{"id":160989,"date":"2026-08-19T13:46:23","date_gmt":"2026-08-19T21:46:23","guid":{"rendered":"https:\/\/xira.com\/p\/2026\/08\/19\/ibms-2026-data-breach-report-houston-we-have-a-problem\/"},"modified":"2026-08-19T13:46:23","modified_gmt":"2026-08-19T21:46:23","slug":"ibms-2026-data-breach-report-houston-we-have-a-problem","status":"publish","type":"post","link":"https:\/\/xira.com\/p\/2026\/08\/19\/ibms-2026-data-breach-report-houston-we-have-a-problem\/","title":{"rendered":"IBM\u2019s 2026 Data Breach Report: Houston, We Have A Problem"},"content":{"rendered":"<figure class=\"wp-block-image alignright\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"798\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2023\/08\/cybersecurity-6949298_1280-1.png?resize=1080%2C798&#038;ssl=1\" alt=\"\" class=\"wp-image-85135\" title=\"\"><figcaption><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">IBM\u2019s recent\u00a0<a href=\"https:\/\/www.ibm.com\/reports\/data-breach\" rel=\"nofollow noopener\" target=\"_blank\">Cost of a Data Breach Report<\/a>\u00a0ought to be a wake-up call for legal. Not just for the raw numbers but for the conclusion that \u201cfrontier AI models have radically shifted the cybersecurity threat landscape.\u201d And that hits home hard for legal even if the legal market was not specifically studied.<\/p>\n<p class=\"wp-block-paragraph\">The underlying research for the report was done by\u00a0<a href=\"https:\/\/www.ponemon.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Ponemon Institute<\/a>. That in and of itself is important because Ponemon isn\u2019t selling a product. It\u2019s an independent research outfit devoted to information and privacy management. So unlike many surveys that are conducted by vendors, there is less likelihood of a bias that pushes the need to buy something. For this particular survey, Ponemon studied 602 businesses in 17 industries and 16 countries.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Raw Numbers<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The raw numbers themselves are startling:<\/p>\n<ul class=\"wp-block-list\">\n<li>The average cost of a data breach last year was almost $5 million, up 12% from the year before.<\/li>\n<li>There was a 56% increase in AI generated cybersecurity attacks.<\/li>\n<li>Ninety-two percent of the organizations that reported an AI related data breach lacked proper AI controls.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The report concludes simply that AI-driven attacks are getting faster and cheaper to launch, and the resulting breaches are getting more expansive to find and then fix.<\/p>\n<p class=\"wp-block-paragraph\"><strong>So Why Is This Important For Legal?<\/strong><\/p>\n<p class=\"wp-block-paragraph\">So data breaches are costing more to fix. What\u2019s new about that; the study didn\u2019t even examine the legal industry. But there is an old and accurate saying, when it comes to data breaches, there are two kinds of firms: those that have been breached and those that don\u2019t know they have been breached.<\/p>\n<p class=\"wp-block-paragraph\">The number of law firms that <strong>have<\/strong> reported data breaches continues to grow and includes some of the largest in the country. Large firms that you would think are pretty sophisticated when it comes to cybersecurity. Firms like Herbert Smith Freehills Kramer (2,700 lawyers), Mayer Brown (1,800 lawyers), and Goodwin Procter (also about 1,800 lawyers). All were\u00a0<a href=\"https:\/\/www.law.com\/international-edition\/2026\/08\/11\/hsf-kramer-mayer-brown-targeted-in-latest-law-firm-data-breaches\/\" rel=\"nofollow noopener\" target=\"_blank\">recently reported<\/a>\u00a0to have been breached. Others include Fox Rothschild, Taft Stettinius &amp; Hollister, and Wiley Rein.<\/p>\n<p class=\"wp-block-paragraph\">Of those, the rumor is that three paid approximately $50 million in ransom as a result of the breaches. And that\u2019s not to mention the cost of finding and fixing the breach, the damage to reputation, and the potential loss of clients and lawsuits. Clearly, law firms are just as much a target and their losses just as great if not more so, than the industries surveyed by Ponemon and IBM.<\/p>\n<p class=\"wp-block-paragraph\"><strong>But Wait, There\u2019s More<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Other aspects of the report could spell trouble for law firms. According to the report, breaches of healthcare organizations remain the most expensive for the thirteenth\u00a0consecutive year. Why? Because these organizations house significant amounts of personally identifiable information (PII) which attackers value. Information that can be used for such things as identity theft, insurance fraud, and other financially related crime. PII is the most frequently stolen information, says the report.