Skip to main content

The Corner View

October, 2024

What’s Inside

In this edition, Jim Moreo shares a comprehensive guide to help you make smart IT decisions for the upcoming budget season, while Patrick Boyd highlights essential cybersecurity steps to protect your data and maintain your firm’s reputation.

— Marriane

Future-Proofing Your Law Firm: Key IT Investments for 2025

As a law firm CIO or COO, planning your 2025 information technology budget involves anticipating future needs, addressing current challenges, and leveraging technology to enhance attorney productivity and security. Firms will need to continue to invest in their cloud migration and hybrid-work plans, but here are some other critical areas to focus on:

Cybersecurity Improvements

With the increasing frequency and sophistication of cyberattacks, investing in the right cybersecurity products and providers is paramount. Good cybersecurity products and providers should include:

Real-time vulnerability scanning

– It is no longer enough to scan your network once a month. Your cybersecurity provider should be scanning your internal network 24/7 and your external network weekly.

Extended Detection and Response (XDR)

– Monitoring network traffic moving in and out and across your network as well as an Endpoint Detection and Response (EDR) product that your security provider manages (MDR).

Security Information and Event Management (SIEM)

– Aggregating and analyzing security logs not just from the obvious firewalls and Windows systems, but also security logs from business systems like your Document Management System (DMS).

Security Posture Review

– A good cybersecurity provider will meet with you regularly to review the security posture of your network’s different components.


Incident Response Contract and Incident Warranty

A reliable cybersecurity provider will offer an on-call SLA contract for incident response in case of a breach. Additionally, they will provide a warranty to cover some of the breach-related costs. Note that incident response contracts are increasingly becoming a requirement for cybersecurity insurance policies.

Important Note: Your Managed Services Provider (MSP) should NOT be your cybersecurity provider. The team responsible for patching and remediating your vulnerabilities should be different from the team that identifies them. This is like an accounting department, where the person who writes a check should not be the same person who signs it. Your MSP and cybersecurity provider should be different people.


Artificial Intelligence and Automation

It will be interesting to see how AI and automation enhance productivity and reduce operational costs in 2025.

According to the “2024 ILTA Technology Survey”, most firms are currently in the “investigating” phase of using AI tools. The top three anticipated uses of generative AI tools in the next 12 months are research, summarizing complex documents, and creating initial drafts of documents. Note: This article was started with an initial Copilot query.

Not surprisingly, Copilot for Office 365 and ChatGPT are the most frequently used AI tools today, with leading legal research and document management system (DMS) vendors making significant AI advancements. Firms should examine their current core business applications to identify new AI capabilities being integrated. For example, the leading DMSs are now adding AI features to generate documents based on the firm’s existing document store and to automatically file and categorize large volumes of unstructured documents and emails.


Security Compliance (ISO & NIST)

More law firms are being asked to demonstrate they follow security regulations and standards like ISO 27001 and NIST CSF. The process of getting these certifications can take 9 to 18 months, so the sooner you get started, the better.

  • The “2024 ILTA Technology Survey” shows that more than 50% of law firms are audited against or certified for security standards or frameworks.
  • 29% follow ISO 27001 certification, up from 26% in 2023
  • 20% follow NIST CSF compliance, up from 14% in 2023

This trend will continue across the range of small to large firms. While these standards can take some time to implement, they help IT departments implement security policies, best practices, and respond more efficiently to client security audits, and cyber insurance applications.

There are good resources and interactive tools available to help firms identify and assess their current gaps in preparation for ISO certification or NIST compliance.

Note: Law firms should ask their IT service providers to demonstrate they are ISO certified or NIST compliant.


Managed IT Services

Most law firms lack the IT staff to monitor their computer systems around the clock and do not have experts for all the technologies they use. A Managed Services Provider (MSP) specializing in the legal industry and committed to cybersecurity (ISO 27001 compliant) can help a law firm keep its IT systems up to date and running smoothly 24/7.

