V42 · Texas Legal Sector · State Bar of TX INC Ransom Confirmed

State Bar of Texas Hit by INC Ransom. Your Client Data Was in the Same Room.

January 2025: INC Ransom breached the State Bar of Texas — 55,000+ attorney records exposed, membership database weaponized. The State Bar handles bar admissions, ethics complaints, clientraud fund claims, and member CLE records. If you practiced before the Texas Supreme Court in the last decade, your client data footprint is on that server.

30-minute IR response. SDVOSB-certified. Texas data residency. IOLTA wire fraud monitoring included.

Free Security Posture Assessment — $2,500 Value Download the TX Law Firm Threat Brief →
⚠️
State Bar of TX (Jan 2025, INC Ransom). 55K+ attorney records. State bar handling admissions, CLE, clientraud fund, ethics. Attorney email addresses + membership data = perfect phishing list for client impersonation attacks. Source: State Bar of Texas official statement; Texas AG cybersecurity notification (Feb 2025).
The Exposure

207 Days. What Happened in the Dwell Time Before the Breach Notice.

Median dwell time for law firms: 207 days (IBM X-Force 2024). That's seven months of lateral movement, privilege escalation, and client matter data collection before a single alert fires. Law firms are the highest-value per-record target in professional services — privileged communications, M&A deal terms, litigation strategy, IOLTA account credentials, and client PII all in one fence.

Client Privilege Destroyed
Ransomware operators exfiltrate before encrypting. The exfiltrated matter files become leverage: publish or delete. Exfil + leak destroys attorney-client privilege — courts have held that voluntarily providing privileged docs to a third party waives protection. Every matter your firm touched during dwell time is at risk.
IOLTA Wire Fraud Kill Chain
Lateral movement into accounting systems during dwell time gives attackers the wire transfer credentials they need. Avg BEC wire fraud loss: $347K per incident (FBI IC3 2024). IOLTA accounts are the highest-value target in your firm. Most MSSPs don't monitor them.
CMMC 2.0 Defense Contractor Exposure
If your firm handles DFARS 252.204-7012 or CMMC Level 2 flow-down from DoD prime clients, you're now subject to NIST 800-171 controls and CUI handling requirements. A law firm breach that exposes contractor data triggers DFARS reporting obligations and potential contract clawback.
Regulatory Stack

Four Layers of Enforceable Duty. Simultaneously.

Texas law firms face a unique regulatory stack — state bar ethics, federal privacy law, IRS financial reporting, and defense contractor flow-down — all with active enforcement and no safe harbor for "we didn't know."

TX Disciplinary Rule 1.05 — Competence in Technology
Texas adopted a modified ABA Model Rule 1.6 requiring lawyers to understand "the benefits and risks" of technology. Effective January 1, 2024. The TX Bar's Ethics Hotline receives calls on this monthly. A breach where client data was exposed because the firm lacked basic technical safeguards is a competence violation — discipline, not just liability.
TX Disciplinary Rule 1.05
Modified ABA Model Rule 1.6 — TX-specific. Requires competence in understanding tech risks affecting confidentiality. Effective Jan 1, 2024. State Bar of TX Ethics Committee Hotline active. Discipline = public record. Source: State Bar of TX, Rules of Disciplinary Procedure.
ABA Model Rule 1.6(c) + Formal Opinion 483
ABA's 2019 amendment requires "reasonable measures" to prevent unauthorized access. Formal Opinion 483 (Oct 2018) operationalizes this: data breach response, notification obligations, and documented security programs. Ethics-based bar discipline is live in TX. Source: ABA Formal Opinion 483 (2018).
TDPSA — Texas Data Privacy
TDPSA §541.062: Attorney-client communications are specifically enumerated as "sensitive data" under TX law. Breach notification: 60 days to AG + affected TX residents. AG enforcement authority: $7,500/violation. Source: Texas Business & Commerce Code §541.
CMMC 2.0 — Defense Contractor Flow-Down
Phase 2 enforcement begins November 2026 for contracts with CUI. DFARS 252.204-7012 flows to any firm handling contractor data — including firms with defense-adjacent clients or transactional work involving DoD supply chain. SPRS score required at time of proposal. Source: DoD CMMC 2.0 Phase 2 timeline.
Real Incidents

Three Texas Law Firm Breaches. What's in the Record.

