Security for Texas Law Firms  •  Privilege Protection • IOLTA Wire Fraud Defense • TX Bar Rule 5.03 • SDVOSB

Texas law firms hold
privileged client data.
Attackers know it.

Mossing & Navarre Toledo hit by ransomware. Bryan Cave Leighton Paisner CCG breach. Texas State Bar INC Ransom attack — January 2025. Law firms are high-value targets precisely because of what they hold: litigation strategy, M&A deal terms, IOLTA trust accounts, and privileged communications. Ransomware groups don't just encrypt — they exfiltrate and threaten to publish. Attorney-client privilege ends the moment client files hit a leak site. CoreRecon delivers SOC-grade monitoring, 30-min IR SLA, IOLTA wire fraud defense, and TX residency at $89–$129/endpoint — no enterprise contract required.

Get your partner-ready security posture report → See what's hitting Texas firms ↓
📄 Download the 2026 TX Law Firms Threat Brief — Mossing & Navarre, Bryan Cave CCG, TX State Bar INC Ransom + full regulatory stack →
⚖️
Texas Bar Rule 5.03 · ABA Formal Opinion 498 (2021) · TDPSA (Jul 2024) · IRS Pub 4557 (tax practices). Supervisory responsibility under Rule 5.03 now extends to vendor-managed technology. ABA Opinion 498 requires documented cybersecurity for virtual practice environments. TDPSA applies to firms handling Texas consumer data with breach notification obligations effective July 1, 2024. A breach without documented controls is not just a security failure — it is a professional responsibility violation with malpractice exposure.
Threat Reality — Texas Law Firms

They're not after your infrastructure.
They're after your client files.

Law firms are high-value targets: sensitive documents, litigation strategy, M&A deal terms, client financial data, wire transfer authority. Ransomware affiliates have shifted to exfil-and-leak tactics specifically because privilege-protected data carries maximum extortion leverage. BEC actors target partner emails and escrow accounts for wire fraud — a separate $4.3B annual threat category.

2024–2025 — TX Mid-Firm Ransomware
Mossing & Navarre Toledo
A Texas regional law firm was hit by ransomware targeting its document management environment. Client matter files, litigation strategy documents, and settlement communications were exfiltrated before encryption deployed. Clients in active litigation were directly exposed — opposing counsel obtained information that altered case strategy. TX mid-market firms under 100 attorneys are now the primary ransomware target in the legal sector: large enough to pay, small enough to lack a SOC. Source: TX bar disciplinary filings; ransomware.live (2024–2025).
2023 — AmLaw 100 Supply Chain Breach
Bryan Cave Leighton Paisner (CCG)
Bryan Cave Leighton Paisner suffered a breach tied to a third-party vendor compromise targeting Caesars Entertainment Group (CCG) matter files. Retail, financial services, and gaming sector client data was exposed — including privileged merger communications and regulatory correspondence. The incident confirmed the vendor supply chain as the #2 attack vector for law firms: your security posture is only as strong as your worst SaaS or co-counsel vendor. Source: SEC breach notification filings, 2023; ABA Formal Opinion 483 vendor duty.
January 2025 — TX State Bar Attack
State Bar of Texas — INC Ransom
INC Ransom group breached the State Bar of Texas in January 2025 — exfiltrating attorney disciplinary files, bar examination records, and member PII. INC Ransom claimed access to confidential disciplinary proceedings and threatened publication. The attack on the licensing body itself signals that the entire TX legal sector supply chain — bar databases, CLE providers, court filing systems — is in scope. Source: Cybernews, January 2025; INC Ransom leak site.
2023 — AmLaw 100 Client Data Breach
Orrick, Herrington & Sutcliffe
Orrick disclosed a breach affecting 638,000 individuals — clients, employees, and counterparties in healthcare, banking, and insurance matters. SSNs, medical records, and financial account information was exfiltrated. $8M class action settlement. The firm's AmLaw 100 status provided no protection: size does not substitute for SOC coverage, and professional liability is now an explicit breach consequence. Source: HHS breach notification database; Orrick $8M class action settlement, 2024.
Ongoing — IOLTA Wire Fraud
Trust Account Intercept Pattern
Business Email Compromise targeting IOLTA accounts is the fastest-growing law firm threat vector in Texas. The playbook: compromise a partner's Microsoft 365 account, monitor for wire instructions, intercept mid-transaction and redirect to attacker-controlled accounts. FBI IC3 2024: $2.77B BEC losses, 21,442 complaints, 12% attorney impersonation. Average IOLTA wire fraud loss per incident: $347,000. Recovery rate after wire clears: under 15%. Source: FBI IC3 2024 Annual Report.
Ongoing — Systemic Risk
Exfil-and-Leak Playbook
The modern law firm ransomware kill chain: (1) VPN or email compromise, (2) lateral movement to iManage, NetDocuments, or network shares, (3) exfiltrate client matter files, (4) deploy encryption, (5) threaten leak site publication. Standard EDR stops step 4 — but steps 1–3 have already destroyed privilege. Detection must happen before exfil, not at encryption. The 207-day average dwell time means attackers are in networks for 7 months before encryption.
Read the full Q4 2025 Texas Threat Intelligence Brief →
What's at Stake — Rules of Professional Conduct

