October is Cybersecurity Awareness Month, and this is part two of our five things every law firm should know to better protect its people, clients, finances, and data.
In our first article, we talked about phishing emails and why employees can no longer rely on obvious spelling mistakes or poor grammar to identify a suspicious message. But what happens when the request does not arrive by email at all?
What if it comes from a voice your employee recognizes?
Advances in artificial intelligence are making it increasingly possible to imitate voices and create convincing fake video. For law firms, that creates a new cybersecurity challenge: hearing or even seeing someone may no longer be absolute proof that the person is really who they claim to be.
Imagine This Happening at Your Law Firm
Your bookkeeper receives a phone call from one of the firm’s partners.
The voice sounds familiar. The partner seems rushed and says something like:
“I need you to send a wire right now. I’m walking into a meeting, so I can’t stay on the phone.”
The request sounds legitimate. The voice sounds right. There may not be anything obviously suspicious about the call.
Would your employee send the money?
The problem is that the person on the other end of the phone may not actually be the partner.
AI Is Changing How Firms Need to Think About Identity
AI technology can be used to create convincing imitations of a person’s voice. Similar technology can also generate or manipulate video.
That means one of the assumptions employees have traditionally relied on — “I know what this person sounds like” — may not provide enough protection for a high-risk transaction.
This is especially important for law firms because employees routinely work with sensitive information and high-value transactions.
High-Risk Requests May Include:
- Wire transfers or other financial transactions
- Passwords or account credentials
- Confidential client information
- Settlement funds
- Changes to payment instructions
- Requests to bypass established procedures
- Access to sensitive documents or systems
These requests deserve additional verification, regardless of how convincing the person making the request may sound.
Create One Simple Verification Rule
Law firms do not need complicated procedures for every phone call.
A good place to start is with one straightforward rule:
An unusual request gets verified — even when you recognize the person making it.
If an employee receives an unexpected request involving money, credentials, confidential information, or a change to normal procedures, they should verify it using a separate, trusted method.
For example, an employee could call the attorney or staff member back using a phone number already saved in the firm’s contacts rather than a number supplied during the questionable interaction.
They could also use a known internal communication channel to confirm the request.
For particularly sensitive transactions, some firms may consider establishing an agreed-upon verification word or another internal authentication procedure.
Verification Does Not Have to Slow Down Your Firm
The goal is not to make employees suspicious of every phone call or video conference.
Instead, teach them to recognize situations where an extra level of confirmation makes sense.
A routine conversation may not require additional verification. An unexpected request to immediately transfer thousands of dollars should.
Taking an extra thirty seconds to verify a high-risk request can be significantly easier than trying to recover money, investigate a security incident, notify affected parties, or determine what information was exposed after an employee acts on a fraudulent request.
Talk About Deepfakes Before Your Staff Encounters One
Cybersecurity procedures are most effective when employees already know what to do before something unusual happens.
During Cybersecurity Awareness Month, talk with your staff about how high-risk requests should be verified. Make sure employees understand that stopping to confirm a request is not an inconvenience — it is part of protecting the firm and its clients.
Employees should know exactly who to contact, which communication channels to use, and which types of requests require additional verification.
Because in the age of AI, “It sounded exactly like him” may no longer be enough.
A simple verification process gives your employees something much more reliable than instinct: a clear procedure they can follow when a request does not feel routine.
Next in Our Cybersecurity Awareness Month Series
Next, we’ll look at what happens when a criminal gets hold of something even more convincing: a real password.