<\/p>\n<p class=\"wp-block-paragraph\">And what do law firms have a lot of: the same type of information. Social Security numbers. Medical records. Financial information. Addresses. You name it. Fox Rothschild, for example, reported that this was the exact information stolen from it: Social Security numbers, financial account codes, and credit information. It\u2019s this type of information that fuels ransomware, according to the report. And it was just this type of ransomware attacks law firm face. Not to mention the fact that, in light of its breach, the Wiley Rein firm was\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/06\/the-wiley-rein-data-breach-lawsuit-yet-another-cybersecurity-wake-up-call\/\" rel=\"nofollow noopener\" target=\"_blank\">recently sued<\/a>,\u00a0not by its clients, but by those whose information was compromised.<\/p>\n<p class=\"wp-block-paragraph\">So clearly law firms are targets. The notion of cybersecurity by obscurity, the idea that law firms have nothing the bad guys want, is long gone, if it was ever viable.<\/p>\n<p class=\"wp-block-paragraph\"><strong>And If That\u2019s Not Enough<\/strong><\/p>\n<p class=\"wp-block-paragraph\">And here\u2019s something else: of the breached organizations studied in the survey, 53% didn\u2019t bother to encrypt sensitive data at rest and in motion, leading to it being compromised. And attackers used impersonations (phishing) in the majority of attacks. The email from what appears to be the managing partner or GC asking for money to be wired. Or a call from someone purportedly in the IT department asking for security credentials.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Another gaping hole Ponemon found: data being copied to removable media. Data on the USB stick that\u2019s misplaced turns up 200 days later on the dark web. Believe me, lawyers use removable media tools more than we would like to admit. I know how easy and convenient it is to use things like USB flash drives. And how easy for them to seemingly vanish.<\/p>\n<p class=\"wp-block-paragraph\">When a breach happens, recovery is difficult and can take years. According to the report, 58% of those surveyed who suffered a breach had not yet recovered. Think about that. And the longer it takes to recover, the more the costs add up. More disruption. An adverse impact on billable hours. It allegedly took Wiley Rein over a year to even discover its breach and over two years to give notice. That\u2019s a lot of down time.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Elephant In The Room<\/strong><\/p>\n<p class=\"wp-block-paragraph\">If all this isn\u2019t enough to keep a managing partner up at night, we now have the specter of AI attacks. \u201cAttackers are using AI as a critical tool \u2026 in generating phishing email, scanning code for vulnerabilities and automating attacks at scale,\u201d according to the report. One in four of the organizations experiencing a breach were attacked through AI. Those attacks have gotten so\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">fast and good<\/a>\u00a0that keeping up with them is difficult. And those AI attacks increased the cost of the data breach, adding $1 million on average.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But here is the real headline from the report: \u201cOrganizations continue to prioritize innovation over security for AI models and applications, which can leave them vulnerable to AI-related breaches.\u201d And this: security incidents involving the so-called shadow use of AI \u2014 personnel using unapproved AI \u2014 more than doubled year over year, according to the report. Most of the organizations studied lacked governance tools to discover this shadow use.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Quite simply, says the report, \u201cAI adoption is outpacing oversight.\u201d Does all this sound familiar? A\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/07\/the-blickstein-group-law-firm-coo-survey-the-more-things-change-the-more-some-things-stay-the-same\/\" rel=\"nofollow noopener\" target=\"_blank\">recent Blickstein Group Study<\/a>\u00a0of COOs in law firms found 69% of the firms surveyed were using both legal-specific and general-AI tools. That would suggest that many firms are allowing use of general-AI tools. That\u2019s scary and shows a lack of governance that could lead to just the sort of breach those in the Ponemon study experienced.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">And the\u00a0<a href=\"https:\/\/www.8am.com\/reports\/legal-industry-report-2026\/?utm_source=aba&amp;utm_medium=referral&amp;utm_campaign=mc-mkt-leadership-lir-blog-productannouncement&amp;utm_content=sponsored-con\" rel=\"nofollow noopener\" target=\"_blank\">2026 Legal Industry Report<\/a>\u00a0from\u00a0<a href=\"https:\/\/www.8am.com\/\" rel=\"nofollow noopener\" target=\"_blank\">8am<\/a>\u00a0demonstrates that over half of its respondents in a law firm study reported their firm has provided no training on the responsible use of AI. Moreover, while seven in 10 lawyers personally use AI, firm-level adoption is much lower.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Even more importantly, only 9% of those surveyed by 8am said their firm had a written policy that was\u00a0<a href=\"https:\/\/www.ncbar.org\/nc-lawyer\/2026-05\/by-the-numbers-what-surveys-show-about-law-firm-ai-adoption\/\" rel=\"nofollow noopener\" target=\"_blank\">actually enforced<\/a>. A 2026 Thomson Reuters Institute\u00a0<a href=\"https:\/\/getperspective.ai\/blog\/legal-tech-trends-2026-6-data-backed-shifts-law-firm-ai-adoption\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>\u00a0revealed that 52% of those surveyed said their organization still had no generative-AI policy. Leading\u00a0<a href=\"https:\/\/www.americanbar.org\/groups\/law_practice\/resources\/law-practice-magazine\/2026\/march-april-2026\/8am-legal-industry-report\/?login\" rel=\"nofollow noopener\" target=\"_blank\">one commentator<\/a>\u00a0to conclude \u201cusage is outpacing structure.