• No results found

BYOD in Law Firms. Role: Decision Maker Segment: Mid-Tier or Mid-Market Orientation: Educational Region: APAC

N/A
N/A
Protected

Academic year: 2021

Share "BYOD in Law Firms. Role: Decision Maker Segment: Mid-Tier or Mid-Market Orientation: Educational Region: APAC"

Copied!
11
0
0

Loading.... (view fulltext now)

Full text

(1)

Role: Decision Maker

Segment: Mid-Tier or Mid-Market

Orientation: Educational

Region: APAC

BYOD in Law Firms

Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(2)

Introduction

BYOD in Law Firms

Every organisation has battles fought within it, few more emotive and critical than the struggle over control of data and the devices used to access it. Time was, corporate data could only be accessed via client software that was firmly under the control of the IT department, on computers that we similarly owned and managed within that domain.

Smartphones have crept into almost all areas of our lives – including work – and have more recently been joined by their big brother; the tablet. Both types of device have become ubiquitous, and employees in all companies increasingly expect to be able to use their mobile devices for work: this can mean anything from accessing email to managing documents in the cloud.

This introduces a huge number of challenges for IT departments. This white paper examines the approaches adopted by legal firms across the Asia Pacific region to the phenomenon of employees using their own devices for work, generally known as Bring(ing) Your Own Device, or BYOD.

We interviewed 50 IT decision makers in law firms of 250+ employees across five Asia Pacific countries in May 2014: Hong Kong, Singapore, Australia, Japan and China. The research shows that employee-owned mobile devices are a well-established work tool among large legal firms in Asia Pacific, where on average just under one in every two employees are using their own device(s) for work and it is apparent that BYOD is the norm, rather than the exception.

For IT departments this means the same device frequently carries both data owned by the law firm – email addresses, access to the CRM system, legal case matter – and personal data, applications and services.

Naturally there are significant “soft and hard” benefits both expected and seen from a seamless transition between the work and personal computing

environment. These include increased productivity and flexibility, delivering higher employee satisfaction and a better level of service for clients. But they bring with them challenges for the law firm and significant risks too, which IT departments in law firms across the Asia Pacific region are struggling to address.

BYOD Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(3)

The Rise of BYOD

39

%

17

%

11%

31%

Employee-owned mobile devices are a well-established work tool amongst large legal firms in Asia Pacific, and seem to occur (to some extent) in all legal organisations. Over the past decade, mobile devices in the shape of smartphones and tablets have become ubiquitous, and as they have become increasingly prevalent in the workplace, they have brought their own set of challenges to IT departments: the range of operating systems brings challenges in management and support, for instance. Our survey found that on average, just under one in every two employees are using their own device or devices for work and it is apparent that BYOD is the norm, rather than the exception in law firms across the region. In half of all firms we surveyed, more than half of employees use their personal devices for work, and a significant proportion of firms (39%) indicate that the proportion of staff who are using their own devices for work is actually higher at half to three quarters.

In fact, only 2% of law firms reported low levels of staff – less than 10% of people, or 25 employees – using their own mobiles devices for work.

BYOD has clearly become commonplace among law firm employees, as it has in many other sectors, and employees now widely expect to be able to use their own mobiles devices for work-related matters.

How many employees in your organisation use their

own mobile devices for work?

2%

51% - 75% 10% or less 76% or more 26% - 50% 11% - 25% Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(4)

Advantages of BYOD

are Huge

BYOD in Law Firms

It’s easy to see why BYOD is so popular.

Law firms are clearly making an investment to allow secure mobile access to their data from personal devices, but is it worth it? Our survey suggests that yes, it is. Significant advantages are attributed to the use of BYOD in the workplace by the law firms we surveyed. Increased productivity, flexibility, levels of service for clients and employee satisfaction were all rated highly – between 4 and 5 on a scale of 1 (not important ) to 5 (very important).

Increased productivity means being able to do more in the same amount of time. Given that many people working in legal firms will be client-facing, it is clear that a significant amount of time will be spent out of the office. Laptops are an obvious solution to such mobile working practices, but mobile devices – and tablets in particular – have a number of advantages that laptops often fail to match, including long battery life and touch-sensitive displays that just make working on the go so much easier. Smartphones meanwhile are more than capable of handling email on the move, and of course are the obvious partner for CRM systems.

