Showing posts with label Litigation Readiness. Show all posts
Showing posts with label Litigation Readiness. Show all posts

Sunday, December 13, 2009

E-Discovery and the role of the CIO?

E-Discovery is one of the hottest legal issues facing companies today. In simple terms, E-discovery is a firm's obligation to produce all documents or information in its possession, including documents that exist only in electronic form, in the event of initiated or threatened litigation. With that obligation comes costs and risk: the costs of potentially reviewing millions of pages of electronic information, and the risk of failing to understand the information that the company itself is creating.

As the head gatekeeper of corporate information, the CIO faces many issues around E-discovery. For example, what information retention strategy should the CIO put in place in view of the fact that the company may one day face a significant lawsuit? And what should the role of the CIO be when the organization is threatened with a lawsuit?

Here are five key issues around E-discovery that the CIO needs to be aware of:

1. Litigation is an active and strategic focus of the business

It is important to recognize that in today's business climate, litigation is not always a last-resort alternative. Increasingly, it is becoming an active strategy of the business and is being critically assessed, based on its potential to generate a positive return on investment.

Other strategic factors, such as the potential impact on the organization's reputation and the ability to create competitive advantage, form part of the equation in evaluating litigation as an ongoing strategic focus.

2. In-house counsel should play an important role in information access and management

In many organizations, the in-house counsel group is treated as a separate silo -- a necessary adjunct that is strictly a cost of doing business -- and its role is to react to problems once they arise. But in-house counsel can also be an excellent resource for the CIO, assisting in the building of IT strategies around access to information, document retention, document destruction, information collaboration, and litigation.

E-discovery includes an obligation to preserve all relevant electronic evidence as soon as litigation is threatened or contemplated. That obligation simply cannot be fulfilled in the absence of complete information about the company's information structure and technology. And whose obligation does it become, the CIO's or in-house counsel's? This is an issue that the company needs to address.

3 more issues to come in the next blogpost....

Saturday, August 15, 2009

In the Event of an eDiscovery Emergency, Break Glass: Preparing for the Inevitable

The incredible information explosion of the last decade -- including the proliferation of collaboration tools such as Sharepoint and all other Web 2.0 applications, text messages, voicemails sent directly to email, social networking, IM messages -- together with the stiffening of records retention consequences and the increasingly stringent records requirements on corporations have all contributed to creating an Information Management Perfect Storm for today's corporation. Courts and regulators expect corporations to know what information and records they have, where same are located/stored, and also to be able to identify, collect, retain, and produce such information in a timely fashion and in a useful (i.e. native) format.

Not having a well thought out information management structure that is adhered to by all employees and a means for quickly organizing the various information repositories and tools can cost more than just money. It can also cost a corporation in terms of lost claims, insufficient defenses, tarnished reputation, and employee frustration and turnover.

Assuming that a corporation has done as much as it possibly can to organize its information and records in a logical fashion while at the same time capturing appropriate metadata and doing all of the other fundamental records management activities, here are two specific things that a corporation can do to prepare for the inevitable litigation, as it is only a matter of time before the corporation wants to sue or is itself sued by another corporation or individual.

Prepare an eDiscovery "Break Glass" Plan

The obligation to preserve records/evidence in any litigation matter arises when litigation has commenced (i.e. the statement of claim has been issued) or it is reasonably foreseeable that litigation will occur. So what happens then? Obviously, relevant records need to be preserved, but how does your corporation go about doing that? It is absolutely essential that an "In the Event of eDiscovery, Break This Glass and Follow These Steps" plan is prepared in close consultation with a corporation's in-house and external legal counsel.

Some of the items to consider in preparing the "Break Glass" plan are as follows:

1. Who is on the eDiscovery Dream Team and who is responsible for notifying them of the actual or threatened litigation? The eDiscovery Dream Team likely comprises your external counsel, who will in all likelihood be leading the charge, together with in-house counsel, IT professionals (system architects, records management system administrators), members of the business that were involved in a particular deal or matter during the honeymoon (which is now ending in divorce) and so on.

2. How will custodians of information/records be identified?

3. Who will prepare the preservation/hold letter or email to send to all custodians?

4. Who will be responsible for taking physical or electronic possession of all relevant records and information sources (i.e. hard drives, etc.)?

5. What procedures will IT use to ensure that all records are collected and stored, including how metadata will be managed, the format that files will take, and so on?