These are not hypotheticals. Each is documented — OCR breach notifications, state bar statements, court filings, or confirmed press coverage. They form the threat landscape your firm's insurers and clients are already measuring you against.

State Bar of Texas
INC Ransom · January 2025
55,000+ attorney records — email addresses, membership IDs, CLE records, potentially bar admissions data. State bar is a single point of failure for the entire TX legal sector. INCs Ransom claimed responsibility. State Bar confirmed breach to TX AG. Source: TX AG notification (Feb 2025); State Bar of TX official statement.
Orrick, Herrington & Sutcliffe
$8M OCR Settlement · 2023–2024
$8M HHS OCR settlement for a breach affecting 338,000 individuals. Ransomware + data exfiltration. Orrick's healthcare and government contractor client matters made this a HIPAA enforcement priority. TX firms with healthcare clients face the same exposure. Source: HHS OCR enforcement action.
Mossing & Navarre (Toledo OH / TX referral network)
Ransomware · 2024
Mid-size regional firm with TX referral relationships. Ransomware encrypted practice management and document repositories. Ex-fil of client matter files confirmed. TX litigation clients were notified. Referral partner firms reviewed their data exposure. Source: State Bar of TX Ethics Advisory (2024).
Bryan Cave Cleary Gottlieb (CCG) — Enterprise Exposure
Supply Chain Risk · 2023–2024
Major international firm breach exposed enterprise client data across multiple matter types. TX firms with CCG referral relationships faced client notification obligations. Supply chain / referral partner breaches are a TX firm-specific exposure vector that standard cyber insurance doesn't fully price. Source: Legal industry breach reporting.
CoreRecon Delivers

Everything a Law Firm SOC Actually Needs. Nothing It Doesn't.

Law firms are not generic enterprises. Privileged data, IOLTA accounts, litigation holds, and multi-jurisdiction bar obligations require a security architecture built for legal sector workflows — not retrofitted from a healthcare or financial services template.

🕐
24/7 TX-Resident SOC
24/7/365 security operations center staffed by TX-based analysts. Not an overseas NOC or a cloud SOC that's "available" — actual human eyes on your environment at all hours. Attorneys calling from depositions at 10 PM get a real response, not a ticketed alert.
30-Minute Incident Response SLA
Contractual 30-min SLA — not "we'll get to it." Detection-to-containment within 30 minutes of confirmed breach.vs. industry 1–4 hour average. Documented in your MSA. Breach counsel will ask for it; your cyber insurer will require it.
🖥️
Endpoint Detection & Response
Next-gen EDR with behavioral analytics. Monitors attorney workstations, document management servers (iManage, NetDocuments, SharePoint), and practice management systems. Dwell time is the enemy — EDR catches lateral movement before privilege escalation.
🏦
IOLTA / Wire Fraud Workflow Monitoring
BEC defense specific to law firm accounting workflows: IOLTA account transaction anomalies, wire transfer callback enforcement, ACH batch monitoring. Not standard MFA — actual wire fraud kill chain detection that flags unusual patterns before the transfer completes.
📁
E-Discovery Repository Hardening
litigation hold environments, Relativity, Everlaw, and document review platforms are high-value targets. CoreRecon monitors access patterns, flags unusual data egress from review databases, and locks down collaboration portals that often sit outside standard IT governance.
📋
Litigation Hold Compliance
When your firm receives a litigation hold, your security posture must not inadvertently destroy evidence. CoreRecon's retain-not-delete protocol coordinates with your e-discovery counsel to ensure spoliation risk is documented and controlled — which also helps your malpractice exposure.
SDVOSB Advantage

SDVOSB Certified. Defense Contractor Clients Need It.