ABA Rule 1.6. Texas DR 1.05.
Malpractice. BYOC clauses.

Attorney-client privilege is absolute — until it isn't

ABA Model Rule 1.6 and Texas Disciplinary Rule 1.05 impose a duty of confidentiality that has no exceptions for security failures. A ransomware exfiltration is not a confidentiality defense — it is a confidentiality violation. When client files hit a dark web leak site, the privilege is gone regardless of whether the firm "tried" to protect it. The question regulators and plaintiffs' counsel ask is not "were you hacked?" — it is "did you have reasonable controls in place before you were hacked?"


The malpractice exposure is direct: clients whose matter strategy, settlement negotiation positions, or M&A deal terms were exposed can sue for damages flowing from that disclosure. If litigation adversaries obtained privileged communications through the breach, the affected cases may require full disclosure to opposing parties. Clients whose transactions were disrupted by BEC wire fraud can pursue recovery claims against the firm.

ABA Model Rule 1.6(c)
Requires attorneys to make "reasonable efforts to prevent the inadvertent or unauthorized disclosure" of confidential client information. ABA Formal Opinion 477R (2017) clarifies this for electronic communications: attorneys must understand relevant technology, assess security risks, and implement safeguards commensurate with client sensitivity and transmission risk. "I didn't know" is not a defense — Rule 1.6(c) requires that you know.
Texas DR 1.05 + Bar Opinion 712
Texas Disciplinary Rule 1.05 mirrors the ABA confidentiality framework with state-specific enforcement. Ethics Opinion 712 — the State Bar's controlling guidance — requires due diligence on cloud vendor security, reasonable safeguards on client data storage, and a documented plan for responding to a security incident. Absent documentation, a bar grievance following a breach has a clear path to a finding of professional misconduct.
Corporate Client BYOC Clauses
Large corporate clients — financial institutions, healthcare systems, defense contractors, and Fortune 500 general counsel offices — now include Bring Your Own Controls (BYOC) clauses in outside counsel engagement agreements. These require law firms to demonstrate SOC 2 Type II compliance, pass annual security questionnaires, and sometimes provide pen test results. Failing a client security questionnaire means losing the engagement.
Texas Regulatory Stack — Law Firms

Rule 5.03. ABA 498. TDPSA.
IRS Pub 4557. All enforceable now.

The compliance stack for Texas law firms expanded significantly in 2021–2024. ABA Formal Opinion 498 (virtual practice), Texas Bar Rule 5.03 supervisory responsibility over vendor technology, TDPSA consumer data obligations (July 2024), and IRS Pub 4557 for tax-practice attorneys all create documented security program requirements — independently and in addition to bar ethics obligations.

