ILTA Voices
Episodes

Aug 16, 2023
Aug 16, 2023
27 min
How are firms adopting Artificial Intelligence in the Risk Management space? Given the fast-paced and highly publicized technology trends involving AI, what are the biggest challenges organizations face today with adopting AI technologies and in particular maintaining security and compliance around client, firm, and personnel data.Questions the moderator will ask the speakers:
Where do AI capabilities exist in the Risk Space? Reporting, Terms of Engagement, Conflicts Searching, Data Analytics, Records, etc.
Data captured at client/matter inception is used throughout an organization, would you tell me what key factors join teams together and how organizations maintain consistency especially with AI “running in the background”?
How do firms control the information and the learning?
How or when does an organization begin to trust its AI?
What are the fears/blocks an organization will address prior to deciding to implement AI technology?
As the industry patterns dictate and pressure increases, how can organizations assess security concerns in a timely and thorough manner?
How do an organizations’ client(s) fit into the mix? If an organization’s client(s) oppose the use of AI technologies with their data, how does the firm comply?
What are the specific steps an organization can take to ensure a successful adoption of AI technologies?Confirmed Moderator:
Elizabeth Suehr, Director of Legal Risk Systems and Strategy, Jenner & Block Confirmed Speakers:-Aaron Rangel, Director of Product Management, iManage
-Bennett Borden, Partner, DLA Piper
Recorded on 08-16-2023

Jul 12, 2023
Jul 12, 2023
24 min
If there was a road map for security and authentication, it’s long gone now! We’re on the road to a Passwordless future and we live in a time where no one even answers their phone! This encore ILTA podcast will quickly bring you up-to-speed and help you…and your users help themselves with better password solutions!
Questions the moderator will ask the speaker(s):
1) This topic was presented at Legal Week and was very popular. Why do you think that is?2) What are the biggest challenges to “secure” authentication today?3) What are most of us doing well, and what do most of us need to do better when it comes to our authentication implementations?4) What is the future of authentication in IT? What are some trends?If you are a listener who is overwhelmed by this topic, where do you recommend people start to become more educated in this area?Moderator:@Corey Reitz - Distinguished Cyber Assurance Architect, Sandia National LaboratoriesSpeakers:@Brian Clarke - Cybersecurity Manager, Porzio Bromberg & Newman@David Forrestall - Managing Partner, SecurIT360@Kenneth Jones - Chief Operating Officer, XerdictRecorded on 07-12-2023.

Jun 27, 2023
Should You Phish In Your Own Pond?
Jun 27, 2023
Jun 27, 2023
18 min
Are controlled phishing campaigns against your members the best way to keep your respective firm secure from phishing? This podcast session will look at phishing simulation tools, their overall pros/cons and alternatives available to keep your members secure from getting hooked with that phish.Questions the moderator asked the speaker: 1. Phishing is thought to have originated in 1995 and love bug struck in 2000. Here we are today in 2023 and phishing is still our number one vector of compromise. We've been able to reduce the risk of malware: why is phishing such a struggle?2. All security programs preach the importance of user awareness training, and it's been a requirement of clients and regulations for many years now. The majority of user awareness programs utilize phishing simulations. So, I guess the questions is, Are phishing campaigns still a good route forward? Are they being successful at training our users not to fall for that phish?3. What's the best approach for including phishing awareness into your program? Is it best to continuously cast a line or occasionally try your luck at the phishing hole?4. I've been hearing more lately about User coaching and how technology can be leveraged to protect users from themselves while presenting coaching opportunities when they do things that they shouldn't. Is this a strategy that's effective in reducing the risk of phishing? I'm not sure it would be a technology talk if we didn't speak about AI. How do you feel the future of AI impacts the threat of phishing and what steps should we be thinking about now to try and get in front of it?Moderator:@David Whale - Director Information Security, Fasken Martineau Dumoulin LLPSpeaker:@Manuel Sanchez, Information Security & Compliance Specialist, iManageRecorded on 06/27/2023

