Corporate Counsel
  • Home
  • News
  • Surveys
  • Resources
  • Lawjobs
  • Advertise
  • Subscribe
  • Bookstore
  • Contact

Topics » IP Insider | Labor & Employment | From the Experts | On the Job | Moves | DC Watch | International

Home > Making Choices to Protect Against Trade Secret Theft

Font Size: increase font decrease font

Making Choices to Protect Against Trade Secret Theft

By Catherine Dunn Contact All Articles 

Corporate Counsel

March 14, 2013

  •    
  •    
  •    
  •      
 
Michael Chertoff

Michael Chertoff

Related Items

  • Employees May Be a Company's Greatest Cybersecurity Vulnerability

As corporations face a growing litany of threats to their networks and precious trade secrets, former U.S. Department of Homeland Security Secretary Michael Chertoff has this piece of advice for the C-suite: “What you really want to ask yourself is, What do I want to protect?”

Chertoff, now senior of counsel at Covington & Burling, delivered his words of wisdom on preventing corporate espionage at a firm panel discussion entitled, “Employee Trade Secret Theft: The Threat from Within.” During the same week when senior U.S. officials sounded further alarms on cyber attacks, the former cabinet member said CEOs and boards can’t simply view cybersecurity as a “technical problem.”

“In reality, decisions about cybersecurity involve profound questions of policy and governance—who gets access, what kind of devices are allowed in the network, what deserves the most protection, and what deserves less protection—that strike at the very heart of business decision making,” Chertoff said at the event, which was held in New York City.

But it’s not only digital intrusions that can threaten the sanctity of a company’s business processes, negotiating positions, research information, and other trade secrets.

“Good, old-fashioned spying and thievery remain still very important,” Chertoff emphasized. Last month, the White House released a report [PDF] outlining its strategy for mitigating the theft of U.S. trade secrets, which included examples of employee theft from companies such as DuPont, General Motors, Cargill, and Dow Chemical.

Chertoff added that safeguarding corporate secrets is a balancing act between, “what is the most cost-effective and least oppressive way to safeguard the most critical assets.” The assets that need to be most protected will differ in every organization, Chertoff said. And he cautioned that trade secret theft isn’t limited to any one industry.

“We’ve seen a wide variety of the kinds of data and information that are being extricated,” he said. “It is simply not true to believe that only high-tech companies are victims of this.”

As corporations determine just what they need to protect, they’ll also want to plan a holistic approach to information security, according to Covington attorneys.

Inadvertent actions by employees can easily jeopardize trade secrets. Among the most common threats are spear phishing (in which employees unknowingly open or download malware) and use of thumb drives, which can infect a company’s network. “Both of these are just employees not paying attention to what they’re doing,” said Washington, D.C.-based partner David Fagan.

The sharing of seemingly innocuous work details on Facebook or Twitter can also put trade secrets at risk. “We see a lot of inadvertent disclosures of private or sensitive” data through social media, said Lindsey Tonsager, an associate in the firm’s privacy and data security practice in Washington, D.C.

The attorneys also recommended reviewing company policies with an eye toward mitigating trade secret risk, such as “what controls you need to put in place for a particular individual when they’re leaving” the company, Fagan said.

While companies commonly have policies around hiring employees, he said, “what we’ve observed is fewer companies have as organized an approach in off-boarding people.”

The ability to bring your own device to work also “raises all sorts of complicated issues that have an effect on trade secrets,” Tonsager said. One policy consideration here, for example, is to make sure employees are on notice that the company can remote-locate or remote-wipe a lost device that may contain sensitive information.

Partner Richard Shea, who chairs Covington’s employee benefits and executive compensation practice, said employers should give employees advance notice with regards to privacy expectations. “You need to tell them whether they have an expectation of privacy or do not have an expectation of privacy in their use of company computers, in their use of networks, their use of email,” he said.

Providing such notice is, in part, a warning to employees, Shea said. But, in a more positive light, it also helps create an “ethos of compliance,” he said.

If employees understand that the company’s viability, and their job, “depends on protecting critical assets from being stolen or accidentally released,” Shea said, “everybody would cooperate.”



Subscribe to Corporate Counsel

You must be signed in to comment on an article

Find similar content

Firms mentioned

    
  • Covington & Burling

Companies, agencies mentioned

    
  • Cargill Inc.
  • General Motors Company
  • The Dow Chemical Company
  • United States Department of Homeland Security

Key categories

    
  • Information Security

Most viewed stories

    
  1. Best Legal Departments 2013
    •      
  2. 6 Things In-House Counsel Must Know About E-Discovery
    •      
  3. 3-D Printing: The Next Big Thing in IP Law?
    •      
  4. Bristol-Myers Squibb: The Caped Crusaders
    •      
  5. U.S. Legal System Ranked as Most Costly
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

The General Counsel and the Compensation Committee

Your Company's Been Hacked -- What Comes Next?

Simpson Helps Yahoo, Tumblr Connect for $1 Billion Deal

Kasowitz Benson Launches in Los Angeles

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Collaboration Is Key to Defending Cyberattacks

Stanford Law Builds on Role as Legal Tech Incubator

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

South Florida Attorneys Lead Force-Placed Insurance Fight

Suit Names Missing Attorney Timothy McCabe For Alleged Fraud
  •      
    • Subscription Required

Appellate Division To Roll Out Electronic Case Filing System

Court Limits Liability for Injury Or Death of One Invited To Help
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Judge Declines to Block Act-of-War Defense in 9/11 Case
  •      
    • Subscription Required

Panel Finds 'Excessive' City Fine for Poaching Antenna From Trash
  •      
    • Subscription Required

Lawsuit Testing Federal Porn Regulation Allowed to Survive

Ex-College QB Can Press Claim Over EA's Video Game
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Water Warriors: Local Governments Bring Pollution Suits
  •      
    • Subscription Required

Sanction Reversed; Filing of Sexually Explicit Chat OKd
  •      
    • Subscription Required

Brooks Looks To Political Ally For Criminal Defense

Attorney Fee Hearing in Waffle House Sex Case Heats Up
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media