Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Increase of IP Cyberthefts on the Horizon, and Many Unprepared

By Ricci Dipshan
October 31, 2016

Though cybertheft of intellectual property is predicted to dramatically increase over the next 12 months, a significant portion of companies has yet to fully secure their IP assets, according to a survey released by Deloitte Cyber Risk Services. The findings come from a survey of just under 3,000 professionals from organizations across multiple industries, including finance, insurance, hospitality and retail.

In a sign of growing anxiety, over half (58%) of respondents surveyed said they believe that IP cyberthefts will increase over the next year, while 4% expect a decrease in such thefts, and 12% do not expect to see any change at all.

The survey also found that around half of all respondent's organizations were not prepared for an IP cybertheft, with 12% lacking the infrastructure and technology to secure their IP and 36% currently working toward improving IP handling process and systems. Only around 17% of organizations had security measures in place to protect, and restrict access to, their IP.
In addition, respondents cited employees and company insiders as the most likely group to cause an IP cybertheft, followed by competitors, party vendors, activist groups, and nation-state actors.

Don Fancher, principal at Deloitte Advisory and global leader for Deloitte Forensics & Investigations, noted that although employees can intentionally steal IP assets to enhance their own position at a competitor company, many can also unintentionally cause a theft as well.
This may happen when “a competitor, or a nation-state, whomever it might be, finds a way to utilize an employee to enter into the internal systems of the company and thereby use that access to then capture IP or other proprietary data,” he said.

Such theft may involve social engineering or phishing scams, as well as malware placed unintentionally on a network-connected computer.

To mitigate suck risks, Fancher stressed the need for training programs so that employees can understand “the value of IP to the organization,” as well as “the threats and the risks that can be exposed if IP is stolen or taken.” He also advised organizations to “limit valuable data to only those employees that absolutely need to see it.” In addition, Fancher advised that those who handle IP assets regularly, such as IP attorneys, should be trained more than others.

“When you get to the more technical aspects of the organization, your R&D department, research scientists, the IP attorneys or other attorneys that are handling these agreements and handling these documents, they need to get even further and more extensive training,” Fancher said.

Fancher added that IP attorneys and in-house counsel can also play an important role in managing how IP data is stored and handled among research scientists.
It is not uncommon, Fancher said, for IP thefts to go unrecognized in an organization for some time. “Many companies do not ever realize they've been hacked or that their system has been infiltrated for many, many months before their own security system identifies it or in some situations the U.S. government identifies it and then alerts the corporations.”

*****
Ricci Dipshan writes for Legaltech News, an ALM sibling of this newsletter. He can be reached at [email protected].

Though cybertheft of intellectual property is predicted to dramatically increase over the next 12 months, a significant portion of companies has yet to fully secure their IP assets, according to a survey released by Deloitte Cyber Risk Services. The findings come from a survey of just under 3,000 professionals from organizations across multiple industries, including finance, insurance, hospitality and retail.

In a sign of growing anxiety, over half (58%) of respondents surveyed said they believe that IP cyberthefts will increase over the next year, while 4% expect a decrease in such thefts, and 12% do not expect to see any change at all.

The survey also found that around half of all respondent's organizations were not prepared for an IP cybertheft, with 12% lacking the infrastructure and technology to secure their IP and 36% currently working toward improving IP handling process and systems. Only around 17% of organizations had security measures in place to protect, and restrict access to, their IP.
In addition, respondents cited employees and company insiders as the most likely group to cause an IP cybertheft, followed by competitors, party vendors, activist groups, and nation-state actors.

Don Fancher, principal at Deloitte Advisory and global leader for Deloitte Forensics & Investigations, noted that although employees can intentionally steal IP assets to enhance their own position at a competitor company, many can also unintentionally cause a theft as well.
This may happen when “a competitor, or a nation-state, whomever it might be, finds a way to utilize an employee to enter into the internal systems of the company and thereby use that access to then capture IP or other proprietary data,” he said.

Such theft may involve social engineering or phishing scams, as well as malware placed unintentionally on a network-connected computer.

To mitigate suck risks, Fancher stressed the need for training programs so that employees can understand “the value of IP to the organization,” as well as “the threats and the risks that can be exposed if IP is stolen or taken.” He also advised organizations to “limit valuable data to only those employees that absolutely need to see it.” In addition, Fancher advised that those who handle IP assets regularly, such as IP attorneys, should be trained more than others.

“When you get to the more technical aspects of the organization, your R&D department, research scientists, the IP attorneys or other attorneys that are handling these agreements and handling these documents, they need to get even further and more extensive training,” Fancher said.

Fancher added that IP attorneys and in-house counsel can also play an important role in managing how IP data is stored and handled among research scientists.
It is not uncommon, Fancher said, for IP thefts to go unrecognized in an organization for some time. “Many companies do not ever realize they've been hacked or that their system has been infiltrated for many, many months before their own security system identifies it or in some situations the U.S. government identifies it and then alerts the corporations.”

*****
Ricci Dipshan writes for Legaltech News, an ALM sibling of this newsletter. He can be reached at [email protected].

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
COVID-19 and Lease Negotiations: Early Termination Provisions Image

During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.

How Secure Is the AI System Your Law Firm Is Using? Image

What Law Firms Need to Know Before Trusting AI Systems with Confidential Information In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.

Pleading Importation: ITC Decisions Highlight Need for Adequate Evidentiary Support Image

The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.

Authentic Communications Today Increase Success for Value-Driven Clients Image

As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.

The Power of Your Inner Circle: Turning Friends and Social Contacts Into Business Allies Image

Practical strategies to explore doing business with friends and social contacts in a way that respects relationships and maximizes opportunities.