Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

<b><i>Online Extra:</b></i> Am Law 200 Firms Spending $7M on Cybersecurity Annually

By Chris DiMarco
August 31, 2015

With unfettered access to critical documents and information, law firms are an attractive target for hackers. Even when firms employ cutting-edge data security techniques, their possession of corporate data still multiplies the surface area of risk for that information. A recent survey of the Am Law 200, which tapped nearly one-third of firm CIOs for their experience, is showing the extent to which the highest grossing firms are spending to mitigate the risk associated with data security.

According to the findings of Chase Cost Management's 'What Price Peace?”survey'spending on information security at Am Law 200 firms rarely exceeds 1.9% of gross annual revenue. Firms spent around $6.9 million on average, though the survey cautions some of that may have gone to non-cybersecurity projects.

While the survey was able to determine the average that respondent law firms were spending on these efforts, harder to determine was whether or not that was enough. Respondents split 50/50 on whether their spending was 'about right' or 'not enough,' though predictably, no respondents indicated there cybersecurity spending was 'too much.'

Firms also varied in what areas they were spending. When asked to rank their top three spending priorities, respondents most frequently indicated a need to strengthen in-house security expertise (22.2% of respondents). The runners-up priority wise split three ways: Assessment to identify gaps in security posture, cyber liability insurance policy and risk transferring, and training for employees to increase awareness each made the priorities list 12.1% of the time.

Overall, the survey suggested that the priorities set by firms were positive. Chase Cost Management wrote, 'Traditionally, many law firms have chosen, likely to control expenses, to give the CIO or IT Director the responsibility for security management and an existing network systems engineer the responsibility for security operations. A hands-up survey of the audience suggests that most firms still do not have dedicated security staff. However, there were a few, albeit larger firms, who have managed to get support for four and five FTEs who are focused on information security initiatives.”


Chris DiMarco writes for'Legaltech News, an ALM sibling of e-Commerce Law & Strategy.

With unfettered access to critical documents and information, law firms are an attractive target for hackers. Even when firms employ cutting-edge data security techniques, their possession of corporate data still multiplies the surface area of risk for that information. A recent survey of the Am Law 200, which tapped nearly one-third of firm CIOs for their experience, is showing the extent to which the highest grossing firms are spending to mitigate the risk associated with data security.

According to the findings of Chase Cost Management's 'What Price Peace?”survey'spending on information security at Am Law 200 firms rarely exceeds 1.9% of gross annual revenue. Firms spent around $6.9 million on average, though the survey cautions some of that may have gone to non-cybersecurity projects.

While the survey was able to determine the average that respondent law firms were spending on these efforts, harder to determine was whether or not that was enough. Respondents split 50/50 on whether their spending was 'about right' or 'not enough,' though predictably, no respondents indicated there cybersecurity spending was 'too much.'

Firms also varied in what areas they were spending. When asked to rank their top three spending priorities, respondents most frequently indicated a need to strengthen in-house security expertise (22.2% of respondents). The runners-up priority wise split three ways: Assessment to identify gaps in security posture, cyber liability insurance policy and risk transferring, and training for employees to increase awareness each made the priorities list 12.1% of the time.

Overall, the survey suggested that the priorities set by firms were positive. Chase Cost Management wrote, 'Traditionally, many law firms have chosen, likely to control expenses, to give the CIO or IT Director the responsibility for security management and an existing network systems engineer the responsibility for security operations. A hands-up survey of the audience suggests that most firms still do not have dedicated security staff. However, there were a few, albeit larger firms, who have managed to get support for four and five FTEs who are focused on information security initiatives.”


Chris DiMarco writes for'Legaltech News, an ALM sibling of e-Commerce Law & Strategy.

Read These Next
Overview of Regulatory Guidance Governing the Use of AI Systems In the Workplace Image

Businesses have long embraced the use of computer technology in the workplace as a means of improving efficiency and productivity of their operations. In recent years, businesses have incorporated artificial intelligence and other automated and algorithmic technologies into their computer systems. This article provides an overview of the federal regulatory guidance and the state and local rules in place so far and suggests ways in which employers may wish to address these developments with policies and practices to reduce legal risk.

Is Google Search Dead? How AI Is Reshaping Search and SEO Image

This two-part article dives into the massive shifts AI is bringing to Google Search and SEO and why traditional searches are no longer part of the solution for marketers. It’s not theoretical, it’s happening, and firms that adapt will come out ahead.

While Federal Legislation Flounders, State Privacy Laws for Children and Teens Gain Momentum Image

For decades, the Children’s Online Privacy Protection Act has been the only law to expressly address privacy for minors’ information other than student data. In the absence of more robust federal requirements, states are stepping in to regulate not only the processing of all minors’ data, but also online platforms used by teens and children.

Revolutionizing Workplace Design: A Perspective from Gray Reed Image

In an era where the workplace is constantly evolving, law firms face unique challenges and opportunities in facilities management, real estate, and design. Across the industry, firms are reevaluating their office spaces to adapt to hybrid work models, prioritize collaboration, and enhance employee experience. Trends such as flexible seating, technology-driven planning, and the creation of multifunctional spaces are shaping the future of law firm offices.

From DeepSeek to Distillation: Protecting IP In An AI World Image

Protection against unauthorized model distillation is an emerging issue within the longstanding theme of safeguarding intellectual property. This article examines the legal protections available under the current legal framework and explore why patents may serve as a crucial safeguard against unauthorized distillation.