What We Do
How we do it
Our Threat Response Unit (TRU) publishes security advisories, blogs, reports, industry publications and webinars based on its original research and the insights driven through proactive threat hunts.
View Threat Intelligence Resources →
Jan 19, 2023
Increased Activity in Google Ads Distributing Information Stealers
THE THREAT On January 18th, 2023, eSentire Threat Intelligence identified multiple reports, both externally and internally, containing information on an ongoing increase in Google advertisements…
Read More
View all Advisories →
About Us
eSentire is The Authority in Managed Detection and Response Services, protecting the critical data and applications of 1500+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events.
Read about how we got here
Leadership Work at eSentire
Dec 13, 2022
eSentire Named First Managed Detection and Response Partner by Global Insurance Provider Coalition
Waterloo, ON – December 13, 2022 – eSentire, Inc., the Authority in Managed Detection and Response (MDR), today announced it has been named the first global MDR partner by Coalition, the world’s first Active Insurance provider designed to prevent digital risk before it strikes. Like Coalition, eSentire is committed to putting their customers’ businesses ahead of disruption by improving their…
Read More
e3 Ecosystem
We provide sophisticated cybersecurity solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs). Find out why you should partner with eSentire, the Authority in Managed Detection and Response, today.
Learn more
Apply to become an e3 ecosystem partner with eSentire, the Authority in Managed Detection and Response.
Login to the Partner Portal for resources and content for current partners.
Blog — May 10, 2018

You're going to need a bigger boat

6 minutes read
Speak With A Security Expert Now

Sheriff Brody said it best when he came face-to-face with the great white shark that was menacing the town of Amity Island in Spielberg’s 1975 blockbuster, Jaws. And the same sentiment holds true for smaller law firms hunting large clients. The risk and responsibilities that come with large clients, such as pharmaceutical companies, disruptor banks, and investment firms, remain the same, regardless of the size of your law firm.

Unlike large firms with comparable resources with which to protect client non-public information, small firms can find themselves trapped between cyberattacks, like ransomware, that don’t prejudice based on the size of firm, and regulators who are indifferent to your size, when investigating a potential violation.

The attack on Wall Street law firms Cravath, Swaine & Moore LLP and Weil, Gotshal & Manges LLP demonstrated how stolen information, such as FDA filings and press releases, could be used to front run trades. In this case, a law firm managed HIPAA protected healthcare data and the stolen information was used to violate SEC rules and federal market laws.

These regulated clients create a significant reporting burden. Consider for example that under HIPAA compliance standards for healthcare operators and New York financial institutions governed by the Department of Financial Services (DFS), you would be required to report a material cyber breach with 72 hours. Moreover, under DFS you would have to contribute to an annual declaration on the part of the client in which not only material breaches are inventoried, but unsuccessful attempts are also documented. This can be a significant task for banks with large security teams, let alone a small law firm outsourcing IT operations.

As an industry, law firms have improved their overall cybersecurity hygiene and practices, which has resulted in a lower-than-average amount of nuisance cyberattacks as compared to other industries like healthcare, manufacturing and energy. That said, criminals consider law firms a lucrative target, and as a result, our research shows the legal industry suffers 30% more malicious attacks than other businesses. This is a symptom of cyber threats evolving from opportunistic means and transactional payments, to targeted and negotiated extortion.

These trends do not delineate by firm size. A 90-day snapshot of eSentire’s security operations statistics comparing large firms to small indicates a proportional volume of security incidents, but not so when examining breaches and security events that require immediate response. For example, consider that a large firm may represent 500-750 attorneys across 20 locations, while a small firm may have 25-50 attorneys at one location. Now consider that the small firm generates about 65,000 security traffic elements that filter down to 20 incidents, leading to one urgent incident requiring immediate response. On the other hand, the large firm generates over 40 times more traffic, 325 security incidents (16 times more), but only one escalation.

While the larger firm generates significantly more security traffic elements, the large firm/small firm ratio of escalated incidents requiring emergency response moves closer to one-to-one as the security events are investigated. Diving deeper, the data indicates that the emergency incidents were born of the same, industry-targeted attack. In other words, both the large and small firm were impacted and breached by the same targeted attack. Neither the criminals, nor their tools discriminate by the number of attorneys.

