{"id":418,"date":"2019-01-29T17:15:34","date_gmt":"2019-01-29T17:15:34","guid":{"rendered":"http:\/\/events.multisite.legal500.com\/event_report\/the-risk-debate-silver-linings-playbook\/"},"modified":"2020-02-07T11:40:13","modified_gmt":"2020-02-07T11:40:13","slug":"the-risk-debate-silver-linings-playbook","status":"publish","type":"event_report","link":"https:\/\/my.legal500.com\/events\/report\/the-risk-debate-silver-linings-playbook\/","title":{"rendered":"The risk debate: silver linings playbook"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-700140\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/main-2-1-1.jpg\" alt=\"\" width=\"1900\" height=\"1140\" \/><\/p>\n<div class=\"editorial column span-20\">\n<div class=\"column span-13 sjpages last\">\n<div class=\"roundtabletextcontainer\">\n<div class=\"gcprofile1\">\n<div class=\"textheaderpagetop insight_feature\">\n<div class=\"roundtabletext\">\n<p class=\"firstpara\">The decade since the fall of Lehman has seen some dramatic changes to the profession, not least law firms\u2019 risk teams. Ten years since Legal Business first collaborated with broker Marsh to create our annual risk management and professional indemnity survey, progress has been made but the threats to the key players within the industry have become more ominous.<\/p>\n<p>We gathered together leading risk experts from some of the UK and international firms most affected by increased regulatory scrutiny, geographical cohesion, data security and PR disasters to reflect on the evolution of law firm risk management and look ahead to see how the landscape could develop over the next ten years.<\/p>\n<p>***<\/p>\n<p><strong><em>Mark McAteer, Legal Business: 86% of respondents to our survey said the risk management culture of law firms has improved over the last decade. Does anyone disagree?<\/em><\/strong><\/p>\n<p><strong>Justine Cowling, DLA Piper:<\/strong>\u00a0There is an organic understanding and appreciation now from partners that we can help them to win business. They feel more confident if they have spoken to the risk team in advance of taking a particular action than if they do not. That, alongside us growing our teams, has really helped our culture.<\/p>\n<div class=\"pullquote\">\n<figure id=\"attachment_700137\" aria-describedby=\"caption-attachment-700137\" style=\"width: 664px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-700137 size-full\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/bigby_nicole_and_robertson_angela-1-1.jpg\" alt=\"\" width=\"664\" height=\"410\" \/><figcaption id=\"caption-attachment-700137\" class=\"wp-caption-text\"><strong>Angela Robertson (right), Taylor Wessing:<\/strong> Perceptions have changed as to what risk means. Partners used to think risk was all about business intake.<\/figcaption><\/figure>\n<p><strong style=\"font-size: 1rem;\">Andrew Cheung, Dentons:<\/strong><span style=\"font-size: 1rem;\">\u00a0In a self-serving sense, it would be great to see you publish that it is top-quality risk managers and general counsel that have caused this improvement in risk culture. However, in reality, a lot of it has to do with legal sector disruption over the last ten years. Client disruption and regulatory disruption are two big factors, as well as disruption caused by technology. These have forced law firms and lawyers to rethink legal service delivery and, fundamentally, what it means to be a lawyer. I believe that this, more than anything, has transformed the perception of risk and compliance in law firms from business prevention to business as usual.<\/span><\/p>\n<\/div>\n<p><strong>Angela Robertson, Taylor Wessing:<\/strong>\u00a0Perceptions have changed as to what risk really means because, up until relatively recently, partners used to think risk was all about business intake; it was about conflict and money laundering, doing your client\u2019s due diligence. As that put barriers in the way of taking on new clients and matters, it did not necessarily go down well. When I set up a team in Clifford Chance back in 2000, it was a business intake team. When you look at how things have changed since there is more dimension to the role.<\/p>\n<p><strong>Roger Butterworth, Bird &amp; Bird:<\/strong>\u00a0We have become effectively an in-house legal department, almost a firm within a firm, which is different and it is recognised as that.