Insight

Into the Breach

Data breaches have become inevitable. Here’s what you can do to respond.

Blue data text breached by an overlayed red target on a black background
JE

John Ettorre

December 22, 2017 02:58 PM

For many years, data breaches were a subject discussed only within the IT industry. But as the sophistication of these attacks has grown and the costs associated with them has mounted, that has become a luxury no one can afford.

By 2012, with data breaches becoming such a common occurrence that they seemed all but inevitable, FBI Director Robert Mueller told an information security conference, “I am convinced that there are only two types of companies: those that have been hacked and those that will be. And even they are converging into one category: companies that have been hacked and will be hacked again.”

With ever-evolving hacker sophistication, the philosophy for defending against data breaches has shifted.

Where IT security professionals might once have tried to erect impermeable walls around their systems, the emphasis is now on proper and timely detection and response to inevitable breaches.

Meanwhile, the prime targets are also changing. Major repositories of valuable commercial secrets—university labs, regulatory agencies, and corporate law firms—are increasingly being targeted by hackers intent on stealing clients’ secrets involving intellectual property or mergers and acquisitions. Government investigators believe, for instance, that the prominent M&A firms Cravath, Swaine & Moore and Weil, Gotshal & Manges were hacked for information that could be used for inside trading.

Wake-up Call

In the last few years, the scale of these breaches—and the consequent damage they can do to consumers’ privacy—has begun capturing wider attention.

A 2014 data breach at Home Depot potentially compromised the private information of 56 million individuals. Others followed at Chase bank (76 million), Anthem Blue Cross (as many as 80 million), and Target (110 million). The granddaddy was a breach of Yahoo’s system, which involved 1.5 billion user accounts.

The case involving the global law firm DLA Piper, which was attacked by ransomware in 2017 that all but shut down the firm for days, got everyone’s attention in the legal arena, says Sharon Nelson, an attorney who specializes in IT threat mitigation through her Virginia-based firm Sensei Enterprises.

“The DLA Piper leak was a showstopper for firms of all sizes. What we keep hearing is, ‘If it could happen to DLA Piper, what hope do any of us have when it comes to protecting client data?’”

What Not to Do

Given the ubiquity of the problem in recent years, endless suggestions have issued forth about what organizations should do in the wake of a data breach. So instead, we asked an expert for a quick rundown on some pitfalls you should avoid after an IT incursion. Here is Sharon Nelson’s list:

•Failing to notify the regional FBI office (some firms just call their local police departments).
•Failing to notify clients who may have been impacted in a timely manner.
•Failing to follow their state data breach notification law (many hide behind the “no one can ascertain for sure what data was compromised” argument).
•Moving too quickly to announce a breach, especially where there is no response plan in place and no facts have yet been gathered by digital forensics. Never let public statements outrun provable facts.
•Using IT generalist staff to conduct breach investigations rather than experts.
•Moving too slowly to announce the breach. It will look like concealment and have a bad PR response when and if the breach becomes public.
•Discussing the breach on social media. A carefully crafted statement on the website is a better idea.
•Failing to instruct employees on how to handle questions about the breach.

You’ll Need a Plan

The foundation of any organization’s effective data breach strategy should be having a solid incident response plan in place.

These IRPs would typically include such components as having a data breach lawyer and a digital forensic consultant lined up ahead of time and having internal IT systems logs and insurance coverage in place to cover such an eventuality, as well as a plan for containment of and recovery from the breach.

Even in the face of the mounting evidence that it’s disastrous to ignore proper IT security, many organizations continue to drag their feet.

Sometimes they’re forced to act by clients, who insist on security audits of their operations before doing business. “Client security audits have proliferated,” says Sharon Nelson. “This train is moving even faster than the adoption of incident response plans.”

Law Firms as Juicy Targets for Hacking

IF robbers target banks simply because that’s where the money is, sophisticated hackers often find law firms as an inviting target for similar reasons: they’re repositories of valuable information.

