ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Endpoint Detection and Response: What Law Firms Actually Need

Antivirus is no longer enough. Understand EDR, MDR and what 24/7 monitoring means for a law firm, and how to evaluate providers without the jargon.

3 min readBy Counsel Cyber Team

Traditional antivirus compares files against a list of known bad software. That worked reasonably well when most malware was reused widely. Today, attackers often use tools that are already on your computers, stolen credentials and custom code that no signature list has seen. Endpoint detection and response, or EDR, was built for that world, and for law firms holding sensitive client data it has become a baseline expectation.

This post explains the terms and what to look for.

The Alphabet Soup

Antivirus (AV)

Blocks known malicious files and some suspicious behavior. Useful, but limited against newer techniques.

EDR

Software on each laptop, desktop and server that records activity, such as processes launched, files changed and network connections, and uses behavior analysis to detect suspicious patterns. It lets a responder see what happened and take action, such as isolating a device from the network.

MDR

Managed detection and response adds people. A security operations team monitors the EDR alerts around the clock, investigates, and responds or guides you through the response. For a firm without in-house security staff, this is usually the difference between having a tool and having protection.

XDR

Extended detection and response applies the same idea beyond endpoints, correlating signals from email, identity, cloud applications and network devices. Vendors define it differently, so ask what is actually covered.

Why Software Alone Is Not Enough

An EDR console can generate a stream of alerts. Someone has to read them at two in the morning on a Saturday, because attackers often strike on weekends and holidays when offices are empty. A firm of thirty people rarely has staff to do that. Monitoring by a team that is awake, trained and authorized to act is what shortens the time between intrusion and containment.

What to Ask a Provider

Coverage

  1. Which operating systems and devices are protected, including Macs, servers and mobile devices?
  2. Does coverage extend to cloud email and identity, such as Microsoft 365 sign-in activity?
  3. What about devices that leave the office?

Monitoring

  1. Is monitoring truly 24 hours a day, every day, by humans?
  2. Who investigates alerts, and what are their qualifications?
  3. How quickly will we be notified of a serious event, and how?

Response

  1. Can the provider isolate a compromised device on its own, or must it wait for approval?
  2. What actions are pre-authorized, and which require a phone call?
  3. Do you support forensic investigation, and is it included or billed separately?
  4. How do you coordinate with our cyber insurance carrier?

Reporting and transparency

  1. What reports do we receive, and how often?
  2. Can we see the alerts and actions taken on our behalf?
  3. How are false positives handled?

Contract

  • What does the service-level agreement promise?
  • What data is collected from our devices, and how is it protected? Remember that telemetry can include file names and user activity.
  • What happens if we terminate?

Law Firm Considerations

  • Confidentiality. The provider will see activity on machines that hold privileged material. Review contract terms, access controls and data handling under your vendor oversight process, consistent with Rule 5.3 concerns.
  • Deadlines. A good response plan minimizes disruption. Discuss in advance how and when a lawyer's laptop could be isolated during a hearing.
  • Insurance. Many cyber insurers ask about EDR and monitoring. Keep documentation of coverage and deployment percentage.

Rolling It Out

  1. Take inventory so every device is known.
  2. Deploy the agent to all endpoints, including servers and partners' devices, with no exceptions.
  3. Remove old antivirus products as the vendor recommends, to avoid conflicts.
  4. Tune policies in a pilot group before turning on blocking.
  5. Confirm that tamper protection prevents users, and attackers, from disabling the agent.
  6. Test detection and response with the provider.
  7. Review coverage monthly for new devices without the agent.

Realistic Expectations

No tool stops everything. EDR and MDR reduce the time an attacker can operate undetected and improve your ability to contain an incident. They work best alongside multi-factor authentication, patching, email security, backups and trained users.

Next Step

Counsel Cyber provides managed detection and response for law firms and can review your current endpoint protection to show where coverage may be thin. Reach out if you would like a plain-language assessment.