<\/p>\n<p><strong>Nicola Gillespie, Linklaters:<\/strong>\u00a0We also have dedicated risk partners in each of our offices who work closely with the central risk team. We are seen much more as peers now. Linklaters was one of the first law firms to set up a risk management function, starting with a small team in about 2000 of only three people. I remember having an early discussion with our board about engagement letters. It\u2019s fair to say that there was limited interest. By contrast this year at our recent annual partners\u2019 conference, we had our managing partner talking about the importance of engagement letters \u2013 and that was unprompted, without anyone in the risk function asking for the subject to be referred to. I have seen a huge evolution in the approach to risk over the years, with partners now driving forward initiatives.<\/p>\n<blockquote>\n<p class=\"pullquote\">\u2018We have moved towards \u201cdo whatever the client asks\u201d, which has its dangers, but people are now appreciating that you have to look after the firm.\u2019\u00a0<em>Roger Butterworth, Bird &amp; Bird<\/em><\/p>\n<\/blockquote>\n<p><strong>Nicole Bigby, Bryan Cave Leighton Paisner:<\/strong>\u00a0We have now started to support a lot of the client-facing work. Partners recognise that we have a deep understanding and practical experience of how to implement all sorts of regulatory changes. We see that now across tax evasion, money laundering, sanctions, GDPR, and broader systems and regulatory controls approaches where we have a huge amount of experience.<\/p>\n<p><strong>Debbie Jukes, Eversheds Sutherland:<\/strong>\u00a0What that allows you to do as well is to partner the fee-earning teams. All those areas that you mention we have worked closely with our fee-earning teams who are out there selling these services to clients. We have the benefit of having experienced resource in technical areas you could never buy in and they have the experience of implementing advice practically. For me that is a real win-win. That partnership is something I have been working on very closely over the past year. It pays such dividends.<\/p>\n<p><strong><em>Mark McAteer: Do you think one of the reasons why there has been this cultural shift is partners now prefer going to their clients and saying, \u2018I need to talk to my risk team about this before I can go ultra vires\u2019?<\/em><\/strong><\/p>\n<p><strong>Andrew Clark, Allen &amp; Overy:\u00a0<\/strong>There is certainly more of that. What has changed is really the client piece and the fact that we are so much more focused on connecting the work we do to clients and client relationships. If all of our work is centred on clients there is little problem selling risk or the value of the risk part of the firm. Once you move away from that it becomes more difficult. The challenge for us all going forward is that we are covering all those important bases but are we being successful in ensuring risk awareness is permeating across the culture of the firm.<\/p>\n<figure id=\"attachment_700138\" aria-describedby=\"caption-attachment-700138\" style=\"width: 664px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-700138\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/cheung_andrew_dentons-1-1.jpg\" alt=\"\" width=\"664\" height=\"410\" \/><figcaption id=\"caption-attachment-700138\" class=\"wp-caption-text\"><strong>Andrew Cheung, Dentons:<\/strong>\u00a0\u2018Client and regulatory disruption have forced law firms to rethink legal service delivery.\u2019<\/figcaption><\/figure>\n<p><strong>Nicola Gillespie:<\/strong>\u00a0I wonder also if one of the factors in the growth of a risk management culture in law firms is that many partners have grown up with it in the way that previous partners had not. There will have always been a risk and compliance or in-house legal function during their time at the firm.<\/p>\n<p><strong>Roger Butterworth:<\/strong>\u00a0When I started out people used to say, \u2018Look after yourself first, look after the firm second and look after the client third,\u2019 which was meant as a bit of a joke but there is a reason for it. We have moved towards \u2018do whatever the client asks\u2019, which has its dangers but in a proper way people are now appreciating that, yes, you have to look after the firm.<\/p>\n<p><strong><em>Mark McAteer: Is there still a struggle for a lot of firms as they get larger to create a consistency in risk management?