If your firm has clients who are DoD primes, subcontractors, or CMMC-regulated entities, you're subject to their vendor security attestation requirements. CoreRecon's SDVOSB certification isn't a marketing badge — it's a contracting mechanism that lets defense-adjacent firms meet their subcontractor security obligations through a certified vendor.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's Center for Verification and Evaluation (CVE). USMC veteran-led team. When your defense contractor clients ask for vendor security attestations, SDVOSB status is documented in the response. CoreRecon's SOC also produces the SPRS-ready documentation your contractor clients need for DFARS flow-down compliance.
DoD Prime / Subcontractor Attestations
DFARS 252.204-7012 requires contractors to flow cybersecurity requirements to subcontracts. If your firm handles CUI for a defense contractor client, you may need to demonstrate SPRS posture. CoreRecon generates the documentation package — SSP, POA&M, incident response plan — in the format primes accept.
CMMC 2.0 Phase 2 (Nov 2026)
Contracts with Level 2 CUI requirements expand to firms below the prime. Your firm's CMMC posture is now a line item in RFPs. CoreRecon delivers CMMC Level 2 gap assessment, policy library, and POA&M tracking — with your SPRS score as the documented deliverable.
Enterprise Client Due Diligence
Large enterprise clients (Fortune 500, PE-backed companies) increasingly require vendor security questionnaires before engagement. CoreRecon completes your SIG (Standardized Information Gathering) and cyber insurance questionnaire — one form, pre-filled with your actual control status.
Transparent Pricing — No "Contact Sales"

Published Rates. Month-to-Month. No 3-Year Lock-In.

CoreRecon publishes pricing because law firms shouldn't need to spend 90 minutes on a sales call to learn whether a cybersecurity provider is in-bounds. Three tiers. Per-endpoint. All include 24/7 SOC coverage and 30-minute IR SLA.

Sentinel
$89/endpoint/mo
min. 10 endpoints
  • 24/7 SOC monitoring — TX-resident analysts
  • Endpoint detection & response (EDR)
  • Email threat analysis + BEC monitoring
  • Monthly vulnerability summary report
  • TDPSA / ABA Rule 1.6 compliance mapped
Command
$2,500+/mo
flat-fee retainer
  • Everything in Fortress, plus:
  • Dedicated vCISO (contracted as security officer)
  • On-site incident response capability
  • Full policy library + annual review
  • Bar ethics compliance documentation package
  • Direct line to 24/7 IR team — no queue
30-minute IR SLA is contractual across all tiers — documented in your Master Service Agreement. Industry average response time: 1–4 hours (SANS 2024 IR Survey). We measure against that standard every month and report it to you.
SLA Proof

30 Minutes vs. Industry Standard: The Gap Is the Risk.

The 30-minute SLA isn't marketing — it's the difference between containment and dwell time. Ransomware operators complete the full attack chain (initial access → lateral movement → credential harvesting → encryption) in 45–90 minutes on average. Most MSSPs detect and respond within 1–4 hours. The window between what they offer and what ransomware actually does is where firms lose everything.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to you in your service review.
Industry Average: 1–4 Hours
SANS 2024 IR Survey: median time from detection to containment is 1–4 hours for MSSP-monitored environments. By that time, ransomware has usually completed lateral movement, credential dumping, and encryption across multiple systems. Containment is still necessary — but the damage is already done.
Ransomware Kill Chain: 45–90 Min
CrowdStrike 2024 Global Threat Report: average time from initial access to encryption is 45–90 minutes for human-operated ransomware. The window is tight. A 30-min SLA puts us inside the kill chain. Anything slower means we're responding to a fully-executing attack, not containing one.
TX State Bar Ethics: Prompt Notice
TX Disciplinary Rule 1.05 requires competence in understanding breach risk. A firm that has a 4-hour dwell time before detection and then a 6-hour response delay has 10+ hours of unmonitored exposure — documented in the breach timeline that ethics investigators will ask for.
Compliance Mapping

Framework-to-Control Crosswalk for Texas Law Firms

CoreRecon maps every SOC function to the specific regulation or framework that requires it. When your malpractice carrier, bar committee, or enterprise client asks "what does your security program actually cover?", this is the answer.

