*/
By Alexander Sverdlov
A quick Google search for ‘law firm hacked’ reveals more than 5 million search results of articles and news stories on law firms becoming victims of cybercriminals in the past few years.
Unlike most chambers, many of these law firms will have cybersecurity departments, well-equipped IT departments, large budgets, the fanciest defence software and yet somehow still managed to lose control over their data.
When a breach happens, hackers often stay in the compromised network for months – sometimes years. The ‘average’ detection time is beyond 6 months, but you and I know that ‘average’ could mean 1 day, or 10 years. This causes direct and indirect damage to your clients and employees, your reputation and finances, not to mention the possibility of extortion and the ‘unknown unknowns’.
Can you definitely say – and this question is particularly pertinent when members of chambers and staff are working remotely – that no unauthorized code ran on their computers last week? Did anyone access a compromised website, thus exposing you all to malicious code? Did any malicious code bypass your antivirus program and if it did, what did it do after that? Did it send any confidential documents over an encrypted channel to a server in China? If so, how many documents were lost? Did the hacker then move on to other computers in the same network?
I am a firm believer that sound security architecture will trump any commercial security software and product. If you have well designed and tuned IT infrastructure, you will be head and shoulders above the mass of chambers who only depend on basic security controls provided by their IT support firm. Achieving that, you will have a competitive advantage – and every little bit helps!
The first and likely most important task when designing a chambers’ defences is to step back and look at all the major software elements in it.
Are you using a document management system and a filing system? Are they tightly integrated into your email and collaboration systems?
A weakness or a vulnerability in any IT system could lead to a security breach in all of them.
A chain is only as strong as its weakest link!
And a chambers is only as resistant to a hacking attack as its least protected IT system.
Unfortunately, antivirus and firewalls are weak and unreliable against hackers – they are straightforward to bypass and present no challenge.
What helps:
Vulnerability management has to become a part of your IT management strategy. If you can’t answer the question ‘how many vulnerabilities did you have last month and are they fewer this month,’ then how can you even be sure that you haven’t already been hacked?
Vulnerability management as a process should be a part of a more sophisticated approach. Hackers have had decades to hone their skills and breach methods. If all you are using to protect chambers against trained hackers is a firewall and an antivirus, it is time to upgrade.
Some examples of processes that need to be in place for your chambers to be secure:
As the founder of Atlant Security, I can help you establish a solid foundation of defending client data and funds against cyberattacks. If you want to get started on a journey to turn your chambers into a fortress, get in touch!
A quick Google search for ‘law firm hacked’ reveals more than 5 million search results of articles and news stories on law firms becoming victims of cybercriminals in the past few years.
Unlike most chambers, many of these law firms will have cybersecurity departments, well-equipped IT departments, large budgets, the fanciest defence software and yet somehow still managed to lose control over their data.
When a breach happens, hackers often stay in the compromised network for months – sometimes years. The ‘average’ detection time is beyond 6 months, but you and I know that ‘average’ could mean 1 day, or 10 years. This causes direct and indirect damage to your clients and employees, your reputation and finances, not to mention the possibility of extortion and the ‘unknown unknowns’.
Can you definitely say – and this question is particularly pertinent when members of chambers and staff are working remotely – that no unauthorized code ran on their computers last week? Did anyone access a compromised website, thus exposing you all to malicious code? Did any malicious code bypass your antivirus program and if it did, what did it do after that? Did it send any confidential documents over an encrypted channel to a server in China? If so, how many documents were lost? Did the hacker then move on to other computers in the same network?
I am a firm believer that sound security architecture will trump any commercial security software and product. If you have well designed and tuned IT infrastructure, you will be head and shoulders above the mass of chambers who only depend on basic security controls provided by their IT support firm. Achieving that, you will have a competitive advantage – and every little bit helps!
The first and likely most important task when designing a chambers’ defences is to step back and look at all the major software elements in it.
Are you using a document management system and a filing system? Are they tightly integrated into your email and collaboration systems?
A weakness or a vulnerability in any IT system could lead to a security breach in all of them.
A chain is only as strong as its weakest link!
And a chambers is only as resistant to a hacking attack as its least protected IT system.
Unfortunately, antivirus and firewalls are weak and unreliable against hackers – they are straightforward to bypass and present no challenge.
What helps:
Vulnerability management has to become a part of your IT management strategy. If you can’t answer the question ‘how many vulnerabilities did you have last month and are they fewer this month,’ then how can you even be sure that you haven’t already been hacked?
Vulnerability management as a process should be a part of a more sophisticated approach. Hackers have had decades to hone their skills and breach methods. If all you are using to protect chambers against trained hackers is a firewall and an antivirus, it is time to upgrade.
Some examples of processes that need to be in place for your chambers to be secure:
As the founder of Atlant Security, I can help you establish a solid foundation of defending client data and funds against cyberattacks. If you want to get started on a journey to turn your chambers into a fortress, get in touch!
By Alexander Sverdlov
Update from the Chair of the Bar
By David Green
Mário Barroso, Head of R&D and Method Development at AlphaBiolabs, examines the forensic science underpinning hair drug testing, its evidential scope and limitations, and why it remains the gold standard for evidencing patterns of drug use in family proceedings
Unlocking your aged debt to fund your tax in one easy step. By Philip N Bristow
Clement Cowley, Partner at The Penny Group, discusses the upcoming changes to pensions and Inheritance Tax and the potential impact on your financial future
Save the Children UK is the latest charity to benefit from a £500 donation from AlphaBiolabs via the company’s Giving Back initiative
The Chief Legal Officer to the Metropolitan Police, barrister Brett Welch, tells Anthony Inglese CB about his mission and the work to turn the Met around
Barrister apprenticeships – shortly to provide the fourth pathway to the Bar – are an ideal opportunity to support local talent and ‘grow your own’, say Tim Coulson and Dr Jane Dennehy
Born from a grievance, their research project grew into a book and is now challenging the status quo. Emma Price and Emma-Louise Fenelon reveal the key findings – and the critical next steps
Grok around and find out – or not? Mariya Peykova investigates the nudification scandal, what the law has to say about sexually explicit deepfakes, and whether stronger regulation is needed
Oliver Lewis spotlights an overlooked yet rapidly evolving area of law – coercive and controlling behaviour within care contexts