Safe space: Information security in law

The rapid rise of generative AI and other technologies is creating new safety challenges for security leaders in professional services firms. So how is it changing the role of information security? For Toks Oladuti, Chief Information Security Officer at Dentons, it’s all about managing risk regardless of the technology.How is technology like AI and cloud computing changing security policies and procedures in law firms?

Ultimately what we do is risk management. It doesn’t really matter what the technology is – they all pose variations on the same risk. People talk about the risks of Generative AI (GenAI) to business information, but they are essentially the same risks that we have with any other technology where you input data, it does some processing and then it spits out more data.

It doesn’t matter whether it’s a cloud platform, GenAI or some new-fangled technology that we’ve not imagined yet. Ultimately, it’s about managing the risks of what data goes in and what comes out, who has access to it and where it’s shared. The underlying basics don’t change.

I believe it’s a case of how you mature your processes and controls around risk management as a whole, and that’s always a continuous process. You should always aim for improvement.

What is different is the amount of interest in GenAI, coupled with unrealistic expectations and a lack of understanding of the reality of what the technology can and can’t do.

GenAI is everywhere, but it still forms part of a standard business decision – if there is a competitive edge to using GenAI, we should be examining it.  

What are the most significant cybersecurity risks currently facing firms?

In my view, everything and nothing changes. I suspect we’ll be doing the same things this year as last year, with variations depending on what is going on externally. A priority for me right now is the supply chain. I work in the legal sector, providing services, so we are part of someone else’s supply chain and we also have suppliers that are part of our supply chain.

Supply chain breaches are not likely to reduce any time soon. This means we have a lot of scrutiny from our clients into how we manage supply-chain risk, and we are doing the same with our own suppliers and their supply chain. This focus will continue to get more complicated as the level of regulatory scrutiny increases, which will mean closer examination of the finer details, so that we can raise any red flags and respond quickly.

It’s not just about third parties – you have subcontractors to consider too. I have thousands of suppliers across my organisation. One of the challenges we face now is how do you prioritise the risks among those, because you can’t look at them all. You need a business risk-based approach to classifying suppliers, prioritising the level and depth you need to consider across areas of business criticality.

With so much data to consider, how do you ensure you’re prioritising activities and not getting overwhelmed by information?

Ten years ago, technology was all about best of breed. We all had a lot of well-advertised tools doing separate things. Now, the focus is more on integration and consolidation, reducing our technology footprint so that we can get what we need when we need it.

Having an all-singing, all-dancing tool that we can’t manage properly and don’t use to its full capability is pointless. If I have a consolidated tool set that gives me the information I need for now, that’s all I need.

Then, as part of that continuous improvement, as I need more information or enhanced capabilities, I will look to bring new tools in. For me, getting the basics right across the whole security stack we cover is critical.

How far does the size of firm present additional security issues, given the number of offices and people?

I’ve worked in organisations which are centralised and those that are very decentralised. Working in a very large, decentralised organisations means that one of my priority areas of focus is strong governance by making sure that we have the right policies in place, which sets the mandatory controls and requirements that everyone has to meet to reduce risks to the business. It’s up to the decentralised business units to implement those policies in the most appropriate manner for them.

I also make sure that I offer central core security services that are universally required across the organisation, operating like an internal services provider. Depending on the level of maturity, skills set and resources of each business unit, there might be variations on which of these services they require and consume.

Internal audits are critical in supporting and driving strong governance and compliance. By measuring and monitoring gaps against our internal policies across the firm, we can ensure that we are holistically compliant. More importantly, we can also then address gaps, taking a risk-based approach to remediation and prioritising focus areas.

Are there particular risks faced by law firms, as opposed to other businesses? 

In the legal sector, we manage a large amount of client data just through the way that we deliver and provision our services. We need to make sure this data is secure, that we’re handling and managing it in a manner that clients expect and demand through their terms and conditions, as well ensuring we are compliant with different data regulations across multiple jurisdictions and different countries.

Again, we still need to make sure that we’ve got good governance behind this and that we’re doing the necessary monitoring and measuring to ensure we’re compliant. We need to make sure that our people, processes, technology and data are all properly risk managed.

What roles and job titles have you seen appearing in internal security teams?

The past five years have seen more roles in application security and security architecture, as well as more specialism around governance risk and compliance, and identity and access management. I think there still needs to be a big focus on continuous training and upskilling in existing teams, which is critical as we mature and take on more capabilities, and new technologies and services.

In another competitive year for hiring talent, what advice can you give to managers on attracting and retaining people?

I believe recruitment is split into two camps: roles where you need someone with experience and those where you don’t. Sometimes,  we focus on experience when we don’t actually need it.

Over the years, I have had to recruit many roles. Only some of those have needed experience. I think we need to get away from a focus on skills shortages to instead looking at ability, aptitude and attitude. You can train people on skills, processes, workflows and technology, but if they don’t have the right work ethic and passion, that is where you’ll struggle.

When you see a job advert for a junior role in which they’re asking for things such as five years’ experience, that’s nonsense. For an entry level threat analyst, for instance, what I need is someone who is curious, who likes to solve problems, who sees things through to the end and is excited by the unknown.

None of this requires years of experience, or a big cyber or tech background. If we can adopt job adverts that are based more on required characteristics than unnecessary skills, I think that would be a really good step forward.

Discover how Totum can help you or your firm source the right technology talent, view our technology recruitment services.

To discuss the themes covered in this article or for more information on working with Totum’s specialist technology team, contact Ross Mackenzie at [email protected]

Share This Post:

Subscribe to our Newsletter

* indicates required