ABA Cybersecurity Recommendations

It’s not unreasonable to think that the common cyber practices and investment levels of a large law firm are not the same as those that a small firm can manage. There is no one-size-fits-all when it comes to establishing standards of reasonable care. The ABA Cybersecurity Handbook: A Resource for Attorneys, Law Firms and Business Professionals (ABA 2017), contains a resource-right-sized approach with a checklist that smaller firms can use to build a simplified cybersecurity program:

  1. Inventory hardware, applications. Keep a register of all laptops, servers, and applications. This should include cloud services, such as Amazon EC2, Microsoft Office 365, or other document management services.
  2. Identify and audit data and related obligations. By extension, you have the obligation to understand the legal and regulatory boundaries in which your clients operate, and to meet those requirements. Ensure you understand your obligations.
  3. Engage an IT consultant. Managed services firms can provide device management (updates and patching), along with basic system on-boarding and off-boarding processes. They can also help you encrypt devices and set up private networks to encrypt email and file transfers.
  4. Investigate the security of cloud service providers. Cloud services supply multi-tenant offerings that extrapolate the need for on-site management services. Remember, however, that cloud service providers are obligated to protect their servers from attack, but they are not responsible for the consequences if your credentials are hijacked.
  5. Establish cybersecurity and acceptable use policies. Leverage a consultant to build fundamental policies about the management, transfer, and storage of client confidential information.
  6. Protect sensitive data and avoid portable media. Avoid using media, such as USB keys, to store and transfer non-public information. USB keys are a main source of infection and are difficult to control if the data is not removed once the authorized use is complete.
  7. Require encryption. Unfortunately, password credentials are routinely acquired by unauthorized users. For this reason, you should encrypt hard drives or devices. Encryption offers an additional layer of security. The following links provide step-by-step instructions on how to encrypt your mobile hard drive or device:
  8. Establish a back-up system. Leverage an outsourced IT service to routinely backup and then test backups to reduce the business disruption impact in the event of a cyber breach. Backups are the best defense against ransomware attacks and avoiding having to pay ransoms.
  9. Establish a records management policy (control and destruction). Determine how documents are stored, who has access, and establish “least privilege” with a “need to know” attitude and consider how you securely destroy old documentation.
  10. Consider cyber insurance. Engage an agent to weigh the cost and benefits of insuring your business against cyberattacks and whether your business disruption, lost revenue, or other non-cyber specific policies cover cyber incidents.
  11. Review website security. Use an outsourcing service to manage your website, keep it patched and up-to-date, and consider how you protect data that is collected through Web forms or application.
  12. Establish mobile device rules. Use a Mobile Device Management (MDM) software to remotely establish required security settings (such as minimum password strength), forced encryption, and the ability to perform a remote device wipe to remove all data (called a poison pill) when the device is lost or stolen. MDM adds an additional layer of security but is costly and not a default feature of most mobile devices.
  13. Use VPN security. The best way to protect data in motion from such attacks is to use a Virtual Private Network (VPN) service. A VPN creates a secure and encrypted connection through which your data travels from you to the intended recipient. No information (including passwords) are transmitted in the clear. There are many low-cost and easily deployed VPN services.

As you look to expand business or retain your key clients in a growing environment of cyber threats, remember Sheriff Brody’s advice: Size does matter when you’re going after big fish. Weigh the benefits and risks, and recognize that there is chum in the water, put there by criminals and regulators alike. And be prepared for the behemoth that might bite your line.

This article originally appeared on Law Journal Newsletters.

View Most Recent Blogs

eSentire is the Authority in Managed Detection and Response, protecting the critical data and applications of 1500+ organizations in 80+ countries from known and unknown cyber threats. Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk, and enables security at scale. The Team eSentire difference means enterprises are protected by the best in the business with a named Cyber Risk Advisor, 24/7 access to SOC Cyber Analysts & Elite Threat Hunters, and industry-leading threat intelligence research from eSentire’s Threat Response Unit (TRU). eSentire provides Managed Risk, Managed Detection and Response and Incident Response services. For more information, visit www.esentire.com and follow @eSentire.