

Corporate Counsel

February 13, 2013

  •    
  •    
  •    
  •      
 
data_security

© maxkabakov - Fotolia.com

Paul Mandell

Paul Mandell

Despite the growing threat of computer security breaches, some 30 percent of general counsel in a recent survey said their companies were not prepared to deal with such a crisis. And experts say more GCs need to overcome their technophobia and help their firms face the increasing risk.

“Among the most fearsome threats facing corporations in 2012 was an increasing proliferation of cybersecurity breaches of various orders of complexity and impact,” according to the “2012 General Counsel Survey,” by global consultants Consero Group. The survey, produced in partnership with Applied Discovery Inc., is based on responses from 48 general counsel in December 2012.

“From terrorism to competitive attacks to random hacking, global businesses have their hands full keeping systems and data safe,” the report warned.

“Indeed, the stakes are high for general counsel in this area—particularly in highly regulated industries,” it said.

Some 28 percent of the GCs surveyed indicated that their companies had experienced a cybersecurity breach over the last 12 months. And that figure may be low.

“It’s safe to assume that a breach is a source of great anxiety and embarrassment for large companies. So there is a natural disinclination to report it,” explained attorney Paul Mandell, founder and chief executive of Consero. The group is located in Bethesda, Maryland.

“But cybersecurity was clearly a very hot topic and a source of concern for the general counsel,” Mandell added.

The theft of company data by employees is also a growing concern, Mandell said, and “there was quite a bit of discussion [among general counsel] about employees bringing their own devices [BYOD] to work. It’s a huge issue.”

So far there is very little understanding of what the best practices are in the BYOD area, he said.

Mandell explained that much of the anxiety about cybersecurity stems from “lawyers not generally being tech savvy by nature,” and the fact that no one has found a perfect solution for protecting data.

The report explained that a company’s GC also must be aware of international regulatory requirements regarding digital security, while ensuring compliance and addressing breaches when they result in litigation or government action.

The trend Mandell sees is for general counsel to increasingly explore the addition of tech-savvy attorneys, like those who handle intellectual property.

Stan Stahl, cofounder and president of Los Angeles-based Citidel Information Group, another cybersecurity consultant, said he’s not surprised that 30 percent of GCs say their companies are not prepared.

“We find the companies we go into are woefully unprepared” to deal with a cyber breach, Stahl said. “There is the misconception that firewalls and anti-viral programs protect everything, and that’s a myth.”

He also agreed that the 28 percent who reported security breaches might be low because “the incentives are to not report them.”

Stahl explained, “If you report a breach, your costs are going to be, say, about $200 per record, and you may have 1,000 people in your database. If you do not report that breach and don’t get caught, you can save yourself $200,000. So I would tend to think that a significant number of breaches go unreported.”

He concurred with Mandell that some of the problem is that top management, including the general counsel, does not understand how technology works. They have a tendency to simply send the problems to IT.

“The IT folks may know technology, but not necessarily security,” Stahl said. “Many attacks that come in today take advantage of human weaknesses, and not just weak technology.”

He gave the example of a payroll clerk who clicks on a link purporting to be from Facebook about her high school reunion. Instead, the link downloads malware onto the company computer system, traces her keystrokes, and allowes hundreds of thousands of dollars to be diverted from the company’s payroll account.

What can the GC do? The most important thing is to create an ongoing culture of cybersecurity best practices across the company. “It’s not like you can just get a flu shot and now you’re OK,” Stahl said. “It’s more like everyone has to diet and exercise every day.”

Stahl added, “Our motto is, it takes the village to secure the village.”

See also: "Obama announces cybersecurity executive order," The National Law Journal, February 2013.



Subscribe to Corporate Counsel

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • Counsel Corporation
  • Applied Discovery
  • Consero Group

Key categories

    
  • Corporate & Business Law
  • Corporate Governance and Compliance
  • Internet and Technology Law

Most viewed stories

    
  1. Safeguarding Brand Reputation In Social Media
    •      
  2. Another SEC Whistleblower, More On the Way
    •      
  3. Patent Board's SAP Ruling is First Under New AIA Rules
    •      
  4. Are GCs More Than Just Legally Trained Executives?
    •      
  5. What to Look for in a Board's Risk Director
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

In-House Counsel Go to Privacy Boot Camp

In-House Changes at News Corp Ahead of Corporate Split

Proskauer, Former CFO Settle Bias Suit

Global Firms Cope With Istanbul Unrest

D.C. Circuit Nominations a Defining Moment

D.C. Circuit Nominees Widely Respected Within the Bar

Nine Tips to Avoid Starring in a Spreadsheet Horror Story

Snapshot: Tom Gelbmann

The Recorder 25: California Golden Again for Many Firms
  •      
    • Subscription Required

Capital Accounts: Judicial Branch's Brothers Don't See Eye to Eye
  •      
    • Subscription Required

Miami Photographer Sues Pop Star Justin Bieber
  •      
    • Subscription Required

Jeremy Alters Settles With Argentinian Firm For $1 Million
  •      
    • Subscription Required

Alcotest Should Be Discontinued Right Away, DWI Lawyers Say

Lawyer's Fudging of HUD Forms Draws Supreme Court Censure
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Restaurant in Union Square Park Ruled Permissible
  •      
    • Subscription Required

Magistrate Judge Finds Few Benefits to Class in Settlement
  •      
    • Subscription Required

Third Circuit Could See Rise in Pay-for-Delay Litigation

Cozen Debt Forgiveness Is Campaign Contribution, Court Says
  •      
    • Subscription Required

Sorry, Charlie, Your Wife Won't Support You

Top Reasons to Take Your Husband's Name

Interim Dean Named at Texas Wesleyan University School of Law
  •      
    • Subscription Required

Water Works: H2O Kept Lawyer-Lobbyists Busy
  •      
    • Subscription Required

Fighting Over The Fifth
  •      
    • Subscription Required

Atlanta School Defendants Rely On New Jersey Officers' Case
  •      
    • Subscription Required

Chimp Attack Victim Is Denied $150M State Lawsuit

Auto Body Case May Lead To CUTPA Reassessment

  • About Corporate Counsel   |
  • Contact Corporate Counsel   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy (updated 6/14/13) |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media