Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

Are Lawyers “Getting” Cybersecurity?

June 8, 2016

This is a question I am asked frequently. As one reporter put it, "It seems like lawyers were scared straight about cybersecurity for about a minute after the Panama Papers leaks and some NY law firms were exposed as targets of hackers." I am happy to say that their attention was caught for more than a minute.

The larger firms have been "scared straight" for some time. They all know that an advanced hacker with advanced tools and sufficient funding can breach them. I suspect they've all been breached, some multiple times. So they began some time ago to invest a lot of money in cybersecurity.

While they are anxious to keep the bad guys out as the first line of defense, they have surrendered to the inevitable – that they will be breached and must detect, respond and recover. A lot of money is going into Intrusion Detection Systems (some are affordable for small firms too) and Intrusion Prevention Systems (IPS), usually far more advanced and expensive. An IPS generally monitors network activity, looks for attack behaviors or activity that deviates from baselines. They can take automated actions in response to what is detected – and they do much more than I can cover in a blog post.

Even mid-sized firms are rapidly adopting encryption and seeking security audits and remediation of vulnerabilities. I know because we're hiring in this area – and so are many others. Since we've been preaching from a bully pulpit for many years, it is gratifying to see law firms and others battening down the hatches. The last line of resistance is the solo/small market which tends to feel it is less of a target and that cybersecurity is too hard to understand and too expensive to implement. That isn't really true and we have seen smaller firms moving to become more secure, but that movement is slower and often compelled by clients.

Cybersecurity remains the number one topic John and I are asked to speak on, so we'll be carrying our metaphorical bottle of "Doctor Good" (minus the snake oil but with the miracle elixirs) to Medicine Shows (otherwise known as CLEs) across the country for the foreseeable future.

E-mail: Phone: 703-359-0700
Digital Forensics/Information Security/Information Technology
http://www.senseient.com
http://twitter.com/sharonnelsonesq
www.linkedin.com/in/sharondnelson