{"id":162072,"date":"2026-09-02T07:35:56","date_gmt":"2026-09-02T15:35:56","guid":{"rendered":"https:\/\/xira.com\/p\/2026\/09\/02\/the-cybersecurity-control-money-cant-buy\/"},"modified":"2026-09-02T07:35:56","modified_gmt":"2026-09-02T15:35:56","slug":"the-cybersecurity-control-money-cant-buy","status":"publish","type":"post","link":"https:\/\/xira.com\/p\/2026\/09\/02\/the-cybersecurity-control-money-cant-buy\/","title":{"rendered":"The Cybersecurity Control Money Can\u2019t Buy"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Law firms spend enormous amounts of money protecting their networks. They use firewalls, endpoint detection, multifactor authentication, security monitoring, and email filtering. The list of technologies designed to keep attackers out keeps growing. And yet, sometimes an attacker doesn\u2019t need to defeat any of them.<\/p>\n<p class=\"wp-block-paragraph\">Recent reports of cyberattacks on some of the world\u2019s largest law firms offer a sobering reminder of that reality. WilmerHale reportedly paid at least $18 million to the cyber extortion group Luna Moth after an attack, while Goodwin reportedly paid about $10 million. Weil reportedly paid between $18 million and $20 million after a separate incident. Combined, the ransom payments alone approach $50 million.<\/p>\n<p class=\"wp-block-paragraph\">Those figures are staggering, but the ransom amounts aren\u2019t the most important part of the story.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Attack Wasn\u2019t Necessarily Sophisticated<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Goodwin said its incident began when a single employee was deceived into providing credentials to an unauthorized person. In another recent incident, Mayer Brown said an employee mistakenly sent documents to someone who had misrepresented their identity. The firm said the third party never gained access to its systems.<\/p>\n<p class=\"wp-block-paragraph\">Different incidents, but each has the same underlying lesson. Sometimes the easiest way to bypass sophisticated cybersecurity defenses is to simply convince someone to help you.<\/p>\n<p class=\"wp-block-paragraph\">Social engineering has existed for decades, but attackers continue to refine it. Today\u2019s attacks may involve someone impersonating an IT technician, calling an employee directly to request remote access, or creating enough urgency and credibility that the victim believes the request is legitimate.<\/p>\n<p class=\"wp-block-paragraph\">That poses a particularly difficult challenge for law firms because attorneys and staff are trained to be responsive. Clients expect quick answers, and partners want problems solved. Attackers understand these workplace dynamics and exploit them to their advantage.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Technology Can\u2019t Fix Everything<\/strong><\/p>\n<p class=\"wp-block-paragraph\">None of\u00a0this\u00a0means firms should stop investing in cybersecurity technology. Strong technical controls remain essential and can limit damage even after a mistake occurs. But technology has limits.<\/p>\n<p class=\"wp-block-paragraph\">An employee who voluntarily provides credentials may circumvent protections designed to prevent unauthorized access. Someone who approves a multifactor authentication request they didn\u2019t initiate can defeat one of the industry\u2019s most important security controls. An employee who grants remote access to someone they believe is from IT may effectively escort an attacker past a layer of expensive security technology.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s why cybersecurity awareness training can\u2019t be an annual video employees click through while answering email. Employees need to understand how attacks happen and how to independently verify whether someone claiming to be from their IT department or technology provider is legitimate. Most importantly, they need permission to slow things down when something doesn\u2019t feel right.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Make Verification Normal<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Law firms can make social engineering significantly harder by establishing simple verification procedures.<\/p>\n<p class=\"wp-block-paragraph\">If someone claiming to be from IT unexpectedly contacts an employee, the employee should know how to verify that person\u2019s identity using a trusted phone number, an internal messaging system, or an established help desk process. Requests involving passwords, remote access, financial transactions, sensitive documents, or multifactor authentication should automatically trigger additional scrutiny.<\/p>\n<p class=\"wp-block-paragraph\">The goal isn\u2019t to make employees suspicious of everyone. It\u2019s to make verification part of the firm\u2019s culture. Attackers thrive on urgency. They want employees to act before\u00a0thinking,\u00a0whether the request supposedly comes from the managing partner, the accounting department, an IT provider, or an important client.<\/p>\n<p class=\"wp-block-paragraph\">A culture that encourages employees to pause and verify unusual requests removes one of the attacker\u2019s greatest advantages.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Human Element Still Matters<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Another lesson buried in these enormous ransom figures is that cybersecurity isn\u2019t only a problem for firms without adequate resources.<\/p>\n<p class=\"wp-block-paragraph\">The firms being targeted are among the largest and most sophisticated legal organizations in the world. They have substantial technology budgets, experienced security\u00a0professionals, and access to virtually every cybersecurity tool available.\u00a0Attackers are\u00a0successfully\u00a0targeting people\u00a0all the same.