Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Digital Evidence

Cyber Defense

Security teams are under pressure to do more than wait, and some proposed measures feel like common sense until someone asks whether they are lawful. The answer usually depends on whose systems and whose data a measure touches.

Reviewed

01 GUIDE

Cyber Defense: what usually happens

Your network, their network

Inside its own environment, a company generally has wide latitude to watch, block, and isolate. The line moves once a measure reaches outside, and so-called hacking back into an attacker's infrastructure can itself be unauthorized access under federal and state computer crime laws, whatever the motive. That can include logging into a server the attacker controls using credentials found during the investigation. Deception tools such as decoy files and honeypots are widely used, but design matters, for instance whether a beacon reports back from someone else's machine. Before trying anything that touches a system you do not own, the safer course is to involve law enforcement or the relevant provider.

Watching your own people

Monitoring sits at the center of cyber defense, and it is also where employment and privacy law meet. New York requires private employers that monitor employee phone, email, or internet use to give prior written notice and to post that notice, and other states have their own rules on monitoring and recording communications. Reading the contents of personal accounts accessed from a work device raises different questions from reviewing company systems. Biometric sign-in tools can trigger specific statutes in some states. A defensible monitoring program usually rests on a written policy employees have acknowledged and on a clear security purpose, with access to what is collected kept narrow.

Sharing what you learn

Exchanging threat information with peers, industry groups, and government partners helps everyone, and federal law has offered certain protections for sharing cyber threat indicators through recognized channels. Those protections come with conditions, including removing personal information not needed to describe the threat, and their status has not been static. Contracts with customers and vendors may also restrict what you can disclose about an incident or a vulnerability. When companies ask us about defensive measures, we review the proposed tool or practice against the systems it touches, the data it collects, and the agreements already in place, so the security team knows where the boundaries are before an incident tests them.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

03 CASE RESULTS

Matters we have handled

Prior results do not guarantee a similar outcome.

05 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

06 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about cyber defense and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.