Adam has been in the IT industry in since 2003, specializing in Managed Services for multiple clients...
Adriana Linares is a legal technology consultant with her company, LawTech Partners. For 25 years, Adriana has...
| Published: | November 27, 2025 |
| Podcast: | New Solo |
| Category: | Legal Technology , Practice Management , Solo & Small Practices |
Security, security, security. In your law firm’s tech package, there is probably no more important word than security. Your clients depend on it. Your business depends on it.
You and your firm can get hacked. It happens. Bad people want to get into your firm. They can dig through your email. They can get into your Microsoft 365 One Drive or Google accounts. Guest Adam Alexander, president of the Orlando-based IT firm Internetwork IT, explains two recent breaches, how they happened and how much damage hackers can do.
Once inside, hackers can hold your business – and your reputation – for ransom. The scary part? While evil doers are worming through your data, you may not even know it.
In this important episode, even if you think you know all about security, take a moment to get your head around the latest threats and safeguards. What’s an admin account? What’s two-factor authentication? Who holds the key to your kingdom? If you haven’t thought about this for a while, today’s the day.
Questions or ideas about solo and small practices? Drop us a line at [email protected],
Topics:
Special thanks to our sponsors Wyzer Staffing, ALPS Insurance, 8am, CallRail, and LEX Reception.
Previous appearance on New Solo, “AI And The Evolving Security Threats (And Protections)”
Previous appearance on New Solo, “The Microsoft 365 Special: Your Questions, Expert Answers”
Microsoft Defender Threat Intelligence
“Set up multifactor authentication for Microsoft 365”
American Bar Association, “Insurance Strategies to Mitigate AI and Cyber Risks”
Announcer:
So if I was starting today as a New Solo, I would entrepreneurial aspect, change The way they’re practicing Leader, What it means to be, make it easy to work with your clients, New approach, new tools, new mindset, New Solo. And it’s making that leap. Making that
Adriana Linares:
Welcome to another episode of New Solo on Legal Talk Network. Today we are talking security, security, security. I received an email from a dear friend, a colleague and a past guest on New Solo named Adam Alexander that really opened up my eyes. So I asked him to come back and give us a security update and revisit some important security things that we should be doing to protect our internal firm data and our client data. So welcome back Adam Alexander.
Adam Alexander:
Glad to be back. As always, it’s always fun to be here with you. Definitely looking forward to it and kind of getting some security things to help new solos and also just law firms in general.
Adriana Linares:
Yeah, I know that a lot of my listeners, our listeners are far from being new solos. They just appreciate the content. So we’re going to hopefully scare the bejesus out of everybody into making sure they’ve got their security right, because you sent me this email and this is what opened up my eyes. I thought, oh, time for a security reminder. You said, this is the email I sent to our clients after a couple of them got hacked, which of course nobody wants to hear about. You have a section of the email that says what happened during the compromise and it’s a step-by-step. You spaced out what happened and it says the hacker was in the account for more than a week. That is really terrifying to think about someone sitting watching emails from a law firm’s inbox or an attorney’s inbox for a week. What happened?
Adam Alexander:
So one thing that people I think don’t consider or realize that happens is this is also concerning where someone is literally logged into your email account and not just intercepting a couple of emails or anything like that. So what happens is they log into your email account, they have full access to everything. If you are using OneDrive email, anything in your 365 account or Google account, if you’re using that, they’re going to sit there and download everything that they can get their hands on. And this is concerning the email portion. So we’re talking your emails, email history, and these two parts are important, your signatures and your contacts. I will always got the assumption that they’ve downloaded this information. And the reason why this is important is because even if you change your password, even if you redo your two FA, all of that, they have a copy.
Now, what they can do with that from this point on is send emails with your signatures to your contacts, to whoever they want, looking like it’s coming from you, asking for money, asking for information from your clients. So that’s really important. And what happened in both of these cases is that they take time to download and search through your emails and get what they need. And then a week or two later they sent an email saying, Hey, we’ve been in your email for about a week now and we have all of your information. And so that’s how really they found out what was happening. And I do want to preface this with one client did not have two factor authentication set up and one client did have two-factor authentication set up, and that one was interesting. He knew right when it happened, when they got this notification email from the hacker, he immediately was like, that happened when I was going on my trip to Ireland because my phone freaked out.