Increased flexibility is demanded by professionals, and those in the legal profession are arguably the original – if not ultimate – knowledge worker; no other white collar profession has so much demand for knowledge on the move that they can often be seen carting trolleys of documents around with them. What’s more, the legal profession is unusual in that very often the knowledge workers are also client-facing and own the company or partnership too. So when they demand flexibility in their working practices, they expect to get it.

Increased levels of service for clients – the third advantage cited by our survey respondents – flows naturally from increased flexibility. When a client needs legal advice, they often need it immediately, and of course mobile devices that provide access to a law firm’s information systems are the ideal tool.

And finally, it’s easy to see how employees that are more productive, able to work more flexibly, and offer increased levels of service to their clients will experience increased overall levels of satisfaction.

Clearly, law firms need to ensure they support employees who want to use their own personal devices for work-related tasks. Failing to do so will hit productivity, employee satisfaction and – by extension – client satisfaction as the level of service they experience inevitably declines.

What are the advantages of BYOD and how important are these?

67

%

4.2

Employee

4.2

Satisfaction Level of Service for Clients

4.4

4.4

Increased Flexibility Increased Productivity BYOD Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(5)

Advantages Come

From Access to a

Wide Variety of Law

Firm Data

Law firm employees are accessing all types of information on their personal devices, with an overwhelming

proportion (80%) of them accessing work email, legal documents, case matter documents and customer data. Email is the number one application, available on mobile devices for 96% respondents’ law firms. With many lawyers working out of the office, mobile email will be essential in most law firms. While laptops can supply this, they tend to rely on the ability to log into wifi, whereas tablets and smartphones provide a much more immediate user experience, with always-on connection available thanks to 3G/LTE networks, and audible or tactile notifications of incoming emails.

Customer relationship management (CRM) data and legal documents from third parties are also frequently supported or available, each being accessible from mobile devices in 88% of law firms. CRM data will be useful because if properly configured and used, it provides that immediate, company-wide view of interactions with a client, and availability of CRM systems over mobile devices means this view can be updated in the field instead of stacking up as ‘paperwork’ to be completed back at the office.

Legal documents from third parties could relate to any number of materials, from statute law to case law and beyond. Mobile access to such documents can be crucial, especially in court where a sudden turn of events can make it imperative to research documents not prepared in advance.

In just slightly fewer law firms (81%), case matter is also available on employee-owned devices. This could be in the form of client documents, contracts and other confidential information that is necessary to have on hand for client meetings and even ad-hoc client requests – which again may not respect regular office hours.

Billing information is also available remotely from mobile devices at a majority of law firms, though this is less prevalent (reported by 65% of respondents), than the other types of data described above.

96%

88%

81%

What types of data and IP owned by the firm are either stored or otherwise

available on these devices?

88%

65%

Email

Legal Documents from Third Parties

CRM Data

Case Matter (Client Documents, Contracts and Other Confidential Client Information) Billing Information Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(6)

Though the Mix

of Work and

Personal Data on

Mobile Devices is

Pronounced…

BYOD in Law Firms

As might be expected, employees overwhelmingly store or access their own information on their devices.

Personal email is found on 91% of these mobile

devices, and if anything, we might be surprised it is not on a higher proportion. Setting up personal email on smartphones and tablets has never been easier, with the result that many devices will provide access to multiple email accounts – both work and personal.

It should come as no surprise then to find out that personal contacts are stored on the personal mobile devices of employees in 75% of law firms.

Personal documents are stored or available on 84% of mobile devices, while photos and videos are on 82% - a state of affairs encouraged by the ubiquitous presence of cameras on smartphones and tablets. With increasingly good optics and detectors and an increasing array of apps to enable, manipulate, manage and share them, the proliferation of photos and videos on mobile devices will only increase. One consequence of this is the increased prevalence of third-party apps that also have access to the data and services on a host device, and the increased integration with social sites (social content is found on personal devices in 74% of law firms). These third-party apps bring with them risks to data security.

Clearly, firm-owned and personal data and applications

sit side-by-side on employee-owned mobile computing devices that are used for work purposes, and the seamless transition from one to the other is a growing “norm” for legal sector employees as seen in other industries although, of course, the risks in the legal sector are particularly high, with the risk – in extreme cases – of revocation of a licence to practice.

What types of data and IP owned by the individual may be either stored or

otherwise available on these devices?