Regulation / Framework Required Control CoreRecon Function
TX Disciplinary Rule 1.05 Competence in technology risk; confidentiality of client data 24/7 SOC monitoring, EDR, documented incident response capability
TX DR 1.05 (modified ABA 1.6) Reasonable measures to prevent unauthorized access; breach response 30-min IR SLA, breach notification workflow, documented IR plan
ABA Model Rule 1.6(c) + Formal Opinion 483 Written information security program (WISP); breach notification Policy library, vCISO retainer, WISP authorship (Command tier)
TDPSA §541 60-day breach notification to TX AG + affected residents; data minimization Breach detection, IR team coordinates notification, forensic documentation
CMMC 2.0 Phase 2 (DFARS 252.204-7012) SPRS score, SSP, POA&M, incident reporting to DoD within 72 hours SPRS gap assessment, POA&M tracking, DFARS incident response plan
HIPAA (where applicable — healthcare client matters) Security Rule controls, PHI breach notification within 60 days HIPAA-mapped SOC, PHI access monitoring, OCR-level incident response
IRS Pub 4557 (WISP — for firms with financial services clients) Written information security plan; annual review; incident documentation WISP review support, vCISO retainer (Command tier), annual policy review
Cyber Insurance (cyber liability / E&O carriers) Minimum basic controls questionnaire (Critical, High, Medium control categories) Control documentation package, carrier questionnaire completion support
How We Compare

Built for Law Firms. Not a Generic Enterprise Package.

Most MSSPs serve banks, healthcare systems, and manufacturers. Law firms have a different risk profile: privileged data, IOLTA accounts, litigation holds, and bar ethics obligations. CoreRecon is built for legal sector workflows from day one.

Capability Generic MSSP CoreRecon
TX-based SOC analysts Cloud SOC — offshore or mixed TX-resident analysts, US-based
30-min IR SLA (contractual) 1–4 hour best-effort Contractual. Measured monthly.
IOLTA wire fraud monitoring Standard BEC (not law-firm-specific) IOLTA workflow monitoring included (Fortress+)
Bar ethics compliance documentation Not offered TX Bar Rule 1.05 mapped controls (Command tier)
CMMC / SPRS documentation Available as add-on (3–6 month project) Quarterly gap assessment included (Fortress+)
Litigation hold / e-discovery hardening Not offered Retain-not-delete protocol (Fortress+)
Published pricing "Contact sales" — 90-min call to get a quote Published. $89–$129/endpoint. Month-to-month.
SDVOSB contracting Not available SDVOSB-certified. CVE-verified.
See full competitor comparison →
Free Assessment — $2,500 Value

Find Out Where Your Firm Actually Stands.

Our Security Posture Assessment covers your endpoint exposure, email threat landscape, wire fraud workflow gaps, and bar ethics compliance posture. It's free. Takes 20 minutes to complete. We'll deliver a written report with prioritized findings — not a sales deck.

What the Assessment Covers
Endpoint coverage audit — which workstations and servers are actually monitored.
Email threat exposure — phishing simulation results, BEC attack surface.
IOLTA / wire fraud workflow gaps — where your accounting workflow is exposed.
TX Bar Rule 1.05 compliance posture — documented readiness score.
CMMC / SPRS gap (if applicable) — current score vs. contract requirement.
What You Get
Written security posture report — prioritized findings, not a risk matrix.
30-min debrief call with a TX-based analyst (not a sales rep).
Remediation roadmap — what to fix first, what can wait.
No obligation — if you're not a fit, we'll tell you.
Start Your Free Security Posture Assessment →
Research Brief — June 2026

Download the TX Law Firm Threat Brief.

8 documented incidents. State Bar of TX (INC Ransom). Orrick. Mossing & Navarre. Bryan Cave CCG. TX regulatory stack mapped (Rule 5.03, ABA 1.6, Formal Opinion 483, TDPSA, CMMC 2.0). 35+ verified sources. Print-ready PDF.

What's in the Brief
Named incidents: State Bar of TX INC Ransom, Orrick $8M OCR, Mossing & Navarre, Bryan Cave CCG, and 4 regional TX firm incidents with confirmed dates and vectors.

TX regulatory stack: TX DR 1.05, ABA Model Rule 1.6(c), Formal Opinion 483, TDPSA §541, CMMC 2.0 flow-down requirements for defense-adjacent firms.

IOLTA wire fraud kill chain: BEC attack sequence specific to law firm accounting workflows, with FBI IC3 loss data and TX-specific jurisdiction notes.
How to Get It
Gate: Name + firm email + phone. Takes 30 seconds.

Delivery: Instant access to the PDF. Confirmation email with link. No drip sequence.

