Employers will have to show they prepared workers to avoid breaches, lawyer says

Advertisement

Advertise with us

TORONTO - Amid the mass transition to remote working as a result of the COVID-19 pandemic, most employers are likely focused on operational issues in order to get their employees up and running in their new home offices.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 01/04/2020 (2361 days ago), so information in it may no longer be current.

TORONTO – Amid the mass transition to remote working as a result of the COVID-19 pandemic, most employers are likely focused on operational issues in order to get their employees up and running in their new home offices.

However, in addition to IT issues, experts say employers would be well advised to equip and train their staff to be vigilant against data breaches during this time, as periods of upheaval present a golden opportunity for cybercriminals looking for a way into a company’s network.

In most jurisdictions, a business is typically legally responsible for breaches caused by employees, contractors and service providers.

A woman uses her computer keyboard in North Vancouver, B.C., on Wednesday, December 19, 2012. With the use of web-based video and audio conferences proliferating during the COVID-19 crisis, cyber security experts warn they pose a threat as well as an opportunity in the age of telework. THE CANADIAN PRESS/Jonathan Hayward
A woman uses her computer keyboard in North Vancouver, B.C., on Wednesday, December 19, 2012. With the use of web-based video and audio conferences proliferating during the COVID-19 crisis, cyber security experts warn they pose a threat as well as an opportunity in the age of telework. THE CANADIAN PRESS/Jonathan Hayward

“Even if they screw up — even if they did something they weren’t supposed to do by accident — the employer is on the hook,” says Brent Arnold, a partner with Gowlings WLG.

Security experts warn that criminals can take advantage of the chaotic COVID-19 situation to trick people into downloading software that can be dangerous or disruptive.

For instance, ransomware can block access to information systems until a fee is paid, potentially shutting down the organization. Other malware may steal customer information or employee passwords.

Many organizations weren’t prepared to have so many employees suddenly work from home as part of government and corporate efforts to deal with the highly contagious COVID-19 coronavirus.

Under employment law, Arnold says, an employer is usually liable for their workers unless there’s actual fraud or the employee is “doing something their not supposed to be doing — on purpose.”

“You’ll see situations where somebody also sues the employee, but it’s generally recognized that it’s the company that’s ultimately liable for this.”

But Arnold says there’s an important distinction between being at fault for something going wrong and being legally liable for the consequences of the mess that follows.

“The fact that a company gets breached doesn’t mean they are liable,” he says. “They’ll be liable if they didn’t take reasonable measures to stop that from happening.”

Arnold says most courts don’t expect the precautions to be perfect “because medium and small businesses can’t afford to take all of the possible precautions.”

But he says organizations should be able to prove to a court or regulator that they’ve taken at least the basic steps — such as setting up security technology, procedures and training.

Similarly, Arnold acknowledges that an organization may be under pressure to compensate employees affected by such as breach — the loss of a computer, for instance, or leak of family information.

“If I’m the employee, I suppose the position that I take is: you put me at risk by requiring me to do this on my own computer, on my own equipment, in my own home, using my own WiFi and you didn’t give me adequate training to spot this sort of a thing.”

It’s not likely that employees would sue, Arnold says, but it’s more possible if there’s a written employment agreement

“And, interestingly, it’s not the rank-and-file employees that we see getting caught by these (scams) all the time. It’s often executives, people who are in a hurry. . . . They’re the ones, often, who are more likely to click on an email that they’re not supposed to.”

Chandra Majumdar, who leads the national cyber threat management practice for EY Canada, says there’s been exponential growth in phishing emails that tempt the reader to click on an attachment or web link that appears to be about COVID-19 or the coronavirus.

“What we’re noticing is that the majority of the attacks — more than 90 per cent of the attacks that we’re seeing — (try to) steal your credentials, your personal information, using well-known botnets.”

Proofpoint executive vice-president Ryan Kalember says there are two known criminal groups — which he calls threat actors — dubbed TA564 AND TA542, that have been targeting Canada with emails that may look like information updates from their executive teams.

A Canadian example provided by Proofpoint shows a fairly clumsy attempt to make an email look as if it’s “Update #49984” from the Public Health Agency of Canada — a legitimate government organization — although the sender’s email address doesn’t belong to the government.

“We’re not necessarily as attuned as we ought to be to social engineering attempts (like this),” Kalember says. “Everyone is looking for information and updates. . . . to be communicated from the executives of their own company.”

Majumdar says that many companies weren’t prepared for the extent of the COVID-19 crisis but advises organizations to stick with the technology they already know if possible.

“It’s not a good idea to introduce critical changes at this point because people are not trained on this and this is how (organizations) open themselves up to being exploited by attackers,” Majumdar says.

As a lawyer, and leader of the Gowlings technology sub-group, Arnold says there may be ways for companies to protect themselves from fines and penalties by having good security practices in place for itself — but still get caught up with a breach at a smaller suppliers with less preparation in place.