In 2009, the Federal Bureau of Investigation warned American law firms that they were being specifically targeted by hackers intent on breaching their computer security. Two years later, the bureau organized an educational meeting with the managing partners of top law firms, paying special attention to firms with offices in Russia or China.

If law firms needed that warning then, either about state-sponsored players or hackers with fewer resources, the threat is hardly news to them today.

After all, two-thirds of U.S. law firms were breached in 2016, and 18 firms reported losing a client after failing an IT security audit, according to one survey.1

An American Bar Association study2 found that 40 percent of firms that suffered a data breach in 2016 reported significant downtime and loss of billable hours.

The list of firms that have suffered breaches reads like a who’s who of marquee names. The Chicago-based firm Johnson & Bell was hit with a class action suit in late 2016 over its alleged failure to protect client information. The irony of the DLA Piper breach is that the firm promoted itself as a specialist in cybersecurity.

The Panama Papers case, which involved the leaking of 11.5 million legal documents from a Panamanian law firm that specialized in setting up offshore entities, represented an earthquake-sized wakeup call in the legal sector.

Related Articles

Canadian Firms Explore AI, But Few Fully Embrace the Shift


by David L. Brown

BLF survey reveals caution despite momentum.

Canadian Firms Explore AI, But Few Fully Embrace the Shift headline

Tampa Hospital Suffers Recent Data Breach


by Gregory Sirico

Tampa General Hospital, a non-profit research based medical center, suffered a sizeable data breach that put 1.2 million patients' information at risk.

Laptop reading hacked with translucent medical model in foreground

Biometric Points of Contention


by Gregory Sirico

The collection of individuals' biometric data via smartphones, facial recognition software and more—presents a challenge to consumers, lawyers and legislators.

Animated man with blue eyes and digital pixelations across his face

Privacy Practice


by Casey Waughn

Data protection is all the rage among tech companies and state, national (and even transnational) governments alike. Is it a passing fad or here to stay? And how should businesses and groups of all sizes handle compliance with a blizzard of new laws?

Data protected inside of a bubble requiring multiple identification processes

New England States With Incoming Legislation


by Gregory Sirico

Best Lawyers takes an in depth look at newly proposed bills, litigation and cases coming out of four New England states.

Two New England attorneys stand on the steps to a grand courthouse

Biometric Privacy: It’s Not Just an Illinois Issue


by Molly K. McGinley and Kenn Brotman

How BIPA Litigation May Impact Companies Outside of Illinois

Blue fingerprint that's reflective with black background

How Does Your Firm Measure Up?


by Best Lawyers

Best Lawyers Intelligence provides your firm with valuable industry data.

Best Lawyers 27th Edition Stats

An Interview With Jean-Paul Jassy of Jassy Vick Carolan


by Best Lawyers

The 2019 "Lawyer of the Year" winner for First Amendment Law in Los Angeles speaks about his career highlights.

Jean-Paul Jassy, 2019 "Lawyer of the Year" winner for First Amendment Law

An Interview With Bastian Finkel of BLD Bach Langheid Dallmayr, Germany's 2019 "Law Firm of the Year" Winner in Insurance Law


by Best Lawyers

A look at the new European policies changing the insurance landscape in Germany.

Bastian Finkel 2019 "Law Firm of the Year" Interview

Cloud Computing: An Exercise in Architecting Trust


by Kelly L. Frey Sr.

As businesses delegate infrastructure to cloud providers, lawyers must ensure contracts are built to balance control, responsibility and trust.

Cloud with green and blue orb next to a man connected with lines

Recent Developments on Privacy and Data Protection in Brazil


by Ricardo Barretto Ferreira da Silva and Camila Taliberti Ribeiro da Silva

A change of paradigm is urgent and requires a robust legislation on personal data protection.

