Law firm preparing its systems and response plan for a ransomware attack

For a 10–50 employee law firm, ransomware preparation should focus on six critical areas: prevention, identity protection, endpoint security, backups, employee training, and incident response.

The objective isn’t to assume your firm can prevent every attack. It’s to make sure a successful phishing email, stolen password, or compromised computer doesn’t become a firm-wide crisis.

In 2026, law firms should have multi-factor authentication (MFA), managed endpoint detection and response (EDR), isolated and tested backups, continuous security monitoring, employee security training, and a written incident response plan.

Most importantly, your firm should know how it will continue operating if email, documents, case management software, or other critical systems suddenly become unavailable.

Why Are Law Firms Attractive Ransomware Targets?

Law firms hold exactly the kind of information cybercriminals want.

Depending on the practice, that may include:

  • Confidential client communications
  • Personally identifiable information
  • Medical records
  • Financial information
  • Settlement information
  • Banking and wire-transfer instructions
  • Corporate records
  • Litigation strategies
  • Intellectual property
  • Case files and evidence

This creates two forms of leverage for ransomware attackers.

The first is operational disruption: encrypt systems and prevent the firm from accessing its data.

The second is data extortion: steal sensitive information and threaten to publish it.

That means having backups alone isn’t enough.

A modern ransomware strategy must address both business recovery and data protection.

For New York attorneys, protecting client information also intersects with professional responsibilities and state data-security requirements. In its January 16, 2026 article, How to Prepare and Respond to Ransomware Attacks, the New York State Bar Association discusses ransomware preparedness for attorneys, including security safeguards, backups, multi-factor authentication, incident response, and obligations involving confidential information.

New York's General Business Law § 899-bb—part of the SHIELD Act framework—also requires covered persons or businesses that own or license computerized data containing New York residents' private information to develop, implement, and maintain reasonable safeguards to protect that information.

The 6-Part Ransomware Readiness Framework for Law Firms

Law firms don’t need dozens of disconnected cybersecurity products.

They need a coordinated strategy.

Here’s a practical six-part framework.

1. Protect Accounts With MFA and Strong Access Controls

Many ransomware incidents begin before ransomware is ever installed.

Attackers may first gain access through:

  • Stolen passwords
  • Phishing emails
  • Compromised remote-access credentials
  • Old employee accounts
  • Administrator accounts
  • Social engineering

That’s why identity protection is the first layer of ransomware defense.

At minimum, MFA should protect:

  • Microsoft 365
  • Email
  • Remote access
  • VPN connections
  • Cloud applications containing client information
  • Administrative accounts
  • Other critical systems that support MFA

Where practical, firms should move toward phishing-resistant MFA, particularly for privileged and high-risk accounts. CISA's #StopRansomware Guide recommends phishing-resistant MFA as part of ransomware prevention and identity protection.

Don’t forget former employees

A firm’s access-control process should also ensure that accounts are promptly disabled when attorneys or staff leave.

Ask your IT provider:

“Can you show us every active account with access to our systems—and whether MFA is enforced?”

That’s much more useful than simply asking, “Do we have MFA?”

2. Detect Ransomware Before It Spreads

Traditional antivirus is only one piece of protection.

Law firms should use managed Endpoint Detection and Response (EDR) and continuous security monitoring to identify suspicious behavior.

The objective is to detect activity such as:

  • Malicious software execution
  • Suspicious account behavior
  • Unauthorized administrative activity
  • Attempts to disable security tools
  • Unusual access patterns
  • Malware spreading between systems

Speed matters.

A threat contained on one workstation is very different from an attacker gaining access to servers, backups, Microsoft 365, and dozens of computers.

Your IT or cybersecurity provider should have a documented process explaining:

  1. Who receives security alerts?
  2. Who investigates them?
  3. Is monitoring continuous?
  4. Who can isolate an infected computer?
  5. Who contacts firm leadership during a serious incident?

Security software without a response process creates false confidence.

3. Build Backups Ransomware Can’t Easily Destroy

Backups are one of the most important parts of ransomware preparation—and one of the areas firms should scrutinize most carefully.

The FBI's ransomware guidance recommends regularly backing up data and securing those backups so they aren't connected to the computers and networks they're protecting.

CISA's #StopRansomware Guide similarly recommends maintaining offline, encrypted backups and regularly testing their availability and integrity in a disaster-recovery scenario.

For a law firm, a strong backup strategy should answer five questions:

What are we backing up?

Identify critical data and systems, including servers, documents, databases, and other business-critical information.

Where are the backups?

At least one recovery option should be isolated from the production environment so attackers cannot easily encrypt or delete it.

Are backups encrypted?