I couldn’t log in, I couldn’t use my face id, my fingerprint, I was locked out of my phone. And what’s important with that is that’s how they get around two factor authentication. So now they have access to his phone, which sends a two-factor authentication code, and then they log in. So I just want to make that point too, that two-factor authentication is also not foolproof at this point. Let’s say 95, 90 8% foolproof, they have to get access to your two-factor authentication methods one way or another to get around it. But so that’s something to consider. It’s not just someone logs into your account and right away they have all of your email contacts, signature OneDrive files, everything at that point. And you can’t take that back. You can’t take that back from their computer once they have it. Right? So
Adriana Linares:
Let’s unpack this just a little bit because let’s just make it clear if your Microsoft 365 account and the one that you get your email through is also if you are using OneDrive, you’re using Outlook, you’ve got your calendar on there, you’ve got your contacts in there, maybe your contacts from Outlook and your calendar are syncing to your case management system. So any information that you’ve got on your case management system calendar and contacts is coming over to Outlook. And you did say, well, let’s say you don’t use Microsoft 365 or you’re not a Microsoft subscriber but you’re a Google subscriber. It’s the same if you get compromised like this and they can get to your email and figure out your password. They’re also going to have access at that point to all of your Gmail information. Okay? So just getting into your email is a problem because that is the account that you therefore also use to log into things like your bank, your case management system, everything.
So once they can see what you’re doing, when you reset your password or they are going to send an email that says, reset my password from the bank, maybe they do it at two o’clock in the morning, they’re in your inbox, you’re asleep, the email comes in, they get the code, but then they delete it and they purge it from the trash. You don’t know what happened. I think what I want to talk about is remind people that you’re like, how can this happen? How are they in my inbox? Well, just like you can sit at your computer at your desk and look at your inbox, but you can also be on an airplane on the way to Ireland using wifi, logged into your laptop and looking at your email. And you can land in Ireland, turn on your local connection for broadband there and look at your emails on your phone is the way that a third party, a bad actor can also be looking at your email.
Adam Alexander:
I do remember mentioning this, we talked a little bit about this in the last podcast. This is where VPNs are so important and that scenario, logging into a public wifi, especially in an airport or a hotel, that’s easy for someone to get access to your computer.
Adriana Linares:
There’s so many ways. So what happened to this client is somehow these bad actors got ahold of their user ID and password. One of them did not have two-factor authentication, shame on them and the other one did. So how did it happen as far as, and you might not have the perfect answer, but give us a broad scenario of how having two-factor authentication can still lead to how it’s still risky. And then how do we prevent that?
Adam Alexander:
Let me make one bullet point here too. Especially if you’re a smaller firm and you’re the attorney. So you’ve created the account. If you have admin access to your account, now they can do whatever they want. If they get in there, they could lock you out of your entire account.
Adriana Linares:
Okay,
Wait, we have to talk about that because that’s confusing. Because it’s confusing, but it makes sense. And in case you haven’t listened to a past episode with Adam Alexander, he’s my favorite IT guy. And when he sets up your Microsoft 365 account, what he means is if you’re a solo someone, you has to have administrative access to the Microsoft 365 account that does things like reset a user’s password, pretend you have one assistant, reset adds a new user, resets a password if somebody needs it, changes security settings on the account deals with billing and subscriptions, right? So the admin account for your Microsoft 365 account can be you if you are a true solo, but it shouldn’t and this is why, right, Adam? So I think this can be confusing. So when I’m a New Solo and I call you up, I’m like, Hey, I’m starting my law firm. I want to have Microsoft 365, here’s my user ID and password, Adam, what do you do next to help me set up that account correctly? And the most securely,
Adam Alexander:
The ideal way to do it is you have all of your email accounts set up the way you want them, but you have an unlicensed user that has full admin privileges. So the unlicensed user can’t get a phishing attack or anything like that.
Adriana Linares:
But what do you mean by an unlicensed user? What is that? They don’t have Outlook, they don’t have Word am I not paying for them? Because that makes a big difference for a lot of firms. I hear you saying, oh my god, it’s going to cost me another $25 a month to have this admin account. It’s probably worth it. But is that what you mean?
