ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ransomware at a Law Firm: A Hypothetical Hour-by-Hour Walkthrough

A hypothetical ransomware incident at a small firm, hour by hour, showing what to do, who to call and which decisions to make before attackers force them.

3 min readBy Counsel Cyber Team

Reading about ransomware in the abstract rarely changes behavior. Walking through one scenario, step by step, often does. What follows is a hypothetical incident at an imaginary 15-attorney firm. It is not a real case, and the details are invented to illustrate decisions you may face.

Hour 0: The First Sign

At 7:40 on a Monday morning, a paralegal cannot open a document. Then another. A text file named something like "READ ME" appears in a shared folder, and file names show an unfamiliar extension. The instinct is to restart the computer and see if it fixes itself.

That instinct is wrong. Restarting can destroy evidence and does nothing to stop encryption on other machines.

What to do immediately

  1. Disconnect the affected computer from the network by unplugging the cable or turning off Wi-Fi. Do not power it off unless told to by your IT provider.
  2. Tell the firm administrator and your IT provider by phone, not by email, since email may be compromised.
  3. Ask other staff to stop working and not open files until further notice.

Hour 1: Containment

The IT provider or incident responder works to find out how far the problem has spread. Typical actions include isolating servers, disabling affected accounts, and checking whether backups are intact and offline.

At the same time, the firm should gather its incident contact sheet. This is where preparation pays off.

  • Cyber-insurance hotline and policy number
  • Outside counsel experienced in breach response
  • IT provider emergency line
  • Managing partner and designated decision-makers

Many cyber-insurance policies require notice before you hire responders or negotiate with anyone. Reading the policy now, rather than in a panic, matters. Confirm the specifics with your broker.

Hours 2 to 4: Understanding Scope

Responders try to answer three questions.

  1. How did the attacker get in? Common routes include stolen credentials, phishing and unpatched remote-access systems.
  2. What did they reach? Was data only encrypted, or was it copied as well?
  3. Are they still in the network?

The second question drives legal obligations. Many ransomware groups copy data before encrypting it. If client information left the building, the firm may have notification duties.

Hours 4 to 24: Decisions and Communication

Client confidentiality and notice

ABA Model Rule 1.4 concerns communication with clients, and ABA Formal Opinion 483 discusses lawyers' obligations after a data breach, including the duty to monitor for breaches, stop and mitigate them, and notify affected current clients when confidential information is involved. State breach-notification laws and client contracts may add deadlines. Counsel should guide these decisions, and your state bar is the right place to confirm specifics.

Law enforcement

Reporting to the FBI, for example through IC3, is commonly recommended. Your breach counsel can advise on timing.

Operating without systems

A firm that cannot open its case files still has court deadlines. Practical steps:

  • Pull paper calendars and docket sheets, if any exist.
  • Use clean, newly issued devices or cloud-based tools that were not affected.
  • Call courts and opposing counsel when deadlines are at risk, since extensions are often available for genuine emergencies.

The Ransom Question

Whether to pay is a business and legal decision with no guarantee either way. Payment does not ensure that data is restored or that stolen data is deleted, and there may be legal restrictions depending on who the attacker is. This is another reason to involve experienced counsel and your insurer early, and another reason to have reliable backups so the question is less urgent.

Days 2 to 7: Recovery

  • Restore from clean backups, after confirming the attacker is out.
  • Reset passwords firm-wide, especially administrator accounts.
  • Enforce multi-factor authentication everywhere before systems reconnect.
  • Rebuild affected machines rather than trusting them.
  • Document everything for insurers, clients and any regulators.

What Would Have Changed the Outcome?

In this hypothetical, several things could have helped: MFA on remote access, prompt patching, endpoint detection that flagged unusual encryption activity, an isolated backup, and a rehearsed plan. None is exotic. All are things a managed provider can help put in place.

Rehearse Before You Need It

Spend an hour with your partners walking through this scenario using your real contacts and your real systems. The gaps you find in an hour will be cheaper than the ones you find on a Monday morning.

Counsel Cyber helps law firms prepare incident response plans and run tabletop exercises. If you would like to rehearse before it matters, we can help you set one up.