Legal services is the most reported sector in IC3’s non-critical ransomware complaints
In its 2025 Internet Crime Report the FBI’s Internet Crime Complaint Center counted more than 1,400 ransomware complaints from businesses and organizations not related to a critical sector. Legal services was the largest single share of them, at 18 percent, ahead of contracting services at 17 percent.
Read that number carefully, because it is easy to read as something it is not. The 18 percent is a share of the complaints IC3 received, not a rate at which law firms are attacked. It says legal services reported more of this than any other sector outside critical infrastructure. It does not say what share of firms were hit, and no such figure exists, because nobody knows how many firms never reported.
The FBI is unusually direct about the limits of its own figures. IC3 says its ransomware loss totals are artificially low, because they do not normally include the full range of costs a victim actually bears, and because some organizations report an incident without reporting any loss amount at all.
A group that targets law firms by calling them
The FBI has now warned about the same actor twice, fourteen months apart. It issued a Private Industry Notification on 23 May 2025 titled “Silent Ransom Group Targeting Law Firms”, and a FLASH alert on 26 May 2026. The 2026 alert states that while the group has victimized companies in many sectors including insurance, finance and healthcare, it has consistently targeted US-based law firms since Spring 2023.
The method is a phone call. Someone telephones the firm posing as its own IT support, asks to image the device or create a backup file, and is granted access by a member of staff who believes they are being helpful. Data then leaves over consumer file sharing services or onto a storage device inserted on site. In the 2026 pattern the pressure calls go to the firm’s clients as well as its employees.
There is no encryption. This matters, and it is the reason this section sits apart from the ranking above rather than under it. The FBI describes this group as conducting data theft and extortion without relying on traditional ransomware encryption. Nothing locks. No ransom note appears on a screen. A firm can be fully operational, with every file where it should be, and already be the subject of an extortion demand over copies that left days earlier. Controls tuned to notice encryption will not notice this.
One honest qualification, from the FBI’s own footnote to the 2025 notification. It notes that the group targets other sectors too, including medical and insurance companies, and that most of its victims are law firms or companies with similar naming conventions. The Bureau is telling you that part of its own law-firm attribution may be an artifact of how the victims are named. We would rather hand you that sentence than let you find it later.
This page is about protecting your firm. If you came looking for the other thing we do, the forensic examination of a device or a mailbox as evidence in a client’s matter, that is digital forensics for attorneys, where your firm is the buyer of an investigation. Here your firm is the thing being protected. The same offering for regulated financial firms sits at managed security and compliance.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
What requires this of you, and what does not
What follows is a description of the rules as they are written, not an assessment of your firm. We have not seen your systems and we are not in a position to tell you where you stand against any of this. Where an obligation is soft we say so, because you can read the instrument yourself and a page that overstated it would not survive the reading.
The ethics rule says should
Model Rule 1.1 is two sentences and neither mentions technology. A lawyer shall provide competent representation to a client, and competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation. The word technology does not appear in the rule at all.
It appears once in the comments. Comment [8] says a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. One instrument, drafted by the same body at the same time, says shall about competence and should about technology. That contrast is the whole of the ethics argument and it needs no gloss from us.
Forty states, the District of Columbia and Puerto Rico have adopted a duty of technology competence, according to the tracker Robert Ambrogi maintains, as of its most recent entry in April 2025. Two things about that count are worth knowing. There is no official register, so a lawyer’s personal blog is the most complete tally anyone keeps. And adopted does not mean identical: Montana put the language in its preamble rather than in Comment [8], and North Carolina reworded it. The accurate description is a duty of technology competence, which is the tracker’s own phrase, rather than adoption of Comment [8] as written.
Opinion 483 does require you to tell your clients
Having said all that about softness, here is the part that is not soft, and it is the one most often missed. ABA Formal Opinion 483 says lawyers have a duty to notify clients when their information has been compromised. The trigger is stated in terms of the work rather than the data: notice is owed where the lawyer’s ability to perform the legal services for which the lawyer was hired is significantly impaired. And the opinion says that duty is owed irrespective of what type of security efforts were implemented beforehand. Doing everything right does not remove it.