91

%

74%

75%

84

%

82

%

Email Personal Documents

Photo & Video

Contacts Social Content BYOD Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(7)

The Benefits

of BYOD Bring

Significant Risk

The disadvantages of BYOD are equally evident and perceived as moderately challenging by legal firms. Data security is the number one area for concern, with legal firms scoring it, on average, 4.2 on a scale of 1 (not important) to 5 (very important). This should come as no surprise given the risks to law firms and their employees associated with data – especially privileged client data – falling into the wrong hands.

Risks can come from any number of places: devices being lost or stolen, devices being connected to other devices, the apps running on them, or unauthorized access through services running on them.

The consequences of these risks can be profound. The duty of care that lawyers have in respect to their relationship with clients and protection of client information (known as legal professional privilege), is unrivalled in any other profession. It extends beyond the qualified lawyers to every member of the law firm or in-house practice, including support staff, consultants and locums.

The details of legal professional privilege may differ from region to region, but is broadly consistent across common law countries, where it makes demands such as:

• Affairs of clients must be kept confidential

• Information must never be disclosed to a client if it will conflict with its duty of confidentiality to

another client

Failure to sustain such standards can result in litigation from clients, or other actions against the individual or law firm concerned that could result in revocation of a licence to practice.

Data security is clearly important in such an environment. The risk of data loss is rated at 3.9 on the scale of 1 to 5, and explains the focus put on automatic data locks and other technologies intended to mitigate this risk.

Other disadvantages of BYOD that are highlighted by law firms include a lack of control over geographical location of confidential customer data, and a lack of control over the dissemination of confidential customer data, both rating around 3.9 on a scale of 1 to 5. Compliance with local jurisdictions appears to be a top challenge across the board; for 39% of respondents it is rated very important. There is some correlation to the geography of respondents here, indicating that this concern may depend on the likelihood or severity of sanctions in a particular country (such as Singapore).

What are the disadvantages of BYOD and how challenging are these?

Data Security Data Loss Control over Geographical Location of

Confidential Customer Data Control over Dissemination of Confidential

Customer Data Remote Device Access and Management by IT Maintaining Separation Between Personal and Work Data Control over the Phone Number When an Employee Leaves

Network Integrity IT Support For Employees Compliance with Local Jurisdictions

5 1 4.2 3.9 3.9 3.8 3.7 3.7 3.7 3.6 3.6 3.4 Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(8)

These Risks

Translate into

Real-World Problems

BYOD in Law Firms

Many of these risks and disadvantages of BYOD have translated into real problems that have been experienced by half or more of the firms surveyed – a shockingly high proportion, especially given the reticence that companies of any type usually express in relation to data breaches. Perhaps most worryingly, half of firms reported that either an individual or the firm was exposed to criminal prosecution as a result of BYOD (with a slightly increased trend in Hong Kong), which is examined in more detail on the following page. This is also a very high number, and may be connected to issues around the geographical location of customer data, which, while not being a

security breach per se, is an area of increasing legislation around the globe, with associated increasing risk of a company falling foul of the law and being left open to prosecution.

What is clear from the survey is that virtually all the issues faced are not specific to any one country but are seen across all five.

Law firms can employ a range of measures to mitigate against these problems – particularly the risk of

exposure to criminal prosecution. In some jurisdictions, demonstrating indicative behaviours to achieve specific outcomes can help. These may include:

• Ensuring you comply with the law in respect of your fiduciary duties in relation to confidentiality and disclosure.

• Outsourcing only to providers who have taken all appropriate steps to ensure the confidential information.

But there does seem to be a general picture here of law firms experiencing problems that reflect a current debate around the efficacy of data security measures in law firms – particularly international law firms who work on highly confidential matters for large, international clients. A recent article in the New York Times described how some financial institutions are asking law firms to fill in 60-page questionnaires detailing their cyber security measures, while others are doing on-site inspections1

1

http://dealbook.nytimes.com/2014/03/26/law-firms-scrutinized-as-hacking-increases/?_php=true&_type=blogs&_php=true&_type=blogs&_r

Which of the following problems have you faced in connection to BYOD?

61% 51% 51% 44% 37% 33% 28% 28% Netw or k Br eac hes or V iruses Exposur e of Indi viduals or the Fir m to Criminal Pr osecution Netw or k Connecti vity Issues I nter net Issues Ne glig ence Claims R educed Le vel of Ser vice for Clients Disciplinar y Action by a R egula tor y Bod y Lac k of Email Access BYOD Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(9)

Control Over

Geographical

Location of

Confidential

Customer Data

One aspect of BYOD in law firms that deserves closer examination is that of control over the geographic location of confidential customer data, such as case matter.

