Verizon recently released its 2026 Data Breach Investigations Report, and law firms should take note.
Each year, the DBIR provides a useful look at what is actually happening in cyber incidents and confirmed data breaches. It is not based on speculation or scare tactics. It is based on real-world reported incidents.
For law firms, especially small and mid-sized firms, the report is another reminder that cybercriminals are not only targeting large corporations. They are looking for opportunity. If a system is exposed, software is unpatched, credentials are stolen, or remote access is poorly protected, that may be enough to create a serious problem.
The DBIR does not break out Pennsylvania law firms as their own category, but law firms generally fall within the broader professional services category. In that category, Verizon reported 3,578 incidents and 2,558 confirmed data breaches. The top breach patterns for professional services were system intrusion, social engineering, and basic web application attacks.
That should not surprise anyone. Law firms hold valuable information. Client files, settlement details, trust account information, tax records, employment records, business documents, family information, medical information, and other confidential materials may all be sitting inside a law firm’s systems. To a cybercriminal, that data can be valuable.
One of the most important findings in the 2026 report is the rise of vulnerability exploitation. According to Verizon’s SMB-focused summary, vulnerability exploitation as an initial access vector is now up to 31%, which is jump from the prior year. The same summary also notes that the median time to fully resolve a critical vulnerability is now 43 days.
In plain English, attackers are increasingly getting in through unpatched software, exposed systems, remote access tools, web applications, and other technology that has not been properly secured.
For a law firm, that matters.
Most firms now rely heavily on technology to operate. Email, case management software, cloud storage, billing systems, document management platforms, remote access tools, outside IT providers, phone systems, and payment processors may all be part of the firm’s day-to-day operations. Every one of those systems creates some level of exposure if it is not patched, configured, monitored, and protected.
The second major issue is ransomware.
The DBIR explains that ransomware was involved in 48% of breaches, while also cautioning that this statistic should not be read as the probability that any one organization will be hit. Instead, it means that among the detected and reported breaches in the DBIR dataset, 48% involved ransomware.
For a law firm, ransomware is not just an IT inconvenience. If systems are locked, the firm may not be able to access calendars, client files, email, billing records, or key documents. Attorneys may have trouble communicating with clients, meeting deadlines, sending invoices, or continuing normal operations.
If data was taken before the systems were encrypted, the issue becomes even more serious. The firm may also be dealing with client notification obligations, reputational harm, possible ethics concerns, and an insurance claim.
That is why cyber risk cannot be viewed only as an IT issue. For law firms, it is also a management issue, a risk management issue, and an insurance issue.
The key takeaway from the first part of this discussion is simple: law firms should not assume they are too small, too local, or too specialized to be targeted. Cybercriminals are looking for weak points. An unpatched system, stolen credential, exposed remote access tool, or poorly protected application may be enough to create a breach.
Now is a good time for law firms to review the basics with their IT provider. Are systems being patched? Is remote access protected? Are backups in place? Are critical applications monitored? Are vulnerabilities being addressed quickly? Are access points protected with multifactor authentication?
Law firms should also look at these issues through the insurance lens. If a breach or ransomware event happens, does the firm understand what its cyber policy may cover? Are there exclusions, sublimits, or security requirements that could affect coverage? Has the firm accurately represented its security controls on the insurance application?
The 2026 Verizon DBIR is not a reason for law firms to panic. It is a reason to prepare.
Cybercriminals are looking for opportunity. Law firms need to make sure their systems, procedures, vendors, and insurance coverage are ready before an incident happens.