The Panama papers and Paradise papers cyberattacks against law firms. The issues of data harvesting emerging from the Cambridge Analytica scandal. The volume of reported data breaches. Cyber-attacks and data breaches are becoming inevitable as increasingly high quantities of information are stored electronically. In addition, GDPR has introduced requirements to notify the relevant supervisory authorities and individuals who may be adversely impacted much more promptly (within 72 hours of becoming aware).
As a result, there is a greater need for stronger controls around data security, both within your organization and for companies holding your data. A robust records management policy is integral to your company’s ability to understand what information is available, where it is, and in what format. Most importantly, it sets a clear framework for handling, managing, and storing that data.
You may have agreements with your external partners on how they manage and handle your data; historically, companies may have relied on this with little further investigation.
However, if you have ever handled the fallout of a data breach by one of your suppliers, you will appreciate the pressures of trying to assess the potential risk and exposure the breach might have on your company. All of which must be done within very tight timescales if you need to notify the authorities and individuals concerned.
USING LEGAL SPEND MANAGEMENT SOFTWARE TO IMPROVE DATA SECURITY
One often-overlooked tool that can help (both with an immediate investigation and future risk assessments) is a legal spend management system (Onit’s European legal spend management solution BusyLamp eBilling.Space). Integrated legal spend and matter management software can provide a wealth of information to help legal operations understand and manage the data that the law firms hold for you and can support you in building a records inventory.
Legal spend management tools can provide clarity on the following:
- The external law firms used,
- What type of work outside counsel are undertaking, and
- Who at the law firms has worked on the matter and therefore had access to your data.
Knowing the data shared with your law firm is vital for an immediate investigation. Access to the matter details in your legal spend management system will provide you with a good starting point to gather information. Basic information will include the law firm’s name and the person(s) in your firm who may be working on the matter(s). It will also provide a contact point at the law firm. Finally, based on the work, you will have a rough idea of the documents shared with the firm.
If you are looking to assess the risks of sharing your data both now and in the future, legal spend management software will provide details of the number of times your company has used the firm. With this, you can assess the risks and controls in place with all your outside counsel and carry out appropriate system security assessments. You can also more easily check that the law firms have implemented and are complying with your records management and retention policies.
The amount and sensitivity of the data sent to your law firms comes from the type of work undertaken. Most companies will generally share similar types of data for specific categories of work with their external partners. As an example, for an employment issue, details about the employee and the grievance will be shared with the external counsel. Using the information in a legal spend management system about the types of work done by the law firms will help you assess the risks and controls each law firm has in place to protect your data and consider the best and most appropriate ways to transfer your data. Furthermore, it can help you build your records inventories.
Finally, as law firms record the time that a timekeeper spends working on a matter, invoice data captured by e-billing software will allow you to see who has access to your information at the firm.
Knowing and understanding the type and volume of data that your company has shared with your law firms will help you a) respond to and manage any data breach or data loss and b) understand the potential risks to your data. This knowledge will help you assess whether you are using the best legal technology for sharing your data and whether the processes you have in place to transfer your data are appropriate.
Learn more about BusyLamp from Onit, our end-to-end legal spend management solution built for European corporate legal departments.


Kanchan Joshi is one of Onit’s Customer Success Engineers in our Pune, India office. Over Kanchan’s nearly two years with Onit, she has played an essential role in delivering quality support to our customers, believing that “quality speaks for itself!” Kanchan’s team received one of the highest rating NPS scores and believes that her “success story is about playing an important role within the team and working towards achieving customer delight!” Kanchan sees that all four of Onit’s values make the company succeed by not only working towards a few of them, but by balancing and applying the appropriate value in the right situations.

Alexandra Divin is a program manager in Onit’s Houston office. Throughout her three years at Onit, Alexandra has led her team to a multitude of project completions and continuously provides insight and guidance through milestones of our implementations. Recently, Alexandra faced the challenge of getting an implementation back on track. She was able to gain back the client’s trust, work through the various challenges, and continue to drive towards a successful go live despite the hurdles they previously experience.
Sejal Supariwale is a quality assurance engineer in Onit’s Pune, India office. Over the past 18 months, Sejal has played a critical role in the quality of Onit’s solutions delivered to our clients. Sejal and her team were part of delivering a tool to efficiently validate the system fields and their attributes specified by clients which are then produced in a report. By delivering this tool, the team has been able to reduce field testing from 2-3 days down to 2 hours in addition to automating manual tasks. This is crucial to the success of Onit’s solutions delivered to our clients. Sejal embodies Onit’s value of passion as she continues to create something new, conceptualize a new idea and thrive to produce the best output: “I had, I am and I will always be driven by this force.”
Josie Johnson is Onit’s marketing director in our Houston office. Over the past year, Josie has served an essential role in planning and executing Onit’s exceptional events such as tradeshows, customer forums, special event dinners, and so much more. Josie has been able to see the success of her team blossom over the past year as a specific member began in the “starting out” phase and transitioned to the “growth and development” phase of a marketing events manager. Josie feels rewarded each time she sees this member take on a challenge and succeed. Josie is presenting Onit’s value of purpose each and every day as she sees the company rowing in the same direction rather than struggling against the currents that may come our way. This overall creates more positivity for Onit’s customers and the employees.















