Introduction 1 / 8
Case study · 6–8 minutes

Priya's Wednesday

An eight-attorney firm. A confidential merger matter. And a paralegal who did absolutely nothing wrong.

This walkthrough shows how a firm can be compromised without anyone clicking a bad link or opening a bad file — and why that possibility matters to the standard of care rather than only to the IT budget.

You will be asked to predict what happens at several points. The wrong answers are the ones most attorneys pick, which is what makes them worth working through.

No technical background needed. Any term appears like this — — and you can tap it for a plain-English definition at any time.

Scene 1 · Wednesday, 12:15 p.m.

An article over lunch

Priya is a paralegal at the firm. Over lunch she reads State Bar Weekly, a legal news site she has visited most weeks for four years.

🔒 statebarweekly.com/practice/fee-agreement-amendments
Practice Management

Proposed amendments would reshape fee agreement disclosure

A working group has circulated draft amendments that would expand written disclosure requirements for contingency arrangements, drawing early comment from practitioners in several districts.

Valid certificate · the real site · the real article

She clicked no link in an email. She opened no attachment. She downloaded nothing. She read an article on a site she trusts, and closed the tab.

What she could not see is that attackers had quietly compromised State Bar Weekly some days earlier, and were serving malicious code to a fraction of its visitors.

What could Priya have done differently?
Consider it seriously before answering. Most people assume there was something.
Scene 2 · 12:15 p.m.

What loading the page did

The compromised site exploited a flaw in Priya's web browser — one the browser's maker does not know exists. Simply rendering the page was enough to install software on her laptop. No prompt appeared. Nothing was downloaded that she could see.

That is a . The vendor has had zero days to fix it. There is no update to install, because nobody has written one. And no antivirus has a description of it, because nobody has seen it before.

Does the firm's antivirus catch this?
The firm runs a reputable product, kept current.
Scene 3 · 12:16 p.m.

The call home

A minute later the newly installed program opens a connection out to a server the attacker controls, and waits for instructions.

It uses on the standard web port — the same protocol as every site the firm visits all day.

Does the firm's firewall block that connection?
The firm has a business-grade firewall, properly installed.
Scene 4 · That night

"But our documents are in the cloud"

Priya left at 5:30. Her LexVault session is still open in her browser, the way it is most evenings.

Late that night the malware uses that session to work through a confidential merger matter belonging to one of the firm's clients — and begins downloading every document in it.

Priya has never worked on that matter.

LexVault is a secure cloud platform with strong controls. Are the client's files safe?
This is the most common assumption among firms that have moved to the cloud.
Scene 5 · The same day, twice

What each setup sees

Identical attack. Identical firm. The only difference is whether anything is watching behavior.

Antivirus + firewall only
With behavior monitoring

Tap any alert on the right to see why that moment was abnormal.

Scene 6

Four things to take away

1
This attack needed no mistake by anyone.Nobody clicked a bad link or opened a bad file. The same zero-day could just as easily have arrived through an email, a routine software update, or a document from opposing counsel.
2
Zero-day attacks have no signature.Tools that work by recognizing known threats cannot see something never seen before. That is a structural limit, not a product defect.
3
Firewalls check where traffic goes, not what is happening on your computer.The malicious connection looked exactly like ordinary browsing, because the attacker made it look that way.
4
Your cloud platform's security ends where your laptop begins.LexVault was never breached. Everything happened on one laptop, through one real session.

Antivirus and firewalls are still necessary. They are just no longer sufficient. They stop a large volume of routine, known attacks every day, and removing them would be a serious mistake. The gap is specifically the attacks built to be new.

The first takeaway is the one worth sitting with. Training matters, and a firm should still run it. But a defense that depends on every person being alert every time is a defense that assumes away the case you just read.

If it is widely known that antivirus cannot detect zero-day attacks, is relying on it alone a reasonable effort?

That is a question about foreseeability, and it is one each firm has to answer for itself. Nothing on this page answers it for you.

Scene 7

Reasonable efforts checklist

Three quick questions, then a six-item review of your firm.

Question 1
What could Priya have done to prevent the infection?
Question 2
Why did the document platform allow the downloads?
Question 3
What made the attack detectable on the monitored side?

Six questions about your firm

Nothing is recorded or sent anywhere — this runs entirely in your browser.

Reasonable efforts

See how EDR protects law firms →

Priya's Wednesday is an illustrative composite, not a report of a specific incident. LexVault, State Bar Weekly, and the firm are fictional. Document counts and times are used to show how an attack unfolds and are not statistics. References to professional responsibility are general and simplified; the Model Rules are not themselves binding and states adopt their own variations. Nothing here is legal or ethics advice — consult your own counsel or bar association about your obligations.