Imagine walking into your law office on a Monday morning, turning on your computer, and discovering that nothing works. Client files are inaccessible. Your case-management system is not working. Years of documents, emails, financial records, pleadings, and confidential client information are suddenly unavailable. Then you see the message: Your data has been encrypted. Pay a ransom if you want it back. This scenario is not theoretical for South Florida law firms. In July 2026, the Miami law firm Golden Glasko Haddy & Associates was hacked with ransomware! Public reporting has not independently established the full extent of the incident, but it illustrates the type of threat facing law firms today.
Cybersecurity is a lawyer’s responsibility
For attorneys, protecting technology is also about protecting client confidentiality. Florida Bar Rules require lawyers take responsibility for information relating to client representation. Florida Bar Ethics Opinions specifically addresses cloud computing and states that attorneys may use cloud services only when they take reasonable precautions to protect confidentiality, ensure adequate security, maintain access to their information, and appropriately investigate the service providers they use.
Start With the Basics
- Protect every account. Enable multi-factor authentication wherever possible. Require strong, unique passwords and use a reputable password manager. Passwords should never be shared, and computers should be locked whenever employees leave their desks.
- Protect every device. Computers should have business-grade endpoint protection, firewalls, encryption, and current security updates. Remote access to firm resources should use an approved secure method, such as a properly configured VPN when appropriate.
- Take phishing seriously. Employees should verify senders, inspect links before clicking, question unexpected attachments, and independently confirm requests involving money, passwords, or sensitive information. An urgent email supposedly from a managing partner requesting a wire transfer should never be trusted simply because it looks convincing.
- Back up everything and test the backups. Backups should be secure, separated from production systems, and periodically tested.
- Train your staff. Technology alone cannot prevent every attack. Written cybersecurity policies, phishing-awareness training, and clear procedures for reporting suspicious activity are critical. And if an incident occurs, employees should know exactly whom to contact and what to do immediately.
Here is a link to a draft CyberSecurity Policy document. The document is in Word format so you can edit it before converting to PDF and forwarding to your staff.
Legal Computer Consultants provides comprehensive technology solutions to South Florida’s legal profession, helping law firms protect their systems, their data, and their ability to operate.
Peter Rabbino
Legal Computer Consultants
www.LegalComputer.com
peterr@LegalComputer.com
LinkedIn: @peterrabbino
This article provides general technology and cybersecurity information and is not legal advice.


