Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.
Employees are increasingly using the cloud to access their personal email, documents, music and other data from anywhere at any time. They expect their employers' digital data will be similarly accessible. Beyond user experience, cost and complexity provide compelling reasons for moving your law firm's technology operations to cloud providers. This article discusses what to look for in a cloud service provider and other issues that will help determine if moving to the cloud is the right move for your firm.
|The growth of technology has created many challenges for small- to medium-size businesses (SMBs), including law firms: continually upgrading hardware, staying abreast of the latest in security developments and hiring multiple staff members with different skills.
First, SMBs typically purchase server hardware with the expectation it will last for years. A year or two later, they discover they need to double the capacity of that system in order to meet technology needs. These costs are often not budgeted.
Additionally, security has moved from a simple firewall and anti-virus software to very expensive, hard-to-manage security systems, including log review and correlation (SIEM) systems, next-generation firewalls, host intrusion detection systems and sandboxing of all incoming files. Your IT department can no longer consist of one person wearing many hats, including maintaining infrastructure, ensuring data security and providing end-user support. To reduce this complexity and its associated costs, many firms are moving to the cloud.
|Cloud services can be broken down into three major categories: software as a service (SaaS), platform as a service (PaaS) and infrastructure as a service (IaaS).
SaaS requires the least amount of technical knowledge and, as a result, allows for the least amount of IT administrative control. In the SaaS model, a cloud provider is responsible for everything from the hardware to the application. These types of services are all run primarily from a Web browser and require nothing to be downloaded or installed on the client's workstation. Examples of SaaS solutions include Dropbox, Salesforce, GoToMeeting and Office 365.
PaaS allows for more control but requires more technical knowledge than SaaS solutions. PaaS cloud solutions take care of the hardware and the operating system, allowing the user to focus on the applications. This is an ideal solution for application developers, who don't need knowledge of the underlying OS or hardware. Examples of PaaS solutions are Force.com, Apache Stratos and OpenShift.
IaaS requires the greatest amount of technical knowledge and grants administrators the most control. IaaS cloud providers are responsible for the underlying hardware or infrastructure through a host of virtual devices, including firewalls, networks and virtual servers and workstations. The company is responsible for managing the OS and the applications. This is the most flexible cloud-computing model and is highly scalable. Examples of IaaS are Amazon AWS, Microsoft Azure and Google Compute Engine.
|Security considerations are still paramount when migrating to a cloud solution. Maintaining good security and operational practices is a critical and nonnegotiable factor. In fact, these policies, standards and procedures are more important than ever to ensure that you are appropriately protecting your cloud implementation. Since cloud solutions are Internet accessible, if they are not appropriately secured, malicious actors can sometimes get in more easily than if the equipment is on your own premises.
When an IT service provider proposes that you use a cloud system implemented by that vendor, it's critical you also implement a vendor risk management plan (VRMP) so you can make sure your managed service provider is following appropriate security procedures to protect your data. A VRMP will also let you assess whether the cloud solution you are considering is appropriately secure as well. And, finally, it is important you have a business continuity plan in place so your employees and your managed service provider know what to do if your cloud system fails, suffers a hacking attack or has otherwise been rendered unavailable.
|Moving to the cloud by yourself is not a simple process, and any organization should carefully consider the pros and cons of such a shift. Determining if moving to the cloud is right for your organization can be broken down into several steps:
Migrating IT services to a client service provider (CSP) benefits law firms by reducing their technology infrastructure's physical footprint in their offices, including built-in redundancy, easy scalability with better physical security and access to advanced security features. Ultimately, this all results in lower IT capital expenditures.
When utilizing a CSP, firms no longer need to find additional space to house servers or ensure sufficient power and cooling for these systems. A CSP can offer almost unlimited room for growth. Additionally, a proper data center must have redundancies to ensure that no single failure results in lost data or downtime. A well-run CSP already has redundancies, ranging from power and cooling to storage and security, built in. Further, most major CSPs have multiple data centers around the globe, allowing for regional diversity at the push of a button to prevent downtime and lost data in the event a natural or manmade disaster takes one data center offline.
Many organizations need to expand and reduce their IT resources as needed, such as during peak- and slow-use times. Because new hardware requires a large initial investment and then ongoing operational costs to maintain, SMBs simply cannot always scale on their own. CSPs allow organizations to rapidly spin up and turn off IT resources based on demand. They offer a "pay as you go" (or "pay as your grow") model, so organizations only pay for what they use.
Data centers must be physically secured to prevent unauthorized physical access. Well-run CSPs have dedicated facilities to house all physical servers and supporting equipment and typically go to great lengths to ensure no unauthorized access is allowed. Some CSP data centers can be compared to a military installation with multiple checkpoints and armed security.
Building a proper data center can be an expensive endeavor that requires a lot of upfront capital expenditures. Technology is also still advancing at a rapid pace, so ensuring that your data center is utilizing the latest options means maintaining a relatively rapid and expensive refresh rate. CSPs make this easier because you rent your equipment and can easily replace it. Additionally, with virtualization technologies, you can easily move your devices from old hardware to new hardware.
Cloud service providers are utilized by a wide variety of clients from many different sectors, including government, health care and financial services. As a result, CSPs must adhere to specific security and compliance standards issued by regulatory organizations for all these fields. However, firms need to understand that not all security, compliance standards and regulatory responsibilities are passed on to the CSP. When a company engages a CSP to assist with satisfying these security and regulatory requirements, it must understand what the cloud provider is responsible for and what the firm will still be responsible for.
On the other hand, because of the requirement to have security elements in place, CSPs like AWS and Azure allow you to implement tools which evaluate your organization's configurations to create a gap analysis showing where you need to address vulnerabilities. These tools are based on industry best practices and are usually referenced by compliance standards and regulatory organizations.
Both AWS and Azure have security tools that can be leveraged to assist in providing law firms the next level of protection. Most of these tools would be extremely costly if purchased separately. By taking advantage of a CSP, the cost of entry becomes significantly more affordable. Some of the services businesses should consider include:
Cloud service providers can remove many of the day-to-day burdens of maintaining IT infrastructure in law firms and allow them to concentrate on their core business functions. Law firms in the cloud can scale IT infrastructure to meet their current demands, giving firms many of the benefits of IT in larger organizations without the costs associated with maintaining technology or hiring expensive experts.
*****
Michael Smith is a security architect at Citadel Information Group. He has over 20 years' experience in managing information technology and information security. With experience in corporate, nonprofit and classified networks, Michael has extensive experience across numerous technologies and how to secure them. Michael holds a Bachelor of Science in Information Technology from Arizona State University. He can be reached at [email protected]. Mike Paul is the chief technology officer at Innovative Computing Systems and has over 15 years of experience in the legal field. In his current role, along with evaluating new technologies and designing various systems around providing these solutions to the legal community, he also provides the glue for the internal technology Innovative uses. Paul holds a bachelor's degree from Northern Arizona University. He can be reached at [email protected].
|ENJOY UNLIMITED ACCESS TO THE SINGLE SOURCE OF OBJECTIVE LEGAL ANALYSIS, PRACTICAL INSIGHTS, AND NEWS IN ENTERTAINMENT LAW.
Already a have an account? Sign In Now Log In Now
For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473
In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.
During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.
The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.
Practical strategies to explore doing business with friends and social contacts in a way that respects relationships and maximizes opportunities.
As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.