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>Houston, We Have a Problem<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Putting all this together reveals a perfect storm. You have\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">complacency and disinterest<\/a>\u00a0by law firm leaders who often don\u2019t understand cybersecurity and its risks or care all that much. You have an\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">over reliance<\/a>\u00a0on cyber insurance and internal staff. And cyberattacks using AI are increasing in speed and vulnerability at an alarming rate.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">To top it off, you have lawyers and law firm leadership more interested in the adoption of shiny new AI toys than in providing the guard rails to protect data that attackers are more and more interested in.<\/p>\n<p class=\"wp-block-paragraph\">The Mayer Brown, Goodwin Procter, and Wiley Rein attacks are just the tip of the coming iceberg. It\u2019s an Apollo moment:\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity expert: \u201cHouston, we have a problem.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Law firm response: \u201cThis is Houston. Say again, please.\u201d<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\">\n<p class=\"wp-block-paragraph\"><strong><em>Stephen Embry is a lawyer, speaker, blogger, and writer. He publishes\u00a0<a href=\"https:\/\/www.techlawcrossroads.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechLaw Crossroads<\/a>, a blog devoted to the examination of the tension between technology, the law, and the practice of law.<\/em><\/strong><\/p>\n<p class=\"wp-block-paragraph\">\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/08\/ibms-2026-data-breach-report-houston-we-have-a-problem\/\" rel=\"nofollow noopener\" target=\"_blank\">IBM\u2019s 2026 Data Breach Report: Houston, We Have A Problem<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n<figure class=\"wp-block-image alignright\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"798\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2023\/08\/cybersecurity-6949298_1280-1.png?resize=1080%2C798&#038;ssl=1\" alt=\"\" class=\"wp-image-85135\" title=\"\"><figcaption><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">IBM\u2019s recent\u00a0<a href=\"https:\/\/www.ibm.com\/reports\/data-breach\" rel=\"nofollow noopener\" target=\"_blank\">Cost of a Data Breach Report<\/a>\u00a0ought to be a wake-up call for legal. Not just for the raw numbers but for the conclusion that \u201cfrontier AI models have radically shifted the cybersecurity threat landscape.\u201d And that hits home hard for legal even if the legal market was not specifically studied.<\/p>\n<p class=\"wp-block-paragraph\">The underlying research for the report was done by\u00a0<a href=\"https:\/\/www.ponemon.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Ponemon Institute<\/a>. That in and of itself is important because Ponemon isn\u2019t selling a product. It\u2019s an independent research outfit devoted to information and privacy management. So unlike many surveys that are conducted by vendors, there is less likelihood of a bias that pushes the need to buy something. For this particular survey, Ponemon studied 602 businesses in 17 industries and 16 countries.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Raw Numbers<\/strong><\/p>\n<p class=\"wp-block-paragraph\">The raw numbers themselves are startling:<\/p>\n<ul class=\"wp-block-list\">\n<li>The average cost of a data breach last year was almost $5 million, up 12% from the year before.<\/li>\n<li>There was a 56% increase in AI generated cybersecurity attacks.<\/li>\n<li>Ninety-two percent of the organizations that reported an AI related data breach lacked proper AI controls.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The report concludes simply that AI-driven attacks are getting faster and cheaper to launch, and the resulting breaches are getting more expansive to find and then fix.<\/p>\n<p class=\"wp-block-paragraph\"><strong>So Why Is This Important For Legal?<\/strong><\/p>\n<p class=\"wp-block-paragraph\">So data breaches are costing more to fix. What\u2019s new about that; the study didn\u2019t even examine the legal industry. But there is an old and accurate saying, when it comes to data breaches, there are two kinds of firms: those that have been breached and those that don\u2019t know they have been breached.<\/p>\n<p class=\"wp-block-paragraph\">The number of law firms that <strong>have<\/strong> reported data breaches continues to grow and includes some of the largest in the country. Large firms that you would think are pretty sophisticated when it comes to cybersecurity. Firms like Herbert Smith Freehills Kramer (2,700 lawyers), Mayer Brown (1,800 lawyers), and Goodwin Procter (also about 1,800 lawyers). All were\u00a0<a href=\"https:\/\/www.law.com\/international-edition\/2026\/08\/11\/hsf-kramer-mayer-brown-targeted-in-latest-law-firm-data-breaches\/\" rel=\"nofollow noopener\" target=\"_blank\">recently reported<\/a>\u00a0to have been breached. Others include Fox Rothschild, Taft Stettinius &amp; Hollister, and Wiley Rein.