A question from an international law firm, at a round table meeting last week, about the Legal Practice Council's ("LPC") attempts to educate South African lawyers on technology generally, and AI in particular, clarified local attorneys' views that not much was being done. 🌐 Well...I'm pleased to see that the LPC has just proved us all wrong. The LPC, on Friday last week, published the new Practical Vocational Training (PVT) Structured Coursework Programme for Candidate Legal Practitioners (CLP) for 2026 onwards. 👩🎓 A significant chunk of the coursework forming part of the attorneys admission exams will require knowledge of IT related matters. CLPs will be assessed on both their knowledge of technology law and the use of technology to enhance and improve their law practices. 👨💻 The coursework will cover topics such as: ☑️Introduction to information and communication technology for legal professionals; ☑️ Awareness of cyberattacks; ☑️Security of personal information; ☑️Protective risk management strategy; ☑️Awareness and protecting against fraudulent transfers out of the trust account; ☑️Data response plans addressing technology, organisational processes and staff training; ☑️Responsibility for personal/ commercial information; ☑️Specific cyber security tips; ☑️The future of artificial intelligence as a boon and a threat to legal practitioners; ☑️The use of technology in the legal industry, including electronic discovery and case management systems; ☑️The legal framework for cyber law in South Africa, including the Electronic Communications and Transactions Act and the Protection of Personal Information Act (I'm not sure why the Electronic Communications Act and Cybercrimes Act were left out though); ☑️Cybersecurity and data privacy considerations for legal professionals and their clients; ☑️Ethical and professional considerations when using technology in practice; and ☑️Drafting policies and procedures for technology use in a law firm. This is exciting news because, for years, I've spoken at many South African legal sector events urging lawyers to "get with the programme". With technology now being comprehensively incorporated into CLP training, we're going to see a whole new generation of tech savvy lawyers! 🤖 👩⚖️ #TechLawyers #FutureOfLaw #AILawyers #LegalInnovation
Cyber Law Awareness
Explore top LinkedIn content from expert professionals.
Summary
Cyber law awareness means understanding the rules, regulations, and responsibilities related to digital information, cybersecurity, and online conduct. As technology becomes central to legal practice, staying informed about cyber law helps both legal professionals and organizations protect sensitive data and comply with privacy standards.
- Know your legal duties: Regularly review and update your knowledge of privacy laws, cybersecurity regulations, and contractual obligations to ensure your practice meets current standards.
- Build strong partnerships: Work closely with legal and IT teams to coordinate incident response, clarify authorization boundaries, and address cyber risks together.
- Invest in training: Encourage ongoing education in cyber law for yourself and your colleagues so everyone understands how to handle cyber threats and protect client data.
-
-
During cybersecurity incidents, I have found that my best ally in almost every case hasn't been the CISO. It's been the company's legal department. That's not to say the CISO hasn't been *an* ally, but I've come to find that the attorneys I work with have a better grip on the legal risks that incidents and subsequent response action(s) pose. Just because we have the technological capability to do certain things across employee endpoints, doesn't mean we should, and it could be potentially illegal depending on the circumstances. 📜 BYOD + State Privacy Laws If an employee uses a personal device under a BYOD policy, and your IR team accesses personal photos, texts, or banking apps in the process, you may have just violated California's CCPA, Illinois BIPA, etc. 📜 The Electronic Communications Privacy Act (ECPA) Intercepting or accessing stored electronic communications (even on a company-issued device!) without proper authorization triggers ECPA exposure. You need legal sign off on the scope of endpoint monitoring first. 📜 The Computer Fraud and Abuse Act (CFAA) If incident responders access systems or endpoints beyond what's explicitly authorized in policy or by the device owner, the company could face civil liability under the same law usually invoked against a threat actor. Not every attorney is up to speed on where incident response and insider risk management intersects with these laws. Cybersecurity practitioners and leaders should still pursue their own continuing education on cyberlaw and ask questions of counsel. But CISOs and cybersecurity leaders also need to make sure they understand their lane relative to their function within the business. In most cases we advise, not decide. Deferring to the company's legal team can help protect you. Make friends with them. Make use of it.