Sensitive client information must remain protected even within backup systems.

How often are backups tested?

A successful backup notification doesn’t prove successful recovery. Perform actual restoration tests on a defined schedule.

Regular backup testing confirms whether your firm can actually restore critical data and systems when recovery matters.

How quickly can we recover?

Your firm should understand its realistic recovery time.

Ask:

“If ransomware encrypted our systems at 9:00 tomorrow morning, when could our attorneys work again?”

If nobody can answer that question, your disaster recovery strategy isn’t complete.

4. Train Employees to Recognize the Attack Before It Starts

Your employees are part of the cybersecurity system.

Attorneys and staff should receive recurring training covering threats such as:

  • Phishing
  • Fake Microsoft 365 login pages
  • Malicious attachments
  • Business email compromise
  • Password theft
  • Suspicious links
  • Social engineering
  • Fraudulent payment requests

Training should not be treated as a once-a-year compliance exercise.

Combine education with periodic phishing simulations and clear reporting procedures.

Employees need to know exactly what to do when something looks suspicious.

A useful rule is:

Report first. Investigate second.

An employee who reports a suspicious email immediately gives your security team time to investigate before other employees interact with it.

5. Patch and Reduce the Attack Surface

Ransomware groups don’t rely exclusively on phishing.

Attackers also exploit vulnerabilities in software, remote-access tools, network devices, and other internet-facing systems.

Your ransomware preparation plan should therefore include:

  • Automated operating-system patching
  • Third-party application updates
  • Firewall and network-device updates
  • Secure remote access
  • Removal of unsupported software
  • Removal of unnecessary administrative privileges
  • Regular review of unused accounts
  • Vulnerability management

The FBI advises organizations to keep operating systems, software, and applications current. CISA's #StopRansomware Guide also includes vulnerability and patch management among its ransomware-prevention recommendations.

For managing partners, the important question isn’t:

“Are we patched?”

Ask:

“How quickly do we deploy critical security patches, and how do we verify they were successfully installed?”

Specificity matters.

6. Create and Test a Ransomware Incident Response Plan

This is where many otherwise well-protected firms fall short.

They have security products.

They have backups.

But nobody has documented what happens at 8:15 Monday morning when 20 employees suddenly can’t open their files.

At minimum, a strong incident response plan should establish the following before an attack occurs:

  • Who declares a security incident
  • Who contacts the IT/security team
  • Who has authority to isolate systems
  • Who contacts cyber insurance
  • Who coordinates legal obligations
  • Who communicates with employees
  • Who handles client communication
  • Who contacts law enforcement when appropriate
  • How evidence and logs are preserved
  • How systems are restored
  • How business operations continue during recovery

The FBI's ransomware guidance recommends developing both an incident response plan and a business continuity plan and encourages ransomware victims to report incidents to law enforcement.

For New York law firms, the response may require coordination among firm leadership, IT and forensic professionals, the firm's insurer, legal counsel, communications professionals, and other advisors depending on the circumstances.

The New York State Bar Association's 2026 How to Prepare and Respond to Ransomware Attacks discusses this coordinated approach and the issues attorneys should consider when preparing for and responding to ransomware.

What Should a Law Firm Do Immediately After Discovering Ransomware?

The exact response depends on the incident, so your firm’s established incident-response plan and professional advisors should take the lead.

But a useful framework is:

1. Contain

Immediately involve your cybersecurity team and isolate affected systems as appropriate to stop further spread.

2. Preserve

Don’t start randomly deleting files, wiping computers, or destroying evidence.

Your forensic and legal teams may need logs, system images, emails, and other evidence to determine what happened.

3. Activate

Activate the firm’s documented incident response and business continuity plans.

4. Notify

Contact the appropriate internal leadership, cybersecurity professionals, cyber insurer, legal advisors, and law enforcement based on the circumstances and your response plan.

5. Investigate

Determine:

  • How attackers entered
  • Which systems were accessed
  • Whether data was stolen
  • Whether ransomware spread
  • Whether attackers still have access

6. Recover

Restore from known-clean systems and backups only after the environment is safe to recover.

The priority is not simply getting computers turned back on.

It’s recovering without reintroducing the attacker.

Should a Law Firm Pay a Ransom?

This is not a decision a managing partner should make alone—or make for the first time during an attack.

It can involve legal, insurance, forensic, operational, sanctions, law-enforcement, and ethical considerations.

The FBI states that it does not support paying a ransom. Among other concerns, paying does not guarantee that an organization will regain access to its data, and ransom payments encourage perpetrators to target additional victims.

Your firm’s incident response plan should therefore establish before an incident who will participate in ransom-related decisions and which outside advisors must be contacted.

