Law Letter Hub Articles

Cybercrime Update: Issues for Law Firms

1 December 2019

This is my first article in my capacity as the Professional Indemnity Insurance Scheme Claims Manager for the Law Society of Tasmania. I thought it was a timely opportunity to revisit the issue of cybercrime and the current issues that are impacting on the legal profession. I recently attended the 2019 State Legal PII Roundtable meeting in Sydney. The meeting is attended by representatives from across Australia with a focus on the current risk and risk management issues for lawyers across Australia.

We were fortunate enough to have a keynote speaker, Mr Warrick McClean, who is a Principal and the Chief Executive Officer of Coleman Grieg Lawyers, a midsize firm located in Western Sydney. In his capacity as the Chief Executive Officer of a midsize firm he is uniquely placed to understand the emerging issues that impact upon firms of this size. In his keynote address, in addition to discussing technological innovation for law firms he identified key considerations for law firms as they relate to cybercrime and the impact on firms.

Types of Attack that are Occurring – Who is at Risk
The take home message is that cybercrime is on the increase and fraudsters are becoming more sophisticated. Cybercrime is not limited to the large high-profile firms that have an international profile. Cybercrime is in fact directed toward smaller firms, including those operated by sole practitioners. The reasoning is smaller firms are less likely to spend resources and time on educating staff in the area of cybercrime and the types of cyberattack. In addition, smaller law firms are less likely to have adequate cyber security systems in place and to have access to an IT provider or cyber security expert that has the skill to manage these issues. This is particularly true once a law firm’s IT system has been compromised and subjected to a cybercrime attack.

The types of attacks that are on the increase include the following:

Phishing Attacks

These are attempts to access and obtain sensitive information and gain access to client funds. Often this occurs in the context of conveyancing transactions where the fraudster who is posing as a client, sends an email stating that the bank account details have changed. Settlement funds are then directed to the fraudsters account.

A recent example of this with a slight twist involved a client who was involved in a conveyance for the purchase of a property. The fraudsters were monitoring his Bigpond email account. The client received an email from the fraudster posing as the law firm to transfer money to the law firm’s account for settlement. The email was not sent by the law firm but by the fraudster who was monitoring the clients email account. This was not detected until the client rang the firm the following week to check that the funds had been received.


Ransomware
This type of attack is on the increase and includes an attack on a firm’s computer systems and smart phones used by legal and support staff. The purpose of these attacks is to encrypt devices until a ransom has been paid. Ransomware is often spread by staff inadvertently clicking on links that look genuine. In 2017 international law firm DLA Piper was the subject of a significant ransomware Petya attack. This resulted in a largescale interruption to business and operations.

Data Theft a Key Issue – The Value of a Client’s Information
One of the key issues identified in the keynote address was the theft of data from legal firms. There is no doubt that lawyers have a professional, ethical and commercial obligation to keep their client’s data safe, secure and confidential. Lawyers routinely deal with client information that is an extremely valuable commodity to cyber criminals. Data held can include commercially sensitive information, tax file numbers and for those firms working in the area of personal injury law this includes client’s health records. Data theft is on the increase as law firms often have a piecemeal approach to storing data and often the smaller firms do not have the financial capabilities or expertise to invest in efficient software to safeguard them from a cyberattack.

Theft of data and a breach of a client’s sensitive information has broad-reaching ramifications. This can include financial, legal and reputational damage to the firm. The potential financial costs incurred following a cyberattack can be substantial. There are the costs associated with engaging an IT provider to undertake a review and audit to determine what data has been accessed as a result of a cyberattack. This work may take days or weeks depending on the nature of the breach. In addition, substantial audit and review may be required to enable a firm to comply with reporting obligations pursuant to the Privacy Act 1988.

In the circumstances where ransomware is used a firm may experience substantial business disruption for an extended length of time. Business disruption may have a flow-on effect to multiple clients and commercial matters leading to ongoing financial damage. In the recent DLA Piper example cited above, the firm was unable to conduct business for over three days with all firm computers and smart phones disabled by encryption.

Reputational loss may arise once the general public become aware of the breach. Reputational loss may result in the loss of existing clients or impact on the retention of new clients if the general public believe that a firm has the inability to manage sensitive client data in a confidential manner. Reputational loss can be very difficult to manage with firms often taking many years to develop and nurture a client base.

Considerations Moving Forward
In summary, some of the important practical considerations for firms to consider are as follows:

  1. Firms should have a proactive approach to cyber security not simply a reactive approach once a breach takes place. For example, undertaking a review with an IT provider to ensure that data is retained in a secure environment with adequate protections to prevent unauthorised access and dissemination.
  2. In a situation where a breach takes place from a cyberattack, firms should have contingency plans in place that enable access to an IT provider and cyber security expert in a timely manner. Depending on the complex nature of the cyberattack this may require a significant level of expertise and resources from the IT provider.
  3. Consideration should be given to appropriate top-up insurance cover to assist firms manage remediation following a cyberattack. As stated above, these additional financial costs may be incurred depending on the nature of the cyberattack or data breach.
  4. Consideration should be given by firms to business continuity plan measures and the management of business disruption. One strategy recommended is that firms should review their current client engagement letters to determine if business disruption is contained within that engagement to manage potential liability issues.
  5. Cybercrime risk management should form an integral part of a law firm’s risk management strategy. This includes ensuring that staff are provided with education on the current techniques used by cyber criminals and that firms have robust internal mechanisms to communicate to staff the current cyber alerts.

Fleur Dewhurst
Lawyer
Professional Indemnity Insurance Scheme – Claims Manager
PO Box 79, Lauderdale Tas 7021
0427 800 030
fleurcd@hotmail.com

  • Cybercrime targets all firm sizes, with smaller firms often more vulnerable to sophisticated attacks.
  • Data breaches can cause significant financial, legal, and reputational harm to law firms.
  • Proactive cyber risk management and staff education are essential for legal practice security.

Lawyer
Professional Indemnity Insurance Scheme – Claims Manager

Search More Articles  Visit the search page to search more articles