May 24, 2023
Legal Operations and eDiscovery
May 24, 2023
May 24, 2023
20 min
Legal Operations is a broad emerging discipline that encompasses all aspects of the business of law including litigation support, technology, service delivery and more. Thus, eDiscovery is a major operational consideration for law firms and corporate law departments tasked with managing and securing data. Organizations typically handle eDiscovery along a spectrum where they insource or outsource certain elements of the process. What are the risks and benefits of different eDiscovery service models? How might development of key personnel to manage aspects of service give firms a competitive advantage?
Questions Ann asked the speakers:
-How would you describe the significance of eDiscovery services as a component of legal operations for a law firm or corporation?
-What are some of the costs associated with developing talent to manage eDiscovery within the firm, and how are those costs justified?
-What additional considerations should be weighed when determining how much of the eDiscovery process to insource?
-Once you start a team, how can you grow the team and what additional areas could the group serve?Moderator:
@Ann Halkett - Director, SOLVED eDiscovery Services, a division of AHBL MLPSpeakers:
@Joy Holley - Legal Operations Consultant, Vertex Advisor
@Richard Robinson - Director of Legal Operations and Litigation Support, Toyota North AmericaRecorded on 05/24/2023

Apr 26, 2023
Apr 26, 2023
14 min
This session will focus on how companies can continuously monitor and assess their security posture by looking at drift from their control baselines in the cloud. Questions Corey asked the speaker:1) What is continuous monitoring generally and why is it important?
2) What are some of the benefits of implementing continuous monitoring in a cloud environment?
3) What are some of the different cloud security control sources that should be considered when determining what to monitor?
4) At a high level, how do you begin to implement continuous monitoring in one or more of the major cloud providers (i.e. Amazon, Microsoft, Google)?
5) What are some best practices when implementing continuous monitoring in the cloud?Moderator:@Corey Reitz - Distinguished Cyber Assurance Architect, Sandia National LaboratoriesSpeaker:Sarah Luiz - Cyber Security ConsultantRecorded on 04-26-2023

Apr 25, 2023
Apr 25, 2023
20 min
Welcome to ILTA’s Risk Management: Data Analytics & Intelligence series.
Over the course of this program, we will provide access to experts in the legal industry to discuss challenges of adoption and the benefits of using cloud technologies and Data Analytics to enhance processes, leading to efficiency, cost-savings and secured compliance.
We will review the obstacles, challenges and successes of adoption focusing on matter intelligence. How are organizations leveraging data related to client/matter lifecycle to enhance processes, compliance, and security, build relationships (Business Development), and streamline cost saving efforts. Specific topics will include, Artificial Intelligence opportunities, adoption practices, security concerns and compliance.
Questions Elizabeth asked the speakers:
1) What is the biggest challenge your organization faces today as you begin adopting Cloud Technologies and ensuring security compliance across the board?
2) As new Cloud-Based technology is adopted by your organization, describe the security concerns your organization faced, how the organization was able to move forward given the concerns and the impact on people, processes and policy once adopted.
3) What are the specific steps an organization can take to ensure a successful adoption, both from a people and system perspective?
4) Data captured at client/matter inception is used throughout an organization. What were the key factors in joining differing areas | departments (Risk, Business Development, Finance, etc.) to develop a consistent “Master Data” foundation to leverage for reporting and intelligence organization wide? Moderator:@Elizabeth Suehr - Director of Legal Risk Systems and Strategy, Jenner & BlockSpeakers:
@Damien Riehl - VP, Litigation Workflow and Analytics Content, FastCase
@James Hannigan - Director of Legal Project Management, Coblentz Patch Duffy & Bass, LLPRecorded on 04-25-2023

Jan 23, 2023
IG/Data Gov Education
Jan 23, 2023
Jan 23, 2023
35 min
What can we do as IG professionals to increase our firms understanding and acceptance of IG core values so that change management is not such a steep hill? In this session, we will explore different options.
Moderator:@Andrew Corridore - Information Governance Compliance Manager, Akin, Gump, Strauss, Hauer & Feld, L.L.P.
Panelists:@Christopher Hockey, IGP - Director of Information Governance and Management, Bond, Schoeneck and King, PLLC@Matthew Estrada - Senior Information Governance Specialist, Kirkland & Ellis
Recorded on 01-23-2023

Jan 18, 2023
Jan 18, 2023
24 min
This podcast interview session addresses how to create an insider threat/insider trust program that mitigates insider risks while respecting employee's privacy rights. Best practices and advice for starting a new insider threat program will be shared.Questions Corey will ask speakers:1) To help those who are just starting to create an insider threat/insider trust program within their company, what are some available resources that you would recommend checking out?2) What are some insider threat/insider trust best practices that you have found to be invaluable when standing up a program?3) How does a company create an insider threat/insider trust program that is effective at mitigating insider risks while simultaneously respecting employee's privacy rights? Can it be done?4) What future changes do you anticipate in the world of insider risk management in relation to tools, regulations, processes, etc. in the next 5 years?5) Should an insider threat/insider trust program be a discreet or very public function? Can you explain why you feel the way that you do?Moderator: @Corey Reitz - Distinguished Cyber Assurance Architect, Sandia National Laboratories Speakers:@Joshua Smith - Senior IT Security Analyst, Ogletree DeakinsMichael Theis - Chief Engineer & Assistant Director for Research, National Insider Threat Center, CERT/SEI, Carnegie Mellon UniversityRecorded on 01-18-2023