Adam Alexander:
That’s correct. It’ll actually be a user that has no license, no fees, it’s just a username and a password and nothing else. The important thing with that is there’s no email, so there’s no access for someone to send a phishing email to it to gain access to the account. It’s literally a username and password and nothing else free because there’s no license to it. But also they would have to actually know that username and password to have access to it. They can’t really hack into it with a fake email or hack into it any other way.
Adriana Linares:
And is this something that Microsoft provides to business users as a security measure?
Adam Alexander:
Yes, that is correct. So that is an option that Microsoft provides. Thinking about Google, Google actually Google does not provide that. You do have to buy a license. You can just do the cheapest $5 license for Google, Microsoft 365. You can create as many unlicensed users as you want. Maybe you have a billing admin and then you want full global admin. You can do that. But yes, you can create as many unlicensed free users as you prefer.
Adriana Linares:
Okay. And I think what happens sometimes with law firms who use outsourced it that outsourced IT company has that account and they are the holders of that account. But
The bad part of that is, and I’ve had to deal with this is the law firm will say, well, our IT company are the only ones that have access to that. And then I say, but you’re actually the account owner and you’re the law firm who’s paying the IT company. So you should still have that admin user ID and password somewhere securely stored so that if something happens to your IT company, you are still able to manage your own account or if you want to leave them. Correct. Okay. I think that’s very important that we remind people that there is this admin account that can control a lot of the Microsoft 365 billing subscriptions, users, passwords, and it doesn’t necessarily have to be you because chances are that you as the named partner of a law firm are going to be the target and chances are that a bad actor can probably guess what your email address is.
It’s going to be your domain and either first initial last name or first name, last name, something like that. So the admin account seems important. Great. And then you said one of the accounts did not have two-factor. Obviously it can take just a few missed clicks to get past two-factor authentication. If a user isn’t paying attention and there’s a popup or maybe you think it’s your assistant that’s logging in and you’re getting the message and you are busy. So there seems to be a lot of ways that two-factor authentication can be bypassed, especially if you’re using either email as the second way to get that code or a text message as the second way to get that code. Or Microsoft is really pushing the authenticator apps now it’s forcing you to use the authenticator app. Can you talk to us about that and why authenticator apps might be the best way to help prevent inadvertent breakthroughs through your two FA?
Adam Alexander:
Yes, and definitely if you’ve done two FA anytime recently, you’ll notice like Adriana said, they’re pushing the two FA authenticator app instead of just text codes and email two FA. And that’s because if someone somehow spoofs your cell phone number, they don’t have to have direct access at that point to your cell phone. If they can manage to spoof your cell phone number and get your text messages without you knowing, then they can obviously get a two text code, but they can’t get a two code directly from the Microsoft authenticator, which is why that’s so much more important. And actually the authenticator, you have to use your fingerprint twice for it to go through and you have to know what number the code is and all of that kind of stuff. So it’s way, way, way more secure. The only way for them to get access to that is pretty much direct access to your phone. So going back to you’ve logged into a public wifi and you don’t realize that they’re on your phone or anything like that.
Adriana Linares:
So I do want to mention for the Mac users that are out there, because there are so many Mac users now that a lot of us who use a Mac actually get our iPhone text messages sent to iMessage on the Mac. And so now if you think again about maybe you’ve lost your laptop, hopefully it’s encrypted, but all the ways that we sometimes make it easy for someone to get those two factor authentication codes when it’s by text or by email. I will admit that I’m one of those people that when Microsoft kept pushing for the Authenticator app, I was like, no, no. And that’s because many years ago I was scarred when I dropped my phone into a lake, a lake got in the way and it wasn’t as easy way back then. I mean we’re talking like 10 or 12 years ago to recover from a lost broken or stolen phone to get the Microsoft Authenticator app back. It’s easier now. So if you have that same PTSD that I used to, please know that it’s easier. Now, Adam, does the Microsoft Authenticator app cost anything?
Adam Alexander:
No, it is free. I want to point something out with the Authenticator app.
Adriana Linares:
Yeah,
Adam Alexander:
It’s a white symbol with a blue lock icon and there’s another authenticator that looks almost just like it.