-
🚨 𝐀𝐧𝐨𝐭𝐡𝐞𝐫 𝐀𝐮𝐬𝐭𝐫𝐚𝐥𝐢𝐚𝐧 𝐋𝐚𝐰 𝐅𝐢𝐫𝐦 𝐇𝐢𝐭 𝐛𝐲 𝐚 𝐂𝐲𝐛𝐞𝐫 𝐀𝐭𝐭𝐚𝐜𝐤: 𝐀 𝐖𝐚𝐤𝐞-𝐔𝐩 𝐂𝐚𝐥𝐥 𝐟𝐨𝐫 𝐭𝐡𝐞 𝐋𝐞𝐠𝐚𝐥 𝐒𝐞𝐜𝐭𝐨𝐫 🚨 Brydens Lawyers has confirmed a ransomware attack, with cybercriminals allegedly stealing 600GB of sensitive client and firm data. While the full extent of the breach is still being investigated, this incident is yet another reminder that law firms remain prime targets for cyber threats. Law firms have clear cyber obligations – are we meeting them? 🔹 Legal and regulatory obligations – The Privacy Act, professional conduct rules, and contractual obligations with clients are sources of strict data security requirements. 🔹 Regulatory expectations – Legal regulators, including the Law Society and state-based regulators, have minimum security expectations for firms, including appropriate governance, risk management, and security controls. Compliance isn’t just best practice—it’s a professional obligation. 🔹 Cyber governance, not just training – A well-governed firm doesn’t just run annual cyber training and call it a day. Effective cyber governance includes: ✅ Leadership accountability – senior management must take ownership of cyber risk, not just IT teams. ✅ Incident response planning – ensuring the firm is ready to respond quickly and decisively. ✅ Ongoing cyber hygiene – regular testing, risk assessments, and meaningful engagement with cybersecurity risks at all levels of the firm. 🔹 Client expectations – Many corporate and government clients now require specific cybersecurity measures in legal service contracts. Firms that fall short risk losing work. This isn’t just a theoretical risk—it’s happening right now. Law firms need to ask: 📌 Do we meet (or exceed) the cybersecurity standards expected by regulators? 📌 Would we be able to respond effectively if we were attacked tomorrow? 📌 Are we investing in governance, not just ticking compliance boxes? Cybersecurity is an organisation wide issue. Law firms must lead by example. https://lnkd.in/gNnk5-um #CyberSecurity #LawFirms #Privacy #DataBreach #CyberRisk #LegalEthics #cyberattack #cyber
-
I can’t be the only one who thinks it’s time for a Cybersecurity Law Certification — not covering the technical side (that’s for the cybersecurity engineers), but the areas that cybersecurity lawyers navigate daily. IAPP: Imagine a certification (and an accompanying reference book) that validates expertise across at least these six domains: 1. Regulatory & Compliance: Cybersecurity regulations (e.g., NIS2, SEC disclosure rules, NYDFS, HIPAA Security Rule), and industry standards/frameworks (NIST CSF, ISO 27001, PCI DSS, FedRAMP). 2. Incident Response: Legal guidance during incidents as advising on reporting deadlines, managing privilege over forensic investigations, drafting breach notifications, and coordinating with regulators and law enforcement. 3. Vendor Management: Pre-contracting to post-contracting activities as negotiating cybersecurity clauses, advising on supply chain security, and embedding warranties, liability caps, and audit rights. 4. Governance & Risk Management: Advising boards and executives on cyber governance, fiduciary duties, liability exposure, risk registers, policies, compliance roadmaps, and cyber insurance. 5. Cross-Border & Emerging Tech Issues: Navigating data localization, cross-border transfers, and global investigations, while tracking evolving laws like the EU Cyber Resilience Act, DORA, and China’s Cybersecurity Law. 6. Enforcement & Litigation: Representing companies in regulatory inquiries and enforcement actions (FTC, SEC, Data Protection Authorities), managing shareholder suits and class actions, addressing potential criminal liability under cybercrime laws, etc. Such a certification would not only formalize what we already practice, but also strengthen the recognition of “Cybersecurity Law” as its own discipline within the legal profession.
-
October is Cybersecurity Awareness Month, and a timely reminder that cyber incidents aren’t just technical events, they’re legal ones too. In the latest episode of our Tools of the Trade podcast, I’m joined by Ana Bruder and Stephen Lilley, partners in Mayer Brown’s Cybersecurity & Data Privacy practice, to discuss why calling a lawyer after a cyber incident is a critical first step. We cover legal risks, regulatory obligations, law enforcement coordination, ransomware response, and practical prevention tips. 🎧 Tune in to learn how legal strategy strengthens cybersecurity: https://lnkd.in/g2-Bujqb Learn about how Mayer Brown participates in Cybersecurity Awareness Month and access our insights and resources here: https://lnkd.in/gfuE2Bu4 #CybersecurityAwarenessMonth #ToolsOfTheTrade #MayerBrown