Opinion 483 sets no deadline. It contains no clock of any length. If you have been told there is a 30-day or 72-hour ethics deadline for telling a client, that number came from somewhere else, usually a state breach statute that applies to different data on a different trigger. Real clocks exist and they bind, but they are not in 483.
One consequence worth stating, because it cuts against the intuition the section above builds. An incident that encrypts nothing and takes nothing can still impair your ability to do the work, and an incident that takes copies while leaving your systems running perfectly can too. Neither of those looks like a breach in the way people picture one.
The requirement that is hard is the CLE
Florida requires every member of the Bar to complete 30 credit hours every three years, and at least 3 of those 30 must be in approved technology programs. That has been the rule since 8 January 2024. Note the phrasing the rule itself uses: three of the thirty, carved out of the total rather than added on top of it.
The history is the part worth having, because it says more about how hard this obligation bites than any assertion could. When Florida adopted the technology requirement in 2017, the hours were additive: the court raised the cycle from 30 hours to 33 precisely to make room for them. In 2024 it cut the total back to 30 and kept the three. So a Florida lawyer today completes the same 30 hours per cycle that were required before technology CLE existed. The bar added a requirement and then removed the hours that paid for it.
What your state requires, and it is not the same everywhere
This is where a national page has to be careful, and where we have seen other pages get it wrong in a way that could cost a reader something. The general shape is that most states require reasonable security measures and do not require the program to be written down. One state requires it in writing, and it reaches firms well outside its own borders.
Massachusetts. 201 CMR 17.03(1) requires every person that owns or licenses personal information about a resident of the Commonwealth to develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts. There is no law-firm carve-out and no size exemption anywhere in the regulation. It applies based on where your client lives rather than where your office is, so an out-of-state firm with one Massachusetts client is inside it. It also covers paper as well as electronic records, which makes it broader than the statutes below. What it is not is a fixed standard: the regulation scales the safeguards to the size and resources of the business, and requires the technical elements only to the extent technically feasible. For a two-attorney firm the honest reading is that there is no exemption, only calibration.
New York. GBL 899-bb(2)(a) requires reasonable safeguards of anyone holding the private information of a New York resident, and that duty carries no size threshold at all. Two qualifications matter for a small firm. The word written does not appear anywhere in the section, so this is not a written-program mandate. And the list of specific safeguards is a deemed-compliance route rather than a mandate: meet them and you are deemed compliant, with the items introduced as examples. Small businesses have their own scaled way into that same safe harbour, which is a route in rather than an exemption out.
Florida. Section 501.171(2) requires reasonable measures to protect and secure data in electronic form containing personal information. The security duty carries no size threshold, though other parts of the statute do, and it never mentions law firms. It reaches your firm by definition rather than by name: a partnership, professional association or other commercial entity that acquires, maintains, stores or uses personal information is a covered entity. It requires no program and nothing in writing. The statute does not establish a private cause of action, and its civil penalty reaches the notice duties rather than the security duty, so a failure of the security duty is not the thing that penalty is for.
The practical answer for a firm with clients in several states is that the strictest rule you touch is the one that governs your paperwork, and for most firms that is Massachusetts. We are not going to tell you which of these reaches you. That is a question for the firm, and you are better placed to answer it than we are.
Why firms buy this anyway
Everything above is a reason the law will probably leave you alone. Firms still buy this, and the reasons are worth stating plainly, because none of them is a regulator.
The licence is not the control. You can buy every product in these plans yourself, and the prices are public. What the claims data says is that owning the tool is not what decides the outcome. At-Bay, reporting across more than 100,000 policy years, found that 60% of one ransomware group’s victims had a leading endpoint detection product in place and were compromised anyway. Beazley Security reported that in approximately 53% of the business email compromise cases it handled in the first quarter of 2026, the organization had multi-factor authentication enabled. Both of those firms sell insurance against the loss, so neither has a reason to flatter the tooling.
