Mossing & Navarre Toledo hit by ransomware. Bryan Cave Leighton Paisner CCG breach. Texas State Bar INC Ransom attack — January 2025. Law firms are high-value targets precisely because of what they hold: litigation strategy, M&A deal terms, IOLTA trust accounts, and privileged communications. Ransomware groups don't just encrypt — they exfiltrate and threaten to publish. Attorney-client privilege ends the moment client files hit a leak site. CoreRecon delivers SOC-grade monitoring, 30-min IR SLA, IOLTA wire fraud defense, and TX residency at $89–$129/endpoint — no enterprise contract required.
📄 Download the 2026 TX Law Firms Threat Brief — Mossing & Navarre, Bryan Cave CCG, TX State Bar INC Ransom + full regulatory stack →Law firms are high-value targets: sensitive documents, litigation strategy, M&A deal terms, client financial data, wire transfer authority. Ransomware affiliates have shifted to exfil-and-leak tactics specifically because privilege-protected data carries maximum extortion leverage. BEC actors target partner emails and escrow accounts for wire fraud — a separate $4.3B annual threat category.
ABA Model Rule 1.6 and Texas Disciplinary Rule 1.05 impose a duty of confidentiality that has no exceptions for security failures. A ransomware exfiltration is not a confidentiality defense — it is a confidentiality violation. When client files hit a dark web leak site, the privilege is gone regardless of whether the firm "tried" to protect it. The question regulators and plaintiffs' counsel ask is not "were you hacked?" — it is "did you have reasonable controls in place before you were hacked?"
The malpractice exposure is direct: clients whose matter strategy, settlement negotiation positions, or M&A deal terms were exposed can sue for damages flowing from that disclosure. If litigation adversaries obtained privileged communications through the breach, the affected cases may require full disclosure to opposing parties. Clients whose transactions were disrupted by BEC wire fraud can pursue recovery claims against the firm.
The compliance stack for Texas law firms expanded significantly in 2021–2024. ABA Formal Opinion 498 (virtual practice), Texas Bar Rule 5.03 supervisory responsibility over vendor technology, TDPSA consumer data obligations (July 2024), and IRS Pub 4557 for tax-practice attorneys all create documented security program requirements — independently and in addition to bar ethics obligations.
| Mandate / Pressure | What It Requires | Consequence of Non-Compliance | CoreRecon Coverage |
|---|---|---|---|
| ABA Formal Opinion 477R | Attorneys must understand the security risks of electronic communications, assess the sensitivity of client information, and use security measures commensurate with risk. Strongly recommends encryption and multi-factor authentication for sensitive matters. | Basis for Rule 1.6(c) professional responsibility finding. Documented non-compliance increases malpractice exposure. | Sentinel MFA deployment, encrypted email enforcement, annual security awareness training with attestation records |
| Texas Ethics Opinion 712 | Due diligence on cloud vendor security, reasonable safeguards on client data, documented incident response plan for cloud-stored files. | Bar grievance following a breach with no documented controls = professional misconduct finding. | Sentinel Documented security program, vendor due diligence framework, incident response playbook |
| Cyber Insurance Carrier Requirements | MFA on email and remote access, EDR on endpoints, documented backup/recovery procedures, written IR plan. Now conditioning coverage — not just underwriting factors. | Coverage denial post-breach if required controls were absent at time of incident. | Fortress All four carrier-required controls documented; annual coverage attestation package |
| Corporate Client Security Questionnaires | GCs from financial institutions, healthcare, and defense sectors now send annual security questionnaires. Questions cover SOC 2, penetration testing, MFA, encryption, and IR response time. | Failing the questionnaire = losing the client engagement. No SLA means no engagement. | Fortress SOC 2-aligned controls documentation; questionnaire response support package |