Source tag: v42_tx_law_firms_brief

36 sources including State Bar of TX official statements, TX AG notifications, HHS OCR enforcement actions, FBI IC3 2024 Annual Report, ABA Formal Opinion 483, and NIST 800-171.
Download the TX Law Firm Threat Brief →
FAQ

Questions Texas Law Firms Ask Before Signing.

Direct answers. Not legal advice. Not a substitute for your breach counsel — but enough to know whether we're a fit.

We operate under the same confidentiality obligations your firm does. Our SOC never accesses your data content — only metadata, access patterns, and anomaly signals. We're covered by your existing client engagement letter confidentiality provisions, and we sign a custom NDA for any engagement where your matter data is in scope. Our infrastructure is isolated from your document management systems — we monitor endpoints, not the content of privileged communications.
We coordinate directly with your e-discovery counsel. When a breach occurs during active litigation, the spoliation risk is as serious as the cybersecurity risk — a forensic investigation that overwrites ESI is a malpractice exposure. CoreRecon's retain-not-delete protocol locks the investigation to metadata analysis first, preserves the chain of custody for your e-discovery team, and only accesses content through forensically-sound processes that your litigation counsel can defend in a hearing.
It complements it. Cyber insurance carriers require documented control evidence at application and at renewal — CoreRecon produces that documentation. If you have a covered incident, your carrier may require specific response steps that we execute with them, not against them. We do not act as a claims adjuster, but we provide the forensic documentation your carrier needs to process the claim without contesting the breach cause. Some firms also have E&O / malpractice coverage with cyber extensions — we'll coordinate with your broker to avoid duplication.
Yes — materially. CMMC Level 2 flow-down under DFARS 252.204-7012 requires specific controls that generic MSSPs don't implement. We map your SPRS score at onboarding, build the SSP (System Security Plan), track your POA&M (Plan of Action & Milestones), and prepare the documentation package your prime contractor's C3PAO will accept. If you're Level 2, we run a gap assessment in the first 30 days and produce a roadmap. Phase 2 enforcement (Nov 2026) makes this non-negotiable for active contracts.
Phase 1 (EDR deployment, endpoint onboarding, initial SOC coverage): 5–7 business days. Phase 2 (IOLTA workflow integration, litigation hold protocol, policy library alignment): 15–30 days. Full coverage across all CoreRecon functions: 60–90 days. We don't do "rip and replace" on your existing IT infrastructure — we layer on top and coordinate with your existing IT provider, who doesn't need to be replaced. You'll have a named technical lead from day one.
Yes — and they know your firm's name. Our TX SOC operates 24/7/365. We don't use a rotating overnight pool where the analyst is reading your alert for the first time. Your incidents are worked by analysts who know your environment, your baseline, and your firm's operating hours. An attorney calling from a Sunday deposition gets a live analyst, not a voicemail.
We activate our breach response protocol immediately on your notification. CoreRecon's IR team coordinates the forensic investigation, manages the TX AG and State Bar notification timeline (TDPSA: 60 days; TX DR 1.05: "prompt" but no hard deadline — we move fast), and produces the documentation your breach counsel needs for any regulatory response. The 30-minute SLA applies from the moment you receive the notification, not from when we detect it ourselves.
Yes. Our standard agreement is month-to-month for Sentinel and Fortress. Command tier (dedicated vCISO) is a 12-month retainer for continuity of the vCISO relationship. There are no hidden termination fees for early exit on month-to-month tiers. We win on results, not contract lock-in.
📍 Texas-Based SOC
🎖️ SDVOSB-Certified (CVE)
🇺🇸 USMC Veteran-Led Team
🛡️ 24/7 SOC — 30-Min IR SLA
⚖️ TX Bar Rule 1.05 Mapped
📋 Month-to-Month

The State Bar Breach
Wasn't Your Fault.
The Next One Will Be.

State Bar of TX (Jan 2025). Orrick $8M. Mossing & Navarre. The incidents are documented. Your bar obligations are clear. The only question is whether your firm has a documented security program with a contractual IR SLA — or a hope and a default cyber insurance policy.

Start the free assessment. Takes 20 minutes. Written report with prioritized findings. No sales deck.

Start Your Free Security Posture Assessment →