AI-Era Threat Readiness
AI-Era Threat Readiness for Law Firms
Fake voices and polished phishing emails are easier to create. We identify the few protections that need to change and help your firm rebuild them with a legal-risk-first approach that complements your existing IT operations.
Threat readiness
Business-focusedFocus on the controls that actually changed.
We cut through hype and focus on the practical legal-risk changes around wire fraud, impersonation, MFA, and verification workflows.
1
Identify real threats
2
Assess control gaps
3
Rebuild the right defenses
The problem
Hype makes firms spend money in the wrong place.
You may have heard that artificial intelligence has transformed cyberattacks and that your firm is in immediate danger. Some of that is true, but much of it is not. The right response is to fix the few protections that genuinely need to change.
What changed is how cheaply attackers can research a small firm, how convincing impersonation can be, and how unreliable voice recognition is as proof. Attackers still want your passwords and your clients' money, and they still arrive through email and sign-in accounts.
The answer is not a new product. It is redesigning three or four specific protections that no longer work as well as they used to.
What is actually documented
The published record is narrower than the headlines.
- In November 2025, an AI developer reported that a threat actor used its models to automate 80 to 90 percent of the effort involved in an intrusion, with human involvement limited to critical decision points.
- That developer later analyzed 832 accounts banned for malicious cyber activity between March 2025 and March 2026, mapping the techniques onto MITRE ATT&CK, with results contributed to Verizon's 2026 Data Breach Investigations Report.
- A major security vendor testing a frontier model under a restricted-access program in 2026 reported that current models are highly capable at finding software vulnerabilities and converting them into working exploit paths in near-real-time.
- In spring 2026, providers of the most capable models chose not to release them through unrestricted public access, launching controlled-access programs limited to selected technology firms, security companies, financial institutions, and governments.
What is not happening
AI is not autonomously running end-to-end attacks in the real world. The most recent published international assessment reports that general-purpose AI systems have not been observed conducting complete attacks independently, and that autonomous attacks remain limited because these systems cannot reliably execute long, multi-stage attack sequences.
Your firm is not being targeted by a machine that thinks. The documented pattern is a human attacker using AI as a force multiplier. The human still chooses the target and makes the decisions.
No product solves this. Any vendor selling your firm an AI-powered defense against AI-powered attacks is selling a narrative. The controls that work against a well-assisted attacker are the same ones that work against a well-resourced human attacker. They simply have to be implemented rather than assumed.
Your existing security spend is not wasted. Most of it still works. The next section identifies exactly which parts do not.
What genuinely changed
Five things changed for firms your size.
Being small is no longer enough protection.
Small firms were often overlooked because researching them took too much time. AI has lowered that cost, so attackers can learn more about a firm before making contact.
Polished phishing emails are harder to spot.
Poor grammar and generic greetings used to be common warning signs. A fake message can now sound like a real partner, so staff need a verification procedure that works even when the message looks perfect.
A familiar voice is no longer proof.
Calling back to confirm wire instructions is not enough if the person on the call can be imitated. Firms that move client funds need a second check that does not depend on recognizing a voice.
Internet-facing systems need faster updates.
If attackers can turn newly discovered weaknesses into working attacks quickly, waiting a month to update public systems may be too slow.
Your vendors affect your risk too.
Your firm depends on practice-management, document, e-signature, billing, title, escrow, and e-discovery providers. Their weaknesses can affect you even when your own systems are well managed.
Which controls still work
Some protections still work exactly as intended.
| Control | Status | Why |
|---|---|---|
| DMARC at enforcement | Holds | Domain authentication is cryptographic. It does not care how well written the message is. |
| FIDO2 security keys or passkeys | Holds | Credentials are bound to the legitimate site. A perfect lure still fails. |
| Dual authorization above a threshold | Holds | Requires compromising two people through two channels. |
| Pre-shared challenge phrase | Holds | Cannot be synthesized from public material. |
| Least-privilege access and ethical walls | Holds | Limits blast radius regardless of how entry occurred. |
| Tested backups | Holds | Recovery is unaffected by attacker sophistication. |
| SMS, app code, or push MFA | Degraded | Real-time relay attacks defeat these, and better lures raise the rate at which users approve. |
| Callback verification by voice recognition | Degraded | Voice is no longer proof of identity. |
| Training based on spotting bad writing | Degraded | The tells it teaches are gone. |
| Monthly patching of internet-facing systems | Degraded | The exploitation window is shorter than the cadence. |
| We are too small to be targeted | No longer valid | Targeting cost collapsed. |
Six of your controls still do exactly what you bought them to do. Four need work. That is the entire finding.
