“You’re gonna need a bigger boat.”
Sheriff Brody said it best when he came face-to-face with the great white shark that was menacing the town of Amity Island in Spielberg’s 1975 blockbuster, Jaws. The same sentiment holds true for smaller law firms hunting large clients. The risk and responsibilities that come with large clients, such as pharmaceutical companies, disruptor banks, and investment firms remain the same, regardless of the size of your law firm.
Unlike large firms with comparable resources with which to protect client non-public information, small firms can find themselves trapped between cyber attacks, like ransomware, that don’t prejudice based on the size of the firm, and regulators who are indifferent to your size, when investigating a potential violation.
The attack on Wall Street law firms Cravath, Swaine & Moore LLP and Weil, Gotshal & Manges LLP demonstrated how stolen information, such as FDA filings and press releases, could be used to front run trades. In this case, a law firm managed HIPAA protected healthcare data and the stolen information was used to violate SEC rules and federal market laws.
These regulated clients create a significant reporting burden. Consider for example that under HIPAA compliance standards for healthcare operators and New York financial institutions governed by the Department of Financial Services (DFS), you would be required to report a material cyber breach with 72 hours. Moreover, under DFS you would have to contribute to an annual declaration on the part of the client in which not only material breaches are inventoried, but unsuccessful attempts are also documented. This can be a significant task for banks with large security teams, let alone a small law firm outsourcing IT operations.
As an industry, law firms have improved their overall cybersecurity hygiene and practices, which has resulted in a lower than average amount of nuisance cyberattacks as compared to other industries like healthcare, manufacturing, and energy. That said, criminals consider law firms a lucrative target, and as a result, the legal industry suffers 30% more malicious attacks than other businesses, according to eSentire threat data. This is a symptom of cyber threats evolving from opportunistic means and transactional payments to targeted and negotiated extortion.
These trends do no delineate by firm size. A 90-day snapshot of eSentire’s security operations statistics comparing large to small firms indicate relative volume of security incidents, but closer to par breaches and security events that require an immediate response. For example, consider that a large firm may represent 500-750 attorneys across 20 locations versus a small firm, which may have 25-50 attorneys at one location. Now consider that the small firm generates about 65,000 security traffic elements that filter down to 20 incidents, and lead to one urgent incident requiring an immediate response. On the other hand, the large firm generates over 40 times more traffic, 325 security incidents (16 times more), and one escalation.
While the larger firm generates significantly more security traffic elements, the ratio of escalated incident and incidents baring emergency response moves closer to one-to-one as the security events are investigated. Diving deeper, the data indicates that the emergency incidents were born of the same, industry-targeted attack. In other words, both the large and small firm were impacted and breached by the same targeted attack. Neither the criminals, nor their tools, discriminate by the number of attorneys.
ABA Cybersecurity Recommendations
It’s not unreasonable to think that the common cyber practices and investment levels of a large law firm are not the same as those that a small firm can manage. There is no one-size-fits-all when it comes to establishing standards of reasonable care. The ABA Cybersecurity Handbook: A Resource for Attorneys, Law Firms and Business Professionals, contains a resource-right-sized approach with a checklist that smaller firms can use to build a simplified cybersecurity program:
- Inventory hardware, applications: Keep a register of all laptops, servers, and applications. This should include cloud services, such as Amazon EC2, Microsoft Office 365, or other document management services.
- Identify and audit data and related obligations: By extension, you have the obligation to understand the legal and regulatory boundaries in which your clients operate, and to meet those requirements. Ensure you understand your obligations.
- Engage and IT consultant: Managed services firms can provide device management (updates and patching), along with basic system onboarding and off-boarding processes. They can also help you encrypt devices and set up private networks to encrypt email and file transfers.
- Investigate the security of cloud service providers: Cloud services offer multi-tenant offerings that extrapolate the need for on-site management services. But remember, cloud service providers are obligated to protect their servers from attack, but not responsible for the consequences if your credentials are hijacked.
- Establish cybersecurity and acceptable use policies: Leverage a consultant to build fundamental policies about the management, transfer, and storage of client confidential information.
- Protect sensitive data and avoid portable media: Avoid using media, such as USB keys, to store and transfer non-public information. USB keys are a main source of infection and are difficult to control if the data is not removed once the authorized use is complete.
- Require encryption: Unfortunately, password credentials are routinely acquired by unauthorized users. For this reason, you should encrypt hard drives or devices. Encryption offers an additional layer of security. The following links provide step-by-step instructions on how to encrypt your mobile hard drive or device:
- Establish a backup system: Leverage an outsourced IT service to routinely back up and then test backups to reduce the business disruption impact in the event of a cyber breach. Backups are the best defense against ransomware attacks and avoiding having to pay ransoms.
- Establish a records management policy (control and destruction): Determine how documents are stored, who has access, and establish ‘least privilege’ with a ‘need to know’ attitude and consider how you securely destroy old documentation.
- Consider cyber insurance: Engage an agent to weigh the cost and benefits of insuring your business against cyber attacks and whether your business disruption, lost revenue, or other non-cyber specific policies cover cyber incidents.
- Review website security: Use an outsourcing service to manage your website, keep it patched and up-to-date, and consider how you protect data that is collected through web forms or application.
- Establish mobile device rules: Use a Mobile Device Management (MDM) software to remotely establish required security settings (such as minimum password strength), forced encryption, and the ability to perform a remote device wipe to remove all data (called a poison pill) when the device is lost or stolen. MDM adds an additional layer of security but is costly and not a default feature of most mobile devices.
- Use VPN security: The best way to protect data in motion from such attacks is to use a Virtual Private Network (VPN) service. A VPN creates a secure and encrypted connection through which your data travels from you to the intended recipient. No information (including passwords) are transmitted in the clear. There are many low-cost and easily deployed VPN services.
As you look to expand a business or retain your key clients in a growing environment of cyber threats, remember Sheriff Brody’s advice: size does matter when you’re going after big fish. Weigh the benefits and risks, and recognize that there is chum in the water put there by criminals and regulators alike. And be prepared for the behemoth that might bite your line.