Overview
Managing the threat of insider risks is a data security and legal concern for all organizations. As its name implies, an “insider threat” originates inside an organization and can be an activity by a “bad actor employee” that poses a threat to the security of information held by the organization.
In addition, an insider threat can arise from an innocent and inadvertent action by people inside an organization (such as an employee who unintentionally opens a phishing email or clicks on a malicious link).
Epstein Becker Green is a law firm that is distinguished in the field of information security. The firm’s Data Privacy, Cybersecurity & Data Asset Management practice includes industry-leading, credentialed privacy and cybersecurity attorneys with experience with workforce cybersecurity, insider threats, data loss prevention, and breach response. We counsel clients across a broad range of industries, including financial services, health care, and technology, on insider threat assessments and preventative programs and technologies compliant with applicable law.
Our team is made up of attorneys with a diverse spectrum of certifications and qualifications, including:
- Certified Common Security Framework (CSF) Practitioners by the Health Information Trust (HITRUST)
- Certified Information Systems Security Professionals (CISSP) by the International Information Systems Security Certification Consortium (see www.isc2.org)
- Certified Professionals in Healthcare Information and Management Services (CPHIMS) by the Healthcare Information and Management Systems Society (HIMSS)
- Certified Ethical Hacker (CEH) by EC-Council
- Certified Information Privacy Professionals by the International Association of Privacy Professionals (IAPP)
Epstein Becker Green’s attorneys have served in high-level cybersecurity and data privacy positions with the Centers for Medicare & Medicaid Services and the National Security Agency, as well as Chief Information Security and Compliance Officers in health care and private organizations.
Our Services
Our legal services are directed at helping our clients (i) avoid a damaging loss of trade secrets, proprietary technologies, protected health and personally identifiable information, and other confidential business information and (ii) immediately respond to data loss incidents caused by malicious employees and other insiders, with advice grounded in our long-standing experience in these complex areas. We partner with our clients to prevent or mitigate losses from an insider data breach or theft, including reputational harm, lawsuits, regulatory actions, and loss of trust. We are a workforce management firm with distinguishing cybersecurity knowledge and significant experience in assessing and combatting threats posed by employees and third-party business partners to our clients’ data and proprietary technologies.
As a result of our risk management capabilities, we are able to provide legal advice on all aspects of cybersecurity. Our services include:
- conducting formalized and well-documented insider threat and vulnerability assessments;
- recommending policies and techniques to reduce the risk of damaging data breaches and the loss of valuable data and technologies;
- providing workforce management policies and cybersecurity training designed to protect organizations from the loss of trade secrets and other critical business information;
- reviewing vendor and contractor relationships and agreements for key protections;
- assisting clients with responses to government audits and investigations into security and privacy breaches;
- conducting forensic investigations into claims of misappropriation by employees and others of trade secrets and other data breaches, and litigating those claims;
- responding to network hacking and security incidents caused by malevolent insiders and outsiders; and
- advising on the international, federal, and state laws and regulations concerning data privacy, security, and breaches.
In addition, Epstein Becker Green is exceptionally well positioned to provide counseling on conducting robust risk assessments of administrative, physical, and technical safeguards around critical data, including personnel practices, and developing documentation of a defensible cybersecurity program. Our insider threat risk assessments are protected by the attorney-client privilege to the fullest extent permitted by law. If a breach or other security incident occurs, whether caused by an employee, business partner, or outsider, Epstein Becker Green can skillfully guide your organization through the ensuing investigation, documentation, and response.
Read less
Focus Areas
Contacts
- Member of the Firm
Media
Events
Insights
Insights
- PublicationsThe Challenge of AI Governance: The Blessing and the Curse of Safeguarding Personal Data15 minute read
- Media CoverageBrian Cesaratto Quoted in “New Jersey Legislation to Watch: A Midyear Report”3 minute read
- Blogs
Privacy Officer's Roadmap: Data Breach and Ransomware Defense – Speaking of Litigation Video Podcast
42 minute read - BlogsVideo: California's Upcoming Cyber Audit and Automated Tech Rules - Employment Law This Week2 minute read
- Media CoverageAlaap Shah Quoted in “2024 Outlook: The Cybersecurity Trends Health System Leaders Need to Know”3 minute read
- PublicationsUSA: Future of Cybersecurity Law and Regulation2 minute read
- Media CoverageAlaap Shah Featured in “You Gotta Get the Data Right! Talking EMPI”2 minute read
- Media CoverageBrian Cesaratto Quoted in “Best Practices for Detecting and Managing Fraud”3 minute read
- Media Coverage
Alaap Shah Featured in AHLA Connections Magazine: Member Spotlight
3 minute read - Firm Announcements
Epstein Becker Green’s Brian Cesaratto and Francesco DeLuca Named 2022 BTI Client Service All-Stars
3 minute read - PublicationsNew York Will Require Employers to Provide Notice of Email and Other Electronic Employee Monitoring2 minute read
- PublicationsMonitoring Employee Email or Other Electronic Usage: New York Will Require Employers to Provide Notice8 minute read
- PublicationsDesigning a Trusted Framework for the Application of AI in Health Care2 minute read