New data collected by ACC Foundation suggests that a staggering 36 per cent of in-house counsel worldwide have experienced a data breach at either their current company or a former employer. Moreover, the threat of cybersecurity seems to be growing only stronger. According to the international survey, the largest ever investigation into in-house cybersecurity concerns, 47 per cent of all in-house lawyers who had experienced a data security breach said that the breach had occurred in the last two years, in either 2014 or 2015.
Australia and New Zealand lagging behind
While cybersecurity challenges continue to grow and diversify, the 'ACC Foundation: The State of Cybersecurity Report' suggests that the preparedness of GC in Australia and New Zealand is failing to keep pace with that of in-house departments elsewhere. Only eight per cent of surveyed in-house counsel reported that their company had responded to the growing cyber threat with an increased spend on security. This figure appears insubstantial when compared with a global average increase of 23 per cent. The region is also lagging on the question of financial preparedness, with only 25 per cent of respondents saying that their company holds cybersecurity insurance, compared to around 47 per cent of companies worldwide. Of those in-house lawyers globally who reported experiencing a data breach, only 19 per cent said that damages associated with the breach were fully covered by insurance.
Inside job
When one imagines cybersecurity protection, complex software systems and state-of-the-art technologies may spring to mind. However, what emerges from the ACC report is that vulnerability to cyber attack is not merely a technological challenge. In fact, a vast majority of those in-house counsel who reported a data breach at their present or past company suggested that the rupture had distinctly human origins. Employee error was found to be responsible for approximately 24 per cent of system breaches, while a further 15 per cent were the result of an intentional inside job. Despite the prevalence of employee error, less than half of respondents said that their companies had mandatory cybersecurity training for their employees, and even fewer companies regularly track and test employee knowledge.
Getting involved
Growing threat and chronic underpreparedness make for a gloomy outlook, with most in-house counsel expecting cybersecurity risk to increase in the coming year. However, around 57 per cent of respondents said that legal departments would become more involved in tackling cybersecurity challenges in the future. Further, around half of survey respondents said that they wanted to increase their role and responsibility in cyber matters going forward. Sources: Association of Corporate Counsel; Australasian Lawyer
Email your news and story ideas to: [email protected]