Nevertheless, he says, both companies would be held accountable to privacy regulations and possibly litigation.

“The big company doesn’t get out of it by allocating the risk to the small company,” Arnold says.

“If I’m a customer who’s been affected by this, I’m probably going to sue both of them.”

This report by The Canadian Press was first published March 31, 2020.

Report Error Submit a Tip

More Stories

Remote work poses liability risks for employers

David Paddon, The Canadian Press 6 minute read Preview

Remote work poses liability risks for employers

David Paddon, The Canadian Press 6 minute read Wednesday, Apr. 1, 2020

TORONTO - Amid the mass transition to remote working as a result of the COVID-19 pandemic, most employers are likely focused on operational issues in order to get their employees up and running in their new home offices.

However, in addition to IT issues, experts say employers would be well advised to equip and train their staff to be vigilant against data breaches during this time, as periods of upheaval present a golden opportunity for cybercriminals looking for a way into a company's network.

In most jurisdictions, a business is typically legally responsible for breaches caused by employees, contractors and service providers.

"Even if they screw up — even if they did something they weren't supposed to do by accident — the employer is on the hook," says Brent Arnold, a partner with Gowlings WLG.

Read
Wednesday, Apr. 1, 2020

Lauded Manitoba author chronicled life in the Interlake

By Sheldon Birnie 5 minute read Preview

Lauded Manitoba author chronicled life in the Interlake

By Sheldon Birnie 5 minute read Wednesday, Sep. 16, 2026

Longtime Manitoba author, editor and professor David Arnason died on Monday at age 86.

Read
Wednesday, Sep. 16, 2026

Snowbird replacements ‘extremely manoeuverable, powerful,’ RCAF commander says

Kyle Duggan, The Canadian Press 4 minute read Preview

Snowbird replacements ‘extremely manoeuverable, powerful,’ RCAF commander says

Kyle Duggan, The Canadian Press 4 minute read Updated: 6:46 AM CDT

GATINEAU - The Royal Canadian Air Force welcomed on Thursday the first two of its new trainer aircraft, the CT-157 Siskin II — the same planes that will replace the old Tutor jets flown by the Snowbirds aerial demonstration team.

The turboprop planes will soon be headed to 15 Wing Moose Jaw, where the air force eventually will station 19 of them to serve as its main training fleet.

Acquiring the Siskin II, also known as the Pilatus PC-21, is part of the RCAF's plan to modernize its fleets and overhaul its training.

RCAF Commander Lt.-Gen. Jamie Speiser-Blanchet said the modern aircraft are well suited both to aerial acrobatics and to preparing pilots for the more advanced aircraft the air force is bringing online.

Read
Updated: 6:46 AM CDT

We used to love a good thunderstorm

Jessica Scott-Reid 5 minute read Preview

We used to love a good thunderstorm

Jessica Scott-Reid 5 minute read 2:00 AM CDT

Growing up on the prairies, even as a city girl, summertime thunderstorms were always cause for excitement. That first rumble signalled it was time to go search for the sleeping bags.

We’d cuddle under them on the front step, under the awning, as we watched the rain pour. And we’d stay out there until we were soaked.

If the lightning wasn’t bad enough for our parents to call us in, we neighbourhood kids would then throw on our bathing suits and go play in the warm puddles. It was some of the best stuff of summer.

As a mom now, with a little girl of my own, I was excited to watch her growing up loving Winnipeg thunderstorms, too.

Read
2:00 AM CDT

‘She was looking to destroy me’: convicted harasser faces new charges

Dean Pritchard 6 minute read Preview

‘She was looking to destroy me’: convicted harasser faces new charges

Dean Pritchard 6 minute read Yesterday at 6:54 PM CDT

When Agnieszka Ciochon-Newton moved into the 55-plus apartment building on Stradbrook Avenue last year, she came across as “timid, soft-spoken and sensitive,” said building manager Tanya Owen.

Little did Owen know the meek-looking 58-year-old woman would soon turn her life and the lives of many of her tenants upside down and threaten her career and family.

“She was looking to destroy me for a simple tenant disagreement,” Owen said Thursday.

Court records show Ciochon-Newton was arrested earlier this month and charged with seven counts of criminal harassment, two counts of uttering threats and one count each of fraud, breaking and entering, attempting to obstruct justice, intimidation of a justice official, mischief and defamatory libel.

Read
Yesterday at 6:54 PM CDT

Space war and other distractions

Gwynne Dyer 5 minute read 2:00 AM CDT

When Troy Meink, the chief of the U.S. Space Force, announces for no obvious reason that the United States “now has on-orbit space-control weapons,” people naturally assume that something is up. Why is Meink admitting the truth now? He’s even boasting about it!