<\/em><\/strong><\/p>\n<p><strong>Andrew Clark:<\/strong>\u00a0There are certain things you can do: you can have global risk management policies; you can have anti-corruption and anti-money laundering, share dealing, whistleblowing policies and so on, but there is an element that also has to be done locally. You are not able to police every contract or other commitment the firm is entering into in all of its locations. The danger is that things fall between the gaps because the more we do on risk management, the more that is expected, and the more that is assumed.<\/p>\n<figure id=\"attachment_700141\" aria-describedby=\"caption-attachment-700141\" style=\"width: 664px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-700141\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/matthews_alison_shoosmiths-1-1.jpg\" alt=\"\" width=\"664\" height=\"410\" \/><figcaption id=\"caption-attachment-700141\" class=\"wp-caption-text\"><strong>Alison Matthews, Shoosmiths:<\/strong>\u00a0\u2018There is always a time lag in claims \u2013 the challenge is anticipating where the claims may come from and what bear traps others have encountered.\u2019<\/figcaption><\/figure>\n<p><strong>Juliet Tainui-Hernandez, Norton Rose Fulbright:\u00a0<\/strong>It is a multi-faceted attack. I do not think it is just down to the risk team and it is not just down to the management. The longer we have the risk management function in place the better it gets, because each year you can add something additional, and then we just turn the screws slightly. We are partnering now with our fee-earning teams to drive training.<\/p>\n<p><strong>Angela Robertson:\u00a0<\/strong>It is definitely moving on. Part of it is down to the perception that since risk teams started evolving they have tended to be UK-based with smaller teams in some other jurisdictions to take account of time differences. Because that was largely regulatory driven, ie UK regulatory driven, there has been scepticism on the part of some of the international offices. Part of it is just this perception that the UK is seeking to drive everything and it is difficult to break that down, unless there is a client focus.<\/p>\n<p><strong><em>Mark McAteer: The last ten years was about establishing the risk culture centrally. Is the next main challenge to establish that more systemically across the board?<\/em><\/strong><\/p>\n<p><strong>Nicole Bigby:\u00a0<\/strong>It is the balance. Our position is not dissimilar to the challenge that many of our in-house teams and clients have. They are being asked to do more continuously with less. We have expanded and have done a huge amount of work internally with the board to be very clear about what we do and do not do. So we have a very clear mandate. But also we are quite clear with the business about where there are issues where it makes time and good sense for my team to be involved and where the issues are immaterial. Things need to come to me only when they are material, because otherwise you are everything to every man and every woman. That is not manageable.<\/p>\n<blockquote>\n<p class=\"pullquote\">\u2018The really significant risks are information security risks: that we do not take care of data or we are shown not to have taken care of data.\u2019\u00a0<strong><em>Jo Riddick, Macfarlanes<\/em><\/strong><\/p>\n<\/blockquote>\n<p><strong>Roger Butterworth:\u00a0<\/strong>I agree. They have to be trusted to sometimes work it out themselves and make the right decision.<\/p>\n<p><strong>Nicole Bigby:\u00a0<\/strong>Yes, and have a measure of self-responsibility and be resilient.<\/p>\n<p><strong><em>Mark McAteer: GDPR and associated data threats across the board have created even more pressure this year. We know that IT and data security is a top-ranking issue every year. Has it been noticeably different in the last 18 months?<\/em><\/strong><\/p>\n<p><strong>Roger Butterworth:\u00a0<\/strong>Yes, absolutely. It has happened to one law firm here unfortunately. It can happen to any of us and if you have something that looks like a data incident you have to drop everything else, track it down and deal with it.<\/p>\n<p><strong>Justine Cowling:\u00a0<\/strong>We have considered it important that our clients and community know about the cyber incident which affected us \u2013 how the malware operated and the extensive damage it caused in a very short period of time. But it would have been a lot worse if we had had client data taken, which we did not. Due to the incredible sophistication of the incident, while we had a good indication, we could not confirm that with 100% certainty within the first 72 hours. So that makes life interesting given our new reporting obligations.