Nobody wants to be reading this guide in the middle of an incident, which is why it is best read now. Ransomware at a law firm is both an IT emergency and a professional responsibility problem. The decisions made in the first day shape how much is lost, how quickly operations resume, and how defensible the firm's response will be. What follows is a general walkthrough, and it is no substitute for a rehearsed plan and qualified incident response help.
Recognize the signs
Typical indicators include files with strange extensions, a ransom note on screen or in folders, programs that will not open, servers that stop responding, or security tools suddenly disabled. Sometimes the first sign is a call from a client saying they received a suspicious message from your firm.
Hour 0 to 1: Contain
- Isolate affected machines. Disconnect them from the network by unplugging the cable or turning off Wi-Fi. Do not power them off if you can avoid it, since memory can hold forensic evidence, though follow your incident responder's guidance.
- Do not delete anything and do not try to clean up. Resist the urge to reboot repeatedly or run random tools.
- Alert your IT provider or response team immediately. Use a phone call. Assume email may be compromised.
- Disable suspected accounts. If a specific user account seems to be involved, your administrator can reset credentials and revoke sessions.
- Protect backups. Verify that immutable or offline copies are intact and disconnect any backup systems that are reachable from the infected network.
Hour 1 to 4: Assess and activate
Assemble the team
Name an incident lead. Typical roles include a decision-making partner, the technical lead, someone to document the timeline, and someone to handle communications. Keep the group small and use a communication channel that attackers cannot read, such as phones or a clean out-of-band messaging method.
Call the right outside parties
- Cyber-insurance carrier or broker. Many policies require prompt notice and may provide a panel of response firms. Calling before hiring your own vendor can protect coverage.
- Incident response firm. If you have one on retainer, activate it.
- Outside counsel experienced in breach response. They can advise on privilege and notification duties.
- Law enforcement. The FBI encourages victims to report ransomware, and reports can be made through IC3.
Start a log
Record what was seen, who was notified and what was done, with times. Preserve logs and screenshots. This record supports the investigation, insurance claim and any later questions.
Hour 4 to 12: Scope the problem
The central questions are what was encrypted, whether data was stolen, and how the attacker got in.
- Many groups steal data before encrypting, so assume exfiltration is possible until the investigation says otherwise.
- Determine which systems and which client matters are affected.
- Identify the entry point, such as phished credentials, an exposed remote service or an unpatched device, and close it before restoring. Otherwise the attacker returns.
- Reset credentials broadly, including administrator, service and VPN accounts.
Hour 12 to 24: Plan recovery and communicate
Recovery planning
Decide recovery order by business priority: email and calendar, document access, practice-management and billing. Restore from clean backups into a clean environment, not onto the compromised systems. Deciding whether to pay a ransom is a major business and legal decision to make with counsel, insurer and law enforcement. Payment does not guarantee data return and may carry legal risks, so do not treat it as a shortcut.
Client and ethics obligations
If client information may have been accessed, the firm may have duties to notify. Model Rule 1.4 addresses communication with clients, Rule 1.6(c) concerns reasonable efforts to protect information, and ABA Formal Opinion 483 discusses a lawyer's obligations after a data breach, including notifying affected current clients. State breach notification laws and bar opinions may add requirements, so involve counsel quickly. Courts and opposing counsel may also need to be informed about deadlines affected by the outage.
Staff communication
Tell staff plainly what is known, what to avoid, and how they will communicate. Instruct them not to speak to the press and to route inquiries to a designated person.
What to prepare in advance
- A written incident response plan with phone numbers, including outside-of-network copies
- Immutable backups and a tested recovery process
- A relationship with an incident response provider before you need one
- Your cyber-insurance policy and notice instructions on hand
- A tabletop exercise at least annually
After the first day
The incident continues for days or weeks. Document lessons learned, close the gaps and review whether monitoring would have caught it sooner.
Counsel Cyber offers incident response planning for law firms, tabletop exercises and 24/7 monitoring intended to catch attacks early. If you would like to rehearse this scenario with your partners, we can set up a session.