The engagements
Fixed-scope engagements, priced individually.
Prices for these specialized engagements are shown below. For the complete public service catalog, view the one-time services page.
AI Threat Briefing for Partners
$1,450
A 90-minute session with your partners plus a written briefing document: what is actually documented, what is projection, and what it means for your firm specifically. Includes a one-page summary the managing partner can circulate and a list of questions to put to your IT provider, your software vendors, and your insurance broker. Written so you can hand it to your existing IT provider and ask them to implement it.
View pricingWhat an Attacker Can Learn About Your Firm
$2,450
What someone can learn about your firm from public sources: how partners write, which matters and clients are visible, who works for the firm, what technology you use, and when your firm moves money. Delivered with a prioritized plan to reduce the exposure.
View pricingVerification Protocol Redesign
$1,850
We rebuild your funds-transfer verification so it does not depend on recognizing a voice or a face. Pre-shared challenge phrases established at matter intake through a channel separate from email, mandatory out-of-band confirmation, dual authorization thresholds, and a written procedure your staff can follow under pressure. Documented so it can be attached to a client engagement letter and shown to an insurer.
View pricingSign-In Protection That Phishing Cannot Easily Steal
$3,450
Security keys or passkeys for every attorney and staff member with mailbox access. We turn off older, weaker sign-in methods and document emergency access. This works even when a phishing message looks convincing.
View pricingAI-Era Tabletop Exercise
$3,950
A facilitated exercise built around a convincingly faked confirmation of altered wire instructions on a closing, with timed injects, plus a written after-action report.
Major cyber insurance carriers now require a documented tabletop exercise completed within the previous twelve months as a condition of coverage. If your renewal asks whether you have tested your incident response plan in the last year, this is the engagement that lets you answer yes with documentation.
View pricingAI-Era Threat Readiness Program
Recommended$11,950
All five engagements as a single scoped program, saving $1,200 versus purchasing separately.
View pricingWho this is for
Use this when the firm moves money and the procedure has to hold up under pressure.
Good fit if
- Your firm handles real estate closings, settlements, escrow, or any recurring funds transfer.
- Your wire verification procedure depends on recognizing a voice.
- Your staff still authenticate with app codes or push approvals.
- A client or insurer has asked what you are doing about AI-enabled fraud.
- You want a straight answer about what is real before you spend anything.
Not the right service
This is not an AI product pitch.
Not the right service if
- You are looking for an AI-powered security product, because we do not sell one and are skeptical of firms that do.
- You want a vendor who will tell you the threat is worse than the published research supports.
How we approach this
Our backgrounds – a former attorney and a security researcher – are on our About page.
Frequently asked questions
The questions that actually matter.
AI is documented as assisting real intrusions, with one developer reporting a threat actor automated 80 to 90 percent of the effort involved in an intrusion using its models. What is not documented is AI conducting complete attacks independently. The realistic threat model is a human attacker moving faster and writing better, not an autonomous machine.
Voice synthesis has advanced to the point where a short sample of someone speaking is enough to work from, and lawyers leave a great deal of recorded speech in public. This is why we treat voice as no longer being a form of verification and rebuild the procedure around something that cannot be synthesized.
No. Every recommendation we make involves controls that already exist and are widely available. The work is redesigning procedures and configuring identity properly, not purchasing a product.
Not useless, but the part that teaches staff to detect fraud by writing quality no longer works. Training has to shift from detection to procedure: a staff member should verify a wire change the same way whether the message looks suspicious or looks perfect.
Hardware security keys and passkeys bind credentials to the legitimate website, so a user cannot hand them to an attacker even if the fake site is flawless. Text message codes, app codes, and push approvals can all be relayed in real time by an attacker. As lures get better, the gap between these two categories widens.
That reasoning used to hold, because researching a small firm was not worth an attacker's time. The cost of that research has collapsed. Being small is no longer a security control, though it does mean the right response is proportionate rather than expensive.
Some of it, yes, and we say so plainly in the briefing document. If your provider will implement phishing-resistant authentication, shorten the patch window on internet-facing systems, and get DMARC to enforcement, that covers a meaningful share of it. The verification protocol redesign and the tabletop are the pieces that typically need someone who knows how law firms actually move money.
Research in this area moves quickly. We re-verify every source before each delivery and date the briefing document accordingly.
Related services
The usual next step after the briefing.
Free starting point
Free Zero-Access Exposure Review™
2 minutes. No internal access. No passwords.
If your firm wants to know what it already exposes before it changes any controls, the free review is the fastest place to begin.