Multiple people in a crowd with gridlines and white circles overlayed with orange blocks in the cent

My Data My Rules: An Overview of Data Protection in Brazil


by Fábio Pereira

Technology pixels on a biometric hand scanner with fingerprints at the top

Cyber School


by Elizabeth S. Fitch and Theodore M. Schaer

Cybersecurity and the Claims and Litigation Management Alliance’s School of Cyber Claims

One red opened digital file that indicates a data breach on a computer

Trending Articles

The Family Law Loophole That Lets Sex Offenders Parent Kids


by Bryan Driscoll

Is the state's surrogacy framework putting children at risk?

family law surrogacy adoption headline

Algorithmic Exclusion


by Bryan Driscoll

The Workday lawsuit and the future of AI in hiring.

Workday Lawsuit and the Future of AI in Hiring headline

Best Lawyers 2026: Discover the Honorees in Brazil, Mexico, Portugal, South Africa and Spain


by Jamilla Tabbara

A growing international network of recognized legal professionals.

Map highlighting the 2026 Best Lawyers honorees across Brazil, Mexico, Portugal, South Africa and Sp

Unenforceable HOA Rules: What Homeowners Can Do About Illegal HOA Actions


by Bryan Driscoll

Not every HOA rule is legal. Learn how to recognize and fight unenforceable HOA rules that overstep the law.

Wooden model houses connected together representing homeowners associations

Holiday Pay Explained: Federal Rules and Employer Policies


by Bryan Driscoll

Understand how paid holidays work, when employers must follow their policies and when legal guidance may be necessary.

Stack of money wrapped in a festive bow, symbolizing holiday pay

Reddit’s Lawsuit Could Change How Much AI Knows About You


by Justin Smulison

Big AI is battling for its future—your data’s at stake.

Reddit Anthropic Lawsuit headline

Florida Rewrites the Rules on Housing


by Laurie Villanueva

Whether locals like it or not.

Florida Rewrites the Rules on Housing headline

US Tariff Uncertainty Throws Canada Into Legal Purgatory


by Bryan Driscoll

The message is clear: There is no returning to pre-2025 normalcy.

US Tariff Uncertainty Throws Canada Into Legal Purgatory headline

Alimony Explained: Who Qualifies, How It Works and What to Expect


by Bryan Driscoll

A practical guide to understanding alimony, from eligibility to enforcement, for anyone navigating divorce

two figures standing on stacks of coins

Can a Green Card Be Revoked?


by Bryan Driscoll

Revocation requires a legal basis, notice and the chance to respond before status can be taken away.

Close-up of a U.S. Permanent Resident Card showing the text 'PERMANENT RESIDENT'

UnitedHealth's Twin Legal Storms


by Bryan Driscoll

ERISA failures and shareholder fallout in the wake of a CEO’s death.

United healthcare legal storm ceo murder headline

The 2026 Best Lawyers Awards in Chile, Colombia and Puerto Rico


by Jamilla Tabbara

The region’s most highly regarded lawyers.

Map highlighting Chile, Colombia and Puerto Rico for the 2026 Best Lawyers Awards

New Texas Family Laws Transform Navigating Divorce, Custody


by Bryan Driscoll

Reforms are sweeping, philosophically distinct and designed to change the way families operate.

definition of family headline

What Is the Difference Between a Will and a Living Trust?


by Bryan Driscoll

A practical guide to wills, living trusts and how to choose the right plan for your estate.

Organized folders labeled “Wills” and “Trusts” representing estate planning documents

Why Skechers' $9.4B Private Equity Buyout Sparked Investor Revolt


by Laurie Villanueva

Shareholder anger, a lack of transparency and a 'surprising' valuation.

Skechers shareholder lawsuit headline

How Far Back Can the IRS Audit You?


by Bryan Driscoll

Clear answers on IRS statutes of limitations, recordkeeping and what to do if you are under review.

Gloved hand holding a spread of one-hundred-dollar bills near an IRS tax document