Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Knowledge Management and Innovation at Dorsey & Whitney
Caroline Sweeney, Director
CyberSecurity in Law Firms: Building Trust with Clients


Protecting Sensitive Client Information in Discovery
You might be wondering, why is cyber security such a big deal for a law firm? Well, law firms come into possession of a lot of client files when representing companies in litigation or other capacities. Those files may contain sensitive information, like personally identifiable information (PII), company trade secrets, and even personal health information (PHI). Inadvertent disclosure of this information can be extremely damaging and costly and may also violate certain laws. As recently as June 2023, an attorney was sanctioned by a Court in Nevada for, among other violations, failing to redact personally identifiable information (multiple birth dates and the name of a minor child) in public court filings. The attorney was fined $3,000 for this redaction failure (see Davis v. Clark Cnty. Sch. Dist., 2:11-cv-01896-JAD-NJK (D. Nev. June 16, 2023)).
When it comes to protecting sensitive information, the requirements are pretty straightforward, given the various–and evolving-federal, state, and even international, laws that address data protection requirements. In the e-discovery context, this presents a requirement for the law firm handling the e-discovery–or directing an e-discovery vendor-to ensure sensitive information is identified and redacted. It is important to leverage technology that can help identify various forms of PII and PHI and redact it, thereby ensuring against sanctions and properly protecting client information.
Raising awareness among law firm attorneys regarding the need to identify and redact sensitive client information is key. Drafting e-discovery review protocols that include directions on how to handle sensitive information and having process checks to confirm that sensitive information is redacted prior to production ensure client data is properly protected.
A New Law Firm Role
But e-discovery is not the only area in which a law firm encounters cyber security challenges. Law firms routinely receive sensitive client information related to, say, mergers and acquisitions.
Indeed, law firms are hiring cyber security professionals to help with managing client cyber security requirements. These are positions that did not exist a dozen years ago. A recent google search showed 13,000 legal cyber security jobs posted on LinkedIn. These law firm cyber security team members use various, often cutting-edge, technologies (representing new law firm spend) to monitor data flow into, within, and out of the law firm as part of the vigilant effort to protect against cyber breaches and maintain the security of client files.
Law firms proactively addressing cyber security may also be relying more heavily on the information governance professional to oversee the intake, secure storage, secure access, and proper disposition of client files. This administrative role is key to a law firm’s proactive cyber security program.
A Law Firm Cyber Security Awareness Team
Having cyber professionals and a strong information governance program is not enough, however. Many law firms have received certifications and regularly undergo security audits to comply with external security certifications and client mandates. Often, as a requirement for maintaining these security credentials, a Cyber Security Committee is formed to routinely review information security data and address security compliance within the law firm. They may also develop protocols around security issues, such as those for data encryption and remote work.
Training is always an opportunity, but in the cyber security context, it is a requirement. Educating employees to raise awareness of various scams and ‘phishing’ attempts that might result in a cyber breach is critical, as is monitoring participation in the training. This is true for any business in the 21st century, not just law firms.
A law firm that is aware and proactive about cyber security can build trust with their clients and differentiate themselves from competitors
Law Firm Services Related to Cyber Security
Of course, cyber security concerns and processes are not unique to law firms. Our clients face similar challenges and requirements around cyber security. Those needs present an opportunity to the law firm. At a recent meeting of some of my law firm peers, nearly everyone in the room was working on a data breach review for a client. This means firms are able to leverage their expertise in e-discovery to assist clients in identifying sensitive information exfiltrated during a breach. These data breach reviews are often very time-sensitive due to the various notification laws in place and require a rapid response time, e-discovery processes, technology, and expertise, in conjunction with lawyer expertise regarding data breach notification laws and negotiation with breach offenders, provide law firms with a unique opportunity to help clients in these unfortunate situations.
Data breach review is not, of course, the only opportunity. It is not uncommon for law firms to offer entire practice advisory services around cyber security. Such legal services might include offering legal guidance on a company’s data privacy compliance efforts, negotiating various vendor contracts to ensure security and privacy considerations are addressed favorably for the client, maintaining awareness of various national and international privacy laws, helping craft privacy and security policies, and cyber incident response planning.
While cyber security presents varied challenges and certain requirements for law firms, it is also another opportunity for law firms and their clients to collaborate. A law firm that is aware and proactive about cyber security, as described above, can build trust with their clients and differentiate themselves from competitors. A win-win for all.

