Get Comfortable Shoes

I recently bought a new pair of leisure shoes.

That may not sound like a big deal, but these are probably the most comfortable shoes I’ve owned in decades.

Believe it or not, I had been wearing the same brand of tennis shoes I wore in high school and college. They were getting harder to find, but I kept making the effort.

Why?

Because they were familiar.

My wife and daughters kept telling me, “Don, those shoes are out of style, and they can’t possibly be comfortable.”

Eventually, I tried on the shoes they recommended.

I couldn’t believe what I had been missing.

It felt like I was walking on air. I had become so accustomed to my old shoes that I didn’t realize how uncomfortable they actually were.

Naturally, I started thinking about how this relates to my work and my company.

How many things do we continue doing the same way simply because that is how we have always done them?

When I looked at my own typical workweek, I realized there were still a few things I was doing the same way I had done them 20 or 30 years ago.

Not because they were the best methods.

Just because.

Technology has made many parts of our lives easier, but we do not always take advantage of it. Sometimes we dismiss a new system by saying, “I’m good,” or, “I don’t have the time or interest to change.”

But think about how much has changed in the tools we use every day:

Many of these changes are designed to make our lives easier and, perhaps more importantly, make things easier for our clients.

One small change we made involved our post office routine.

Our mail is delivered to a P.O. box, and someone from the office used to make a trip there every day. Sometimes we had mail. Sometimes we didn’t.

On the days when the box was empty, we had wasted time and gas.

A friend told me about the Postal Service’s Informed Delivery program. Each morning, we can receive images of the mail expected to arrive that day.

No picture, no trip to the post office.

It was a very small change, but it saved us time, money and unnecessary effort.

Comfortable.

I suggest taking a little time to look at what you do, how you do it and what equipment or systems you use.

Are you still doing something the same way simply because it is familiar?

There may be a better, easier and more comfortable option available.

Get comfortable shoes.

You’ll love them.

I hope this helps.

I’m Don I, your insurance guy.

Cyber Risk for Law Firms: People, Vendors, and Insurance Coverage

In Part 1, we talked about Verizon’s 2026 Data Breach Investigations Report and why law firms should pay attention to vulnerability exploitation and ransomware.

Now let’s talk about two other issues that are especially important for law firms: the human element and third-party risk.

The human element continues to play a major role in data breaches. The 2026 Verizon report found that the human element was present in 62% of breaches. That does not mean employees are bad. It does not mean lawyers or staff members are careless. It means people are busy, and cybercriminals know how to take advantage of that.

Lawyers, paralegals, office managers, and administrative staff deal with emails, phone calls, text messages, invoices, attachments, wire instructions, document requests, calendar invitations, and client questions all day long. In that environment, one message that looks legitimate can create a serious problem.

And these attacks are not limited to the obvious phishing email with poor grammar and misspelled words. Verizon’s report points out that social engineering is moving beyond email. Attackers are using phone calls, text messages, mobile devices, fake IT support requests, fake vendor communications, and fake client messages. Verizon’s SMB-focused summary also notes that mobile-based phishing simulations had a 40% higher median success rate than email-based simulations.

For law firms, that should get your attention.

A fake wire instruction can lead to a financial loss. A fake password reset can give someone access to your systems. A fake document link can compromise a computer. A fake call from “IT support” can trick someone into sharing access. A fake email that appears to come from a client can start a chain of events that becomes much larger than one message.

So the question should not be, “Does this message look real?

The better question is, “Did we verify this through a trusted process?

That is an important distinction. Cybercriminals are trying to create urgency. They want someone to act quickly. They want someone to skip the normal process. That is why law firms need written procedures for payment changes, wire instructions, password resets, file access, and unusual client or vendor requests.

If new wire instructions are received, they should be verified through a known phone number already on file – not the number in the email. If someone requests access to sensitive information, there should be a clear approval process. If someone claims to be from IT support, staff should know how to confirm that request before giving access.

The second issue is third-party risk.

Most law firms rely on outside vendors. That is normal. But it also means your cyber risk is not limited to what happens inside your own office. Verizon’s 2026 report found that breaches involving third parties increased and now account for 48% of breaches.

Think about the vendors that may touch a law firm’s data or systems: IT providers, cloud software companies, case management platforms, document storage systems, billing software, phone providers, payment processors, marketing vendors, and other outside services.

If those vendors have access to your data, your systems, or your credentials, their security matters too.

That does not mean every law firm needs to conduct a full-scale security audit of every vendor. But firms should be asking basic questions before there is a problem.

Do they use multifactor authentication? Do they have written security procedures? Do they carry cyber insurance? What happens if they have a breach involving your data? Who has to notify whom? Who pays for what? How quickly will you know?

