Law Firms

Nobody clicked anything. The firm was breached anyway.

Most security training for firms teaches people to spot bad emails. This case study is about the attack that gives them nothing to spot — and what that means for the standard of care rather than the IT budget.

No mistake

was required

No link clicked, no attachment opened. A defense that depends on everyone being alert every time does not address this case at all.

Rule 1.6(c)

reasonable efforts

Attorneys are expected to make reasonable efforts to prevent unauthorized disclosure of, or access to, information relating to a representation.

Competence

includes technology

Most states now recognize that maintaining competence includes keeping abreast of the benefits and risks of relevant technology.

Priya's Wednesday

An interactive case study for attorneys, partners, and office managers. A paralegal reads a legal news article over lunch. By midnight a confidential merger matter is leaving the firm. Takes 6–8 minutes and ends with a reasonable-efforts checklist for your own firm.

Open the case study in a full window → Better on a phone, and easier to circulate to the firm.

Training assumes there was something to catch.

Awareness training is worth running, and it stops a great deal. But an attack that arrives through a trusted site gives even a careful person nothing to decide and nothing to decline.

What remains is whether anything in the firm would notice a laptop or an account behaving unlike itself — and whether anyone would see it that night, rather than when a client calls.