
Your firm's biggest security gap may be sitting in your chair
You've told your staff a hundred times to watch for scams. Then an email arrives for you. Are you ready?
You may think you’re immune to “human risk,” and it's your employees you have to worry about. Whether you’re running a small law office with half a dozen lawyers or a large multi-practice firm with dozens of partners, associates, and admins, there is no single person who is immune to human risk.
Unfortunately, that includes you as owner or managing partner.
We had a call with a client recently about ways to mitigate his firm’s exposure to phishing attacks. He told us, with some confidence, that he could spot an email attack.
Of course, we then sent him a phishing email simulation that tricked him into clicking a link.
No matter the size of your organization, a simple email scam can take out your entire firm in one click.

Human risk is everybody’s problem.
Human risk happens when your everyday behavior crosses a potential security threat. That could mean receiving and reacting to an email, visiting a website, or even finding a stray USB drive on your way into the office and plugging it into your laptop to see who dropped it so you can return it.
Even something as innocent as taking an office selfie can open you to an exploit you didn’t see – like when you accidentally capture a password someone wrote down on a Post it over your shoulder.
All of these can lead to unintended consequences. And none of them is a random outcome. Someone is working on this full time.
Artificial intelligence (AI) makes a fake email look real.
As AI gets better at content that looks real, very real, inside an email, the attachments it includes, or the landing page that one click can take you to, it’s very easy to fall prey to an exploit.
For example, you could receive an email apparently sent by a known vendor; you may not realize that there are many ways for bad actors to obtain information about the software tools your firm uses. How would anyone know that you’re using Clio, MyCase, or Filevine? Because you’re running a law firm.
One of the simplest vulnerabilities that many people have encountered is a credential exploit. That’s where a form pops up and requests that you log in with your credentials to see a message. So you enter your company credentials or you accept their invitation to view the content somebody supposedly shared with you. Many people just blindly do this. We’ve all become so fatigued entering credentials for every website.
After you enter your credentials you are taken to a landing page that says, “Content unable to load” or something similar. It seems innocuous. What's happened in the background is that immediately, the attackers will leverage your credentials to impersonate you.
They will also test to see whether you’re using multi-factor authentication (MFA). If not, they're going to try to get a foothold into your firm, sending email to your employees pretending to be you so they can now compromise your firm with ransomware or to exfiltrate client data.
Human risk has become big business.
Hacking, malware, and exploiting human risk has become a full-time job for some hackers and bad actors. You and your employees go home and sleep, you wake up the next day and you go back to work. While you were sleeping, they were plotting and planning, and if you didn't get hacked it was just because they weren’t ready yet.
Large breaches that yield stolen user names and passwords are then sold to brokers who also sell malware-as-a-service that bad actors can purchase.
All these exploits lead to one of two things: money or data. Often both. Any successful human risk exploit leaves you and your firm’s reputation shaken.

Building a habit of asking first.
We use our Cypress Grove Human Risk Mitigation Platform to find gaps in your firm's security awareness and close them. The goal isn't to get a certificate. It's to train your firm so that every unexpected request gets questioned before it gets answered. We know it's working when someone at your firm gets a call from us, asking to log in to a partner's laptop, and stops to ask how they can be sure it's really us. That's the posture we're training. Not suspicion of everything. A habit of checking first.
One last question worth asking yourself.
If an email arrived tomorrow from a vendor your firm actually uses, referencing an actual issue, addressed to you and not to your staff, would you catch it?
If you're not sure, you're in good company. Our client was certain. That was the problem.
Cypress Grove Technologies is the Strategic Growth Infrastructure and Risk Mitigation Partner for professional services firms in New York. If you're uncertain about your firm's human risk security posture, we're happy to discuss it with you.