| Texas Business & Commerce Code §521.053 | Breach notification to affected individuals within 60 days of discovery. Notification to Texas AG if breach affects 250+ residents. | Civil penalties up to $500 per failure to notify; AG enforcement for systematic non-compliance. | Command Breach notification workflow, 30-min SLA detection-to-notification, client and AG notification templates |
| Texas Bar Rule 5.03 — Supervisory Responsibility | Partners and supervising attorneys are responsible for the security conduct of supervised lawyers and non-lawyer assistants — including vendor-managed technology platforms. Delegating IT to a vendor does not transfer Rule 5.03 accountability. | Bar discipline for failures of supervised individuals or vendor platforms. Post-Orrick, supervising attorneys in breached firms face personal exposure in addition to firm liability. | Fortress Documented vendor oversight program, Rule 5.03 supervisory controls map, evidence package for bar response |
| ABA Formal Opinion 498 (2021) — Virtual Practice | Lawyers working remotely must implement additional safeguards: encrypted home networks, VPN enforcement, device security policies, and documented protocols for client communication security. ABA Opinion 498 creates documented obligations for remote/hybrid law firm arrangements. | Firms without documented virtual practice security fail ABA Competence (Rule 1.1) and Confidentiality (Rule 1.6) standards. Malpractice insurers use Opinion 498 as the baseline for remote work coverage conditions. | Sentinel VPN enforcement, encrypted endpoint policy, remote work security attestation for malpractice renewal |
| TDPSA — Texas Data Privacy and Security Act (Jul 1, 2024) | Texas law firms holding consumer personal data (client PII, employee records, HR data) are subject to TDPSA if annual revenue exceeds $25M or firm processes data of 100K+ consumers. Requires privacy notices, opt-out mechanisms, data security requirements, and 30-day cure window after AG notification. | TX AG enforcement authority. Civil penalties up to $7,500/violation. No private right of action — but AG can compel audits. Non-compliance exposed at discovery in litigation. | Fortress TDPSA data mapping, consumer request workflow, privacy notice review, 30-day cure-period response plan |
| IRS Publication 4557 — Tax Practice Security (Tax Attorneys & CPA Co-Counsel) | Law firms with tax practices or serving as co-counsel on tax matters must maintain a Written Information Security Plan (WISP) under IRS Pub 4557 — the same WISP requirement that applies to CPAs and tax preparers. WISP must document data inventory, access controls, incident response, and vendor oversight. | FTC Act Section 5 enforcement for unreasonable security practices. IRS PTIN suspension risk for non-compliant practitioners. Exposure in IRS examination of firm's tax clients. | Sentinel WISP authorship, tax client data handling protocols, IRS 4557-compliant incident response documentation |
These are the controls that actually stop exfil-and-leak attacks — not checkbox compliance theater. Each maps to a CoreRecon tier so you know exactly what you're buying.
| Control | Why It Matters for Law Firms | Common Gap | CoreRecon Coverage |
|---|---|---|---|
| MFA on Practice Management | Clio, MyCase, and Smokeball accounts are the primary lateral movement target. Compromised credentials mean instant access to all client matter files. | Single-factor login on practice management SaaS; attorneys resisting MFA friction | Sentinel MFA deployment, phishing-resistant enforcement, conditional access policy |
| Email Security with Impersonation Defense | Partner impersonation and opposing counsel spoofing are the primary initial access vectors in law firm breaches. Standard spam filters miss targeted BEC. | No DMARC/DKIM enforcement, no impersonation-aware filtering, no BEC playbook | Sentinel DMARC enforcement, impersonation detection, BEC response playbook |
| Endpoint Detection & Response (EDR) | Attorney laptops carry privileged documents. Remote work and BYOD expand the attack surface significantly — standard AV misses lateral movement. | Legacy AV on attorney endpoints; no behavioral detection; BYOD without MDM | Fortress EDR deployment, behavioral detection, BYOD enrollment and policy enforcement |
| Encrypted Backups with Immutability | Attackers destroy backups before deploying ransomware. Immutable offsite backups are the difference between a 30-minute recovery and a ransom payment. | Local-only backups; no immutability; untested restore procedures | Fortress Encrypted immutable offsite backup, monthly restore testing, documented RTO/RPO |