<\/p>\n<p class=\"wp-block-paragraph\">Of those, the rumor is that three paid approximately $50 million in ransom as a result of the breaches. And that\u2019s not to mention the cost of finding and fixing the breach, the damage to reputation, and the potential loss of clients and lawsuits. Clearly, law firms are just as much a target and their losses just as great if not more so, than the industries surveyed by Ponemon and IBM.<\/p>\n<p class=\"wp-block-paragraph\"><strong>But Wait, There\u2019s More<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Other aspects of the report could spell trouble for law firms. According to the report, breaches of healthcare organizations remain the most expensive for the thirteenth\u00a0consecutive year. Why? Because these organizations house significant amounts of personally identifiable information (PII) which attackers value. Information that can be used for such things as identity theft, insurance fraud, and other financially related crime. PII is the most frequently stolen information, says the report.<\/p>\n<p class=\"wp-block-paragraph\">And what do law firms have a lot of: the same type of information. Social Security numbers. Medical records. Financial information. Addresses. You name it. Fox Rothschild, for example, reported that this was the exact information stolen from it: Social Security numbers, financial account codes, and credit information. It\u2019s this type of information that fuels ransomware, according to the report. And it was just this type of ransomware attacks law firm face. Not to mention the fact that, in light of its breach, the Wiley Rein firm was\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/06\/the-wiley-rein-data-breach-lawsuit-yet-another-cybersecurity-wake-up-call\/\" rel=\"nofollow noopener\" target=\"_blank\">recently sued<\/a>,\u00a0not by its clients, but by those whose information was compromised.<\/p>\n<p class=\"wp-block-paragraph\">So clearly law firms are targets. The notion of cybersecurity by obscurity, the idea that law firms have nothing the bad guys want, is long gone, if it was ever viable.<\/p>\n<p class=\"wp-block-paragraph\"><strong>And If That\u2019s Not Enough<\/strong><\/p>\n<p class=\"wp-block-paragraph\">And here\u2019s something else: of the breached organizations studied in the survey, 53% didn\u2019t bother to encrypt sensitive data at rest and in motion, leading to it being compromised. And attackers used impersonations (phishing) in the majority of attacks. The email from what appears to be the managing partner or GC asking for money to be wired. Or a call from someone purportedly in the IT department asking for security credentials.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Another gaping hole Ponemon found: data being copied to removable media. Data on the USB stick that\u2019s misplaced turns up 200 days later on the dark web. Believe me, lawyers use removable media tools more than we would like to admit. I know how easy and convenient it is to use things like USB flash drives. And how easy for them to seemingly vanish.<\/p>\n<p class=\"wp-block-paragraph\">When a breach happens, recovery is difficult and can take years. According to the report, 58% of those surveyed who suffered a breach had not yet recovered. Think about that. And the longer it takes to recover, the more the costs add up. More disruption. An adverse impact on billable hours. It allegedly took Wiley Rein over a year to even discover its breach and over two years to give notice. That\u2019s a lot of down time.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Elephant In The Room<\/strong><\/p>\n<p class=\"wp-block-paragraph\">If all this isn\u2019t enough to keep a managing partner up at night, we now have the specter of AI attacks. \u201cAttackers are using AI as a critical tool \u2026 in generating phishing email, scanning code for vulnerabilities and automating attacks at scale,\u201d according to the report. One in four of the organizations experiencing a breach were attacked through AI. Those attacks have gotten so\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">fast and good<\/a>\u00a0that keeping up with them is difficult. And those AI attacks increased the cost of the data breach, adding $1 million on average.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But here is the real headline from the report: \u201cOrganizations continue to prioritize innovation over security for AI models and applications, which can leave them vulnerable to AI-related breaches.\u201d And this: security incidents involving the so-called shadow use of AI \u2014 personnel using unapproved AI \u2014 more than doubled year over year, according to the report. Most of the organizations studied lacked governance tools to discover this shadow use.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Quite simply, says the report, \u201cAI adoption is outpacing oversight.