Monday, November 7, 2011

Dealing With A Ghastly Scandal

"Appalled" would be far too mild a word to describe my reaction to the Penn State sexual assault allegations.

For those of you looking for a lesson as to how something awful can totally spin out of control for your organization, review that first sentence. "… the Penn State sexual assault allegations." Not the Jerry Sandusky sexual assault allegations-this awful episode is now totally within the Penn State brand. It doesn't matter that Sandusky, a former longtime defensive coordinator for the PSU football team, was no longer working for the University when these terrible events started coming to light. The incomplete and apparently uncoordinated response of the PSU leadership to what was witnessed and reported by a graduate student places a significant amount of blame at the very top of the Penn State athletic department.

We know from reading the initial reports that there may be a valid legal defense for the two Penn State administrators, who have been arraigned on charges of failing to report criminal sexual activity involving children, and perjury. We know that iconic coach Joe Paterno is not accused of any legal wrongdoing. But surely somebody at least contemplated whether there could be a valid moral, public relations or business justification for failing to do more on the information the athletic department received in 2002.

Irrespective of the fact that what was being reported was a criminal sexual assault on a child by an individual with almost total access to the Penn State athletic facilities, and who enjoyed the trust of everyone at the University, I have to believe that some adult in this miserable process thought about what this would be like if the administration's attempt to sweep it under the rug was unsuccessful, or if the benign assumption about Sandusky was wrong. How someone could possibly believe that there was any type of upside - moral, business, personal - in not making this a formal investigation and complaint is simply staggering.

Under the circumstances, it's probably wise to revisit a few of my basic truisms about corporate conduct. No. 1 -- whitewashing something like this and being found out almost always creates a situation far worse than does reporting the misconduct when it first surfaces. No. 2 -- a cover-up will almost always be found out; and the worse the conduct, the more likely the cover-up will be unsuccessful. No.3 -- there is no proper explanation, at least not one that you can make and continue to look at yourself in the mirror each day, for not intervening to stop a sexual assault on a child, and/or not immediately reporting what you observed to the police. No.4 -- there are certain circumstances in which there is no such thing as the "benefit of the doubt."  And last -- the more difficult the choice confronting the organization (i.e., confronting the individuals in the organization making the choice), the more likely that the easy choice is the wrong one.

All of us know how we would like to think we would act in circumstances similar to those confronting Joe Paterno, his graduate assistant, and the Penn State athletic director and Penn State's senior vice president for business and finance. Reminding ourselves of the truisms above might help our decision-making process become closer to our ideal.

UPDATE:  I agree with the assessments expressed here.

UPDATE #2:  The inevitable conclusion (note that there has been sentiment to ask Paterno to step down for some time; this provides the obvious mechanism since he seemed impervious to hints).  The PSU Board and its alumni supporters simply could not stand the thought of showing up at the remaining games this season and being confronted by protests and signs saying "Welcome molesters", and the like.  As the article says, someone finally decided to act like an adult at State College.  The decision comes at least 13 years too late.

Friday, November 4, 2011

Boston, Florida

There are any number of reasons not to have a business located in Massachusetts-the lousy weather, the Boston driving experience, the high taxes, the overregulated and pro-union employment law regime-you know, the whole blue state thing. So while companies are willing to have some element of their operations there, it makes sense for the the prudent employer to keep as many people on the outside of the Massachusetts state line as possible.

Imagine, then, the surprise and frustration of the employer in a recent Bay State court case that found itself defending claims under the Massachusetts Wage Act brought by an employee who lived in Florida, and based his sales operations for the company from his home there. He sued in Massachusetts Superior Court, alleging that his former employer owed him more than $100,000 in unpaid commissions and accrued vacation pay.

Although the company tried to dismiss the case for lack of jurisdiction, sensibly arguing that the employee was not covered by Massachusetts law, a state judge found differently. Noting that the sales director had business cards that listed the corporate offices in Massachusetts for contact purposes, that the sales paperwork was sent to and from Massachusetts, and that the employee frequently traveled to Massachusetts to confer with the company representatives, the court determined that there were sufficient, contacts with the Commonwealth to allow application of Massachusetts law. The fact that the employee also frequently traveled to 30 other states where he had customers, and did not physically live or work in the state, was of no import.

This is a troubling result, for several reasons. Not the least among them--the Wage Act mandates treble damages and attorneys fees for successful plaintiffs.

Anyone with employees who consistently conduct business in Massachusetts should assess whether they may unintentionally subject themselves to the jurisdiction of Massachusetts state courts as a result. At the very least, it would be smart to take steps to minimize regular activity that involves contact with, or travel to Massachusetts, to avoid a similar claim.

Disclosing Cyber Security Risk Assessments

In what I would characterize as a hat tip to the obvious, the SEC Corporate Finance division issued Disclosure Guidance requiring public companies to do a better job of advising investors about so-called "cyber security risks". In a classic example of closing the door of a horseless barn, the Commission is finally getting around to telling companies that they really should be paying attention to information technology problems that might affect the value of their stock.

From my perspective, the cyber security issue often begins with the employees of a company. The easiest access into a company's information technology system is through an employee, either deliberately or as a result of day-to-day IT security sloppiness. In fact, hackers now are much more likely to simply target specific employees, or groups of employees, to insert their malware into a company system. For example, at EMC Corporation's RSA security unit, which manufactures computer log-in devices used throughout the industry, two small groups of employees received e-mails containing an innocuous, corporate type message, and attached spreadsheet labeled "2011 Recruitment plan." One employee retrieved the file from the spam folder and when she opened the attachment, she introduced a virus inside the company network that eventually gave a hacker access to proprietary company data, allowing it to conduct later attacks against RSA's customers.