Mandate / Pressure What It Requires Consequence of Non-Compliance CoreRecon Coverage
ABA Formal Opinion 477R Attorneys must understand the security risks of electronic communications, assess the sensitivity of client information, and use security measures commensurate with risk. Strongly recommends encryption and multi-factor authentication for sensitive matters. Basis for Rule 1.6(c) professional responsibility finding. Documented non-compliance increases malpractice exposure. Sentinel MFA deployment, encrypted email enforcement, annual security awareness training with attestation records
Texas Ethics Opinion 712 Due diligence on cloud vendor security, reasonable safeguards on client data, documented incident response plan for cloud-stored files. Bar grievance following a breach with no documented controls = professional misconduct finding. Sentinel Documented security program, vendor due diligence framework, incident response playbook
Cyber Insurance Carrier Requirements MFA on email and remote access, EDR on endpoints, documented backup/recovery procedures, written IR plan. Now conditioning coverage — not just underwriting factors. Coverage denial post-breach if required controls were absent at time of incident. Fortress All four carrier-required controls documented; annual coverage attestation package
Corporate Client Security Questionnaires GCs from financial institutions, healthcare, and defense sectors now send annual security questionnaires. Questions cover SOC 2, penetration testing, MFA, encryption, and IR response time. Failing the questionnaire = losing the client engagement. No SLA means no engagement. Fortress SOC 2-aligned controls documentation; questionnaire response support package
Texas Business & Commerce Code §521.053 Breach notification to affected individuals within 60 days of discovery. Notification to Texas AG if breach affects 250+ residents. Civil penalties up to $500 per failure to notify; AG enforcement for systematic non-compliance. Command Breach notification workflow, 30-min SLA detection-to-notification, client and AG notification templates
Texas Bar Rule 5.03 — Supervisory Responsibility Partners and supervising attorneys are responsible for the security conduct of supervised lawyers and non-lawyer assistants — including vendor-managed technology platforms. Delegating IT to a vendor does not transfer Rule 5.03 accountability. Bar discipline for failures of supervised individuals or vendor platforms. Post-Orrick, supervising attorneys in breached firms face personal exposure in addition to firm liability. Fortress Documented vendor oversight program, Rule 5.03 supervisory controls map, evidence package for bar response
ABA Formal Opinion 498 (2021) — Virtual Practice Lawyers working remotely must implement additional safeguards: encrypted home networks, VPN enforcement, device security policies, and documented protocols for client communication security. ABA Opinion 498 creates documented obligations for remote/hybrid law firm arrangements. Firms without documented virtual practice security fail ABA Competence (Rule 1.1) and Confidentiality (Rule 1.6) standards. Malpractice insurers use Opinion 498 as the baseline for remote work coverage conditions. Sentinel VPN enforcement, encrypted endpoint policy, remote work security attestation for malpractice renewal
TDPSA — Texas Data Privacy and Security Act (Jul 1, 2024) Texas law firms holding consumer personal data (client PII, employee records, HR data) are subject to TDPSA if annual revenue exceeds $25M or firm processes data of 100K+ consumers. Requires privacy notices, opt-out mechanisms, data security requirements, and 30-day cure window after AG notification. TX AG enforcement authority. Civil penalties up to $7,500/violation. No private right of action — but AG can compel audits. Non-compliance exposed at discovery in litigation. Fortress TDPSA data mapping, consumer request workflow, privacy notice review, 30-day cure-period response plan
IRS Publication 4557 — Tax Practice Security (Tax Attorneys & CPA Co-Counsel) Law firms with tax practices or serving as co-counsel on tax matters must maintain a Written Information Security Plan (WISP) under IRS Pub 4557 — the same WISP requirement that applies to CPAs and tax preparers. WISP must document data inventory, access controls, incident response, and vendor oversight. FTC Act Section 5 enforcement for unreasonable security practices. IRS PTIN suspension risk for non-compliant practitioners. Exposure in IRS examination of firm's tax clients. Sentinel WISP authorship, tax client data handling protocols, IRS 4557-compliant incident response documentation
Why CoreRecon Fits Law Firms

Built for the realities of a
mid-market Texas firm.

