Most people have elevated stress during the holiday season — work, travel, family, money, time. And holiday stress can make people inattentive, tired, frustrated, and willing to take short cuts, especially when it comes to computer and Internet use. This is when mistakes happen. It’s when we decide to evade policy by emailing work home or by using the unsecured airport Wi-Fi because our plane is delayed. It’s also when malicious acts of information theft, sabotage, and fraud can more easily occur and go undetected.
According to a recent survey, insider threats — as opposed to outside actors — can account for nearly 75% of cyber incidents. These incidents occur because of the actions of employees, suppliers, customers, and previous employees. Law firms are not exempt, particularly small to medium size firms. In fact, smaller firms typically have fewer resources to devote to cybersecurity and use more outside suppliers.
End-of-year activities for law firms also make them especially vulnerable to insider threats, whether inadvertent or malicious: the push to bill and collect for more hours, time-sensitive legal matters that must be resolved before the end of the calendar year, attending to year-end tax accounting, case and client review, bonus calculations. Lawyers and their staff feel the strain of extra hours, looming deadlines, and sometimes contentious clients at the same time we all feel holiday pressures at home.
What is at risk?
Continue Reading Law firm insider threats don’t take a break for the holidays — they may get worse.

As technical security improves, human security vulnerabilities are increasingly in the bulls-eye. For a fresh look at social engineering, and how best to defend against it, there’s no better source than a hacker. So, I reached out to Cliff Smith, Ethical Hacker & CISSP at
Whew – we’ve survived yet another round of states enacting or amending their PII breach notification laws. If a trial lawyer’s vacation is the time between her question and the witness’s answer, a data security lawyer’s vacation is when state legislatures are out of session.
Last week’s
You’d think, among all types of businesses, that law firms would be at the front of the pack in having a data security policy. After all, law firms regularly tell their clients how important it is to have effective policies in place for legal compliance and risk management. And law firms certainly possess large volumes of valuable data, such as confidential client information and individual’s personal data, and are subject to a daunting array of
If you had a choice between doctors to perform surgery on you, which would you pick: a doctor who has sat through training on how to perform an appendectomy; or assurance that your doctor will successfully perform your appendectomy?
The indictment filed last Friday by Special Counsel Robert Mueller explains how Russian military intelligence officers hacked into computer systems of the DNC, the DCCC, and Clinton Campaign employees during the 2016 presidential race. With sweeping, specific details that have compelled unanimous confidence among Americans (except apparently
Testing for technical vulnerabilities is a key part of security risk assessment. To get the straight scoop on technical vulnerabilities, and how they’re exploited, why not ask a hacker?
Would you take a deposition by solely following a template of standard questions, without assessing the unique issues and circumstances of the case? Or conduct transaction due diligence by simply marching though a generic punch list, without assessing the unique aspects of the company, the deal, and the industry? Of course not. Your law firm’s data security posture is no different – you need a security risk assessment to understand your firm’s unique vulnerabilities to security threats, and to identify which security controls are already adequate for your firm and which other safeguards are needed.
I had a nagging worry that something was wrong with my car, so I finally decided to take it to the dealer. I couldn’t exactly describe my concern, except there was an intermittent, “funny noise” coming from somewhere in the front end. An unscrupulous dealer would have taken me down a long path of parts replacement, beginning with tires, then wheels, then tie rods, and on and on, perhaps never fixing the real problem. Fortunately, my dealer was honest and performed diagnostics, ultimately discovering that the rack and pinion was failing. The part was under warranty, so the repair cost me nothing and my funny noise is gone.