*/
By Alexander Sverdlov
A quick Google search for ‘law firm hacked’ reveals more than 5 million search results of articles and news stories on law firms becoming victims of cybercriminals in the past few years.
Unlike most chambers, many of these law firms will have cybersecurity departments, well-equipped IT departments, large budgets, the fanciest defence software and yet somehow still managed to lose control over their data.
When a breach happens, hackers often stay in the compromised network for months – sometimes years. The ‘average’ detection time is beyond 6 months, but you and I know that ‘average’ could mean 1 day, or 10 years. This causes direct and indirect damage to your clients and employees, your reputation and finances, not to mention the possibility of extortion and the ‘unknown unknowns’.
Can you definitely say – and this question is particularly pertinent when members of chambers and staff are working remotely – that no unauthorized code ran on their computers last week? Did anyone access a compromised website, thus exposing you all to malicious code? Did any malicious code bypass your antivirus program and if it did, what did it do after that? Did it send any confidential documents over an encrypted channel to a server in China? If so, how many documents were lost? Did the hacker then move on to other computers in the same network?
I am a firm believer that sound security architecture will trump any commercial security software and product. If you have well designed and tuned IT infrastructure, you will be head and shoulders above the mass of chambers who only depend on basic security controls provided by their IT support firm. Achieving that, you will have a competitive advantage – and every little bit helps!
The first and likely most important task when designing a chambers’ defences is to step back and look at all the major software elements in it.
Are you using a document management system and a filing system? Are they tightly integrated into your email and collaboration systems?
A weakness or a vulnerability in any IT system could lead to a security breach in all of them.
A chain is only as strong as its weakest link!
And a chambers is only as resistant to a hacking attack as its least protected IT system.
Unfortunately, antivirus and firewalls are weak and unreliable against hackers – they are straightforward to bypass and present no challenge.
What helps:
Vulnerability management has to become a part of your IT management strategy. If you can’t answer the question ‘how many vulnerabilities did you have last month and are they fewer this month,’ then how can you even be sure that you haven’t already been hacked?
Vulnerability management as a process should be a part of a more sophisticated approach. Hackers have had decades to hone their skills and breach methods. If all you are using to protect chambers against trained hackers is a firewall and an antivirus, it is time to upgrade.
Some examples of processes that need to be in place for your chambers to be secure:
As the founder of Atlant Security, I can help you establish a solid foundation of defending client data and funds against cyberattacks. If you want to get started on a journey to turn your chambers into a fortress, get in touch!
A quick Google search for ‘law firm hacked’ reveals more than 5 million search results of articles and news stories on law firms becoming victims of cybercriminals in the past few years.
Unlike most chambers, many of these law firms will have cybersecurity departments, well-equipped IT departments, large budgets, the fanciest defence software and yet somehow still managed to lose control over their data.
When a breach happens, hackers often stay in the compromised network for months – sometimes years. The ‘average’ detection time is beyond 6 months, but you and I know that ‘average’ could mean 1 day, or 10 years. This causes direct and indirect damage to your clients and employees, your reputation and finances, not to mention the possibility of extortion and the ‘unknown unknowns’.
Can you definitely say – and this question is particularly pertinent when members of chambers and staff are working remotely – that no unauthorized code ran on their computers last week? Did anyone access a compromised website, thus exposing you all to malicious code? Did any malicious code bypass your antivirus program and if it did, what did it do after that? Did it send any confidential documents over an encrypted channel to a server in China? If so, how many documents were lost? Did the hacker then move on to other computers in the same network?
I am a firm believer that sound security architecture will trump any commercial security software and product. If you have well designed and tuned IT infrastructure, you will be head and shoulders above the mass of chambers who only depend on basic security controls provided by their IT support firm. Achieving that, you will have a competitive advantage – and every little bit helps!
The first and likely most important task when designing a chambers’ defences is to step back and look at all the major software elements in it.
Are you using a document management system and a filing system? Are they tightly integrated into your email and collaboration systems?
A weakness or a vulnerability in any IT system could lead to a security breach in all of them.
A chain is only as strong as its weakest link!
And a chambers is only as resistant to a hacking attack as its least protected IT system.
Unfortunately, antivirus and firewalls are weak and unreliable against hackers – they are straightforward to bypass and present no challenge.
What helps:
Vulnerability management has to become a part of your IT management strategy. If you can’t answer the question ‘how many vulnerabilities did you have last month and are they fewer this month,’ then how can you even be sure that you haven’t already been hacked?
Vulnerability management as a process should be a part of a more sophisticated approach. Hackers have had decades to hone their skills and breach methods. If all you are using to protect chambers against trained hackers is a firewall and an antivirus, it is time to upgrade.
Some examples of processes that need to be in place for your chambers to be secure:
As the founder of Atlant Security, I can help you establish a solid foundation of defending client data and funds against cyberattacks. If you want to get started on a journey to turn your chambers into a fortress, get in touch!
By Alexander Sverdlov
The beginning of the legal year offers the opportunity for a renewed commitment to justice and the rule of law both at home and abroad
By Louise Crush of Westgate Wealth Management sets out the key steps to your dream property
A centre of excellence for youth justice, the Youth Justice Legal Centre provides specialist training, an advice line and a membership programme
By Kem Kemal of Henry Dannell
By Ashley Friday of AlphaBiolabs
Providing bespoke mortgage and protection solutions for barristers
Joanna Hardy-Susskind speaks to those walking away from the criminal Bar
From a traumatic formative education to exceptional criminal silk – Laurie-Anne Power KC talks about her path to the Bar, pursuit of equality and speaking out against discrimination (not just during Black History Month)
Yasmin Ilhan explains the Law Commission’s proposals for a quicker, easier and more effective contempt of court regime
Irresponsible use of AI can lead to serious and embarrassing consequences. Sam Thomas briefs barristers on the five key risks and how to avoid them
James Onalaja concludes his two-part opinion series