Direct Answer
Some of the biggest IT mistakes that can leave a law firm vulnerable to ransomware are relying on traditional antivirus alone, not using Multi-Factor Authentication (MFA), assuming backups will work without testing them, failing to keep computers and software updated, and not training employees to recognize cyberattacks.
Ransomware protection requires multiple layers of security because no single safeguard can stop every attack.
This article covers five common mistakes law firms should avoid.
Why This Matters
Ransomware can prevent attorneys and staff from accessing the computers, files, and systems they need to work.
Attackers may also steal information before encrypting it, creating additional concerns about confidential client information and regulatory obligations.
Law firms should therefore think about ransomware protection before an attack occurs.
The objective is not to depend on one security product. It is to reduce the opportunities an attacker has to gain access, spread through the firm's systems, and cause damage.
Editor's Insight
Ransomware does not need every cybersecurity safeguard to fail.
It needs an opening.
That opening might be a stolen password, a phishing email, an unpatched computer, or another security weakness.
The more layers of protection your firm has in place, the harder it becomes for one mistake or security failure to turn into a ransomware incident.
1. Relying on Traditional Antivirus Alone
Traditional antivirus remains useful, but ransomware and other modern cyberattacks do not always behave like traditional computer viruses.
Attackers may use legitimate software, stolen credentials, scripts, or other techniques that traditional antivirus may not recognize as a virus.
Endpoint Detection and Response (EDR) provides an additional layer of protection by monitoring activity on computers for suspicious behavior.
The Response in EDR is particularly important.
When malicious activity is detected, EDR can act immediately to stop or contain it while the technician is being notified.
As we explain in What Is Endpoint Detection and Response (EDR), and Why Do Law Firms Need It?, the question isn't whether you have antivirus. The question is whether you can detect and respond when an attack isn't a traditional virus.
2. Not Using Multi-Factor Authentication
A password can be stolen through phishing, reused from another compromised account, or obtained in other ways.
If a password is the only thing protecting an account, the person who steals it may be able to log in.
Multi-Factor Authentication adds another requirement before access is granted.
We saw this protect one client when an attorney entered her Microsoft 365 credentials into a phishing website. An attacker immediately attempted to log in from overseas.
MFA prevented the attacker from accessing the account, and the SIEM system (Security Information and Event Management) issued an alert so the password could be changed.
Without MFA, the stolen password could have been enough to gain access.
3. Assuming That Having Backups Means the Firm Can Recover
Having backups and being able to recover from backups are not the same thing.
Backups can fail, important information can be omitted, or a problem can go unnoticed until the firm needs to restore its data.
Ransomware can also make recovery more complicated if backup systems are not properly protected.
Law firms should test backups and periodically perform disaster recovery exercises to verify that systems and information can actually be restored.
As we explain in How Often Should Law Firms Test their Backups?, testing confirms that the firm's recovery plan works before it is needed during an actual emergency.
4. Failing to Keep Computers and Software Updated
Security updates often correct vulnerabilities that attackers can exploit.
When computers, operating systems, applications, firewalls, or other technology are not kept current, known security weaknesses may remain available to attackers.
This becomes especially important when software reaches the end of its supported life and the manufacturer stops providing security updates.
Keeping technology updated does not guarantee that ransomware cannot occur.
It closes known openings that attackers may otherwise be able to use.
5. Not Training Employees to Recognize Cyberattacks
Many cyberattacks begin with a person.
An employee may receive a phishing email, fraudulent login page, malicious attachment, or request designed to trick the employee into providing information or taking an unsafe action.
Technology provides important protection, but employees also need to recognize suspicious activity.
Cybersecurity awareness training should teach attorneys and staff how to recognize common threats, what actions to avoid, and how to report something suspicious.
As we explain in How Often Should Law Firms Conduct Cybersecurity Awareness Training?, training should be an ongoing part of the firm's cybersecurity program.
Two Questions We Hear
Can cybersecurity software guarantee that our law firm will never get ransomware?
No.
No cybersecurity product can guarantee that a ransomware attack will never succeed.
The objective is to use multiple safeguards to reduce the likelihood of an attack succeeding and limit the damage if something gets through.
That includes protecting accounts, computers, email, backups, and employees rather than relying on one security product.
If our law firm has backups, why do we need other ransomware protection?
Backups are an important part of recovering from ransomware, but recovery should not be the firm's first line of defense.
A ransomware attack can interrupt operations, consume significant time, and may involve stolen information in addition to encrypted files.
The better approach is to combine reliable backups with safeguards designed to prevent, detect, and contain an attack before recovery becomes necessary.
How Avenue M Helps
Avenue M Computers has provided IT and cybersecurity services to law firms in New York since 2010.
We help law firms implement multiple layers of ransomware protection, including:
- Endpoint Detection and Response
- Multi-Factor Authentication
- Backup management and testing
- Security updates and patching
- Cybersecurity awareness training
- Cybersecurity risk assessments
We also monitor and manage the firm's technology so that cybersecurity is an ongoing responsibility rather than something addressed only after a problem occurs.
Three Key Takeaways
- Do not rely on one cybersecurity product to protect your law firm from ransomware.
- MFA, EDR, tested backups, security updates, and employee training provide different layers of protection.
- The time to eliminate a weakness in your ransomware protection is before an attacker finds it.
Related Articles
- What Is Endpoint Detection and Response (EDR), and Why Do Law Firms Need It?
- Why Is Multi-Factor Authentication (MFA) Essential for Law Firms?
- How Often Should Law Firms Test Their Backups?
- How Often Should Law Firms Conduct Cybersecurity Awareness Training?
- What Happens During a Cybersecurity Risk Assessment?
- What Should Every Law Firm Include in an Incident Response Plan?
Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.


