Extract from Michael C. Maschke, Sharon D. Nelson, and John W. Simek’s article “The Cybersecurity Control Money Can’t Buy”
Law firms spend enormous amounts of money protecting their networks. They use firewalls, endpoint detection, multifactor authentication, security monitoring, and email filtering. The list of technologies designed to keep attackers out keeps growing. And yet, sometimes an attacker doesn’t need to defeat any of them.
Recent reports of cyberattacks on some of the world’s largest law firms offer a sobering reminder of that reality. WilmerHale reportedly paid at least $18 million to the cyber extortion group Luna Moth after an attack, while Goodwin reportedly paid about $10 million. Weil reportedly paid between $18 million and $20 million after a separate incident. Combined, the ransom payments alone approach $50 million.
Those figures are staggering, but the ransom amounts aren’t the most important part of the story.