So be very careful when you go to the play store or Apple store to download it. That is kind of an annoyance and usually when I have someone set that up, I send them a picture of the icon, just be sure you’re downloading the actual Microsoft one. So just be careful with that, but it’s very easy to set up and also going kind of back to that unlicensed user, it’s also very easy to log into the admin panel and have the user redo to FA just in case you do drop your phone into a lake or anything like that. So don’t worry about that. As long as you have access to admin panel, you just click redo two FA and they just log in again, they haven’t like it’s the first time
Adriana Linares:
And does it cost me anything extra to two-factor authentication for all of my users, whether I’m using Microsoft 365 Google or basically any other subscription service,
Adam Alexander:
It is free. And recently, I want to say within the last year, Microsoft has been forcing it to be enabled by default.
Adriana Linares:
Right, so basically for you not to have two-factor authentication turned on using the Microsoft app, if you’re a Microsoft 365 subscriber, you are willfully declining to use a security method.
Adam Alexander:
Correct.
Adriana Linares:
Okay, great. I will say too as also Google user, Google has its own authentication app. I think it’s called Google Oath, OATH, so if you are a Google subscriber, just know that it has an answer for this as well. I know we talk about Microsoft 365 a lot and truly most of the world’s attorneys are Microsoft 365 users. There are certainly some that use Google instead, but just know that whatever Microsoft does, Google does also. Okay. Anything else you want to remind us or tell us about just basic security when it comes to reminding everybody that if you have not activated these important security features you should, is there anything else we should think about? How about password managers? How are you feeling about those?
Adam Alexander:
Password managers are good. I will say we use one password and generally will recommend one password just because of how their systems work and things like that. But one thing to consider with a good password manager is that it encourages you to use random passwords. It encourages you to use two FA. It encourages you to use better security in that sense. And what I mean by a good password manager is it’s easy to use on your phone. It’s easy to use in a browser. It’s easy to set up and do things like, again, I’ll use one password as an example. We set up our two FA codes within one password and it’s so, so easy to log into sites on your phone on a browser because it’ll automatically do the username, the password, the two FA code. And that’s why it’s important is because it encourages you to use two FA because it’s so easy to use. Now you don’t have to have, I used to have so many two FA codes in my duo and my Microsoft Authenticator and all of that, and it was such a pain even though I had them in there. General users are just going to look at it like, oh, I’ve got another two FA code. Where’s my phone? Oh, it’s across the room,
Adriana Linares:
But
Adam Alexander:
This, it just automatically does it. So that’s how to properly use a password manager and to find one that works for you and is easy for you and your users to integrate with.
Adriana Linares:
A lot of today’s apps are asking for pass keys like
QuickBooks for example. Okay, I’ll give you an example. I used QuickBooks and a while ago it said, and Gmail is doing this too, your account will be more secure if you set up a pass key. I have to tell you, I don’t even know what a passkey is, but I use RoboForm instead of what you use one password for, I use RoboForm. And RoboForm came up and it said, Hey, do you want to create a pass key for this account? And I was like, yes, thank you. You helpful little password managing security robot. Yes. And all I did was click yes and it set it up. I honestly dunno what it does, but when I go to log onto QuickBooks again, I’ve put in my master password and boom, there it is. It connects with the pass key that it created for QuickBooks. So it’s almost impossible not to do a good job when you have the right tool set up to protect your accounts.
Okay, now we’ve mentioned a lot about Microsoft 365 and Google, but don’t forget everything has two factor authentication and security for you. I have Clio account, I have my case account, a LEAP account, all kinds of accounts, and guess what they all do? They have two-factor authentication that I can turn on from the admin settings for my entire organization reminding everybody that I’m not a law firm. So please, please, please, please, we are begging you to turn that on for all of your accounts for all of your users. I don’t care that the gal in the corner office whose name is on the billboard out front says, please don’t turn it on. It’s a pain. You tell that attorney that you are being negligent by not turning on these features. Please turn them on. Adam, any last words of wisdom from you about this before we move on to our next segment?
