Dan Schiappa, the chief product officer at cybersecurity firm Arctic Wolf, hasn’t seen the global cyber landscape change over the years so much as he’s seen it metamorphose. And, despite defenders’ continued work in thwarting and responding to attacks, the attackers seem to remain one step ahead.
“As defensive technologies get better, it’s an arms race with the adversarial part of the market. No matter how good we get, they just seem to get even better,” he explained.
Amid attackers’ seemingly ever-growing intelligence and agility, there’s the legal sector: an industry where there’s continual handling of highly sensitive information and data, as well as significantly-sized funds, making it a prime target for those with nefarious intentions. For instance, in its research, the Solicitors Regulation Authority found that 75% of solicitors firms had been the target of a cyber-attack.
“Security is something that legal firms know they need, but they don’t have the expertise to drive it themselves,” Schiappa noted. Given that cybersecurity proficiency isn’t always available in-house, how can legal firms help bolster their defences, thereby lessening both the likelihood of attack and the severity of an attack if it occurs? Further, how can a robust security programme be put in place?
As well as serving as the CPO for Arctic Wolf, Schiappa has held high-ranking, security-related positions at the likes of Sophos and Microsoft. And after sitting down with him, here are a handful of cyber considerations and recommendations that legal firms — as well as applicable advice for all firms, regardless of sector — can take heed of.
Minimising Human Error Through Effective Security Training
When discussing cybersecurity, it’s hard not to mention the matter of human error. Just last month, DIGIT reported on research where 55% of cybersecurity professionals cited human error as the number one cause of cloud data breaches, ahead of exploitation of vulnerabilities at 21%.
“Human beings are still the weakest link in cybersecurity,” said Schiappa, and with the act of phishing and socially-engineered attacks, it’s “very low-hanging fruit” for adversaries. Further, Schiappa underscored that “with generative artificial intelligence, that’s going to become even more difficult to defend against and easier to perpetrate.”
With this in mind, training employees on cybersecurity resilience and associated best practices continually — their strengths are rooted in other areas, rather than cyber, after all — is key.
“Train your people — make sure they understand to look at everything with a sceptical eye, and that they’re very cautious about things, particularly if there’s a time urgency to it. That’s how they usually get people to throw away their logic: the attackers try to create some urgent, emergency situation where people respond and forget about the basics.”
Prioritising Cybersecurity When Pivoting to the Cloud
The COVID-19 pandemic helped to accelerate many industries’ digital transformation efforts, not least with cloud adoption and uptake. In the legal sector alone, 70% of respondents reported that they used cloud computing up from 58% in 2019, according to the 2022 American Bar Association Legal Technology Survey Report.
However, with a shift to the cloud comes additional security considerations — and it’s being cognizant of these, as well as adhering to related best practices, that can help firms to ensure that they’re being as cyber secure as possible.
“‘I don’t have to worry about security anymore, because I put everything in the cloud’ — that’s a famous last words statement. It just moved the cheese, as they say, to another area of concern. Companies have to recognise that it’s just different security,” explained Schiappa. “There’s no doubt that there are better things about the cloud than traditional IT infrastructure, but there are also things that are different that you have to protect.”
Speaking of the benefits, one notable positive of the cloud is that it can help companies to centralise data — especially useful when working with supply chain partners. However, Schiappa advocated for firms to create a cloud environment where data can never reside locally, as to reduce risk.
As an example, Schiappa mentioned Microsoft 365, and the configuration option that enables an organisation’s users to download items to their desktop. “Just turn that off,” he said. “Don’t allow that to happen — force it to take place in the browser, do not let anyone keep a local copy of it.”
What’s more, Schiappa says that data on the cloud needs to be encrypted. “One of the oldest and most trusted forms of security that people forget? To encrypt the data. They’ll put up 57 levels of defence and then if someone can get through it they just get free access to the data. Encrypt it — that’s the last line of defence. Vendors like Microsoft and Amazon and others have great mechanisms for doing that.”
