Insights

Deutsch Kerrigan Article /

Cyber Security for a Remote Workforce

April 8, 2020

Victoria J. Cvitanovic and Dominik J. Cvitanovic

share this page

COVID-19 has impacted the data privacy/cyber security arena as much, if not more, than any other area of the law. The number of people working remotely has boomed due to non-essential business employers being ordered to allow their employees to work from home, executive orders restricting gathering size, and CDC guidance encouraging social distancing. This presents significant concerns to businesses without a large online distributed presence or regular remote working before COVID-19.

Businesses’ servers are being pushed to the limit to see if they can withstand much higher levels of traffic. Employee meetings are now taking place on Zoom or Google Hangout rather than a conference room, and these video streams are taking on more and more employer bandwidth. Slowdowns can result in frustrated employees bypassing common security protections, such as only viewing a confidential document through a remote desktop, to maintain their workflow and complete tasks. It is essential that businesses invest in making sure their servers are up to the task of handling remote work efficiently.

Employees are also using personal devices for work at unprecedented rates. Personal device use can open up businesses to potential threats, especially if employees have not been provided with and/or warned to use Virtual Private Networks (“VPNs”).  VPNs allow users to share data on public networks as if the devices were directly connected to a private network. Also, employees should be encouraged to keep their devices updated. Those updates users ignore are often are patches designed to fix a security flaw that was recently discovered. The longer users ignore that red number over Settings, the longer devices are exposed to those threats.

Some businesses built their data integrity infrastructure on the assumption that most business would flow through the local private network at their place of business.  With so many employees working out of the office, that assumption may no longer be accurate. The assumption that employees would be using a local private network can result in security blind spots when employees who are usually in the office begin working from home. For example, companies that do allow employees to remotely access work computers must take precautions. Employers should disable the ability to send data between their employees’ virtual desktop and the machine connected still connected at the office. Otherwise, threats from employee personal devices could use the same connection to access work computers and servers.

Due to the number of cybersecurity concerns raised by working from home during COVID-19, employers should refresh employees on their company’s employment information security policies, cybersecurity best practices, bring-your-own-device policies governing employees’ personal devices, and/or cyber incident response plans.  These policies will include recommendations to employees on company password best practices, device security requirements, and instructions not to click on blind links. If your business doesn’t have any of those, it may be time to consult with a cybersecurity attorney.

Firm Highlights

  • Experience

    Burnell Joseph v. Atalco Gramercy, LLC et al., No. 3:23-cv-505, United States District Court for the Middle District of Louisiana

    Bob Kerrigan and Jose Ruiz successfully secured summary judgment dismissal for their client, Velan, Inc., in a complex intentional tort and products liability act involving catastrophic injury. The plaintiff, a precipitation batch tank operator working at the Atalco alumina refinery in Gramercy, Louisiana, suffered severe and debilitating chemical burn injuries to his face, eyes, and body when he was sprayed with caustic liquor while working underneath a tank at the refinery. He claimed that the valve that controlled the flow of liquor into the tank was leaking, which allowed the tank to become filled with liquor after it had been previously verified as empty. He filed suit against Velan, Inc., the manufacturer of the valve that controlled the flow of liquor into the tank, alleging that the valve was unreasonable dangerous in accordance with the Louisiana Products Liability Act. He also filed an intentional tort claim against his employer, Atalco Gramercy, LLC, alleging that Atalco knew the valve was leaking and continued to force employees to work underneath the tank. He claimed that under these conditions, an incident such as his was substantially certain to occur. Following the close of discovery, Velan moved for summary judgment dismissal of the plaintiff’s claims was appropriate because: (1) the plaintiff’s injuries were a result of Atalco’s misuse of the valve; (2) the plaintiff lacked the expert testimony needed to prove his theory of liability under the Louisiana Product’s Liability Act; (3) the Velan valve at issue was not unreasonably dangerous as defined by the Louisiana Products Liability Act; and (4) the plaintiff was unable to prove proximate causation needed to establish his case of liability against Velan. The Hon. Brian Jackson found that under the undisputed facts presented by Velan, summary judgment was appropriate and dismissed the plaintiff’s claims against it, with prejudice.
  • Insight