Adam Alexander:
Yes, definitely. There is one more thing, which is these password managers will generally have a business account and the really important thing with that and actually really useful thing with doing that is that you can create what’s called vaults and so you can have general passwords that your entire company, you might have a website that has a general username and password that’s shared between two or three people and you can share that to them without them having to create their own logins to store in one password or the password manager and also going back to two FA really quick because you can share that vault password to them. Now they also have access to the two FA code without having to set up two FA on three phones for one login and all of that. So that’s something to consider too if you do have a couple websites or some companies have a lot of websites that they just have a general login for and you can share that across users, which makes it really useful and easy.
Adriana Linares:
And the good thing is when a user leaves the firm or retires or you’ve had to let them go,
Once you deactivate their account with that password manager, they don’t have access to those passwords anymore and they don’t have access to the accounts anymore. So yet another level of security that you can set up. Okay, let’s take a quick break. We’ll listen to some messages from some sponsors and when we come back I’m going to ask Adam to give us an update on Microsoft 365 accounts subscriptions. I used to pretty much tell everybody they’d be okay with business Standard, but if you’ve got an extra few bucks a month per user, I think Adam’s going to give us a reason to spend a little bit more. We’ll be right back. Alright, I’m back with Adam Alexander. Adam, I failed to give you a proper introduction when we started. I was so excited to start talking about this email you had sent me. Please remind everybody the name of your company and what you do and how you help your clients
Adam Alexander:
For sure. Yeah, the name of the company is Inter Network. IT website is inter network it.com. I usually kind of break it up as internet work it is to make it a little bit easier. But yeah, we’ve been in it for, actually I’ll say not just it but IT for small to medium business since 2011. The past few years we’ve definitely been getting more and more into cybersecurity, which has been not necessarily a big change for us, kind of slowly grown into it, but it’s just a big change in the industry and I think it’s a lot deeper than what a lot of companies in general think security is. But yeah, we’re definitely here to help with all of those questions and do what we can to keep you secure.
Adriana Linares:
Now you’re based in Florida, that’s how we know each other, but you have clients all over the country and you help remotely. I know you help a lot of my clients. So speaking of things have changed and things have gotten more serious back to Microsoft 365 where again, I think most firms are, and if you’re a Google subscriber, just remember there’s going to be a matching solution for this. I used to always, and I think I still do tell firms that they can pretty much start with Microsoft 365 Business Standard, which is about $12 and 50 cents a month. But a while ago you were like Adriana, you should really push them up to business premium, which is $22 a month per user, which honestly for what it sounds like get it sounds like it’s worth it. Can you talk to us about why we would jump up to the business premium if we are not there or talk to our IT people about business premium and say, Hey, looks like maybe we should have this. What’s the
Adam Alexander:
Difference? So business premium is standard with more security and more device control. For a general explanation, it is more expensive, but there are some security features that you get with it. One is this is more of the IT side of it, but you get one year of logs, which might be important depending if you’re a law firm that has to meet some sort of security regulation. That might be important for you
Adriana Linares:
If you have banking clients, that comes up a lot with banking, government clients,
Adam Alexander:
Medical, right? Yeah,
Adriana Linares:
Definitely. Okay. Medical, yes, of course. Okay,
Adam Alexander:
So that would be one. There’s another one where it includes, it used to be called Advanced Threat protection, which I’m going to call it that to avoid some confusion. That includes things like better spam filtering, phishing filtering, it scans the attachments, it scans the web links that are in emails. That’s a really, really important one to always have, even if you have standard. I would include that. One interesting thing that Microsoft recently did is they used to have a license. It was really cheap too. It was great because it’s only a dollar a month and that’s the license that will let you send an encrypted email. So if you need to send a social security number or receive data from your clients, you could send them an encrypted email and they could safely put credit card numbers, social security numbers, things like that. They’ve gotten rid, unfortunately they’ve gotten rid of the dollar license and move that to the premium license. So you have to have the premium license. Now to have that, that’s an important one to think about for the device control sort of thing. A really big one is what
Adriana Linares:
Does that mean,
Adam Alexander:
Right? So the device control portion is where it connects your laptop or desktop to your Microsoft account. The really nice thing about that is that let’s say your laptop gets stolen out of your car or you forget somewhere or don’t know where it is, you can actually use Microsoft to remote wipe your laptop, which is really important. It also handles the hard drive encryption if God forbid your laptop or someone somehow gets to your building and steals your desktop too, that’s something to consider. They can’t get the information off the hard drive if they pull it out. So that’s important. Now as far as the day-to-day usefulness is you’ll have your users in your firm log in with their email address onto their computer, which makes things so much easier because if something happens, all you have to do is reset their email password and now they’re locked out of their computer. So that makes things a lot easier versus using a local user that now you have to go to the computer, reset their password, or if they have a laptop that they take home, it’s easy to lock them out if something happens and you need to let them go from the company, they don’t have access to the laptop even though it’s in their house or in their car.
