Skip to the main content.
What Size Law Firm Are You?

We've crafted solutions tailored to your firm

Insurance Glossary

The world of insurance for law firms can be confusing, and difficult to navigate. We've created this glossary because these common insurance terms should be easy to understand.

← Blog Home

How to Create a Data Security Plan

1 min read

How to Create a Data Security Plan

The belief that a computer or network breach is a ‘when,’ not an ‘if’ is practically dogma now. Given this reality, every law practice, regardless of size, should have a data security plan in place. Yes, I recognize this task can seem daunting — particularly if you have no idea where to start — but failing to do it simply isn’t an acceptable choice anymore. Here’s why: All clients absolutely expect that whatever sensitive and personally identifying information they provide to you will be properly safeguarded — period. And if that’s not motivation enough, remember our ethical rules and various state and federal regulations are also in play.

The good news is data security plans needn’t be drafted in the form of some long, convoluted treatise on IT security. It’s really more about creating “to do” lists and developing internal guidelines and policies. The entire process can be summarized as follows.

  1. Determine what sensitive and personally identifiable information you have and then identify all the locations where this information is stored.
  2. Determine if there is a legitimate reason to collect and maintain every piece of this information. If certain types of information aren’t really needed, stop collecting them.
  3. Figure out how to properly secure all information that must be kept and then take whatever steps are necessary to do so.
  4. Properly destroy any information that doesn’t need to be maintained. And finally, create an incident response plan so you know what to do if and when a breach occurs.

To help you move forward with this task, I encourage you to take a look at a useful guide put out by the Federal Trade Commission that is intended to help small businesses protect personal and sensitive information. This guide provides the details and instructions most small businesses need in order to make taking the above steps a palatable task. Finally, the FTC has also published a data breach response guide where additional information can be found on what to do if, and when, you experience a breach.

printfriendly-pdf-button-nobg-md-Nov-01-2022-08-44-54-4335-PM

 

Since 1998, Mark Bassingthwaighte, Esq. has been a Risk Manager with ALPS, an attorney’s professional liability insurance carrier. In his tenure with the company, Mr. Bassingthwaighte has conducted over 1200 law firm risk management assessment visits, presented over 600 continuing legal education seminars throughout the United States, and written extensively on risk management, ethics, and technology. Mr. Bassingthwaighte is a member of the State Bar of Montana as well as the American Bar Association where he currently sits on the ABA Center for Professional Responsibility’s Conference Planning Committee. He received his J.D. from Drake University Law School.

Most Dangerous Areas of Practice for Dabbling

3 min read

Most Dangerous Areas of Practice for Dabbling

Asking an attorney not to “dabble” in an unfamiliar area of practice is an easy concept to grasp, but much more difficult to put in practice....

Read More
Why A Lawyer Should Never Try to Shoot from the Hip

3 min read

Why A Lawyer Should Never Try to Shoot from the Hip

As a kid, I always thought any Hollywood cowboy who could shoot from the hip and kill the villain was one tough hombre that no one in their right...

Read More
Stay Out of the Sand Traps: Common Malpractice Mistakes

3 min read

Stay Out of the Sand Traps: Common Malpractice Mistakes

We are all human (although non-lawyers may question from time to time whether lawyers are an entirely different species) and even the best lawyers...

Read More