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s something every law firm should consider, regardless of size. You can spend a fortune making the locks on your doors stronger. But if someone can convince an employee to hand over the key, those locks suddenly matter a lot less. The answer isn\u2019t more fear. It\u2019s better preparation, better training, and a workplace where verifying an unusual request isn\u2019t treated as an inconvenience.<\/p>\n<p class=\"wp-block-paragraph\">Sometimes the most important cybersecurity\u00a0question\u00a0an employee can ask is also the simplest, \u201cHow do I\u00a0know\u00a0you are who you say you are?\u201d<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\">\n<p class=\"wp-block-paragraph\"><em><strong>Michael C. Maschke is the President and Chief Executive Officer of Sensei Enterprises, Inc. Mr. Maschke is an EnCase Certified Examiner (EnCE), a Certified Computer Examiner (CCE #744), an AccessData Certified Examiner (ACE), a Certified Ethical Hacker (CEH), and a Certified Information Systems Security Professional (CISSP). He is a frequent speaker on IT, cybersecurity, and digital forensics, and he has co-authored 14 books published by the American Bar Association. He can be reached at\u00a0mmaschke@senseient.com.<\/strong><\/em><\/p>\n<p class=\"wp-block-paragraph\"><em><strong>Sharon D. Nelson is the co-founder of and consultant to Sensei Enterprises, Inc. She is a past president of the Virginia State Bar, the Fairfax Bar Association, and the Fairfax Law Foundation. She is a co-author of 18 books published by the ABA. She can be reached at\u00a0snelson@senseient.com<\/strong><\/em>.<\/p>\n<p class=\"wp-block-paragraph\"><em><strong>John W. Simek is the co-founder of and consultant to Sensei Enterprises, Inc. He holds multiple technical certifications and is a nationally known digital forensics expert. He is a co-author of 18 books published by the American Bar Association. He can be reached at\u00a0jsimek@senseient.com<\/strong><\/em>.<\/p>\n<p>The post <a href=\"https:\/\/abovethelaw.com\/2026\/09\/the-cybersecurity-control-money-cant-buy\/\" rel=\"nofollow noopener\" target=\"_blank\">The Cybersecurity Control Money Can\u2019t Buy<\/a> appeared first on <a href=\"https:\/\/abovethelaw.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Above the Law<\/a>.<\/p>\n<figure class=\"post-single__featured-image post-single__featured-image--medium alignright\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/i0.wp.com\/abovethelaw.com\/wp-content\/uploads\/sites\/4\/2019\/11\/cybersecurity-GettyImages-1016968886-470x470-300x300.jpg?resize=300%2C300&#038;ssl=1\" class=\"attachment-medium size-medium wp-post-image\" alt=\"\" title=\"\"><\/figure>\n<p class=\"wp-block-paragraph\">Law firms spend enormous amounts of money protecting their networks. They use firewalls, endpoint detection, multifactor authentication, security monitoring, and email filtering. The list of technologies designed to keep attackers out keeps growing. And yet, sometimes an attacker doesn\u2019t need to defeat any of them.<\/p>\n<p class=\"wp-block-paragraph\">Recent reports of cyberattacks on some of the world\u2019s largest law firms offer a sobering reminder of that reality. WilmerHale reportedly paid at least $18 million to the cyber extortion group Luna Moth after an attack, while Goodwin reportedly paid about $10 million. Weil reportedly paid between $18 million and $20 million after a separate incident. Combined, the ransom payments alone approach $50 million.<\/p>\n<p class=\"wp-block-paragraph\">Those figures are staggering, but the ransom amounts aren\u2019t the most important part of the story.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Attack Wasn\u2019t Necessarily Sophisticated<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Goodwin said its incident began when a single employee was deceived into providing credentials to an unauthorized person. In another recent incident, Mayer Brown said an employee mistakenly sent documents to someone who had misrepresented their identity. The firm said the third party never gained access to its systems.<\/p>\n<p class=\"wp-block-paragraph\">Different incidents, but each has the same underlying lesson. Sometimes the easiest way to bypass sophisticated cybersecurity defenses is to simply convince someone to help you.<\/p>\n<p class=\"wp-block-paragraph\">Social engineering has existed for decades, but attackers continue to refine it. Today\u2019s attacks may involve someone impersonating an IT technician, calling an employee directly to request remote access, or creating enough urgency and credibility that the victim believes the request is legitimate.<\/p>\n<p class=\"wp-block-paragraph\">That poses a particularly difficult challenge for law firms because attorneys and staff are trained to be responsive. Clients expect quick answers, and partners want problems solved. Attackers understand these workplace dynamics and exploit them to their advantage.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Technology Can\u2019t Fix Everything<\/strong><\/p>\n<p class=\"wp-block-paragraph\">None of\u00a0this\u00a0means firms should stop investing in cybersecurity technology. Strong technical controls remain essential and can limit damage even after a mistake occurs. But technology has limits.<\/p>\n<p class=\"wp-block-paragraph\">An employee who voluntarily provides credentials may circumvent protections designed to prevent unauthorized access. Someone who approves a multifactor authentication request they didn\u2019t initiate can defeat one of the industry\u2019s most important security controls. An employee who grants remote access to someone they believe is from IT may effectively escort an attacker past a layer of expensive security technology.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s why cybersecurity awareness training can\u2019t be an annual video employees click through while answering email. Employees need to understand how attacks happen and how to independently verify whether someone claiming to be from their IT department or technology provider is legitimate. Most importantly, they need permission to slow things down when something doesn\u2019t feel right.