    No Mercy for Employers in Louisiana Supreme Court’s Recent Magill Decision

    In its recent per curiam opinion, Magill v. Werner Enterprises, Inc. of Nebraska[1], the Louisiana Supreme Court has foreclosed a routine defense strategy to shield employers from direct negligence claims. The high court has extended their 2022 decision in Martin v. Thomas[2], and now allows plaintiffs to pursue direct negligence claims against an employer despite the employer’s stipulation that its employee was in the course-and-scope of employment and caused the accident. Essentially, employers who fail to implement better employment practices will permit plaintiffs to ramp up potential exposure with evidence, if such exists, that heretofore they were routinely barred from introducing at trial. The Supreme Court’s Magill holding should encourage employers to update where needed their policies and procedures pertaining to hiring, training, supervising, and entrusting duties and property to employees, not only for the safety of their employees and customers in this state, but also eliminate employer’s exposure to direct negligence claims. Prior to Martin, a litigation strategy had taken shape where employers stipulated to 1) an employee being in course-and-scope of employment at the time of the accident, 2) that the employee was at fault for the accident being caused, or 3) both. By stipulating these facts, employers were largely able to exclude evidence of any direct negligence on part of the employer and/or narrow the scope of trial to only a contest of the plaintiff’s injuries. The Supreme Court in Martin held that despite an employer admitting their employee was in course and scope when the accident occurred, plaintiffs could pursue direct negligence claims against the employer—as the issue of liability had not been admitted. Accordingly, employers found success by admitting both course and scope and liability—as seen in the Western District of Louisiana’s holding in Ferguson v. Swift Transp. Co. of Arizona[3]. In Ferguson, the defendants stipulated that their employee was acting in course-and-scope at the time of the accident and their employee was 100% at fault for the accident being caused. Due to the employer’s stipulation of fault, Judge Wicks of the Western District of Louisiana held that Martin did not apply and that plaintiffs could not pursue direct negligence claims. In Magill, the Louisiana Supreme Court provided scarce reasoning for their decision. The high court simply affirmed the District Court’s expansion of the holding in Martin and that the employer’s reliance on the Western District’s Ferguson holding was a misapplication of Louisiana law. The Supreme Court also cited the decision in Tardo v. Farrell.[4] where the Fifth Circuit held that even if an employer and employee stipulate to course and scope and fault, those admissions do not eliminate direct-negligence claims because those claims remain separate issues for the trier of fact. The Fifth Circuit notably stated, “the societal decisions as to who actually pays does not change the manner of assessing fault to all parties as required by law.” This statement raises concern, as plaintiffs may now attempt to challenge employer stipulations that historically narrowed trials. The Supreme Court did not explain its reliance on Tardo, so future litigation will likely clarify the decision’s full impact. Under Magill, plaintiffs are permitted to pursue direct negligence claims against the employer despite the employer admitting that their employee was acting in course and scope at the time of the accident and their employee was 100% at fault for the accident being caused. The full effect of the Supreme Court’s decision remains to be seen. In praxis, Magill will permit plaintiffs to put on evidence of direct negligence by an employer in front of a jury who cannot assign fault—as fault has already been stipulated to by the defendants. Employers now face the practical risk that plaintiffs will encourage juries to increase damages as a form of punishment against an employer that admits fault but contests the nature and extent of the plaintiff’s injuries. Employers should use this moment to rigorously review and strengthen policies and procedures related to hiring and training in order to limit exposure when plaintiffs assert direct-negligence claims.  [1] Magill v. Werner Enterprises, Inc. of Nebraska, 2025-00892 (La. 11/12/25) [2] Martin v. Thomas, 21-01490 (La. 6/29/22), 346 So.3d 238 [3] Ferguson v. Swift Transp. Co. of Arizona, 17-1570, 2023 WL 173413 (W.D. La. Jan. 12, 2023) [4] Tardo v. Ferrell, 25-123 (La. App. 5 Cir. 5/28/25), 2025 WL 1516837 (unpublished).