Adriana Linares:
Excellent. So it kind of solves that BYOD issue we used to talk about years ago, which was bring your own device and okay, so they have their own phone, they have their own laptop. How do I control data from our law firm on those devices? So there’s better measures for dealing with that in this other elevated account premium.
Adam Alexander:
Right.
Adriana Linares:
Okay. I want to ask you one more thing about this. You mentioned it which was, and I think this will be really interesting to a lot of people, is you mentioned that it has better antivirus, anti-spam measures and I was doing some remote help with an attorney just today this morning who had a VG security on top of Microsoft 365. It’s hard to explain to people that we don’t need Norton or a VG anymore while saying you can never have too much security. So if you already have those things, that’s fine, that’s okay. I’m not telling you to remove those things, but I am telling you that Microsoft has really baked into all of their services and into their hardware and their software, better security to deal with anti spam and viruses and stuff. So can you talk to us a little bit about that, Adam, and explain what goes on with Microsoft and why? If we don’t have that, that’s okay. If you want another layer that’s either okay or it causes some problems sometimes.
Adam Alexander:
Okay, so going back to what I was mentioning with the Advanced Threat Protection A TP, the reason why I didn’t want to call it, they’ve changed the name to Defender and the reason why I don’t like to say, yeah, just use Microsoft Defender, people immediately think Microsoft Defender on the computer and it’s not the same thing. So let’s look at Defender as two different things. The Microsoft 365 Defender slash Advanced Threat Protection is the one that covers spam phishing, attachment scanning, link scanning in the emails. Then there’s a Microsoft defender that comes with Microsoft Windows, which is the antivirus portion on your computer directly. So that part definitely they’ve made some leaps and bounds with making that so much more useful and actually usable as a threat protection against viruses on the computer. In the past, Microsoft Defender was this kind of throwaway antivirus that was just on there, no one really ever used, but now it has come very, very far and is actually usable. If you do want to upgrade the defender on the computer portion, then you would be looking at something like, you may or may not recognize some of these names, but something like Sentinel One, something like CrowdStrike, which are,
Adriana Linares:
These are third party services,
Adam Alexander:
Right? Correct. They are third party and generally you may have to get them through an IT provider because you have to have an enterprise license to get them. But you can think about those as in layman’s terms, like a Microsoft defender on steroids. There are a full platform that go way beyond what Defender is doing on your desktop in a general sense of what Defender does,
Adriana Linares:
And I know a lot of firms do use those. I think now because I’m just looking at it on my computer, I think it’s just called Window Security now instead of Defender and when I click on it, it has virus and threat protection, account protection firewall and network protection app and browser control, device security, and then it also does some performance and hardware health management. It’s always done those things, but what we’re saying is it’s gotten much better and we’re not talking like, oh, last year Microsoft made this better. It’s been like 10 or 12 years that this has been really very good and can support a lot of what you’re looking for through a Norton or an A VG. And what I find, and Adam tell me if I remember this correctly, when you install a VG or Norton, it actually has to disable Microsoft security and it takes over. So it’s not like you actually have both.
Adam Alexander:
Yeah, generally speaking, and that even goes for Sentinel One and CrowdStrike, if you install something like that, it’ll automatically disable defender as well and take over. So if you are going to disable Microsoft Defender on the computer, make sure you’re doing it with something better and not equal or worse would be the biggest thing to think about.
Adriana Linares:
And so what are you doing for most of your clients now once they get up to Microsoft 365 premium? Do you leave them with Windows security or do you like to add another layer or does it depend on the firm and the firm size?