The application is answered from an archive or from memory. A cyber proposal form is not a questionnaire that gets filed away. Carriers state that the application is deemed attached to and becomes part of the policy, and that a misrepresentation in it is grounds for rescinding the policy that was issued on it. Rescission means the policy is treated as never having existed, so it pays nothing, and it lands after the loss rather than before it. Answering the control sections from a dated record of what was actually running is the cheapest protection available against that mechanism, and it is most of what the monthly evidence pack is for. One caveat we will offer unprompted: the rescission matter usually cited to make this point was resolved on the parties’ own stipulations, with no admitted misrepresentation, no court finding and no published opinion. Anyone citing it to you as precedent is citing a stipulation.
Privilege. For every other kind of client, running the incident response plan and the annual tabletop under a counsel engagement is a workaround we have to explain. For your firm it is simply the natural arrangement, because the counsel is you. This is the one place where an offering built for regulated financial firms fits a law firm better than it fits the buyer it was written for.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Written security program and incident readiness | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Client notification decision file, including the reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and 72-hour notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and a document pack you can hand to an insurer | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.
Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. A firm smaller than that pays the same monthly figure, so a two-attorney firm should weigh it against what a single incident would cost it rather than against a per-seat rate.
Your cyber cover, and how you probably got it
Most pages about law firm cyber insurance describe a transaction their reader has never had. Among ABA survey respondents in 2023, 37% of firms of two to nine attorneys and 31% of solo attorneys reported carrying cyber liability cover at all, both down from the year before. And of the firms that do have it, many did not fill in a standalone cyber application to get it. They got it through their malpractice carrier, sometimes attached automatically to a quote, sometimes on a short bar-endorsed form of about nine questions. One legal malpractice insurer includes first-party cyber protection at no extra charge, with no controls application at all, and sets its limit higher for firms above ten charged-for attorneys than below.
So the first honest thing to say is that controls may not be what stands between your firm and a policy. On the revenue-banded application most small firms would actually see, the phrase about coverage not being bindable does not appear. Endpoint detection and next-generation antivirus are asked as two separate questions, so the second is a complete answer on its own. Backups are a list to tick rather than a threshold to clear. One large carrier’s short cyber form asks for active antivirus and asks nothing about endpoint detection; another puts the control questions in an optional supplement that earns a discount, which is the opposite of a gate.
What controls actually do here is move your price and your options. Multi-factor authentication on email and on remote access, endpoint protection or next-generation antivirus, and backups that are segregated or held offline are the questions that recur across every form we have read. On a preferred programme a no answer can push you out of that programme and onto a quote priced by hand. Anyone telling a two-attorney firm it is uninsurable without a named product is describing a market we could not find in any carrier document. What we did find, consistently, is that the answers change the number.
The trust account
A regulated financial adviser does not hold client money, because the custody rules put it with a qualified custodian. You do, by rule. Model Rule 1.15(a) requires client funds to be held separate from the firm’s own property, and for a firm doing closings, settlements or estates that account is the single largest thing an attacker can reach in one move.
The important sentence is about liability rather than about insurance. If a wire leaves your trust account to the wrong destination, you remain liable to the client for the shortfall regardless of who took the money, and a trust account shortfall is itself a matter your bar can act on. That obligation does not depend on whether anyone reimburses you. It is why this control is worth more attention than its position on any application would suggest.
The cover for it sits in a seam. One legal malpractice insurer states plainly that its policy, and most professional liability policies, do not cover these events. Where cyber cover is bundled with malpractice the sublimit for funds transfer fraud is often around sixty thousand dollars, which is worth setting against the size of a single closing wire. And at least one carrier conditions that coverage on a safe harbour requiring a written, original, notarized disbursement instruction for outgoing trust wires, which is a procedure a firm either follows every time or does not have.