6. When and how will external vendors form a part of the process?

7. Depending on the matter (e.g. termination of an employee), what needs to be done forensically to restore hard drives?

8. What internal auto-deletion processes need to be turned off and for which users/custodians?

Test the "Break Glass" Plan: Carry Out an eDiscovery Fire Drill

It is one thing to have a plan in place, but how well does it work in reality? As the potential consequences of getting eDiscovery wrong can be quite disastrous (for example, imagine if the information collection process/tool changed all of the metadata and made it impossible for any of the records to be authenticated, meaning they were inadmissible in court? Imagine further that in this example, the amount of money at risk in the claim could make or break your company...), it is important that all players involved, from internal IT, Law, and Business groups to external counsel and eDiscovery/records vendors, know their roles and responsibilities and that there are back-up personnel in place in all key areas that know what needs to be done, as timing will be critical.

Make sure that your external consultants and counsel evaluate how well the plan worked and implement their suggestions to improve the process. Every eDiscovery will have its nuances, but if you can have a eDiscovery Break Glass Plan in place, it will at least cover the most important bases and drive your corporation to continually improve its eDiscovery and records management capabilities, which will minimize the cost of eDiscovery and put you in the best position possible to win or significantly reduce potential losses through litigation.

Thursday, July 23, 2009

Questions to Ask Prospective eDiscovery Vendors

When it comes to implementing an eDiscovery product or service, it is extremely important to know what you exactly need. In the eDiscovery realm, customer needs are extremely diverse. Some organizations need a full-service provider to put together soup-to-nuts eDiscovery process support while others need only forensic collection support.

The diversity of requirements and various product offerings makes it difficult to select the perfect eDiscovery vendor. In addition, as the main drivers behind implementing eDiscovery systems and procedures are compliance, litigation readiness, and fine/sanction avoidance (and vendors are well aware of this fact), it is often difficult for an organization that is in the early stages of developing its eDiscovery capabilities to distill the fear-mongering messaging of certain vendors down to what services those vendors actually provide and, most importantly, whether those services are a fit. Please find below a glimpse of a few key questions to be asked of potential vendors.

You will want to break down the questions in the following categories: collection, processing, review, production and pricing models and specific pricing for both implementation and per eDiscovery process that you run. The first four categories are major parts of of eDiscovery process and vendors often specialize in one or two of those activities.

Questions About Collection:

  • How is paper-based information brought into the eDiscovery process?
  • What methods of electronic collection exist (e.g., remote agent desktop collection, disk imaging)?
  • What methods are used to initiate a defensible chain of custody and secure access?
  • How quickly can tapes be restored? What is the cost of tape restoration? Is this a native capability or provided by partners?
  • What methods are used to identify/fingerprint documents?
  • How is chain of custody preserved and spoliation avoided?
  • Where and how is metadata managed and preserved?

Questions About Processing:

  • What culling methods exist?
  • Can culling happen at the point of collection?
  • How is data extracted from different types of media?
  • Are attachments extracted from emails and processed as separate documents? If so, how are they associated with the original email message?
  • Does the product/service support both static and dynamic encryption?
  • Are documents converted to a standard type for review? If so, what type and if there is additional cost?
  • How is deduplication performed (e.g. within custodians, across custodians)?
  • What is the average indexing speed?
  • What methodology is used for metadata management?

Questions About Review:

  • For native file reviews, are native applications required?
  • Does the review application have workflow support?
  • What kind of statistics are provided to manage the workflow?
  • What type of access rights are enabled (e.g. by function or by data)?
  • How are documents indexed and categorized?
  • Are double-byte characters indexed?
  • How is "concept" searching defined and enabled?
  • How is value-add metadata managed?
  • What security protocols are used?
  • How is redaction enabled?
  • How many simultaneous reviewers can the system support?
  • What is the average document to document speed?

Questions About Production:

  • What output options are available (e.g., native, TIFF, PDF, load files)?
  • What is the average turnaround time for exporting data?
  • How does the product support Bates numbering?
  • What fonts are supported?
  • How is output to multiple languages handled?
  • Are there any partners for production services?

Questions About Pricing Models:

  • What software pricing models are available (per user, per CPU, etc.)?
  • Are there recurring charges for installed software (other than typical maintenance fees)?
  • Is there an ASP offering? If so, how is it priced?
  • How is data processing charged (e.g. per GB)?
  • Are there different pricing models for load files to different review applications?
  • What is included in management consulting (e.g., strategic guidance, computer forensics, technology consulting)?

Hope this is useful for all who are trying to move forward with eDiscovery solutions.