ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ransomware at a Law Firm: What to Do in the First Hour

If ransomware hits your firm, the first hour shapes what follows. Here is a calm, step-by-step response guide for managing partners and administrators.

3 min readBy Counsel Cyber Team

It usually starts small. A paralegal cannot open a file. A shared drive shows strange filenames. A note appears on a screen demanding payment. In the first hour after discovery, the decisions you make affect how much data is lost, how long the firm is down and how well you can demonstrate responsible handling later.

This guide outlines what to do first. It is best read before an incident, when you can adapt it to your own environment and print a copy.

Minute Zero: Recognize the Signs

Common indicators include files that suddenly will not open or carry unfamiliar extensions, ransom notes on screens or in folders, systems running unusually slowly, security alerts, and users locked out of accounts. Treat any of these seriously. It is better to raise a false alarm than to wait.

Step 1: Contain, Do Not Destroy

The goal is to stop the spread while preserving evidence.

  • Disconnect affected devices from the network. Unplug network cables and turn off Wi-Fi.
  • Do not power machines off unless instructed. Shutting down can erase information in memory that investigators find useful, though CISA guidance does note that isolating is the priority if you cannot do anything else quickly.
  • Do not wipe or reinstall anything yet. That destroys evidence and may complicate recovery and insurance claims.
  • Isolate backups. Confirm backup systems are disconnected from the affected network so they are not encrypted too.

Step 2: Call the Right People, in the Right Order

  1. Your IT or security provider, who can begin technical containment.
  2. Your cyber-insurance carrier's incident hotline, since many policies require prompt notice and pre-approved vendors.
  3. Breach counsel, often provided or recommended through the policy.
  4. Firm leadership, so decisions have an owner.

Keep a one-page contact list somewhere that does not depend on your own network, such as a printout or personal phone.

Step 3: Establish Out-of-Band Communication

Assume your email and chat may be compromised. Use personal phones or a separate channel to coordinate. Do not discuss details over systems an attacker may be watching.

Step 4: Start a Log

Assign one person to record what happened and when: who noticed what, which systems are affected, who was called, every action taken. This record helps investigators, insurers and later reviews.

Step 5: Do Not Pay or Negotiate Yet

Payment decisions involve legal, insurance and law-enforcement considerations. Government guidance, including from CISA and the FBI, generally discourages paying ransoms, since payment does not guarantee recovery and may encourage further attacks. Any decision should be made with counsel and your carrier, not in a panic.

Step 6: Think About Client Data and Duties

Within the first day, counsel will need to evaluate whether client information was accessed or taken. Many ransomware groups steal data before encrypting. ABA Formal Opinion 483 discusses lawyers' obligations after a data breach, including monitoring for breaches, taking steps to stop and mitigate, and communicating with affected clients, which connects to Model Rule 1.4. State breach-notification laws and client contract terms may add requirements and deadlines. Confirm with counsel familiar with your jurisdiction.

Step 7: Preserve Evidence and Report

Preserve logs and affected devices. Reporting to law enforcement, such as through the FBI or its IC3 portal, is often recommended and may be required by insurance or client agreements.

What Not to Do

  • Do not delete the ransom note or files.
  • Do not restore from backups before confirming the attacker is out, or you may be re-infected.
  • Do not assume the problem is limited to the first machine.
  • Do not delay notifying your carrier while you "see how it goes."

Prepare Now

A response plan does not have to be elaborate. A good one-page plan lists contacts, the first containment steps, decision-makers and where your backups are. Practice it in a short tabletop exercise once a year.

How Counsel Cyber Helps

Counsel Cyber provides monitoring and incident response support for law firms and helps build the plan before it is needed. If you do not have a written one-page response plan, we would be glad to help you draft it.