Listen to this episode

Most Law Firm's are low hanging fruit for hackers

0:0038:08

Recorded November 2020. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella speaks with Alex Pearce about why law firms, especially small ones, are attractive targets for hackers. Pearce explains that criminals know firms centralize sensitive client information and have historically lagged in securing it, and he says law firms have come to be identified as the soft underbelly of corporate America.

They discuss high profile incidents, including the Panama Papers and business email compromise scams that trick firms into redirecting real estate wire transfers. Petronella recounts a client case in which a three person firm lost over half a million dollars after a phishing attack let hackers spy on email and alter wire instructions. Pearce argues most firms probably do not train and test staff regularly, and he notes that, at the time of recording, North Carolina's state bar had recently enacted a continuing legal education requirement covering technology. The conversation also covers client driven security demands, ransomware incidents Petronella Technology Group helped address, front end prevention, cyber insurance underwriting, lawyers' ethical duties, and the California Consumer Protection Act.

Worth remembering

Key takeaways

  1. Law firms concentrate sensitive client information in one place and have historically lagged in securing it, which Pearce says makes them attractive, high value targets for criminals.
    “Criminals have figured out that law firms tend to be places where sensitive information is collected and centralized in one place.”
  2. Pearce argues phishing scams depend on individual vigilance, so firms should run training exercises that trick employees into clicking, which he calls the most effective lesson.
    “I think there's nothing more effective to have someone teach someone a lesson and trick them into a training exercise into clicking on something.”
  3. Beware business email compromise: Craig recounts a three person firm losing over half a million dollars after hackers spied on its email and impersonated wire instructions.
    “And then they impersonated, Oh, no, those weren't the right wire instructions we sent them. These are the right ones. Bam, lost over half a million dollars.”
  4. Pearce argues investing in front end prevention is the better use of time and money, since dealing with an incident is far more expensive.
    “I always think it's better to invest in front-end prevention. And that's the better way to spend your time and money and resources.”
  5. Pearce calls insurance a big and important piece of overall risk management but only a piece, hoping nobody relies exclusively on it against cyber risk.
    “I think insurance is a big and important piece of the overall risk management program, but just a piece.”
  6. Pearce explains that ethical rules on competence and confidentiality have been interpreted as a duty to take reasonable measures to secure client information, scaled to each firm's operations.
    “We have ethical rules that include competence and confidentiality, and notices have been interpreted as including implicitly or in some cases explicitly serve a duty to take reasonable measures to secure client information.”
  7. Craig argues firms should check up on their security every year and do risk assessments rather than assume what they bought last year is still good enough.
    “We can't just make assumptions and speculate that we're okay because what we bought last year might no longer be good enough.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Most Law Firm's at easy targets for hackers and cybersecurity threats because they lack good cybersecurity hygiene. Learn how Security Risk Assessments and basic cybersecurity controls can significantly increase the cybersecurity maturity level of a law firm to make hackers move on to an easier target.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.