Oct 4, 2022
Oct 4, 2022
23 min
In this podcast interview session, the speakers discussed some challenges and solutions when implementing security in a hybrid/remote environment. In addition, they spoke about cybersecurity, regulatory issues, and ethical considerations when client data in discovery and internal investigations is accessed temporary contract attorneys working from home.Questions Jordan asked the speakers:
First, describe your roles at your respective organizations and specifically how you are involved in doc review projects
How have the information security elements of these projects, or your infosec concerns, changed over the last couple years?
What are the important items to consider when planning for a remote document review project?
Differences between “secure VPN”, SessionGuardian, other options? What are different infosec and DLP approaches and technologies you see in the market?
What are some practical, tactical, day-to-day challenges found managing WFH doc review teams … and how does enhanced attention to infosec and careful application of good tools and protocols help?
Describe the roles, goals, and challenges of the law firm, the client, the hosting provider and the doc review staffing provider in today's remote doc review project
Moderator:@Jordan Ellington - Founder and CEO, SessionGuardian
Speakers:@Scott Bilbrey - CEO, Vigilant@Todd Mattson - Chief Practice Systems & Services, Covington & Burling LLP
Recorded on 10-04-2022

Sep 23, 2022
Sep 23, 2022
12 min
This podcast reviews the various categories of vulnerability tools that should be used against custom software web applications and describe a couple of the vendors in each space. The types of scanners that will be covered include Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), Software Composition Analysis (SCA), Interactive Application Security Testing (IAST), and hiring a company to perform penetration testsQuestions that Corey will ask speaker:• What is the state of web application vulnerability testing tools today?• If you are on a tight budget, where would you consider using open source solutions over vendor offerings?• Is there a scanning category where you would not compromise, and absolutely would use a vendor solution? If so, why?• What are some of the limitations that people should be aware of when using various vendor scanning tools?• How has deploying web applications in a cloud infrastructure changed web application scanning?Moderator:@Corey Reitz - Distinguished Cyber Assurance Architect, Sandia National Laboratories
Speaker:Atahan Bozdag - Director of Information Security,MedeAnalytics Recorded on 09-23-2022

Sep 9, 2022
Sep 9, 2022
27 min
The majority of breaches today no longer come through delivered malware as our systems have become very strong with detecting and blocking these resulting in more effort than value for the attacker. Instead, it’s easier, faster and more economical to just try and steal your password, or better yet have you provide it yourself. This podcast takes a look at the security risks that are actually derived from one of our more important security controls… passwords; and look at what we can do to minimize those risks moving forward.
Questions Dave will ask the speakers:
A recent study by Verizon found that more than 80 percent of breaches through hacking involve brute force or the use of lost or stolen credentials. Microsoft estimates that there are 921 password attacks per second. We’ve been educated for years by the security industry and our awareness programs that passwords are the most crucial component to protecting our environments and our information. How is it that this sacred key to our kingdom is actually resulting in opening so many doors for attackers?
NIST has taken steps to try and reduce the bleeding with their new Password guidelines and best practices which encourage passphrases of more characters, less complexity and less changes. Are these steps in the right direction to actually keeping us secure?
Many security tools are now providing artificial intelligence around login requests that look to see if the member is coming from a known device and location prior to providing access. Would implementing these types of risk based controls with MFA and a passphrase by the answer to our problems?
Biometrics for authentication always seemed to be the next logical step for passwords. We have our basic biometrics on devices however, those are all back supported by a password or PIN. Will we ever get to a place where we’re truly only using biometrics for all authentication?
I understand that Apple, Google and Microsoft are working on a solution together that will get rid of passwords. Instead, they will just leverage the biometrics on your phone as your access code to everything. With this in mind do we just need to sit tight and all our troubles will soon be fixed?
Moderator:@David Whale - Director Information Security, Fasken Martineau Dumoulin LLPSpeakers:Sohail Iqbal - CISO, VeracodeEldon Sprickerhoff - Founder and Chief Innovation Officer, eSentirePhillip Solakov - Director, Client Solutions, Optiv, Inc.Recorded on 09-09-2022