Every plan here includes a written wire verification procedure: call-backs to a number agreed at onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who started them, on a different device. It is the least sophisticated control in this offering and the one most likely to be the reason a firm is still solvent.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to the partner who owns thisProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
The written security program
Included in Monitor + Comply and Complete. No rule of professional conduct requires a law firm to hold a written information security program, and Opinion 483 recommends an incident response plan rather than requiring one. If your firm holds personal information about a Massachusetts resident then that state’s regulation does require the program in writing, and that is the one place this becomes a legal question rather than a commercial one.
What the document is worth without a rule behind it is this. The incident response program keeps its three parts separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision Opinion 483 leaves to your judgment, with a filing structure that records why you decided not to notify where that was the outcome, which is the record you would want if the decision were questioned later. The vendor inventory is the list of outside companies that touch client data, their due diligence files, and a 72-hour notice expectation put to each of them in writing. The records schedule and document pack exist so that an insurance renewal, a client questionnaire or a client asking what happened is answered from a folder rather than from a scramble.
An annual tabletop exercise and a written after-action report are included on those two plans. Nothing requires that either, and we say so rather than imply otherwise. It is what turns a written plan into a tested one, and it is the deliverable that most often changes what a firm does next.
An honest boundary. We prepare these documents for the firm to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice, which is a slightly absurd sentence to write to this reader and is true anyway. Where a judgment call belongs to the firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What is included, what is not, and what stays yours
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Helpdesk on the two Monitor plans, which stays with your existing IT provider
- Incident response and forensics inside the monthly fee, which is billed separately
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory or insurance advice
- Writing or sending your breach notifications
- Standing in for the partner who owns your technology and security decisions
- Work on site or outside business hours, except by arrangement
You do
- Name a primary and a backup technical contact, and tell us if that changes
- Respond within four business hours when we escalate something urgent
- Review and adopt the policies we prepare
- Own the accuracy of anything you file with a court, a bar or an insurer
- Tell us before you add people, offices, systems or vendors
- Keep your existing IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
If the worst happens
Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.
Hour one to day ten
- Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
- Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether client information was actually reached. That last question is the one your notification decision turns on, and with an actor that takes copies without encrypting anything it is the only question that matters.
- By day ten, report. A written forensic report the firm, your insurer and if necessary a court can all read. Written to be defensible, because we write reports that go to court.
- Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.
Who does the work
A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.
Two things we put in writing, and you will recognise both. Where privilege matters we work under an engagement from the firm as counsel, set up at onboarding so it is ready rather than improvised at 2am. You do not need us to explain what that protects or why the timing of it matters. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.
A great deal of what we are called for is not an outside attacker at all. A departing associate who copied the client file to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.
The first ninety days
- Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. We hand it over before you ask because you are about to make us one of the outside companies that touches your client data, and you should be able to answer for us the way you would answer for any other vendor.
- Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. Wire verification procedure written and agreed. First backup taken and first restore proven, not assumed.
- Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates prepared, vendor inventory built and the 72-hour expectation put to each provider in writing. The firm reviews and adopts.
- Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing or renewing insurance, we assemble the control evidence for your broker.
What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches client information, your current policies however incomplete, and the name of whoever at the firm owns this decision.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $2,000 | from $2,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your firm grows
Additional named user
$35/mo
Additional workstation
$25/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Our duty to you
We will tell you within 72 hours of becoming aware of a breach affecting a system that holds your client information. That is a contractual commitment we make to you, not a regulated status we hold.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.
How an engagement begins
- A scoping call. Forty-five minutes. We walk your environment and put a fixed number against what it would take to run it properly. There is no charge and no obligation, and we do not produce a written finding about your current state unless you ask us to.
- Written scope. Deliverables, timeline and price, approved by you before any work begins.
- Discovery, deployment and the program. The ninety days above, with a dated record at every step.
Why this work matters
A firm of four people holds the same confidences as a firm of four hundred, with none of the staff to protect them. Almost nothing in the rules requires what is on this page. What argues for it is a named group that calls law firms pretending to be their IT department, a trust account that cannot be un-emptied, and a client who will one day ask what happened to their file. Producing a dated record every month is the whole of this offering.
