It's getting easier than ever to conduct this type of spear phishing attack because of the wealth of private and corporate data contained in sites such as Facebook, or LinkedIn. Companies should be vigilant about training their staffs with respect to unsolicited e-mails from unknown addresses, and particularly the attachments contained in those e-mails. This is in addition to the training that should be going on with respect to things like flash drives, iPods, and other potentially affected hardware that gets plugged into the company server.

The SEC guidance is not particularly helpful, but it does provide a map of at least minimal diligence for disclosure to investors. Public companies are expected to evaluate cyber security risks within their operations and then figure out some way to disclose these risks to investors, without at the same time opening the door to an attack from a hacker who reads the SEC filings. I'm glad I don't have to draft that particular notice.

The Commission also notes that disclosure should occur in the event of an actual data breach. In particular, a company should factor in whether a potential or actual breach exposed it to lengthy government investigation or costly third-party claims, caused significant business interruption, or undermined the value of the company's services or reputation, or led to substantial remediation costs.

Finally, (and this sounds like a semantic nightmare), companies are required to disclose conclusions on the effectiveness of their required SEC disclosures.  So if a cyber attack could affect the company's ability to disclose the required information to the SEC, the company has to disclose that its ability to disclose its ability to disclose its ability to disclose… could be affected as a result of an IT intrusion. 

Fun stuff, huh? The short answer is that every organization, but especially those that sell public stock, should be policing their IT programs at the highest level.  That means senior executive involvement, and perhaps more nerdiness in the so-called C-suite. 

Wednesday, November 2, 2011

If at First You Don't Succeed…

Sue, sue, again. At least that's the approach of the plaintiffs' litigation team in the late and unlamented Dukes v. Walmart litigation that was unceremoniously bounced from the ranks of class-action cases by the Supreme Court last year. You may recall that the Court determined that the Ninth Circuit's approval of the class of approximately 1.5 million women who worked at Walmart during the relevant period was inappropriate and improvident. The majority on the Court focused on the allegation in the class certification that the plaintiffs were all similarly affected by Walmart's centralized policy of decentralization that allowed individual store managers to make employment decisions based on a scheme affected by centralized and pervasive anti-woman bias.
If that sounds like unmitigated lawyer doubletalk, then you agree with Justice Scalia and the rest of the majority.
The plaintiffs' law firm has now refiled the case, this time on behalf of only 90,000 current and former female employees who work for Walmart in California. But this doesn't seem to solve the problem mentioned above-that if these decisions were decentralized, it's almost per se impossible to certify a class based on the resulting treatment. In fact, this will be Walmart's defense in this case--namely that each individual employment decision, or at least each individual store manager's employment decisions, will stand on their own and cannot provide the basis for such a wide-ranging class.
The plaintiffs are alleging that they have new statistical evidence that was not put before the Supreme Court in the original litigation. Short of some kind of clear link between these thousands of employment decisions at issue, plaintiffs may find it's "class dismissed", even in the relatively employee-hospitable environs of the Ninth Circuit.

Tuesday, November 1, 2011

Bootstrapping Time?

I am an infrequent reader of the press releases put out by the Department of Labor, EEOC, and other federal executive agencies because they are frequently agency propaganda about how well they're doing, and fairly transparent attempts to justify why they should receive more tax dollars. But a recent release by DOL relating to an overtime and back wages settlement involving Hilton Reservations caused my eyebrows to jump a little. It wasn't the size of the settlement that caused me some consternation, although $715,000 is nothing to sneeze at. Rather it was the fact that DOL found that Hilton had not complied with the Fair Labor Standards Act by not paying for pre-working shift activity such as booting up the computer, and opening programs required to assist customers, such as e-mail programs.
This is noteworthy, because many employers do not start recording compensable work time until an employee's computer terminal is functional. In fact, in many businesses, employees actually login using their computer terminals, which cannot be done until the computer is booted up and running. That the Department considers this working time to be compensated and calculated into overtime is striking.
For employers that are not counting computer start up time as time worked, it would be a good idea to assess how much time is involved in this process, and keep an eye out for other enforcement reports by the DOL on the subject. There may be a significant alteration in how time is tracked in your future.

Thursday, October 27, 2011

Miracles Still Occur

In our memories especially.  Today is the fourth anniversary of one of the strangest plays in college football history, the Trinity-Millsap Lateral-fest.

Feast your eyes here.

Wednesday, October 26, 2011

Why You Should Actually Read Your Employment Practices Liability Insurance Policy

Important safety tip: all of you with EPLI insurance should run, do not walk, to where your policy is stored, and read the policy carefully. Pay particular attention to the scope of coverage, because if it says you are covered for charges or lawsuits brought against you by an employee, you are not going to be covered in a suit brought by a federal agency, such as the EEOC. At least, that's what Cracker Barrel discovered recently, to the tune of $2 million plus.

What happened in the case was that 10 current or former employees brought employment discrimination charges against the company over a period of several years. The EEOC consolidated the charges into one lawsuit, and transformed it into a wide-ranging class-action. Years later, the case settled for some $2 million in damages and more than $700,000 in attorneys fees.The company's EPLI insurer refused to pay the settlement, citing language in the policy that defined a covered claim as "a civil, administrative, or arbitration proceeding commenced by the service of a complaint or charge, which is brought by any past, present or prospective employee(s)."

The court backed the insurer, noting that the plain language of the policy does not apply to litigation brought by a federal agency, which is clearly not a "past, present or prospective employee" of the company.

So, a quick suggestion-make sure your EPLI policy covers not just actions brought by current or former members of your workforce, but also addresses those situations where your company is the luckless target of federal, state, or local agency legal attention.