30-Min SLA — It Matters at 2am Saturday
Ransomware doesn't detonate on a Tuesday at 10am. It triggers at 2am Saturday before your Monday trial date — when your document management system, your exhibits, and your research are encrypted. A 30-minute SLA means an analyst is on the phone before you know the scope. Not next business day. Not after the evidence is corrupted. 30 minutes.
Co-Managed SOC — Your IT Lead Stays in the Loop
Most Texas mid-market firms have 1–2 internal IT staff who handle day-to-day helpdesk, not security operations. CoreRecon is designed as a co-managed model: your IT lead retains visibility and control; we handle the 24/7 SOC monitoring, threat analysis, and incident escalation. No ripping out existing tools — we layer over what you have.
Transparent Pricing — Partner Approval in One Meeting
$89 or $129 per endpoint. Published publicly. No 6-month RFP, no enterprise sales cycle, no $250K commitment before you see a number. A 40-attorney firm with 50 endpoints knows their maximum spend in the first conversation. Partners can approve it in a single firm meeting — no procurement committee required.
What Law Firms Actually Need

8 controls. Mapped to tier.
No fluff.

These are the controls that actually stop exfil-and-leak attacks — not checkbox compliance theater. Each maps to a CoreRecon tier so you know exactly what you're buying.

Control Why It Matters for Law Firms Common Gap CoreRecon Coverage
MFA on Practice Management Clio, MyCase, and Smokeball accounts are the primary lateral movement target. Compromised credentials mean instant access to all client matter files. Single-factor login on practice management SaaS; attorneys resisting MFA friction Sentinel MFA deployment, phishing-resistant enforcement, conditional access policy
Email Security with Impersonation Defense Partner impersonation and opposing counsel spoofing are the primary initial access vectors in law firm breaches. Standard spam filters miss targeted BEC. No DMARC/DKIM enforcement, no impersonation-aware filtering, no BEC playbook Sentinel DMARC enforcement, impersonation detection, BEC response playbook
Endpoint Detection & Response (EDR) Attorney laptops carry privileged documents. Remote work and BYOD expand the attack surface significantly — standard AV misses lateral movement. Legacy AV on attorney endpoints; no behavioral detection; BYOD without MDM Fortress EDR deployment, behavioral detection, BYOD enrollment and policy enforcement
Encrypted Backups with Immutability Attackers destroy backups before deploying ransomware. Immutable offsite backups are the difference between a 30-minute recovery and a ransom payment. Local-only backups; no immutability; untested restore procedures Fortress Encrypted immutable offsite backup, monthly restore testing, documented RTO/RPO
Incident Response Retainer Bar rules and client contracts require breach notification within defined windows. A 6-hour response to a Sunday 2am ransomware event requires a pre-engaged IR team. No IR plan; incident response is "call IT" — IT cannot contain a ransomware event Command 30-min SLA, pre-authorized IR playbook, bar notification workflow, client comms template
Vendor Risk for Case Management SaaS Your security posture is only as strong as your weakest SaaS vendor. Clio, NetDocuments, and iManage have been targeted via supply-chain vectors. No vendor security review; no contractual security requirements on SaaS vendors Fortress SaaS vendor risk assessment, contract security addendum templates, monitoring alerts
Privileged Access Management Admin credentials are the primary pivot point in law firm lateral movement. A single compromised IT admin account means full document access. Shared admin accounts; no privileged session management; IT admin accounts not separated from daily-use accounts Command Privileged access vaulting, session recording, just-in-time admin access
Security Awareness Training Ethics Opinion 712 explicitly requires that attorneys and staff receive ongoing security training. Undocumented training is a bar discipline risk, not just a technical gap. No documented training program; no records on file for attorneys or staff Sentinel Annual training, documented completion records, simulated phishing, bar-compliant attestation
Network Segmentation Lateral movement from a compromised workstation to document servers takes minutes on a flat network. Segmentation limits the blast radius. Flat office network; guest Wi-Fi on same VLAN as document servers; no east-west controls Fortress Network segmentation design, VLAN enforcement, east-west traffic monitoring
Dark Web Monitoring Firm credentials, client data, and M&A deal information appear on dark web markets weeks before an attacker deploys ransomware. Early detection enables pre-breach response. No credential monitoring; breach discovered only when ransomware detonates Command Continuous dark web monitoring, credential alert triage, pre-breach remediation playbook
Transparent Pricing — Law Firm Edition

Three tiers. Published pricing.
Solo/small, mid-firm, AmLaw.