| Incident Response Retainer | Bar rules and client contracts require breach notification within defined windows. A 6-hour response to a Sunday 2am ransomware event requires a pre-engaged IR team. | No IR plan; incident response is "call IT" — IT cannot contain a ransomware event | Command 30-min SLA, pre-authorized IR playbook, bar notification workflow, client comms template |
| Vendor Risk for Case Management SaaS | Your security posture is only as strong as your weakest SaaS vendor. Clio, NetDocuments, and iManage have been targeted via supply-chain vectors. | No vendor security review; no contractual security requirements on SaaS vendors | Fortress SaaS vendor risk assessment, contract security addendum templates, monitoring alerts |
| Privileged Access Management | Admin credentials are the primary pivot point in law firm lateral movement. A single compromised IT admin account means full document access. | Shared admin accounts; no privileged session management; IT admin accounts not separated from daily-use accounts | Command Privileged access vaulting, session recording, just-in-time admin access |
| Security Awareness Training | Ethics Opinion 712 explicitly requires that attorneys and staff receive ongoing security training. Undocumented training is a bar discipline risk, not just a technical gap. | No documented training program; no records on file for attorneys or staff | Sentinel Annual training, documented completion records, simulated phishing, bar-compliant attestation |
| Network Segmentation | Lateral movement from a compromised workstation to document servers takes minutes on a flat network. Segmentation limits the blast radius. | Flat office network; guest Wi-Fi on same VLAN as document servers; no east-west controls | Fortress Network segmentation design, VLAN enforcement, east-west traffic monitoring |
| Dark Web Monitoring | Firm credentials, client data, and M&A deal information appear on dark web markets weeks before an attacker deploys ransomware. Early detection enables pre-breach response. | No credential monitoring; breach discovered only when ransomware detonates | Command Continuous dark web monitoring, credential alert triage, pre-breach remediation playbook |
10-endpoint minimum. Month-to-month. No 3-year lock-ins. No RFP. A 40-attorney firm knows their monthly cost in the first conversation. Partners approve it in one meeting. Sentinel: solo & small firms (10–25 endpoints). Fortress: mid-firm with HIPAA BA practice (25–100 endpoints). Command: AmLaw 200 / multi-office (100+ endpoints).
30-minute SLA applies to Command tier. Not next-business-day — 30 minutes from alert to analyst on the phone, any time of day, including weekends and holidays. That's the response time your bar obligations demand when client data is at risk at 2am Saturday. Command tier includes a pre-built bar notification workflow so the 72-hour response window is a procedure, not a crisis.
Enterprise MSSPs can cover law firms — but they weren't built for privilege protection, bar compliance, or mid-market pricing. Here's how the three dimensions that matter most compare.
| Dimension | CoreRecon | Cybriant | Trustwave |
|---|---|---|---|
| Transparent Pricing | $89/$109/$129 per endpoint. Published publicly. 10-endpoint minimum, month-to-month. | Quoted per engagement. No published pricing for sub-500 endpoint law firms. | Enterprise contracts starting at 6-figure annual commitment. Not designed for boutique or mid-market firms. |
| SDVOSB & TX-Native | SDVOSB-certified. Texas-based team. TX threat intel built into SOC. Eligible for TX HUB cooperative contracts. | National firm. No SDVOSB certification. No Texas-specific SOC or threat intel. | Global MSSP. No SDVOSB designation. No Texas-specific expertise documented. |
| Law Firm–Specific Controls | Ethics Opinion 712-aware. Bar notification workflow. Practice management SaaS MFA. Exfil-before-encryption detection. | General SIEM and MDR coverage. Bar-specific controls not documented. Customer maps independently. | Compliance modules available at enterprise pricing. Law firm–specific playbooks not disclosed. |
We assess your iManage, NetDocuments, and Clio exposure. We map your BEC attack surface. We benchmark you against ABA 477R and Ethics Opinion 712. Partner-ready report in 14 days.