<\/p>\n<p>People know already that we were not targeted \u2013 we were collateral damage, which demonstrates that this is also a geopolitical risk that as law firms we are all facing and all organisations are facing. On the upside, it gives us now more than ever the ability to say that we need to put security first in everything we do. It is not just about storage of data and making that secure, but about how we control data.<\/p>\n<div class=\"pullquote\">\n<figure id=\"attachment_700139\" aria-describedby=\"caption-attachment-700139\" style=\"width: 664px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-700139 size-full\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/clark_andrew_a_o-1-1.jpg\" alt=\"\" width=\"664\" height=\"410\" \/><figcaption id=\"caption-attachment-700139\" class=\"wp-caption-text\"><strong>Andrew Clark, Allen &amp; Overy:<\/strong>\u00a0\u2018You cannot police every contract. The danger is things fall between the gaps because the more we do on risk management, the more that is assumed.\u2019<\/figcaption><\/figure>\n<p><strong style=\"font-size: 1rem;\">Jo Riddick, Macfarlanes:\u00a0<\/strong><span style=\"font-size: 1rem;\">The really significant risks for all of us are information security risks: that we do not take care of data or we are shown not to have taken care of data. They exist today as much as they will do on 25 May. We can do everything we like about accountability and transparency, chopping down retention periods and cutting HR and marketing data \u2013 which we are all doing \u2013 but the fundamental risks are exactly as they are now: that we do not take care of client confidential and personal data and that exposes us, not just to the regulators, but crucially to our clients and reputationally. That is the big one.<\/span><\/p>\n<\/div>\n<p><strong>Nicola Gillespie:\u00a0<\/strong>What concerned me, Justine, is that our technology team told me that DLA Piper\u2019s IT security was excellent. If that was the case then that does make us all think we must be exposed.<\/p>\n<p><strong>Justine Cowling:\u00a0<\/strong>A number of other firms\u2019 IT people called us within 48 hours to say: \u2018We are set up in exactly the same way.\u2019 The legal sector needs to learn here. We need to up our game and start looking at other sectors, including the financial sector to see what they do.<\/p>\n<p><strong>Andrew Carpenter, Marsh:\u00a0<\/strong>Talking to the cyber insurers, they are more concerned about a firm\u2019s response. The assumption is that you have protections in place and you are looking after your data, but your reputation is key. How you respond to the incident is what is important. It is important to you, from a reputational perspective, for keeping your client. From their perspective, as an insurer, it is responsiveness, and containing and resolving the incident. How are you going to implement your business continuity plan or how are you going to respond to something like that? Who are you going to bring in? Who is your PR consultant? Is your senior management team ready to deal with this?<\/p>\n<blockquote>\n<p class=\"pullquote\">\u2018The assumption is you have protections in place and are looking after your data, but your reputation is key. How you respond to the incident is what is important.\u2019\u00a0<strong><em>Andrew Carpenter, Marsh<\/em><\/strong><\/p>\n<\/blockquote>\n<p><strong>Jo Riddick:\u00a0<\/strong>The issue is giving out information when you do not know what is happening. Being silent is the very worst thing in the world you can do.<\/p>\n<p><strong>Stephen Morton, Marsh:\u00a0<\/strong>Your risks do not fit the natural silos of insurance products. A big cyber breach can cover reputational damage; it can pull in the management; you suddenly have a professional indemnity issue with clients. It covers all of those elements. So the policies will evolve, but the first step is joining up and making sure that those liability policies you hold \u2013 employment practices, management liability, crime, cyber and professional indemnity \u2013 respond effectively.<\/p>\n<p><strong><em>Mark McAteer: With all these risk issues coalescing, are insurance premiums going to go up?