Adam Alexander:
So for us, all of our clients get Sentinel One. That’s just part of our security package that we have for all of our clients, including other things this is getting, that would be getting to a whole rabbit hole of security where security is layers. It’s not, well, I have antivirus so I’m safe, I have antivirus, I have email monitoring, I have all kinds of things, web filters that’s really proper security is relying on 10 products and not one. And so that’s kind of where we are, where with our general package at this point we have a lot of those products including Sentinel one for antivirus now.
Adriana Linares:
Okay. Alright. Let’s take a quick break, listen to some messages from some sponsors and we come back. We’re going to wrap up a couple of suggestions, ideas. We’re going to talk about some wire transfer tips and remind you that you should have cybersecurity locked into your malpractice insurance. We’ll be right back. All right, we’re back with Adam Alexander from Inter Network it another email you sent me a while ago, Adam was about reminding attorneys about cyber liability insurance and how a lot of them don’t have it, haven’t thought about it, think they don’t need it, think it’s too expensive, but it’s a good idea and I’ll come back after you say a few things about it from my perspective, but what have you found as far as liability insurance for security breaches?
Adam Alexander:
So I think there is a misconception of who needs it and who doesn’t. I think a lot of people think, well, I don’t do wire transfer so I don’t need it, but it goes beyond that. It goes into loss of data, business downtime. If you get a ransomware virus and it takes you three, four or five days to get back online properly, it will reimburse you for those three, four or five days where standard insurance won’t do that. This is basically insurance all around any kind of hack email hack, I had to specify, I had to really go into the fact that probably 95 to 98% of hacks now are through email,
Announcer:
And
Adam Alexander:
So it’s really important to have that secure, but once they get into that, they can get into other things. Cyber
Adriana Linares:
That’s they started with.
Adam Alexander:
Yeah, exactly. They have maybe they get your OneDrive and they can extort you for your data and all of that sort of thing, and so it covers that part where the general insurance, they’re just going to say, well, you got hacks. We sent some information to whoever the FBI or a criminal investigation unit, but they’re not going to pay you anything for what happens after that.
Adriana Linares:
I think a lot of times too, lawyers think it’s going to add a big number to their premium and attorneys. It’s not, and what you really need to do, especially really having put in some good security practices in place, but also adding cyber liability insurance to your package, go to your bar’s website, they all have malpractice insurance carriers and start shopping. Start with the one you currently have and say, Hey, I want to add this. How much is it and what is covered? I think it’s really important to understand what is covered. Like Adam said, they’re going to pay you back. That’s not always. That depends on what boxes you check when you sign up for cybersecurity, cyber liability insurance, so you really want to ask a lot of good questions. They may seem dumb to you, but they’re important and shop, shop, shop, shop for malpractice and not only malpractice, I keep saying malpractice, but I mean general liability. These companies are competing against each other for your business and if you get a quote from one and take it to another and say, well, this is what they quoted me and this is what is covered, you’re going to find that oftentimes taking a few minutes to do that shopping can really pay off in the end where you’re getting good coverage for a reasonable amount of your money.
Adam Alexander:
I want to interject two things here and it is funny. I actually had this in quotes in my notes around this subject is we’re too small to get hacked and the truth is hacks and I’ll just say email hacks. Let’s just stick with that. The hacker is just going to blanket send out phishing attempts. They’re not going to care if you have 3000 employees or two. And number two, they prefer to target smaller companies, smaller firms, smaller anything because they know that there’s a better likelihood that they aren’t going to have security products.
And so think about that when you think, well, we’re too small for them to care about. They love that. That’s the first thing that they’re going to be cheering about. That what Adriana was saying about just don’t just go in there and check the boxes on the liability forms. What happens is you can check the boxes and say, sure, we have all this. If you make a claim, they are going to verify that you have all that. They’re going to verify that you’ve got the email protection, something like Microsoft Defender or Sentinel One. They’re going to make sure that you have backups, routers with security. And so just be sure that you have those things if you’re checking yes is what I’ll say about that part.
Adriana Linares:
What you’re basically saying, Adam, is you better be talking the talk.
Adam Alexander:
Yeah, yeah. You’ve got to walk that walk
Adriana Linares:
And be ready to prove it in order to be able to use that. Alright, very good. You had some tips on wire transfers, which of course a lot of law firms have to do and that is a major point of failure when it comes to security and issues. So talk to us about just, you had a super simple tip, I think that made sense and what happened there with one of your clients?