Get your partner-ready report — free →No credit card • No commitment • SDVOSB-certified team
Yes — most cyber insurance carriers now require MFA on email and remote access, EDR on endpoints, documented backup and recovery procedures, and a written incident response plan. Carriers including Chubb, Beazley, and AXA XL have added these as coverage conditions since 2023. CoreRecon Fortress tier satisfies all four requirements. Command tier additionally covers the IR retainer requirement now appearing in carrier questionnaires from Lloyd's syndicates. We provide coverage attestation documentation annually that maps directly to standard carrier questionnaire fields.
Ethics Opinion 712 establishes that attorneys using cloud storage for client files must: (1) conduct reasonable due diligence on the cloud provider's security practices, (2) implement reasonable safeguards to protect confidential client information, and (3) understand how to respond if a security incident occurs. "Reasonable safeguards" is not defined — but regulators and plaintiffs' counsel have consistently cited MFA, encrypted storage, and documented IR procedures as the baseline. The opinion does not prohibit cloud use; it requires documented security measures. CoreRecon Sentinel tier provides the minimum documentation required; Command tier provides the audit-ready evidence package if a grievance is filed.
Texas law (Tex. Bus. & Com. Code §521.053) requires notification within 60 days of discovering a breach of sensitive personal information. Bar rules impose an independent obligation: if a breach compromises confidential client information, attorneys must promptly notify affected clients under Rule 1.15 (safekeeping property) and Rule 1.05 (confidentiality). "Prompt" is not defined, but the State Bar has indicated that 72 hours is the expected window when attorney-client privileged information is compromised. CoreRecon Command tier includes pre-drafted client notification templates, a bar notification workflow, and IR counsel referral — so the 72-hour window is a procedure, not a scramble.
On-call IR means you sign a contract today, hand it to your office manager, and hope you can find the right phone number at 2am on a Sunday when ransomware detonates. Retainer IR — what CoreRecon Command tier provides — means we're already monitoring your endpoints, we see the exfiltration before the ransomware deploys, and we have pre-authorized playbooks that don't require attorney sign-off during an active incident. The 30-minute SLA is only achievable with a retainer model: we know your environment, your key systems, and your data classification before an event occurs. For firms with client data at risk, the 6–12 hour difference between retainer and on-call IR is the difference between a manageable event and a bar grievance.
SCRA (Servicemembers Civil Relief Act) imposes heightened obligations when military client data is involved — and a breach involving military-related legal matters triggers both notification obligations and potential federal liability. MCLE compliance itself doesn't create direct security mandates, but the State Bar's annual reporting requirements mean that a bar discipline action following a breach becomes part of the attorney's public record. Firms with SCRA-adjacent practice areas (family law, consumer debt, housing) are higher-value targets because that data is both sensitive and monetizable. CoreRecon Command tier includes a military client data handling protocol as part of the IR playbook.
We map your full attack surface — endpoints, email, practice management SaaS, document management systems. We assess your BEC exposure, privilege threat posture, and Ethics Opinion 712 compliance gaps. You get a 12-page report you can put in front of the managing partner, your largest client's GC, or your cyber insurer. No credit card. No commitment. Delivered in 14 days.
Get your partner-ready report — free →Delivered within 14 days • No credit card • SDVOSB-certified team
See a sample report — redacted 12-page PDF, real findings.
Need a SOW for managing partner or CFO approval? Build your Scope of Work PDF →
Vendor access to client data is a confidentiality risk under ABA Ethics 1.6. Score your vendor risk scorecard →
Mossing & Navarre Toledo ransomware. Bryan Cave CCG breach. State Bar of TX INC Ransom (Jan 2025). TX Bar Rule 5.03 · ABA 498 · TDPSA · IRS Pub 4557 regulatory crosswalk. IOLTA wire fraud kill chain. 35+ verified sources. Print-ready PDF.