Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Cyber Crime Now Targeting Law Firms

By Collin Hite
August 01, 2017

Cyber attacks and theft are on the rise around the country, and law firms are becoming prime targets. Similar to healthcare providers, a law firm's data (i.e., client files) can be the gold standard. Unlike manufacturers, banks and retailers, law firms are unique organizations that result in them being highly vulnerable.

Why Firms are Vulnerable

Sophisticated hackers no longer try to penetrate outer defenses, such as firewalls, as a matter of practice. Instead, they target individual workstations through social engineering, and hope a careless or unsuspecting employee will open the fake email. If opened, the fraudulent email allows the hacker into the network. As usual, the human element is often the weak link in the defenses employed by law firms. Most firms allow almost every employee (including contract ones) within the organization access to client data, regardless of sensitivity or the need for such broad access. Almost every employee has a computer connected to the firm network and the Internet. All employees are given great latitude to access the Internet and personal email through the firm's computers. In addition, law firms utilize a large amount of mobile technology. Regardless of type, most technology within the firms is not encrypted. Wire transfers are routine for law firms and are enticing to criminals.

Additionally, law firms allow many outsiders, such as cleaning staff and security guards, inside the firm with little background checks or knowledge of who these people are wandering around after hours. For those old enough to remember the original Wall Street movie, how did Bud Fox gather the insider information? He got himself hired as custodian for the cleaning crew inside a law firm. Physical security is an important cybersecurity consideration.

Finally, law firms are not great about ensuring software is regularly updated. Many use older versions of software that is more vulnerable. Two-factor authentication, now an accepted standard by cybersecurity experts, is rarely used at most firms. Cybersecurity training for employees is rare, ineffective when done, and rarely consistent.

Law firms must understand the difference between information technology and information security. Just as tax and personal injury are separate practice areas for attorneys, IT and IS are distinct functions for a firm's operations. Allowing IT to moonlight as your information cybersecurity official is a mistake. All firms need a Chief Information Security Officer (CISO), whether in-house or virtual, to oversee the cybersecurity aspects of operations. Rarely does the firm's IT staff possess the requisite training or functionality to serve both roles.

All of these factors make firms very vulnerable and likely targets. Theft is not the only motivator for cyber criminals. In April 2016, law firm Mossack Fonseca was hacked resulting in the release of client files, now known as the “Panama Papers.” The information contained highly confidential and embarrassing details about clients' efforts to dodge tax laws. In the summer of 2015, some of the nation's largest law firms admitted to being breached, including Cravath Swaine & Moore LLP and Weil Gotschal & Manges LLP. Unfortunately, a common misconception across all industries is that smaller entities are not on the cyber radar for hacking and theft. Incorrect! Criminals are very aware that smaller entities, including law firms, are far more vulnerable.

Hackers no longer grab the goods and run. They can often stay within a network for months, remaining undetected while they collect more and more sensitive data on employees, clients and other private information. Even more problematic, cyber insurance is still an afterthought to many firms.

The Best Defense is an Aggressive Offense

Once firms recognize they are targets, and all are, they must be proactive in addressing the situation. Where to start? A comprehensive cyber risk assessment is critical to structuring a strong, multi-pronged defense. Think enterprise risk management — not to mention ethical concerns if breached. The American Bar Association just re-visited the issue of cybersecurity as an ethical consideration for attorneys and sets out some limited guidance. (See the ABA's Cybersecurity Legal Task Force.)

An assessment becomes the guide to building a robust cybersecurity defense for any law firm. However, once a firm's security is implemented and verified, the process cannot stop there. Just like malpractice insurance, cybersecurity insurance is a must these days. For many firms, a breach exposing large amounts of clients' private information can quickly escalate into a bet-the-firm proposition to survive. The average cost for responding to a breach is approximately $221 per client. Do the math. And that does not even begin to address a firm's costs to re-secure their network, public relations expenses, lost income, and the likely lawsuits from unhappy clients.

Where Does Cyber Insurance Apply to Law Firms

Law firms must recognize that their legal professional liability insurance is unlikely to cover a cyber breach, or at least much of it. The same is true for the firm's CGL and property coverage. Firms face third-party exposures as well as their own first party ones. If a firm's computer network is compromised, the potential for losses, such as business interruption, are large. Even with the best computer security, one thing is certain: the element for human error is always unpredictable. Employee negligence accounts for 25% to 35% of all cyber events. Cybersecurity breaches may also raise ethical issues as well. Thus, it is critical to implement enterprise solutions for risk protection, which needs to include appropriate cyber insurance.