<\/em><\/strong><\/p>\n<p><strong>Andrew Carpenter:\u00a0<\/strong>There was talk of premiums going up. Since the start of the year, my perception is that reserves are being reviewed and rating models re-evaluated. So placing the first \u00a310m or \u00a320m of professional indemnity insurance cover is not necessarily straightforward. There is still little competition in the market for it. There are very few insurers writing it and some meaningful claims are there. You cannot get away from it, but a lot of the claims relate back in time. There are not that many that are current work related. There is a sense the financial crisis is still sorting itself out.<\/p>\n<p><strong>Alison Matthews, Shoosmiths:\u00a0<\/strong>There is always a time lag in relation to claims \u2013 the challenge is in trying to anticipate where the claims may come from and what bear traps others have encountered.<\/p>\n<div class=\"pullquote\">\n<figure id=\"attachment_700142\" aria-describedby=\"caption-attachment-700142\" style=\"width: 664px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-700142\" src=\"\/events\/wp-content\/uploads\/sites\/5\/2019\/01\/tainui-hernandez_juliet_nrf-1-1.jpg\" alt=\"\" width=\"664\" height=\"410\" \/><figcaption id=\"caption-attachment-700142\" class=\"wp-caption-text\"><strong>Juliet Tainui-Hernandez, Norton Rose Fulbright:<\/strong> \u2018The longer we have the risk management function in place the better it gets, each year you add something, and then we just turn the screws.\u2019<\/figcaption><\/figure>\n<p><strong style=\"font-size: 1rem;\">Andrew Carpenter:\u00a0<\/strong><span style=\"font-size: 1rem;\">There is a time lag. That is giving insurers an ability to look at their rating models. There is still capacity out there. There is less than last year but there is still capacity and competition. There may be an adjustment going on but it is not a massive, seismic change. I would not say it is doomsday out there at all.<\/span><\/p>\n<\/div>\n<p><strong>Nicola Gillespie:\u00a0<\/strong>That is next year, isn\u2019t it..?<\/p>\n<p><strong>Andrew Carpenter:\u00a0<\/strong>I do now know, but insurers are taking a long time to make a decision about pricing. It is pricing by committee. You need time to complete your renewals.<\/p>\n<p><strong><em>Mark McAteer: Thank you all for your time.<\/em><\/strong><\/p>\n<p>Click\u00a0<a href=\"https:\/\/www.legalbusiness.co.uk\/analysis\/unstoppable-the-annual-legal-business-risk-survey\/\">here<\/a>\u00a0for the Legal Business Risk survey in full<\/p>\n<div class=\"boxoutstyle\">\n<h2>PANELLISTS<\/h2>\n<ul>\n<li><strong>Nicole Bigby<\/strong>\u00a0Bryan Cave Leighton Paisner<\/li>\n<li><strong>Roger Butterworth\u00a0<\/strong>Bird &amp; Bird<\/li>\n<li><strong>Andrew Cheung\u00a0<\/strong>Dentons<\/li>\n<li><strong>Andrew Clark<\/strong>\u00a0Allen &amp; Overy<\/li>\n<li><strong>Justine Cowling<\/strong>\u00a0DLA Piper<\/li>\n<li><strong>Nicola Gillespie<\/strong>\u00a0Linklaters<\/li>\n<li><strong>Debbie Jukes<\/strong>\u00a0Eversheds Sutherland<\/li>\n<li><strong>Alison Matthews<\/strong>\u00a0Shoosmiths<\/li>\n<li><strong>Sarah O\u2019Neill<\/strong>\u00a0Addleshaw Goddard<\/li>\n<li><strong>Jo Riddick<\/strong>\u00a0Macfarlanes<\/li>\n<li><strong>Angela Robertson<\/strong>\u00a0Taylor Wessing<\/li>\n<li><strong>Juliet Tainui-Hernandez<\/strong>\u00a0Norton Rose Fulbright<\/li>\n<li><strong>Mark McAteer<\/strong>\u00a0<em>Legal Business<\/em>\u00a0(Chair)<\/li>\n<li><strong>Andrew Carpenter<\/strong>\u00a0Marsh<\/li>\n<li><strong>Stephen Morton<\/strong>\u00a0Marsh<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"secondary-sidebar column span-6 last sjpagesright\">\n<div class=\"roundtable_righthand\">\n<div class=\"rankingspos5 advertising\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"featured_media":0,"template":"","class_list":["post-418","event_report","type-event_report","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/event_report\/418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/event_report"}],"about":[{"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/types\/event_report"}],"version-history":[{"count":4,"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/event_report\/418\/revisions"}],"predecessor-version":[{"id":10985,"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/event_report\/418\/revisions\/10985"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/events\/wp-json\/wp\/v2\/media?parent=418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}