Corporate Counsel
  • Home
  • News
  • Surveys
  • Resources
  • Lawjobs
  • Advertise
  • Subscribe
  • Bookstore
  • Contact

Topics » IP Insider | Labor & Employment | From the Experts | On the Job | Moves | DC Watch | International

Home > Data Security for Lawyers Traveling to China

Font Size: increase font decrease font

Data Security for Lawyers Traveling to China

By Alan Cohen All Articles 

The American Lawyer

January 31, 2013

  •    
  •    
  •    
  •      
 

For Western lawyers working in China, doing business can require a curious combination of legal skills and 007-like stealth. Leave your laptop in your hotel room? Expect it to be searched. Call up a website to check the weather? You might load code that pulls data off your hard disk. Does your PC weigh more than it did when you left the States? That could be a homing device, implanted on the sly and now transmitting information about the merger your client is planning. It might sound like stuff from a James Bond movie. But the threats are real, say law firm technology chiefs—and worrisome.

The perils of using technology in China isn't a topic that law firms like to talk about publicly. "This is a very, very sensitive subject in our firm," says one chief information officer who declined to talk about the topic, even on a confidential basis. Says another: "Public statements might be considered the equivalent of 'poking the bear.' On this topic, I believe we are better served staying quietly diligent."

The U.S. government has been less reticent. On its website, the U.S. Department of State advises travelers to China that Internet and telephone use "may be monitored on-site or remotely, and personal possessions in hotel rooms, including computers, may be searched without your consent or knowledge." In February 2012 national intelligence director James Clapper told the House intelligence committee that "China and Russia are of particular concern. . . . Entities within these countries are responsible for extensive illicit intrusions into U.S. computer networks and theft of U.S. intellectual property."

Law firms can be especially at risk, so much so that in November 2011, the Federal Bureau of Investigation briefed the nation's top 200 firms on hacking and other IT security risks they face. One law firm CIO who attended the session said the FBI's message was clear: "They figure law firms are a particular target because big companies use them for deals, and [firms] often have weaker security than the companies themselves." Another CIO says that in the last 18 months he has attended four meetings where "three-letter federal agencies spoke about targeted hacking of law firms." (This CIO says that participants were asked not to provide details of the briefings.)

Austin Berglas, assistant special agent in charge of the cyber branch at the FBI's New York office, says the bureau routinely reaches out to law firms, along with financial institutions, universities, and research centers, because "highly skilled cyber-criminals often target these organizations on behalf of foreign nation-states who seek to gain an advantage socially, politically, or economically."

One law firm CIO, who—like many of the other CIOs quoted in this article—asked not be identified, says that Chinese clients are forthcoming about the risk: "They will say, if you leave your computer on in your hotel room and go to dinner, you can be assured that someone will try to break into it."

Not that this CIO, who oversees technology for an Am Law 100 firm with an office in China, needs to be convinced. Each day he receives a report on "port scans" experienced by the firm. A port scan is essentially the cyberspace equivalent of a tug at a window—someone on the outside checking, on their own and without permission, for a way onto a network. A firewall—the barrier that keeps unauthorized traffic from entering or leaving a law firm's data center—typically has thousands of ports. A hacker needs only to find one that is open and vulnerable. On an average day, this CIO's firm sees more than 3 million port scans: 2.4 million originating from within the United States, 500,000 from China, and 100,000 from every other country on the globe combined. He says he can always tell when there is a holiday inside China: That's when the number of port scans drop significantly.

Security concerns about China are "very legitimate [and] very high on our radar screen," says Linn Freedman, a partner at Nixon Peabody who leads the firm's privacy and data protection group. (Like a growing number of Am Law 100 firms, Nixon has a presence in mainland China, with an office in Shanghai; it has also assembled an internal "privacy council" of attorneys, management, and IT professionals to deal with privacy and security issues.) "There is no privacy in China," Freedman says. "You have to understand that when you are doing any business in that country. There are no statutory or legal protections. It is a whole different atmosphere than doing business in the European Union or the United States, and it is scary."