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Make Verification Normal<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Law firms can make social engineering significantly harder by establishing simple verification procedures.<\/p>\n<p class=\"wp-block-paragraph\">If someone claiming to be from IT unexpectedly contacts an employee, the employee should know how to verify that person\u2019s identity using a trusted phone number, an internal messaging system, or an established help desk process. Requests involving passwords, remote access, financial transactions, sensitive documents, or multifactor authentication should automatically trigger additional scrutiny.<\/p>\n<p class=\"wp-block-paragraph\">The goal isn\u2019t to make employees suspicious of everyone. It\u2019s to make verification part of the firm\u2019s culture. Attackers thrive on urgency. They want employees to act before\u00a0thinking,\u00a0whether the request supposedly comes from the managing partner, the accounting department, an IT provider, or an important client.<\/p>\n<p class=\"wp-block-paragraph\">A culture that encourages employees to pause and verify unusual requests removes one of the attacker\u2019s greatest advantages.<\/p>\n<p class=\"wp-block-paragraph\"><strong>The Human Element Still Matters<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Another lesson buried in these enormous ransom figures is that cybersecurity isn\u2019t only a problem for firms without adequate resources.<\/p>\n<p class=\"wp-block-paragraph\">The firms being targeted are among the largest and most sophisticated legal organizations in the world. They have substantial technology budgets, experienced security\u00a0professionals, and access to virtually every cybersecurity tool available.\u00a0Attackers are\u00a0successfully\u00a0targeting people\u00a0all the same.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s something every law firm should consider, regardless of size. You can spend a fortune making the locks on your doors stronger. But if someone can convince an employee to hand over the key, those locks suddenly matter a lot less. The answer isn\u2019t more fear. It\u2019s better preparation, better training, and a workplace where verifying an unusual request isn\u2019t treated as an inconvenience.<\/p>\n<p class=\"wp-block-paragraph\">Sometimes the most important cybersecurity\u00a0question\u00a0an employee can ask is also the simplest, \u201cHow do I\u00a0know\u00a0you are who you say you are?\u201d<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n<p class=\"wp-block-paragraph\"><em><strong>Michael C. Maschke is the President and Chief Executive Officer of Sensei Enterprises, Inc. Mr. Maschke is an EnCase Certified Examiner (EnCE), a Certified Computer Examiner (CCE #744), an AccessData Certified Examiner (ACE), a Certified Ethical Hacker (CEH), and a Certified Information Systems Security Professional (CISSP). He is a frequent speaker on IT, cybersecurity, and digital forensics, and he has co-authored 14 books published by the American Bar Association. He can be reached at\u00a0<a href=\"https:\/\/abovethelaw.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"c4a9a9a5b7a7acafa184b7a1aab7a1ada1aab0eaa7aba9\" rel=\"nofollow noopener\" target=\"_blank\">[email\u00a0protected]<\/a>.<\/strong><\/em><\/p>\n<p class=\"wp-block-paragraph\"><em><strong>Sharon D. Nelson is the co-founder of and consultant to Sensei Enterprises, Inc. She is a past president of the Virginia State Bar, the Fairfax Bar Association, and the Fairfax Law Foundation. She is a co-author of 18 books published by the ABA. She can be reached at\u00a0<a href=\"https:\/\/abovethelaw.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"c7b4a9a2abb4a8a987b4a2a9b4a2aea2a9b3e9a4a8aa\" rel=\"nofollow noopener\" target=\"_blank\">[email\u00a0protected]<\/a><\/strong><\/em>.<\/p>\n<p class=\"wp-block-paragraph\"><em><strong>John W. Simek is the co-founder of and consultant to Sensei Enterprises, Inc. He holds multiple technical certifications and is a nationally known digital forensics expert. He is a co-author of 18 books published by the American Bar Association. He can be reached at\u00a0<a href=\"https:\/\/abovethelaw.com\/cdn-cgi\/l\/email-protection\" class=\"__cf_email__\" data-cfemail=\"a8c2dbc1c5cdc3e8dbcdc6dbcdc1cdc6dc86cbc7c5\" rel=\"nofollow noopener\" target=\"_blank\">[email\u00a0protected]<\/a><\/strong><\/em>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Law firms spend enormous amounts of money protecting their networks. They use firewalls, endpoint detection, multifactor authentication, security monitoring, and email filtering. The list of technologies designed to keep attackers out keeps growing. And yet, sometimes an attacker doesn\u2019t need to defeat any of them. Recent reports of cyberattacks on some of the world\u2019s largest [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":162073,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-162072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-above_the_law"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/xira.com\/p\/wp-content\/uploads\/2026\/09\/cybersecurity-GettyImages-1016968886-470x470-FpGgt6.jpg?fit=470%2C470&ssl=1","_links":{"self":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/162072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/comments?post=162072"}],"version-history":[{"count":0,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/posts\/162072\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media\/162073"}],"wp:attachment":[{"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/media?parent=162072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/categories?post=162072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xira.com\/p\/wp-json\/wp\/v2\/tags?post=162072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}