In our survey this came out as a top challenge, rated joint-second alongside data loss as a key challenge when law firm employees use their own mobile devices for work. An overwhelming 88% of respondents ranked this as 4 or 5 out of 5 in terms of the size of the challenge.

The problem, of course, is that when an employee moves between jurisdictions, so too do their mobile devices and any data stored on them. Once in another jurisdiction, there is the further question of whether data then accessed from that jurisdiction has travelled to it, given that any data displayed on a device’s screen must, almost by definition, have travelled to it.

The risk comes from the fact that regulators and authorities in Asia have rapidly introduced new laws, regulations and compliance requirements in an attempt to mitigate the security and data privacy risks associated with data hosted on servers and accessed from disparate locations. The rapid rate of legislation as countries attempt to keep up with technological developments is compounded by a lack of consistency across countries, according to a recent white paper issued by the Asia Cloud Computing Association2 (ACCA).

According to the ACCA’s research, legal environments among Asian countries have significant differences, creating a huge challenge for those adopting cloud services and satisfying requirements across the multiple jurisdictions. To take just a couple of examples, China has “strict and unclear restrictions on cross border data flow” and its “province level” regulations do not align with “globally accepted standards”, while Singapore’s regulatory regime is “business friendly” but with “minimal transparency in data access mechanisms”, and in Hong Kong the same issue is present and means that “authorities are permitted to intercept communications”.

Help is available for those trying to navigate the issue of data sovereignty across jurisdictions. The APEC Cross-Border Privacy Rules (CBPR) is a relatively new development and operates where businesses submit their plans for governing data transfers to ‘accountability agents’ that are responsible for assessing and ultimately certifying whether businesses meet the standards set out in the CBPR.

2 The Impact of Data Sovereignty on Cloud Computing in Asia. http://

asiacloudcomputing.org/images/research/DataSovereigntyReport2013_ ExecutiveSummary.v2.pdf Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(10)

Measures in Place

and Planned

BYOD in Law Firms

Beyond these broad approaches, our research indicates that law firms are taking a wide variety of specific precautions to protect the data stored on, and accessed from, personal mobile devices. Password management is used almost across the board – in 88% of law firms. Beyond secure communications, many law firms are also taking steps to control the data itself, with 74% implementing automatic locks on data, 72% having technology in place to prevent loss of mobile data, but only 65% having the ability to remotely wipe data from a mobile device that is lost, stolen, or perhaps belongs to an employee who has left the firm.

Position this as a response – that was the situation they had, and these are the things they have in place now, law firms have recognised that, they are now trying to reach the same compliance standards as their customers. Of the respondents to the survey, 68% have a remote configuration policy, which suggests that employees have to comply with certain device requirements.

Surprisingly, given the high importance of risks and advantages of BYOD, only two-thirds of law firms have carried out an assessment of security threats. As many as one third of law firms may be facing risks they have not properly assessed. Full analysis of employee support needs has also only been done by two thirds of law firms, implying a large number of law firm employees are using their own mobile devices for accessing their law-firm data without suitable support in place.

Broadly speaking though, a wide range of other measures are undertaken, from policy and contractual/user-based measures to sensitive data and device controls, all receiving levels of mentions at 49% or above.

Over the next 12 to 18 months these measures are all set to increase to levels of 75% up to 88%, indicating that formulating a comprehensive mobility and BYOD strategy is clearly underway amongst (large) legal firms in this area and a key priority.

Which of the following measures do you currently have in place for managing

BYOD? And which of these are you planning to put into place for managing

BYOD in the next 12 to 18 months?

Currently in place Planned in next 12-18 months

88

%

88

%

88

%

84

%

84

%

84

%

84

%

82

%

81

%

75

%

79

%

Assessment of security threats Analysis of Support Needs

and Capabilities Identification of the Business

Goals of BYOD Analysis of Existing Policies and

Regulatory Framework List of Allowed Devices Definition of the Segregation of Personal and

Organisational Data Policy for Controlling Sensitive Data Employee Exit Procedure for BYOD List of Explicitly Allowed and Banned Apps Definition of Minimum Device Requirements Understanding of End User Cases,

and Segmenting Accordingly

21 21 39 26 28 35 35 28 32 19 21 66 66 49 58 56 49 49 54 49 60 54 BYOD Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

(11)

Conclusion

BYOD is clearly here to stay, and particularly so in law firms where the people demanding the mobility and flexibility it delivers are very often the partners who will be directing the priorities of the IT department.