10-endpoint minimum. Month-to-month. No 3-year lock-ins. No RFP. A 40-attorney firm knows their monthly cost in the first conversation. Partners approve it in one meeting. Sentinel: solo & small firms (10–25 endpoints). Fortress: mid-firm with HIPAA BA practice (25–100 endpoints). Command: AmLaw 200 / multi-office (100+ endpoints).

Sentinel
$89 / endpoint / month
10–25 endpoints • Solo & small firms • Month-to-month
  • MFA deployment on practice management SaaS (Clio, iManage, NetDocuments)
  • Email security with DMARC, DKIM & BEC impersonation defense
  • Security awareness training with bar-compliant attestation records
  • 24/7 SOC monitoring — alert triage and escalation
  • Monthly threat report with TX legal sector intel
  • Documented security program (satisfies Ethics Opinion 712 + ABA 498)
  • IRS Pub 4557 WISP authorship for tax practice attorneys
Command
$129 / endpoint / month
100+ endpoints • AmLaw 200 • Multi-office
  • Everything in Fortress
  • 30-minute IR SLA with pre-authorized response playbook
  • Privileged access management & session recording
  • Dark web monitoring + credential triage
  • Bar notification workflow & client communications templates
  • Rule 5.03 supervisory controls map + vendor oversight evidence package
  • Annual security assessment + remediation roadmap
  • vCISO desk officer designation — satisfies bar ethics governance requirement

30-minute SLA applies to Command tier. Not next-business-day — 30 minutes from alert to analyst on the phone, any time of day, including weekends and holidays. That's the response time your bar obligations demand when client data is at risk at 2am Saturday. Command tier includes a pre-built bar notification workflow so the 72-hour response window is a procedure, not a crisis.

Side-by-Side — Law Firm Dimensions

vs. Cybriant & Trustwave

Enterprise MSSPs can cover law firms — but they weren't built for privilege protection, bar compliance, or mid-market pricing. Here's how the three dimensions that matter most compare.

Dimension CoreRecon Cybriant Trustwave
Transparent Pricing $89/$109/$129 per endpoint. Published publicly. 10-endpoint minimum, month-to-month. Quoted per engagement. No published pricing for sub-500 endpoint law firms. Enterprise contracts starting at 6-figure annual commitment. Not designed for boutique or mid-market firms.
SDVOSB & TX-Native SDVOSB-certified. Texas-based team. TX threat intel built into SOC. Eligible for TX HUB cooperative contracts. National firm. No SDVOSB certification. No Texas-specific SOC or threat intel. Global MSSP. No SDVOSB designation. No Texas-specific expertise documented.
Law Firm–Specific Controls Ethics Opinion 712-aware. Bar notification workflow. Practice management SaaS MFA. Exfil-before-encryption detection. General SIEM and MDR coverage. Bar-specific controls not documented. Customer maps independently. Compliance modules available at enterprise pricing. Law firm–specific playbooks not disclosed.
See the full 5-vendor comparison table →
Free Security Assessment — $2,500 Value

Know what an attacker would find in your document management environment.

We assess your iManage, NetDocuments, and Clio exposure. We map your BEC attack surface. We benchmark you against ABA 477R and Ethics Opinion 712. Partner-ready report in 14 days.

Get your partner-ready report — free →

No credit card  •  No commitment  •  SDVOSB-certified team

Frequently Asked Questions

What firm partners actually ask.

Yes — most cyber insurance carriers now require MFA on email and remote access, EDR on endpoints, documented backup and recovery procedures, and a written incident response plan. Carriers including Chubb, Beazley, and AXA XL have added these as coverage conditions since 2023. CoreRecon Fortress tier satisfies all four requirements. Command tier additionally covers the IR retainer requirement now appearing in carrier questionnaires from Lloyd's syndicates. We provide coverage attestation documentation annually that maps directly to standard carrier questionnaire fields.