Firms can obtain cyber insurance for first-party and third-party losses. Understanding both and ensuring there is appropriate coverage is a must. First-party coverage can include within its scope: 1) computer data restoration; 2) re-securing a company's information network; 3) theft and fraud coverage; 4) business interruption; 5) forensic investigations; and 6) extortion. Commentators note that first-party losses are usually the higher costs to a business suffering a cyber-attack, so adequate coverage in this area is vital.

Third-party coverage is needed as well. Most coverage in this area will provide for a defense to litigation from your customers for their direct losses due to a breach. Insurance may also cover the following: 1) crisis management; 2) credit monitoring for customers; 3) the cost associated with notifying customers of a breach; 4) media and privacy liability; and 5) responses to regulatory investigations.

Some of the benefits of cyber insurance include lower retention levels. This specialty insurance provides access to the insurer's external resources for legal, forensic and credit protection services. Coverage may provide for privacy regulatory and payment of civil fines and penalties. Ransom and extortion schemes can be covered.

But this is a line of insurance with which the buyer must exercise extreme diligence. Cyber insurance is a newer form of coverage that does not benefit from long term placement in the market. Policyholders and insurers are grappling to understand the scope of coverage through negotiations and court opinions. Coverage disputes are just now yielding some initial legal decisions. All cyber insurance policies are definitely not created alike. For example, some policies may exclude coverage for unencrypted mobile devices, such as laptops. Firms need to develop a thorough understanding of their risks and the scope of the cyber insurance they are placing.

Due diligence in placing such coverage is critical. The Moses Afonso law firm in Rhode Island learned this lesson the hard way. The 10-person firm was a victim of ransomware. Their computers and network were encrypted by criminals until the $25,000 ransom, and a second one, were paid. However, the firm lost over $700,000 in revenue during the episode from lost work without their computer systems. When the system was unlocked, there were still problems for records stored on a temporary server. All in all, an expensive problem. The law firm submitted the loss to its business owner's insurer, which paid $20,000 for losses caused by computer viruses, which are covered under a computers and media endorsement. Now the law firm and insurance company are squaring off in court. The best lesson to learn is that endorsements for “cyber type coverage” tacked on to other policies are rarely the best option. As demonstrated, such endorsements carry low sublimates and are usually restrictive. Moreover, they usually do not provide for collateral response services provided by the insurer, which is almost always the case with true cyber insurance.

A firm's traditional insurance program likely will not cover cyber losses, or contain gaps in such coverage, for data breaches. Cyber insurance policies can fill many of the gaps in traditional insurance and provide direct loss and liability protection for risks created by the use of technology in an organization's day-to-day operations. There is no time like the present for law firms to analyze their insurance programs to determine if their current insurance will cover cyber risks and identify any gaps that need to be filled. It is time for law firms to become cyber savvy.

***** Collin Hite is the practice leader of the Cybersecurity & Data Privacy Group as well as the Insurance Recovery Group at Hirschler Fleischer, P.C. A member of this newsletter's Board of Editors, he also is the founder of the law firm's CyberKnot program. He may be reached at 804-771-9595 or [email protected].

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
COVID-19 and Lease Negotiations: Early Termination Provisions Image

During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.

How Secure Is the AI System Your Law Firm Is Using? Image

What Law Firms Need to Know Before Trusting AI Systems with Confidential Information In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.

Authentic Communications Today Increase Success for Value-Driven Clients Image

As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.

Pleading Importation: ITC Decisions Highlight Need for Adequate Evidentiary Support Image

The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.

Generative AI and the 2024 Elections: Risks, Realities, and Lessons for Businesses Image

GenAI's ability to produce highly sophisticated and convincing content at a fraction of the previous cost has raised fears that it could amplify misinformation. The dissemination of fake audio, images and text could reshape how voters perceive candidates and parties. Businesses, too, face challenges in managing their reputations and navigating this new terrain of manipulated content.

How Much Does the Frequency of Retirement Withdrawals Matter? Image

A recent research paper offers up some unexpected results regarding the best ways to manage retirement income.