\u201d Does all this sound familiar? A\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/07\/the-blickstein-group-law-firm-coo-survey-the-more-things-change-the-more-some-things-stay-the-same\/\" rel=\"nofollow noopener\" target=\"_blank\">recent Blickstein Group Study<\/a>\u00a0of COOs in law firms found 69% of the firms surveyed were using both legal-specific and general-AI tools. That would suggest that many firms are allowing use of general-AI tools. That\u2019s scary and shows a lack of governance that could lead to just the sort of breach those in the Ponemon study experienced.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">And the\u00a0<a href=\"https:\/\/www.8am.com\/reports\/legal-industry-report-2026\/?utm_source=aba&amp;utm_medium=referral&amp;utm_campaign=mc-mkt-leadership-lir-blog-productannouncement&amp;utm_content=sponsored-con\" rel=\"nofollow noopener\" target=\"_blank\">2026 Legal Industry Report<\/a>\u00a0from\u00a0<a href=\"https:\/\/www.8am.com\/\" rel=\"nofollow noopener\" target=\"_blank\">8am<\/a>\u00a0demonstrates that over half of its respondents in a law firm study reported their firm has provided no training on the responsible use of AI. Moreover, while seven in 10 lawyers personally use AI, firm-level adoption is much lower.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Even more importantly, only 9% of those surveyed by 8am said their firm had a written policy that was\u00a0<a href=\"https:\/\/www.ncbar.org\/nc-lawyer\/2026-05\/by-the-numbers-what-surveys-show-about-law-firm-ai-adoption\/\" rel=\"nofollow noopener\" target=\"_blank\">actually enforced<\/a>. A 2026 Thomson Reuters Institute\u00a0<a href=\"https:\/\/getperspective.ai\/blog\/legal-tech-trends-2026-6-data-backed-shifts-law-firm-ai-adoption\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a>\u00a0revealed that 52% of those surveyed said their organization still had no generative-AI policy. Leading\u00a0<a href=\"https:\/\/www.americanbar.org\/groups\/law_practice\/resources\/law-practice-magazine\/2026\/march-april-2026\/8am-legal-industry-report\/?login\" rel=\"nofollow noopener\" target=\"_blank\">one commentator<\/a>\u00a0to conclude \u201cusage is outpacing structure.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>Houston, We Have a Problem<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Putting all this together reveals a perfect storm. You have\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">complacency and disinterest<\/a>\u00a0by law firm leaders who often don\u2019t understand cybersecurity and its risks or care all that much. You have an\u00a0<a href=\"https:\/\/abovethelaw.com\/2026\/03\/lawyers-and-cybersecurity-talk-to-an-expert-before-its-too-late\/\" rel=\"nofollow noopener\" target=\"_blank\">over reliance<\/a>\u00a0on cyber insurance and internal staff. And cyberattacks using AI are increasing in speed and vulnerability at an alarming rate.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">To top it off, you have lawyers and law firm leadership more interested in the adoption of shiny new AI toys than in providing the guard rails to protect data that attackers are more and more interested in.<\/p>\n<p class=\"wp-block-paragraph\">The Mayer Brown, Goodwin Procter, and Wiley Rein attacks are just the tip of the coming iceberg. It\u2019s an Apollo moment:\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity expert: \u201cHouston, we have a problem.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Law firm response: \u201cThis is Houston. Say again, please.\u201d<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n<p class=\"wp-block-paragraph\"><strong><em>Stephen Embry is a lawyer, speaker, blogger, and writer. He publishes\u00a0<a href=\"https:\/\/www.techlawcrossroads.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechLaw Crossroads<\/a>, a blog devoted to the examination of the tension between technology, the law, and the practice of law.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IBM\u2019s recent\u00a0Cost of a Data Breach Report\u00a0ought to be a wake-up call for legal. Not just for the raw numbers but for the conclusion that \u201cfrontier AI models have radically shifted the cybersecurity threat landscape.\u201d And that hits home hard for legal even if the legal market was not specifically studied. The underlying research for [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":160976,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-160989","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-above_the_law"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/xira.com\/p\/wp-content\/uploads\/2026\/08\/cybersecurity-6949298_1280-1-E1UCSy.png?fit=1280%2C946&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/160989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/comments?post=160989"}],"version-history":[{"count":0,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/160989\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media\/160976"}],"wp:attachment":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media?parent=160989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/categories?post=160989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/tags?post=160989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}