In fact the only protections firms have are the ones they create for themselves. What follows are policies that firm CIOs are instituting to protect lawyers who are doing business in China. They are also, the CIOs say, smart steps to take when lawyers travel in any nation where cyber-espionage poses a heightened risk—and that doesn't just mean the usual suspects like Russia; two tech chiefs noted that France has been a surprisingly active hotspot for hacking and cyber-theft.

Take a loaner laptop

The most fundamental precaution is to take a "clean" laptop on the trip. Lawyers should never bring their usual machine—the one they use day in and day out for work (and the one filled with work-related data). Firms generally have a cache of loaner laptops that contain no work product. If these are lost or otherwise compromised, the potential damage is contained.

Other devices that may contain work or personal information—such as a tablet—should be left at home whenever possible. "You try to have a serious discussion with folks on what they need to take and have them trim back," says Matt Kesner, chief information officer at Fenwick & West. "We strongly encourage them not to take their own smartphones and iPads and definitely not their own laptops—not just to China but when they go many places in the world."

While this advice might seem like a no-brainer, another CIO notes that it is not something partners—who are often used to doing things their own way with their own equipment—like to hear. "We had a document where we said, don't go [to China] with your standard laptop, but take a loaner, and a lot of attorneys were not thrilled with that," he says. Making a rule, he adds, was out of the question: The firm just didn't work like that. Besides, "at the end of the day, partners are going to do what they want, and the Chinese know that, and the hackers know that," he says.

Embrace desktop virtualization

By itself, a clean laptop can reduce security concerns but not eliminate them entirely. After all, lawyers could create sensitive work product on their loaner machines during their trip, or visit websites that plant harmful code—known as malware—on the laptops, which among other things can intercept keystrokes or compromise any data that is on the machine. So some firms strive to make loaner laptops as bare-bones as possible, stripping them of Web browsers, word processing software, and email programs, and ensuring that no data is ever stored on them. So if prying eyes do come upon the laptop, there is nothing to see. The trick, in short, is to remove most of the things that make a laptop useful without making it useless. As luck would have it, there is a technology that does exactly that—desktop virtualization. Firms are flocking to it.

What desktop virtualization does is turn a laptop into, in effect, a keyboard and screen. All of the actual applications, computer processing, and data storage takes place back in the firm's data center, where it can be secured. Many firms use platforms developed bya Citrix Systems Inc. or VMware Inc. to accomplish this.

A browser or device that allows javascript is required to view this content.

Continue reading

  • 1
  • 2

Next



Subscribe to The American Lawyer

You must be signed in to comment on an article

Find similar content

Firms mentioned

    
  • Fenwick & West
  • Nixon Peabody

Companies, agencies mentioned

    
  • Yahoo! Inc.
  • Federal Bureau of Investigation
  • United States Department of State
  • VMware Inc.
  • Citrix Systems Inc.
  • European Union

Key categories

    
  • Corporate & Business Law
  • International Law
  • Internet and Technology Law

Most viewed stories

    
  1. Managing Relationships With Legal Project Management
    •      
  2. Best Legal Departments 2013
    •      
  3. Taking the Reins of Legal Department Operations
    •      
  4. Cloud Computing and Unexpected FCPA Jurisdiction
    •      
  5. Hiring Summer Interns? Make Sure You Do it Right
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Interns? Be Sure to Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

In Tricky Prosecutions, Judges Play Peacemakers

Ropers Majeski Tries to Re-Invent Itself
  •      
    • Subscription Required

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Not Covered for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Firm Takes Another Hit in Bid for 'Unconscionable' Fees

New York's Martin Act Faces Test in Challenge to 2005 Case

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

'Follow That Escapee!'

Judge Who Tossed Defense Counsel Accused of 'Partiality'
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About Corporate Counsel   |
  • Contact Corporate Counsel   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media