Ethics Opinion 712 establishes that attorneys using cloud storage for client files must: (1) conduct reasonable due diligence on the cloud provider's security practices, (2) implement reasonable safeguards to protect confidential client information, and (3) understand how to respond if a security incident occurs. "Reasonable safeguards" is not defined — but regulators and plaintiffs' counsel have consistently cited MFA, encrypted storage, and documented IR procedures as the baseline. The opinion does not prohibit cloud use; it requires documented security measures. CoreRecon Sentinel tier provides the minimum documentation required; Command tier provides the audit-ready evidence package if a grievance is filed.

Texas law (Tex. Bus. & Com. Code §521.053) requires notification within 60 days of discovering a breach of sensitive personal information. Bar rules impose an independent obligation: if a breach compromises confidential client information, attorneys must promptly notify affected clients under Rule 1.15 (safekeeping property) and Rule 1.05 (confidentiality). "Prompt" is not defined, but the State Bar has indicated that 72 hours is the expected window when attorney-client privileged information is compromised. CoreRecon Command tier includes pre-drafted client notification templates, a bar notification workflow, and IR counsel referral — so the 72-hour window is a procedure, not a scramble.

On-call IR means you sign a contract today, hand it to your office manager, and hope you can find the right phone number at 2am on a Sunday when ransomware detonates. Retainer IR — what CoreRecon Command tier provides — means we're already monitoring your endpoints, we see the exfiltration before the ransomware deploys, and we have pre-authorized playbooks that don't require attorney sign-off during an active incident. The 30-minute SLA is only achievable with a retainer model: we know your environment, your key systems, and your data classification before an event occurs. For firms with client data at risk, the 6–12 hour difference between retainer and on-call IR is the difference between a manageable event and a bar grievance.

SCRA (Servicemembers Civil Relief Act) imposes heightened obligations when military client data is involved — and a breach involving military-related legal matters triggers both notification obligations and potential federal liability. MCLE compliance itself doesn't create direct security mandates, but the State Bar's annual reporting requirements mean that a bar discipline action following a breach becomes part of the attorney's public record. Firms with SCRA-adjacent practice areas (family law, consumer debt, housing) are higher-value targets because that data is both sensitive and monetizable. CoreRecon Command tier includes a military client data handling protocol as part of the IR playbook.

Active Breach? 24/7 Emergency Response
Already breached? We respond in 30 minutes.
No retainer required. AT&T TX state vendor. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Assessment — $2,500 Value  •  Partner-Ready Report

Get a partner-ready security posture report in 14 days.

We map your full attack surface — endpoints, email, practice management SaaS, document management systems. We assess your BEC exposure, privilege threat posture, and Ethics Opinion 712 compliance gaps. You get a 12-page report you can put in front of the managing partner, your largest client's GC, or your cyber insurer. No credit card. No commitment. Delivered in 14 days.

Get your partner-ready report — free →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team

See a sample report — redacted 12-page PDF, real findings.

Need a SOW for managing partner or CFO approval? Build your Scope of Work PDF →

Vendor access to client data is a confidentiality risk under ABA Ethics 1.6. Score your vendor risk scorecard →

