Securing Your Law Firm logoSecuring Your Law Firm

AI-Era Threat Readiness

AI-Era Threat Readiness for Law Firms

Most of what you have heard about AI and cyberattacks is overstated. A small number of things genuinely changed. This is about those.

The problem

Hype makes firms spend money in the wrong place.

Your firm has been told that artificial intelligence has transformed cyberattacks and you are in immediate danger. Some of that is true. A lot of it is not. A firm that reacts to the hype spends money on the wrong things. A firm that dismisses the subject entirely leaves a small number of genuinely important controls unaddressed.

What changed is the economics of attacking a small firm, the quality of impersonation, and the reliability of voice as a form of verification. What did not change is the fundamental attack path. Attackers still want your credentials and your clients' money, and they still arrive through email and identity.

The correct response is not a new product. It is redesigning three or four specific controls that quietly stopped working.

What is actually documented

The published record is narrower than the headlines.

  • In November 2025, an AI developer reported that a threat actor used its models to automate 80 to 90 percent of the effort involved in an intrusion, with human involvement limited to critical decision points.
  • That developer later analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping the techniques onto MITRE ATT&CK, with results contributed to Verizon's 2026 Data Breach Investigations Report.
  • A major security vendor testing a frontier model under a restricted-access program in 2026 reported that current models are highly capable at finding software vulnerabilities and converting them into working exploit paths in near-real-time.
  • In spring 2026, providers of the most capable models chose not to release them through unrestricted public access, launching controlled-access programs limited to selected technology firms, security companies, financial institutions, and governments.

What is not happening

AI is not autonomously running end-to-end attacks in the real world. The most recent published international assessment reports that general-purpose AI systems have not been observed conducting complete attacks independently, and that autonomous attacks remain limited because these systems cannot reliably execute long, multi-stage attack sequences.

Your firm is not being targeted by a machine that thinks. The documented pattern is a human attacker using AI as a force multiplier. The human still chooses the target and makes the decisions.

No product solves this. Any vendor selling your firm an AI-powered defense against AI-powered attacks is selling a narrative. The controls that work against a well-assisted attacker are the same ones that work against a well-resourced human attacker. They simply have to be implemented rather than assumed.

Your existing security spend is not wasted. Most of it still works. The next section identifies exactly which parts do not.

What genuinely changed

Five things changed for a firm your size.

Obscurity stopped protecting you.

Small firms were rarely safe because they were secure. They were safe because researching them was not worth an attacker's hours. That research cost has collapsed, and the calculation that protected small firms no longer holds.

The phishing signals you trained staff to spot no longer work.

Poor grammar and generic greetings were artifacts of attackers writing at volume in a second language, not properties of fraud. A model supplied with a partner's public biography, published articles, filed briefs, and professional social media can reproduce that register closely enough that the traditional tells are simply absent.

Voice is no longer verification.

The near-universal control at law firms is calling back on a known number to confirm wire instructions, which assumes a familiar voice confirms identity. A short sample of someone's speech — a deposition clip, a webinar, a voicemail greeting — is enough material to work from. For any firm that moves client funds, this is the most important item on this page.

The patch window compressed.

If working exploits can be produced from newly discovered vulnerabilities in near-real-time, the interval between disclosure and exploitation shrinks. A monthly patching cadence on internet-facing systems is now too slow.

Your vendors are the softer target.

Your firm depends on practice management, document systems, e-signature, billing, and depending on practice area, title, escrow, or e-discovery partners. You inherit their exposure and have limited ability to audit it.

Which controls still work

Some controls still do exactly what your firm bought them to do.

ControlStatusWhy
DMARC at enforcementHoldsDomain authentication is cryptographic. It does not care how well written the message is.
FIDO2 security keys or passkeysHoldsCredentials are bound to the legitimate site. A perfect lure still fails.
Dual authorization above a thresholdHoldsRequires compromising two people through two channels.
Pre-shared challenge phraseHoldsCannot be synthesized from public material.
Least-privilege access and ethical wallsHoldsLimits blast radius regardless of how entry occurred.
Tested backupsHoldsRecovery is unaffected by attacker sophistication.
SMS, app code, or push MFADegradedReal-time relay attacks defeat these, and better lures raise the rate at which users approve.
Callback verification by voice recognitionDegradedVoice is no longer proof of identity.
Training based on spotting bad writingDegradedThe tells it teaches are gone.
Monthly patching of internet-facing systemsDegradedThe exploitation window is shorter than the cadence.
We are too small to be targetedNo longer validTargeting cost collapsed.

Six of your controls still do exactly what you bought them to do. Four need work. That is the entire finding.

The engagements

Founding client pricing applies through December 31, 2026.

Prices shown are for firms of 1 to 10 users; 11 to 25 add 40%; 26 to 50 add 80%. Pricing shows the full catalog.