Being Security-minded When Utilising Sector-specific Tech
In 2023, firms can work in a more streamlined, productive manner due to the harnessing and proliferation of innovative sector-specific technologies, such as lawtech tools. A LawtechUK report from 2021 highlighted this burgeoning market, stating that UK lawtech startups and scaleups are growing at a rate of 101%, outpacing the likes of fintech and healthtech.
But when using lawtech — and most kinds of technology — there are practices to adhere to for being as cyber secure as possible.
In terms of ways to help reduce risk when using such tools, and especially when working and sharing information with folks both inside and outwith your firm, Schiappa said: “One is access control, and what I would call a zero trust model.
“You are providing many different outside and inside people to have access to things, and so making sure that you’re limiting what those people can get to is one great element of it. So in the event that they are compromised, you’ve reduced the damage of what they can do inside the organisation.”
Encrypting data within the tools you use is, again, a necessity. Schiappa used an especially good analogy for describing why encryption is wholly important: “I always say if someone breaks into a jewellery store and they can’t steal any of the jewels, it’s a nuisance — but you can wait for the police to show up. If someone’s in there, smashing into the jewellery cases and running out with the jewels, that’s bad — and with encryption, they can break in but not get the jewels. That’s a really important aspect of it.”
Recommended reading
- Professional Services Firms ‘Bearing the Brunt’ of Cyber Attacks
- Three Scots Companies Land Spot in Legal Mentoring Programme
- UK’s Cyber Laws Updated to Boost Resilience to Attacks
Driving Down the Chances of a Ransomware Attack
While ransomware attacks occur in — and encrypt and exfiltrate data from — all industries, Schiappa mentioned that “Attackers look at the legal industry as high-quality, high-value data, and with a soft underbelly. For them, that’s just the perfect combination.”
Schiappa warned that in the contemporary world, ransomware attacks against firms are highly targeted — meaning firms need to preempt such attacks with truly robust cybersecurity defences.
“As we see today, ransomware isn’t like how it used to be in what I would call the ‘pray-and-spray’ model, where you just throw it out as wide as you can, and hope it sticks somewhere. Now, it’s very targeted.”
“They’re going to know quite a bit about the firm already, they’re going to know who’s in the firm, they’re gonna know potentially who the clients are, what data they’re gonna have. They’re gonna go very systematically through that in a very complex way. So, it’s tough for firms to defend without the right security protections,” Schiappa explained.
Complicating matters even further is how generative artificial intelligence could augment ransomware and its deployment moving forward.
“Ransomware-as-a-Service has been around for a long time, but AI is going to make that even more of a problem. You’re going to have very smart, capable attackers who can build very sophisticated models and make those available to other people.
“It’s like the proliferation of nuclear bombs: it takes a lot of science, a lot of money, a lot of research to build one, but if you start giving them to just anybody out there it really raises the risk factor, and that’s what AI is going to do on the cyber landscape. They’ll make the tools and arm other people.”
With the increased threat of ransomware — and in addition to the myriad threats of the current cyber landscape — Schiappa advocates for firms that don’t have the necessary in-house expertise to partner with a company that takes a holistic approach to cybersecurity defence.
“So, somebody who can help you get your basic security hygiene in order, somebody who can do security monitoring for you, somebody who can respond when you have an incident — because the sooner you can respond to an incident, the less damage you’re gonna have. All of those things, interconnected, is really what a good security programme is.”
Reducing Risk in a Continually Evolving Cyber Landscape
As DIGIT’s interview with Schiappa began winding down, he restated how legal firms are more aware of cyber risks now than ever before.
This, undoubtedly, is cause for celebration. But as the cyber landscape continues to shift, evolve, and metamorphose further, a robust defence against attackers will become even more needed for law firms — and all firms, regardless of sector — than it already is.





