A board of directors plays a critical role in shaping a company’s strategy, maintaining relationships with shareholders, and safeguarding the company’s reputation. Appointing a new director may bring welcome...
Chloe Silvester , Head of General Practice, Practical Guidance Stephen Tuck , Legal Writer, Practical Guidance Personal Injury Victoria Ben Newling , Legal Writer, Practical Guidance Personal Injury NSW...
Jennifer Raphael , Senior Legal Writer, Practical Guidance Construction, LexisNexis ® In 2024, several pivotal decisions were made across New South Wales, Victoria, and Queensland concerning Security...
Jennifer Raphael , Senior Legal Writer, Practical Guidance Construction, LexisNexis ® In the ever-evolving landscape of construction law, 2025 promises to be a pivotal year for legal practitioners...
Jada Lam , Practical Guidance Legal Writer – Employment and WHS The Fair Work Act 2009 has been updated with the 'Employee Choice Pathway,' offering new rights for casual employees. Read on for essential...
Data is now the most valuable commodity in the world. Still, few businesses outside the tech sphere have fully come to terms with the value of the data they hold - and the legal industry is no different.
Knowledge Managers undertake a number of data-intensive activities - managing large numbers of documents, precedents and firms’ proprietary data, intranets and other sources of digital information crucial to smooth business function. Different data types have different obligations attached to them, and this means it is important for Knowledge Managers to understand the value of their data and how best to protect it.
What’s the value of data?
How can we understand data’s worth in a monetary sense? One of the models gaining favour is the ‘prudent value’ approach, which ties the economic value of data to key business initiatives.
Using this model, each data source used by a business has a dollar value that is tied to its ability to inform business decisions. For example, a particular precedent developed by a firm may be used across a number of different client matters. Each time that piece of knowledge is used it contributes to the overall financial return for that work.
Considered in those terms, it’s easy to see just how valuable the full trove of knowledge at a legal business can be. It goes without saying that cybersecurity is no longer just an IT issue, it’s a business-wide responsibility - and Knowledge Managers must be fully aware of recommended actions and obligations when it comes to data safety.
Data protection
So, what’s the best way to protect it? We can consider recommended actions under three broad umbrellas: Prevention, Preparation and Compliance.
Prevention
Prevention is about minimising the risks that your business will fall victim to a data breach. It focuses closely on processes and awareness. Some specific preventative measures businesses should take include:
Preparation
Preparation is crucial. Currently the accepted wisdom is that despite the best preventative strategies, data breaches are still highly likely to occur - so it’s best to be ready when they do.
Preparative measures focus on incident response planning and testing. Measures include:
Compliance
Though there are a number of compliance considerations based on data type, the vast majority of legal businesses will be considered APP entities under the Privacy Act and thus subject to the Notifiable Data Breach (NDB) scheme. This is a key piece of legislation and a whole-of-business understanding of its scope and requirements is crucial.
The consequences of non-compliance with the NDB can be severe, ranging from injunctions to prevent certain activities to civil penalties of up to $2.1 million.
There are three steps to complying with obligations under the NDB:
In many ways, Knowledge Managers are data managers. The data they create, store and curate is crucial to the smooth function, success and competitive advantage of their business. With the responsibility for cybersecurity a shared concern, it’s imperative that Knowledge Managers have a detailed understanding of what the obligations are when it comes to cybersecurity and how to prevent an attack.
For more information on data security, mandatory data breach notification, cybersecurity and strategy, check out Practical Guidance Cybersecurity, Data Protection and Privacy.
From simple search to analysis and insight, the powerful intelligence of Lexis Advance sits at the heart of many of LexisNexis' legal solutions. Access exactly what you need with a single subscription.