Feeds

Hacked? Call a lawyer

Feds urge security pros to call in shysters

  • alert
  • submit to reddit

The Essential Guide to IT Transformation

Network administrators tasked with investigating cyber attacks on corporate networks should consider adding a potentially strange and unfamiliar tool to their defensive arsenals: the phone number of the company lawyer.

At least, that was the consensus of a panel of current and former law enforcement attorneys and corporate security heads speaking at the 2001 BNA Cybersecurity and Privacy Forum in Washington Wednesday.

"When we deal with some organizations, such as local law enforcement, we've got to make sure we have good legal advice," said Howard Schmidt, head of Microsoft's security department.

At issue: when investigating a hack attack, security professionals collect and handle evidence that may eventually become Exhibit A in a criminal case. But unlike FBI agents, computer geeks don't have the benefit of a trained federal prosecutor at each elbow, guiding them through the thicket of evidentiary law that, in theory, stands between a cyber attack and a successful prosecution.

Enter a new type of corporate in-house counsel: lawyers who help companies deal with the legal side of cyber security, an emerging niche that's particularly well suited for former prosecutors entering the private sector.

"It is a specialty, like contracts law, or deal law or real estate law," said America Online assistant general counsel Christopher Bubb, who until last month was a New Jersey cybercrime prosecutor. "It's a certain skill set and a knowledge set that's needed to participate in these investigations... It's not something that you learn in law school."

As a deputy district attorney, Bubb participated in the 1999 Melissa virus investigation that eventually identified New Jersey programmer David Smith as the author of the malicious code.That case, said Bubb, hinged on information gathered by AOL's security department, with the careful guidance of the company's legal team. "There's no dichotomy" at AOL, said Bubb. "[Lawyers are] allowed in on the decision making at the front end."

But will hands-on computer security experts pause in their pursuit of an intruder to bring company attorneys into the loop? Christopher Painter, deputy chief of the Justice Department's computer crime section, cited a recent, unscientific survey conducted by the Computer Security Institute (CSI) and the San Francisco office of the FBI, in which only 30 per cent of respondents who suffered cyber attacks said they reported the incident to company lawyers.

"System operators don't think about that," said Painter, an attorney himself. "That's not their concern."

© 2001 SecurityFocus.com, all rights reserved.

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.