AI Threat Briefing for Partners

$1,450

A 90-minute session with your partners plus a written briefing document: what is actually documented, what is projection, and what it means for your firm specifically. Includes a one-page summary the managing partner can circulate and a list of questions to put to your IT provider, your software vendors, and your insurance broker. Written so you can hand it to your existing IT provider and ask them to implement it.

View matching pricing entry

AI-Era Attack Surface Review

$2,450

What an AI-assisted attacker can assemble about your firm from public sources: partner writing samples sufficient for tone and voice reproduction, client and matter inference from public filings and press, staff and reporting structure, technology fingerprinting, and the timing signals that indicate when your firm moves funds. Delivered with a prioritized reduction plan.

View matching pricing entry

Verification Protocol Redesign

$1,850

We rebuild your funds-transfer verification so it does not depend on recognizing a voice or a face. Pre-shared challenge phrases established at matter intake through a channel separate from email, mandatory out-of-band confirmation, dual authorization thresholds, and a written procedure your staff can follow under pressure. Documented so it can be attached to a client engagement letter and shown to an insurer.

View matching pricing entry

Phishing-Resistant Identity Rollout

$3,450

Hardware security keys or passkeys for every attorney and every staff member with mailbox access, enforced through Conditional Access, with legacy authentication eliminated and break-glass accounts documented. This is the single highest-value change available to your firm, because its effectiveness does not depend on how convincing the attack is.

View matching pricing entry

AI-Era Tabletop Exercise

$3,950

A facilitated exercise built around a convincingly faked confirmation of altered wire instructions on a closing, with timed injects, plus a written after-action report.

Major cyber insurance carriers now require a documented tabletop exercise completed within the previous twelve months as a condition of coverage. If your renewal asks whether you have tested your incident response plan in the last year, this is the engagement that lets you answer yes with documentation.

View matching pricing entry

AI-Era Threat Readiness Program

Recommended

$11,950

All five engagements as a single scoped program, saving $1,200 versus purchasing separately.

View matching pricing entry

Who this is for

Use this when the firm moves money and the procedure has to hold up under pressure.

Good fit if

  • Your firm handles real estate closings, settlements, escrow, or any recurring funds transfer.
  • Your wire verification procedure depends on recognizing a voice.
  • Your staff still authenticate with app codes or push approvals.
  • A client or insurer has asked what you are doing about AI-enabled fraud.
  • You want a straight answer about what is real before you spend anything.

Not the right service

This is not an AI product pitch.

Not the right service if

  • You are looking for an AI-powered security product, because we do not sell one and are skeptical of firms that do.
  • You want a vendor who will tell you the threat is worse than the published research supports.

How we approach this

We do not have access to restricted frontier model programs, and we will not claim otherwise. What we do is track the published research from national safety bodies, financial regulators, and vendor threat intelligence teams, and translate it into specific controls for firms that will never read a systemic risk report. Where we state a fact on this page, we cite it. Where the research says a threat is overstated, we say that too.

Our backgrounds — a former attorney and a security researcher — are on our About page.

Frequently asked questions

The questions that actually matter.

AI is documented as assisting real intrusions, with one developer reporting a threat actor automated 80 to 90 percent of the effort involved in an intrusion using its models. What is not documented is AI conducting complete attacks independently. The realistic threat model is a human attacker moving faster and writing better, not an autonomous machine.

Voice synthesis has advanced to the point where a short sample of someone speaking is enough to work from, and lawyers leave a great deal of recorded speech in public. This is why we treat voice as no longer being a form of verification and rebuild the procedure around something that cannot be synthesized.

No. Every recommendation we make involves controls that already exist and are widely available. The work is redesigning procedures and configuring identity properly, not purchasing a product.

Not useless, but the part that teaches staff to detect fraud by writing quality no longer works. Training has to shift from detection to procedure: a staff member should verify a wire change the same way whether the message looks suspicious or looks perfect.

Hardware security keys and passkeys bind credentials to the legitimate website, so a user cannot hand them to an attacker even if the fake site is flawless. Text message codes, app codes, and push approvals can all be relayed in real time by an attacker. As lures get better, the gap between these two categories widens.

That reasoning used to hold, because researching a small firm was not worth an attacker's time. The cost of that research has collapsed. Being small is no longer a security control, though it does mean the right response is proportionate rather than expensive.

Some of it, yes, and we say so plainly in the briefing document. If your provider will implement phishing-resistant authentication, shorten the patch window on internet-facing systems, and get DMARC to enforcement, that covers a meaningful share of it. The verification protocol redesign and the tabletop are the pieces that typically need someone who knows how law firms actually move money.

Research in this area moves quickly. We re-verify every source before each delivery and date the briefing document accordingly.

Free starting point

Start with the free Proprietary Exposure Review

If your firm wants to know what it already exposes before it changes any controls, the free review is the fastest place to begin.

Must match your domain so another firm cannot request your review.

Public records only. Your report goes only to the verified inbox that requested it. We do not sell, share, or broker firm data, and we delete it after 30 days unless you engage us.