Adam Alexander:
Yes, so two easy ways to do it. One, I loved it. I had literally a two person law firm. Tell me the second one, I loved it, but the first one is just before you send the acas transfer, just call the party whoever’s getting it and just say, Hey, these are your numbers correct. Just be sure that’s the easiest way. The second one that I absolutely loved was he told me he does that, but then he’ll send a 100 or $200 transfer and then call him and
Adriana Linares:
Mini transfer,
Adam Alexander:
Little mini transfer and say, did you get it? And when they confirm that they got it, then he’ll send the rest. It has happened and you don’t want to be this person that loses $200,000 and you don’t get it back. That’s where the whole insurance thing comes in because they can get that back for you, but if you don’t have insurance and you send 200, $300,000 to somebody, you don’t get that back and that’s just a direct loss and you still have to send 200,000, $300,000. Again,
Adriana Linares:
I am so freaked out by wire transfers and not necessarily that it’s going to be intercepted, but that I’m going to put in the wrong number. I was just setting one up this morning and I was able to copy and paste it from the bank details that the client had sent me. The first time I was able to copy and paste it, which I was pretty confident. I copied, I pasted it, but the second time it actually made me manually enter it and I was like, oh, but this is so much worse, but so of course I manually entered it. I fat fingered it and I got it wrong and I was like, see, that could have happened the first time. Anyway, the point being I had to call the bank. This was an international wire I was setting up and I called my bank to make sure I was reading the bank statement from the receiving bank correctly.
Yes, that’s fine. And then I asked her, well, how much does this wire transfer cost me? She says, it’s $35. I said, is it $35 whether I’m transferring $3 or 300,000? She said, yes. I said, well, shit, for $35 and I’m not sending a huge amount of money, I’m buying some products, I’m buying. Let’s say I’m spending $3,000, which I am. Okay, well, I’m going to risk. I’m going to pay $35 to send them $100 rather than risk either my entering the information wrong or there being an issue and them not receiving it, so I am going to eat $35. I sent it, I texted the client, I said, Hey, let me know if that transfer. If you see that amount tomorrow, that money should be there and then I’m going to feel good about transferring the rest of it and continuing my transactions because I know I’ve got it. Right. Okay. Adam, we’ve covered a lot on this podcast so far, giving everybody reminders about security and things they need to set up. Anything else, any other words of wisdom you want to share with us for lawyers and law firms out there, whether they’re one or 100 that can help them prevent any hacks, email issues, what other tips you got?
Adam Alexander:
I think the biggest takeaway that I can tell anybody is that security is layers. You’ve got to have the layers and if you don’t, you’re using just one thing for antivirus. You’re just using one thing for email protection, it’s not enough anymore. So just consider that when you’re speaking with a provider. Do they have 5, 6, 7, 10 different products to protect you? That would be the biggest takeaway. If I can put anything in your mind right now, that would be the biggest takeaway.
Adriana Linares:
I think that’s a good one. Remind everybody where they can find friend or follow you.
Adam Alexander:
Definitely. You can always email me at [email protected]. That’s two a’s at the beginning of the email address
Adriana Linares:
Just because you have two first names for your full name. Adam Alexander.
Adam Alexander:
Yeah, Adam Alexander. Yes. That’d be the easiest way with email and phone would be (321) 300-6383, extension one oh one and call me, email me anytime. I’m here I can help out.
Adriana Linares:
Well, Adam, I can’t thank you enough for coming on again as usual and helping us out and to all you listeners, I hope this is a call to action and really encourages you to make sure you’ve done a security checkup, make sure you’ve got all of those accounts set up. Make sure your users are trained on all the things that help us prevent breaches and compromises because it’s really, oftentimes it’s a human issue more than anything. We can talk about technology all day, but when a user isn’t paying attention or a user has a password, that’s easy to guess. There’s not a lot technology can do about that. All right, everyone, thank you so much for listening and we’ll see you next month on New Solo
Notify me when there’s a new episode!
|
New Solo |
New Solo covers a diverse range of topics including transitioning from law firm to solo practice, law practice management, and more.