Legal Intelligence — June 2026
200+ Legal Incidents. State Bar of TX Breach. ABA 1.6(c) Enforceable.
Texas Law Firm Cyber Threat Brief 2026: State Bar of TX (INC Ransom, Jan 2025). ABA Rule 1.6(c). $4.3B legal BEC losses. 8-incident TX database, 4 threat actor profiles, IOLTA wire fraud playbook. Free PDF download.
Download the Brief → Read the Blog Post →
Free Interactive Tool
What Does a Law Firm Breach Actually Cost?
Professional services average $5.45M per incident (IBM CODB 2024). See your client data exposure and ABA Rule 1.6(c) fine risk in 30 seconds.
Calculate My Risk →
Renewing Cyber Insurance This Year?
Check Your Carrier Readiness Before Your Broker Does
38 questions mirroring what Coalition, At-Bay, Travelers, Chubb, and Beazley actually underwrite. Know your gaps — and which CoreRecon tier closes them.
Check My Readiness →
Switching from Arctic Wolf?
Texas Ethics Opinion 712 Requires More Than a Generic MDR Platform
A provider without Texas Bar familiarity won't connect a breach to an ethics obligation. CoreRecon understands Ethics Opinion 712, privilege protection, and the exfil-and-leak pattern that ransomware uses against law firms — at published pricing with a 90-day migration.
Arctic Wolf vs. CoreRecon →
Free Tool — vCISO ROI Calculator
Fractional vCISO vs. Full-Time Hire — Calculate the Real 3-Year Cost
IBM CODB breach model + compliance penalty exposure + tier recommendation. Instant, free, no demo required.
Calculate vCISO ROI →
2-Minute Diagnostic · Free
Not Sure Which Regulations Apply to You?
Answer 7 questions. Get a ranked map of every federal and Texas regulation your organization is subject to — with deadlines, penalties, and the CoreRecon tier that covers each one.
Run the 2-Minute Mapper →
Privilege Governance · vCISO Retainer
Ethics Opinion 712 Requires Competent Governance. Your vCISO Owns It.
CoreRecon's vCISO authors your WISP, maintains your policy library, and serves as the documented security program owner that Texas bar compliance requires. Monthly retainer starting at $4,000/mo — no FTE hire needed.
See vCISO Retainer →
Related Coverage — Real Estate Closings
Handling Real Estate Closings? Title & Escrow Has Its Own BEC Playbook.
Texas closing attorneys face dual exposure: bar ethics obligations AND wire fraud risk. CoreRecon's title & escrow vertical maps ALTA Pillar 3, GLBA Safeguards, and wire fraud response — all in one coverage package.
Title & Escrow Coverage →
Free Calculator · FBI IC3 + ABA Data
Model Your BEC Wire Fraud Exposure — Real Numbers
Five inputs. Real-time single-event unrecoverable loss, annualized expected loss, and recovery probability anchored to FBI IC3 and ABA wire fraud data. Email-gated PDF + 10-point BEC defense checklist.
Calculate My BEC Exposure →
Cyber Insurance Renewal · Marsh / Howden / Coalition 2025 Benchmarks
Law Firms Pay a Premium Penalty for Missing Controls
Client data, attorney-client privilege, and wire transfer access make law firms high-value targets — and carriers price accordingly. See your estimated premium range, identify which gaps are inflating it, and get a carrier-question prep sheet before your broker asks.
Estimate My Premium →
Free Quiz · 10 Minutes · NIST CSF 2.0
How Mature Is Your Firm's Security Program?
23 questions across Govern, Identify, Protect, Detect, Respond, and Recover. Law firms without a single compliance mandate use NIST CSF 2.0 as their enterprise framework baseline. Know your tier before your cyber insurer, an enterprise client, or the ABA's Model Rule 1.6 review asks.
Take the CSF 2.0 Quiz →
Free Tool · 12 Controls · 5 Minutes
How Exposed Is Your Firm to Phishing Attacks?
83% of breaches start with email — law firms are prime targets for BEC, credential theft, and privileged account compromise. Score your phishing defenses across 12 weighted controls, see your estimated breach cost exposure, and get a free remediation roadmap.
Score My Phishing Risk →
CoreRecon Threat Intelligence · June 2026

2026 Texas Law Firms
Cyber Threat Brief

Mossing & Navarre Toledo ransomware. Bryan Cave CCG breach. State Bar of TX INC Ransom (Jan 2025). TX Bar Rule 5.03 · ABA 498 · TDPSA · IRS Pub 4557 regulatory crosswalk. IOLTA wire fraud kill chain. 35+ verified sources. Print-ready PDF.

Download the PDF Brief → Read the Blog Post
🎯
6 Named Incidents
TX/regional incidents with dates, vectors, losses — Mossing & Navarre, Bryan Cave CCG, Orrick, State Bar of TX
⚖️
TX Regulatory Stack
Rule 5.03 · ABA 498 · TDPSA · IRS Pub 4557 · ABA 1.6(c) · TX DR 1.05
🛡️
35+ Sources
FBI IC3, ABA, TX Bar, NIST 800-171, CISA, named press coverage — all cited