Your attorney is a vendor too‚ who do you really, zero trust
Discussion Points: Why is this a risk?
- Increase security incidents targeting law firms
- Law firms trusting other sub-vendors with sensitive information
- Regulatory controls and fines (what if my data leaves the jurisdiction)
- Data transfer using old or antiquated methods
- How do you communicate with your external counsel to understand their internal security, risk profile, sub-vendors, and incident response plans?
- What type of data do most companies send to their external counsel?
- Hardcopy
- Mobile Devices
- BYOD policy consideration
- PC / Laptops
- File Serves
- Cloud Services
- Mobile Device Messaging
- Email, Email, Email
- Who has my data and where is it stored?
- Risk profiles and sub-vendors
- So this is only a problem if I have a solution
- What can you do to better inform and work with your legal department?
- Who else in your organization needs to be aware of data leaving ITs control?
- How to verify and request that data be deleted from sub, sub vendor locations
- Tools and best practices Do you want to be secure or check a box
Cyber Security and Data Protection is much larger than red and blue teams, it takes a village.