Technology’s Effect on Advocacy
The Settings Nobody Changed: Protecting Your Firm and Data from Cyber Attacks By Mark Mina
A firm’s worst week rarely begins with anything that looks like a cyberattack. It begins with someone signing in. No alarm sounds, because as far as the system can tell, nothing strange happened. A user’s password worked, and a normal session opened. Everything that comes afterward happens behind a seemingly harmless login the platform had every reason to trust. Four things open the door to a cybersecurity attack: Reused passwords. When a vendor site gets hacked, that same password opens the firm’s email. A message that looks like an ordinary work email, such as an invoice or a potential new client. Software nobody updated, ignoring prompts to do so and notices of security risks the update would solve. A sign-in nobody noticed (often logging on from another country at odd hours). There is no singular attacker anywhere in that list. A firm builds every opening of those doors itself, slowly, and without meaning to. The threat that finally shows up does not create the opening. It simply walks through one that was already there. What can law firms do to prevent the attacks?
Moving to Microsoft 365 or Google Workspace or any hosted platform buys real protection. The platform takes the data centers, the servers, and the software, updating and maintaining them for users. Law firms, however, are still held accountable to three things: the data a firm puts in, the settings a firm chooses, and the accounts a firm assigns to users and staff. Most major platforms state this plainly in their documentation. From the perspective of a company preventing and shutting down cybersecurity attacks on law firms, most incidents stem from a user permission that was overly permissive that nobody revisited or updated, an account nobody closed, or a sharing setting nobody adjusted. All electronic devices and platforms come with default settings. Never adjusting those settings or misconfiguring them leaves your firm and data exposed. For example, let’s say you use Dropbox or Box.com to create a shared folder for a client to upload documents. Your staff does not adjust any settings and makes the link public to anyone who has it, with no expiration date on visibility. Material can sit in the open for years, and the first sign of trouble is the wrong person finding it. Most firms are still running on the original settings. Another default setting firms rely on deals with multi-factor authentication which commonly prompts only when the platform decides a login looks risky. This is not the same as asking every time. Without conditional access rules, multi-factor authentication
Mark Mina is Founder & CEO of EZ Tek Solutions and has built a thriving managed solutions company serving 50+ businesses across Southern California’s legal, nonprofit, and accounting sectors. He lives the daily reality of implementing AI, cybersecurity, and operational technology, often working with growing law firms.
mark@ezteksolutions.com
24
Consumer Attorneys of California
FORUM September/October 2026
Made with FlippingBook - Online catalogs