Look for an MSP that provides:

  • A Service Desk (Help Desk) with legal experience that offers 24/7 live phone support, access to a comprehensive FAQ knowledgebase, and a ticketing system with monthly reporting and recommendations.
  • Managed Desktop Services with Intune experience to help your IT staff stay on top of application updates and security patches for the firm’s laptops, desktops, and Virtual Desktop Infrastructure (Citrix, AVD, W365).
  • 24/7 monitoring of critical systems including on-premises network infrastructure, connectivity to cloud services, and ability to remediate issues after hours.
  • Cybersecurity Patching and Remediation: Your MSP should be capable of performing after-hours security patching and be on-call to support your staff during a cybersecurity incident. Additionally, your MSP should collaborate closely with your cybersecurity provider.
  • On-site Support as needed: Your MSP should be able to provide “remote hands” in your regional offices.
  • Subscription Management: Helps manage and reduce the cost of support renewals and subscriptions like Microsoft Azure and M365 licenses as well as prepare annual budget estimates.
  • Quarterly Strategic Planning: Your MSP should meet with the CIO or COO quarterly to review the status of the previous quarter’s goals and prepare for next quarter and next year’s goals.

Conclusion

By strategically allocating your 2025 IT budget across these key areas, you can enhance your law firm’s operational efficiency, security, and client service. Stay proactive in adopting new technologies and addressing emerging challenges to maintain a competitive edge in the legal industry.

Feel free to reach out if you need detailed insights or specific recommendations for your firm’s IT strategy!

MSP Matters

Cybersecurity Basics: How to Safeguard Your Firm in an Evolving Digital Landscape

The digital world is constantly evolving and some parts of it are scary.  What can a firm or company do to protect itself when it seems like the barbarians are constantly at the proverbial gate?

The digital world is constantly evolving and some parts of it are scary.  What can a firm or company do to protect itself when it seems like the barbarians are constantly at the proverbial gate?

There are actually several basic steps you can do to protect your data and the data of your clients, not to mention your well-earned reputation.

Passwords: First, make sure you have strong passwords in use.  You hear this mantra a lot, but it’s worth repeating.  Use strong and complex passwords with a mix of the four elements (upper case, lower case, numbers, and symbols) with minimum lengths.  We recommend 12 characters or more as a minimum.

MFA: Multi-factor authentication has become a global standard.  It combines something you know (your password) with something you have (your phone) to provide a barrier to would-be criminals.  It only adds a few seconds to your login/access process but provides a big wall of security.

Patching: Computers (and phones) are not appliances as much as we think of them that way.  They need updates.  Software was written by humans and humans make mistakes.  Routine patching helps make sure your systems are current and protected.  Think of it like a well-maintained vehicle:  It’s going to run better and handle challenges better if it’s in good working order.

Malicious links and attachments: Bad actors will try to get it.  It’s a fact. Consider a Security Information and Event Management (SIEM) tool ideally backed by a team of professionals who can actively monitor risks and in real-time, respond to risks.

Cornerstone.IT has been providing guidance and solutions to these issues and more for 20+ years.  We routinely maintain our clients’ systems, help implement security solutions and give our expert advice to law firms across the country, based on our collective experience.

Cybersecurity Awareness Month

The Current State of Global Cyber-Insecurity In 2024

During this year’s Cybersecurity Awareness Month, we will explore the current landscape of online security threats, examine how individuals can safeguard themselves from potential breaches, and discuss strategies for organizations to empower their employees in defending against cyber-attacks.

Over 80% of data breaches were attributed to phishing attacks, which deceive individuals into disclosing sensitive information such as passwords and credit card numbers. Additionally, nearly 30% of all cyberattacks targeted mobile devices, a concerning trend given the increasing reliance on smartphones for sensitive transactions.

But first, let’s break down what we mean by “cyber-insecure.”

Cyber Insecurity

Cyber insecurity is identified as a major global risk, threatening supply chains, financial stability, and democracy. As with most systems, it is made up of components that involve both machines and humans actively participating in its process.

The Human component: Cyber Skills Shortage

Below are some of the factors that weigh into the lack of skills-acquisition required in protecting their internet-connected infrastructure.

  1. Widening gap; half of smallest organizations lack necessary skills.
  2. Only 15% expect significant improvement in cyber skills education.
  3. Half of the smallest organizations by revenue say they either do not have or are unsure as to whether they have the skills they need to meet their cyber objectives.
  4. Only 15% of all organizations are optimistic that cyber skills and education will significantly improve in the next two years

52% of public organizations state that a lack of resources and skills is their biggest challenge when designing for cyber resilience.

In summary, the cyber skills shortage is a pressing issue that demands immediate action. Without significant improvements in education and resources, our defenses against cyber threats will remain vulnerable. It’s imperative that we act now to bridge this gap and secure our digital infrastructure.