Over the last two years, the sticker price of many AI options has dropped, which can make usage feel inexpensive or even free inside familiar products. At the same time, vendors are shifting to fine‑grained, usage‑based billing and premium pricing for AI‑enabled features in traditional software. As firms embed AI everywhere—from email to document management systems to research platforms—the number of AI‑driven actions and the volume of data pushed through those engines can climb quickly, which is what ultimately drives the bill.
In a cyber incident, the question law firm leaders most dread isn’t ‘What happened?," it’s ‘Where is your documented oversight?’
That’s why clear security policies and standard operating procedures (SOPs) matter so much. They spell out who is authorized to make decisions, who approves access to client data, and how issues get escalated before they become incidents. Without that, even well‑intended IT efforts can look like unmanaged risk.
Since the FTC updated its Safeguards Rule in 2023, many small professional services firms must now maintain a Written Information Security Plan (WISP). This requirement is directly connected to how they prepare and file client tax returns. For firms that handle taxpayer or other sensitive financial information, a documented WISP is no longer optional “good practice” – it is a regulatory expectation tied to both FTC and IRS obligations.
Smaller law firms don’t have “small” risk.They hold the same confidential client, deal, and litigation data as BigLaw—often with fewer resources and thinner margins to absorb a serious cyber incident.
That’s where working with a security consultant who has actually led technology and security inside law firms makes a difference.
Clients in regulated industries (financial services, healthcare, etc.) expect their law firms to manage data security with the same discipline they apply internally. For small firms, that expectation can feel daunting—but it is also a major opportunity for differentiated, visible cybersecurity leadership.asklib.hks.harvard
In May 2025, a Minnesota couple and their teenage son were held hostage in their own home by criminals demanding access to their cryptocurrency wallets. The attackers reportedly forced the victims to transfer their digital assets at gunpoint — a harrowing example of a growing threat known as the “wrench attack.”

Too often, cybersecurity, governance, and risk management get pushed down into operational detail. The conversation centers on firewalls, backups, software settings, and compliance checklists. Those things are unquestionably important, but when they are treated primarily as technical chores rather than leadership responsibilities, they become disconnected from what actually matters: protecting client relationships, meeting professional obligations, and preserving the trust that sustains the firm.

Most law firms think about cyberattacks as something that happens through email or a hacked password.
The FBI is currently warning about a different threat: criminals posing as IT support over the phone and, when that doesn’t work, showing up in person to plug a device into a computer and copy data. No movie magic. No jargon. Just social engineering and weak front-desk process.

ABA and Ponemon reported this year that only 34% of firms have a written plan. The firms that do reduce breach costs by 58%. With the average law firm breach now sitting around $5.08M, that’s roughly a $2.9M difference tied largely to preparation instead of technology. At the same time, ransomware is shifting toward smaller, more “payable” demands, and law firms are firmly in the crosshairs, with 200+ incidents tracked since 2025.