And so, understandably, IT departments are seeking to control this BYOD environment: Password Management, Encryption and Secure Communication (VPN) are the three key control measures (among various others) employed at the same time.

The disadvantages arising from the use of personal devices are also evident: number one concern remains data security/data loss, but the secure and compliant dissemination of client data also appear as challenging. Most worryingly, a very large proportion of law firms report experiences of network breaches and viruses, and half report they have been exposed to the possibility of criminal prosecution due to the use of employee-owned computing devices. To keep this in perspective however, we believe that this may in large part be connected to the increasing difficulties in complying with the law when it comes to moving client data – which will include personal information – across jurisdictions in Asia Pacific countries.

From an IT point of view, the assessment of the threat landscape, analysis of BYOD support needs, and a

minimum definition of device requirements are necessary to maintain security and control, are undertaken by a majority. These and other control measures are set to increase in firms – from slightly over half today to an average of 80% across the varied controls in the next 12 months.

Legal firms see a need for their mobility strategy to achieve what can be seen as a balancing act between successfully aligning the goals and needs of their employees with those of corporate integrity and client confidentiality. They also need to continue driving

company productivity and client satisfaction whilst maintaining corporate data security, client confidentiality and adhering to the relevant local jurisdictions, thus minimizing exposure to criminal investigations/security violations in storing, retrieving, and working with legal case information.

This presents a real opportunity for vendors over the near- and mid-term to guide legal firms in the Asia Pacific region to define and fine-tune their mobility strategy.

IDG Connect is the demand generation division of International Data Group (IDG), the world's largest technology media company. Established in 2006, it utilises access to 38 million

business decision makers' details to unite technology marketers with relevant targets from 137 countries around the world. Committed to engaging a disparate global IT audience with truly localised messaging, IDG Connect also publishes market specific thought leadership papers on behalf of its clients, and produces research for B2B marketers worldwide.

Control Risks is a global risk consultancy specialising in political, security and integrity risk. We help our clients to understand and manage the risks of operating in complex or hostile environments. Our unique combination of services, our geographical reach and the trust our clients place in us, ensures we can help them effectively solve their problems and realise new opportunities across the world. We support clients by providing strategic consultancy, expert analysis and in-depth investigations through to handling sensitive political issues and providing practical on the ground protection and support.www.controlrisks.com

Equinix has helped almost 100 law firms to accelerate their business performance and expansion by connecting them to their customers and partners inside the world’s most networked data centres. Equinix’s global presence where these firms operate has provided them with a reliable, secure, scalable and cost effective platform for higher quality delivery of key technologies to their fee-earning personnel across the globe. Using purpose-built and highly connected facilities, separate from their corporate offices, simplifies BCP and shifts the cost from CapEx to OpEx budgets. Learn more at www.equinix.com

Advantage

Data

Devices

Risk

Problems

Location

Plans

Conclusion

1 2 The Impact of Data Sovereignty on Cloud Computing in Asia. http:// www.controlrisks.com at www.equinix.com

References

Related documents

Reliability of pilot test of SDLA questionnaire (n ¼ 28) Reliability Effective learning (11 questions) Fondness for learning (9 questions) Learning motivation (7 questions)

client is simultaneously advised in writing that the client may nevertheless discharge the lawyer at any client may nevertheless discharge the lawyer at any time and in that

Hypoglossal nerve stimulation, also referred to as an upper airway stimulation (UAS) system, is proposed as a treatment strategy for select patients with moderate to severe

Client & Matter Management provides a single screen through which to access all information regarding a matter, including emails, client details, documents, appointments,

For instance, for the case of a risk neutral decision maker, the structure was similar to the case of a risk adverse decision maker, while in the case of a risk lover decision

4. In the case of a firm of agents where at least one of the agents of the firm has confidential information that could be used to the disadvantage of another client or former client

If the new law firm concludes that the transferring lawyer does possess relevant information respecting a former client that is confidential and that may prejudice the former

 Malicious user: visitor, contractor, malicious employee  Targets: confidential data, client information,. strategic business