Preparation creates options.

Panic eliminates them.

How Long Could a Law Firm Be Down After Ransomware?

There is no responsible universal number.

Recovery time depends on factors including:

  • How far attackers penetrated
  • Number of affected systems
  • Whether data was stolen
  • Whether backups were compromised
  • Backup quality
  • Recovery testing
  • Network complexity
  • Availability of replacement equipment
  • Forensic requirements
  • Third-party applications

That’s why every law firm should establish two business-continuity measurements:

Recovery Time Objective (RTO): How quickly must a system return?

Recovery Point Objective (RPO): How much data could the firm afford to lose?

Different systems may require different targets.  Recovery speed also affects more than productivity because downtime can damage client trust when a firm isn't available when clients need it.

For example, your tolerance for losing access to email may be very different from your tolerance for losing access to an archived system that is rarely used.

The 30-Minute Ransomware Tabletop Test

You don’t need to intentionally shut down your network to discover whether your response plan works.

Run a tabletop exercise.

Put your managing partner, administrator, IT provider, and other appropriate decision-makers in a room and give them this scenario:

It’s 8:15 a.m. Monday. Employees report that documents won’t open. Several computers display ransom notes. Email may be compromised. What happens next?

Then ask:

  1. Who makes the first call?
  2. Who has authority to disconnect systems?
  3. How will employees communicate if email is unavailable?
  4. Where is the incident response plan stored?
  5. How do we contact our cyber insurer?
  6. When were backups last restored successfully?
  7. How will attorneys access tomorrow’s deadlines?
  8. How will employees work if systems remain unavailable?
  9. Who determines whether client information was accessed?
  10. Who handles external communications?

If the group can’t answer these questions quickly, you’ve identified gaps without experiencing an actual attack.

That’s valuable.

Ransomware Readiness Checklist for a 10–50 Employee Law Firm

Before calling your firm ransomware-ready, verify:

  • MFA is enforced across critical systems
  • Administrative access is restricted
  • Former employee accounts are promptly disabled
  • Managed endpoint security is deployed
  • Security alerts are actively monitored
  • Critical systems are patched
  • Backups are isolated and protected
  • Backup restoration is regularly tested
  • Employees receive cybersecurity training
  • Phishing simulations are performed
  • A written incident response plan exists
  • A business continuity plan exists
  • Cyber insurance contact information is readily available
  • The response team knows its responsibilities
  • A ransomware tabletop exercise has been completed

If you can’t confidently check several of these boxes, that’s where your next cybersecurity conversation should begin.

Example: How a Western New York Law Firm Could Prepare for Ransomware

Consider a 30-employee law firm in Western New York that conducts a ransomware readiness review before its cyber insurance renewal.

The assessment identifies three significant gaps:

  • MFA isn’t enforced across every cloud application
  • Backup jobs are running, but restoration hasn’t recently been tested
  • The firm’s incident response plan doesn’t clearly identify decision-makers

Over the next 60 days, the firm:

  1. Expands MFA coverage
  2. Performs and documents recovery testing
  3. Updates its incident response plan
  4. Conducts employee security training
  5. Runs a ransomware tabletop exercise

The important result isn’t that the firm can claim ransomware will never happen.

It can’t.

The result is that leadership knows how the firm will detect, contain, communicate, recover, and continue operating if it does.

Why Western New York Law Firms Work With Ferrari Networks on Ransomware Readiness

Ferrari Networks works with 10–50 employee law firms throughout Buffalo, Niagara Falls, and Western New York.

Our approach to ransomware readiness goes beyond installing security software.

It includes:

  • Multi-factor authentication
  • Endpoint security and monitoring
  • Backup and disaster recovery
  • Microsoft 365 security
  • Patch management
  • Employee cybersecurity awareness
  • Incident response planning
  • Cyber insurance readiness
  • vCIO and strategic technology planning

The objective is straightforward:

Prevent what you can. Detect what gets through. Contain it quickly. Recover confidently.

Is Your Law Firm Prepared for a Ransomware Attack?

Ask your leadership team one question:

“If ransomware hit us tomorrow morning, what would we do during the first 60 minutes?”

If the answer isn’t immediately clear, your firm has work to do.

Start with a ransomware readiness assessment that evaluates your identity security, endpoints, backups, employees, incident response procedures, and ability to continue operating during an outage.

Don’t wait for a ransom note to test your plan.

Related Resources

Continue your research with:

Ready to assess your firm’s ransomware preparedness?

Schedule a 10-minute discovery call with Ferrari Networks to discuss your current security posture, backup strategy, incident response plan, and areas that may need attention.