Those questions are much easier to ask before something goes wrong.

The same is true for your own cyber insurance coverage.

A law firm should know what its policy actually covers before there is a claim. Does the policy provide coverage for ransomware? Business interruption? Data restoration? Breach response costs? Social engineering fraud? Funds transfer fraud?

Are there sublimits? Are there exclusions? Are there conditions that must be satisfied before coverage applies?

And one of the most important questions is this: did the firm accurately answer the questions on the cyber insurance application?

If the application says the firm has multifactor authentication, but MFA is only being used in some places — or not at all — that can become a very serious issue after a claim. If the application says backups are being performed and tested, but no one has verified that, the firm may have a problem when coverage is needed most.

The lesson from the 2026 Verizon report is not that law firms should panic. It is that law firms should prepare.

Review your procedures. Review your vendors. Review your cyber insurance. Make sure your written practices match what is actually happening inside the firm.

Because when a cyber incident happens, the issue is not only whether your computers can be restored.

The issue is whether your firm can keep operating, protect your clients, meet your obligations, and recover financially.

And the worst time to find out you are not prepared is after the breach.

The 2026 Verizon Data Breach Report Is Out: Why Law Firms Should Pay Attention

Verizon recently released its 2026 Data Breach Investigations Report, and law firms should take note. 

Each year, the DBIR provides a useful look at what is actually happening in cyber incidents and confirmed data breaches. It is not based on speculation or scare tactics. It is based on real-world reported incidents.

For law firms, especially small and mid-sized firms, the report is another reminder that cybercriminals are not only targeting large corporations. They are looking for opportunity. If a system is exposed, software is unpatched, credentials are stolen, or remote access is poorly protected, that may be enough to create a serious problem.

The DBIR does not break out Pennsylvania law firms as their own category, but law firms generally fall within the broader professional services category. In that category, Verizon reported 3,578 incidents and 2,558 confirmed data breaches. The top breach patterns for professional services were system intrusion, social engineering, and basic web application attacks.

That should not surprise anyone. Law firms hold valuable information. Client files, settlement details, trust account information, tax records, employment records, business documents, family information, medical information, and other confidential materials may all be sitting inside a law firm’s systems. To a cybercriminal, that data can be valuable.

One of the most important findings in the 2026 report is the rise of vulnerability exploitation. According to Verizon’s SMB-focused summary, vulnerability exploitation as an initial access vector is now up to 31%, which is jump from the prior year. The same summary also notes that the median time to fully resolve a critical vulnerability is now 43 days.

In plain English, attackers are increasingly getting in through unpatched software, exposed systems, remote access tools, web applications, and other technology that has not been properly secured.

For a law firm, that matters. 

Most firms now rely heavily on technology to operate. Email, case management software, cloud storage, billing systems, document management platforms, remote access tools, outside IT providers, phone systems, and payment processors may all be part of the firm’s day-to-day operations. Every one of those systems creates some level of exposure if it is not patched, configured, monitored, and protected.

The second major issue is ransomware. 

The DBIR explains that ransomware was involved in 48% of breaches, while also cautioning that this statistic should not be read as the probability that any one organization will be hit. Instead, it means that among the detected and reported breaches in the DBIR dataset, 48% involved ransomware.

For a law firm, ransomware is not just an IT inconvenience. If systems are locked, the firm may not be able to access calendars, client files, email, billing records, or key documents. Attorneys may have trouble communicating with clients, meeting deadlines, sending invoices, or continuing normal operations.

If data was taken before the systems were encrypted, the issue becomes even more serious. The firm may also be dealing with client notification obligations, reputational harm, possible ethics concerns, and an insurance claim.

That is why cyber risk cannot be viewed only as an IT issue. For law firms, it is also a management issue, a risk management issue, and an insurance issue.

The key takeaway from the first part of this discussion is simple: law firms should not assume they are too small, too local, or too specialized to be targeted. Cybercriminals are looking for weak points. An unpatched system, stolen credential, exposed remote access tool, or poorly protected application may be enough to create a breach.

Now is a good time for law firms to review the basics with their IT provider. Are systems being patched? Is remote access protected? Are backups in place? Are critical applications monitored? Are vulnerabilities being addressed quickly? Are access points protected with multifactor authentication?

Law firms should also look at these issues through the insurance lens. If a breach or ransomware event happens, does the firm understand what its cyber policy may cover? Are there exclusions, sublimits, or security requirements that could affect coverage? Has the firm accurately represented its security controls on the insurance application?

The 2026 Verizon DBIR is not a reason for law firms to panic. It is a reason to prepare.

Cybercriminals are looking for opportunity. Law firms need to make sure their systems, procedures, vendors, and insurance coverage are ready before an incident happens.