ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Hypothetical Ransomware Timeline: The First 24 Hours at a Law Firm

Walk through a hypothetical ransomware incident at a mid-size law firm, hour by hour, to see what decisions matter and what preparation changes the outcome.

3 min readBy Counsel Cyber Team

Planning for a ransomware attack is easier when you can picture it. What follows is a hypothetical scenario, not a real firm or case, built to show the decisions a firm faces in the first day and where preparation makes a difference.

Consider a hypothetical 40-attorney firm with two offices. A paralegal clicked a link in a convincing email last week and entered her credentials on a fake sign-in page. The attacker, now holding her password, has quietly explored the network.

Hour 0: The discovery

At 6:50 a.m., an early-arriving attorney finds that documents on the shared drive have strange file extensions and a text file titled with instructions has appeared in every folder. Files will not open.

What matters now: The first person to notice should not try to fix anything. They should call the help desk or the designated incident contact immediately. A short, written list of whom to call, available on paper or a personal phone, is invaluable when email and shared drives are down.

Hour 1: Contain

The IT provider's priorities are to stop the spread:

  • Isolate affected computers from the network, usually by disconnecting network cables or disabling Wi-Fi, rather than powering them off, because memory can hold useful evidence
  • Disable compromised accounts and force password resets
  • Disconnect or protect backup systems before encryption reaches them
  • Block known malicious addresses at the firewall

Firms with endpoint detection and response and 24/7 monitoring often have the first steps automated or started by the monitoring team before anyone arrives.

Hour 2 to 4: Assess and escalate

Key questions emerge:

  1. Which systems are affected?
  2. Was data copied out before encryption? Many modern ransomware groups steal data first to threaten publication.
  3. Are backups intact and recent?

The firm should now activate its incident response plan. That typically means notifying the managing partner, engaging outside counsel experienced in breach response if the firm does not have one, and contacting the cyber insurance carrier. Many policies require notice promptly and may require use of a particular response firm, so read the policy in advance.

Hour 4 to 8: Decisions and communication

The partners face difficult choices:

  • Operations: Can attorneys work from paper, phones and unaffected cloud systems? Are any court deadlines due today that require a call to the clerk?
  • Clients: ABA Formal Opinion 483 discusses a lawyer's obligations to communicate with current clients about a breach under Model Rule 1.4 where confidential information may be affected. Firms should discuss specifics with ethics counsel and their state bar.
  • Law enforcement: The FBI encourages reporting ransomware incidents, and CISA offers resources. Reporting can be coordinated by counsel and the response team.
  • Ransom: Authorities generally discourage paying, since payment does not guarantee recovery or that stolen data will be deleted, and payments can raise legal issues. Decisions involving payment should involve counsel and the insurer.

Hour 8 to 24: Investigate and restore

Forensic investigators determine how the attacker got in, what they touched, and whether they still have access. Restoration should not begin until the entry point is closed, otherwise the attacker returns.

If backups are clean and tested, restoration begins with the most critical systems: email, document management, practice management and billing. A firm that has practiced restores knows roughly how long this will take. A firm that has not may discover that restoring several terabytes over a standard internet connection takes days.

What made the difference

In this hypothetical, three preparation steps would have changed the outcome:

  • MFA enforced everywhere, which could have blocked use of the stolen password
  • Immutable, tested backups, which turn a crisis into a recovery
  • A printed, rehearsed incident plan, which saves hours of confusion

Build your own timeline

Pull the incident plan from the drawer, or write one. Run a tabletop exercise: pick a scenario like this one, gather the partners, administrator and IT provider, and talk through who does what at each stage. Note where the answers are unclear.

Counsel Cyber's role

We help firms build and rehearse incident response plans and provide monitoring and response when something goes wrong. If you would like to run a tabletop exercise, we can facilitate one for your leadership team.