The “Use of Unique & Individualized Log-in Credentials & Passwords” is one of the most critical cybersecurity initiatives that an employer may take as part of taking reasonable measures to protect confidential information and trade secrets. Having exhausted the list of those cybersecurity initiatives in previous discussions, we now switch gears and focus on another critical issue in this blog post and Part XI of the series. As an important question for all employers and as it concerns the protection of their trade secrets, who should employers involve with and engage in the oversight of a business or company’s trade secrets?
Assigning Responsibility for Trade Secret Oversight in a Business
It is critical for employers to identify, assess, and evaluate how activities and undertakings such as the acquisition of new information containing a trade secret, the implementation of expansion plans, or the creation of new product lines influence and implicate their cybersecurity needs. An employer may appoint and select an individual or group of people to make such assessments, which, by acting as pillars of implementing reasonable efforts for maintaining trade secrets, empowers the employer to keep the details of their trade secret(s) confidential and secret.
However, employers should take caution when selecting and deciding the individual(s) who would be entrusted with oversight of their trade secrets. Irrespective of their relationship with the employer, some of the employees who may be the most qualified to make the assessment and evaluations related to what needs protection and how it should best be protected include, but are not limited to those with technical, legal, and business experience, those with access and visibility across the company or business, and those in senior positions. While an employer may need to create such a position(s) to serve this purpose, a chief legal officer, chief information security officer, chief information officer, a person in a similar position, or a task force comprising such individuals might be the most appropriate for the job.
Depending on the size, nature, and type of a company or business, and if applicable, the employer should seek updates and follow up with the information technology department regularly to streamline communication between the department and facilitate effective operations across those who are tasked with managing the business or company’s intranet and software. Finally, while it still varies with the nature of the company or business, it would also be crucial to involve the employer’s executive committee and/or board with matters involving information security and any cybersecurity measures the employer has put in place and/or implemented.
In Part XII, we shall move the discussion forward by hammering on the “Trade Secret Loss/Theft Response Plan: Best Employer Practices.”
Stay tuned for more legal guidance, training, and education. In the interim, if there are any questions or comments, please let us know at the Contact Us page!
Always rising above the bar,
Isaac T.,
Legal Writer, Author, & Publisher.
