When a firm is under attack, nobody wants to read a fifty-page binder. People need to know who is in charge, what to do first and whom to call. That is why a short plan, a page or two, that people have actually read is more useful than a long document that sits unopened.
Here is an outline you can adapt for a small or mid-size law firm. It is not legal advice, and your counsel and insurer should review the final version.
Why a plan matters now
The ABA's Formal Opinion 483 discusses a lawyer's obligations to monitor for, respond to and communicate about data breaches, and the Model Rules on competence and confidentiality point to the same expectation of reasonable preparedness. Insurance policies often require prompt notice and specific procedures. The hours after a discovery are usually the most confused, which is the best reason to decide things in advance.
Section 1: Purpose and what counts as an incident
Write two or three sentences defining an incident broadly: suspected unauthorized access to email or systems, ransomware or unusual encryption, lost or stolen devices, misdirected sensitive emails, suspected wire fraud and compromised credentials. Say that anyone who suspects an incident must report it immediately and will not be blamed for reporting in good faith.
Section 2: Roles
Assign names and backups, not just titles.
- Incident lead: typically the managing partner or a designated partner. Makes final decisions.
- Technical lead: your IT or security provider contact.
- Communications lead: handles client and staff messages.
- Administrator or scribe: records every action and time.
- Legal advisor: the firm's outside counsel or general counsel with breach experience.
Section 3: Contact list
List phone numbers, not just email addresses, because email may be down or compromised.
- Incident lead and backups.
- IT provider and their emergency line.
- Cyber insurer's claims hotline and policy number.
- Breach counsel and forensic firm, noting any insurer-approved panel requirements.
- Bank contacts for wire recalls.
- Key vendors such as practice management and document management support.
- Local FBI field office or the FBI's IC3 reporting site for fraud.
Keep printed and offline copies in more than one place.
Section 4: First hour checklist
- Report and record. Note the time of discovery and who found it.
- Contain. Disconnect affected devices from the network, for example by unplugging the cable or turning off Wi-Fi, but do not power them off or wipe them unless advised, since evidence may be lost.
- Call the technical lead and the insurer's hotline.
- Secure accounts. From a known-clean device, reset credentials for affected accounts and review MFA settings and mailbox rules.
- Stop the money. If wire fraud is suspected, call the bank immediately to request a recall and then report to law enforcement.
- Preserve evidence. Keep emails, logs and screenshots. Do not delete anything.
- Limit internal discussion to approved channels. Do not communicate about the incident over a possibly compromised email account.
Section 5: Assess and decide
Within the first day or two, work with your technical lead and counsel to answer:
- What systems and accounts were affected?
- Was client or personal information accessed or taken?
- Is the attacker still present?
- Which matters or clients are involved?
Section 6: Notification decision points
Notification can involve several layers, and counsel should guide each one:
- Clients. Consider communication duties under Rule 1.4 and contractual commitments to clients.
- Insurer. Follow the policy's notice requirements.
- Regulators and individuals. State breach notification laws may apply, and they differ among Texas, Arkansas, Louisiana, Oklahoma and Kansas.
- Law enforcement. Consider reporting to the FBI.
- Others. Banks, courts or opposing counsel in specific situations.
Section 7: Recovery
Restore from known-good backups, rebuild compromised systems when needed and reset all potentially exposed credentials. Prioritize systems based on your recovery objectives. Maintain heightened monitoring after restoration, because attackers sometimes return.
Section 8: After-action review
Within two weeks, meet to document what happened, what worked, what failed and what will change. Update the plan, controls and training. Share lessons with staff in a plain, non-punitive way.
Test it
Run a ninety-minute tabletop exercise each year. Present a realistic scenario, such as a partner's mailbox forwarding messages to an unknown address, and walk through the plan. Time how long it takes to find the contact list. Every gap you discover in a drill is one you will not meet during a real crisis.
Keep it alive
Review contacts quarterly, because people and phone numbers change. Make sure new hires know how to report incidents.
Counsel Cyber helps law firms draft concise response plans, arrange access to forensic and legal partners and facilitate tabletop exercises. If you do not yet have a plan, we can help produce a first version in a single working session.