Corporate Counsel
  • Home
  • News
  • Surveys
  • Resources
  • Lawjobs
  • Advertise
  • Subscribe
  • Bookstore
  • Contact

Topics » IP Insider | Labor & Employment | From the Experts | On the Job | Moves | DC Watch | International

Home > Making Choices to Protect Against Trade Secret Theft

Font Size: increase font decrease font

Making Choices to Protect Against Trade Secret Theft

By Catherine Dunn Contact All Articles 

Corporate Counsel

March 14, 2013

  •    
  •    
  •    
  •      
 
Michael Chertoff

Michael Chertoff

Related Items

  • Employees May Be a Company's Greatest Cybersecurity Vulnerability

As corporations face a growing litany of threats to their networks and precious trade secrets, former U.S. Department of Homeland Security Secretary Michael Chertoff has this piece of advice for the C-suite: “What you really want to ask yourself is, What do I want to protect?”

Chertoff, now senior of counsel at Covington & Burling, delivered his words of wisdom on preventing corporate espionage at a firm panel discussion entitled, “Employee Trade Secret Theft: The Threat from Within.” During the same week when senior U.S. officials sounded further alarms on cyber attacks, the former cabinet member said CEOs and boards can’t simply view cybersecurity as a “technical problem.”

“In reality, decisions about cybersecurity involve profound questions of policy and governance—who gets access, what kind of devices are allowed in the network, what deserves the most protection, and what deserves less protection—that strike at the very heart of business decision making,” Chertoff said at the event, which was held in New York City.

But it’s not only digital intrusions that can threaten the sanctity of a company’s business processes, negotiating positions, research information, and other trade secrets.

“Good, old-fashioned spying and thievery remain still very important,” Chertoff emphasized. Last month, the White House released a report [PDF] outlining its strategy for mitigating the theft of U.S. trade secrets, which included examples of employee theft from companies such as DuPont, General Motors, Cargill, and Dow Chemical.

Chertoff added that safeguarding corporate secrets is a balancing act between, “what is the most cost-effective and least oppressive way to safeguard the most critical assets.” The assets that need to be most protected will differ in every organization, Chertoff said. And he cautioned that trade secret theft isn’t limited to any one industry.

“We’ve seen a wide variety of the kinds of data and information that are being extricated,” he said. “It is simply not true to believe that only high-tech companies are victims of this.”

As corporations determine just what they need to protect, they’ll also want to plan a holistic approach to information security, according to Covington attorneys.

Inadvertent actions by employees can easily jeopardize trade secrets. Among the most common threats are spear phishing (in which employees unknowingly open or download malware) and use of thumb drives, which can infect a company’s network. “Both of these are just employees not paying attention to what they’re doing,” said Washington, D.C.-based partner David Fagan.

The sharing of seemingly innocuous work details on Facebook or Twitter can also put trade secrets at risk. “We see a lot of inadvertent disclosures of private or sensitive” data through social media, said Lindsey Tonsager, an associate in the firm’s privacy and data security practice in Washington, D.C.

The attorneys also recommended reviewing company policies with an eye toward mitigating trade secret risk, such as “what controls you need to put in place for a particular individual when they’re leaving” the company, Fagan said.

While companies commonly have policies around hiring employees, he said, “what we’ve observed is fewer companies have as organized an approach in off-boarding people.”

The ability to bring your own device to work also “raises all sorts of complicated issues that have an effect on trade secrets,” Tonsager said. One policy consideration here, for example, is to make sure employees are on notice that the company can remote-locate or remote-wipe a lost device that may contain sensitive information.

Partner Richard Shea, who chairs Covington’s employee benefits and executive compensation practice, said employers should give employees advance notice with regards to privacy expectations. “You need to tell them whether they have an expectation of privacy or do not have an expectation of privacy in their use of company computers, in their use of networks, their use of email,” he said.

Providing such notice is, in part, a warning to employees, Shea said. But, in a more positive light, it also helps create an “ethos of compliance,” he said.

If employees understand that the company’s viability, and their job, “depends on protecting critical assets from being stolen or accidentally released,” Shea said, “everybody would cooperate.”



Subscribe to Corporate Counsel

You must be signed in to comment on an article

Find similar content

Firms mentioned

    
  • Covington & Burling

Companies, agencies mentioned

    
  • Cargill Inc.
  • General Motors Company
  • The Dow Chemical Company
  • United States Department of Homeland Security

Key categories

    
  • Information Security

Most viewed stories

    
  1. Best Legal Departments 2013
    •      
  2. 6 Things In-House Counsel Must Know About E-Discovery
    •      
  3. Bloomberg Names Compliance Chief After Client Data Breach
    •      
  4. 3-D Printing: The Next Big Thing in IP Law?
    •      
  5. Bristol-Myers Squibb: The Caped Crusaders
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Three Strategies for Reducing Class Action Costs

Managing Relationships With Legal Project Management

News Corp. Hires Ex-Skadden Communications Chief Bush

Law Firm Leaders' Confidence Slipping, Says Survey

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

LegalTech West Coast to Kick Off With 'Tech Audit' Keynote

Stanford Law Builds on Role as Legal Tech Incubator

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Rothstein Bankruptcy Trustee Files New Reorganization Plan
  •      
    • Subscription Required

Fla. Bar Wants Disbarment for Former Judge
  •      
    • Subscription Required

Bar Candidate Quits N.Y. Job To Satisfy N.J. Practice Bylaw

Pro Bono Work Proposed as Condition for Bar Admission
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Court Officials Seek to Reform Process of Naming Acting Justices

NYC Defends Police Department's Use of Stop-and-Frisk

Immigrant Investor Program Gets Watchful Eye

Judge Orders Parties to Hire Neutral Expert to Probe Facebook

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Water Warriors: Local Governments Bring Pollution Suits
  •      
    • Subscription Required

Sanction Reversed; Filing of Sexually Explicit Chat OKd
  •      
    • Subscription Required

Lenders Win On Foreclosures
  •      
    • Subscription Required

Justices: Doc Interviews With Defense Are Attorney Work Product
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media