keeps targeting law firms for a simple reason. It is not only the volume of data a firm holds. It is the sensitivity. A firm sits on client files, trust account records, settlement details, privileged advice and that the firm has a duty to protect. When an attacker can threaten to lock or publish all of it, the firm is under real pressure to pay. That pressure is the product the criminal is selling.
How an attack usually unfolds
The image of ransomware as a sudden event is misleading. The is the last step, not the first. In most cases the attacker has been inside the network for days or weeks before anything visibly breaks.
Access often begins with a stolen password or a . From there the attacker moves quietly. They map the network, find where the files and backups live, work out which accounts have the most access, and copy client data out to their own systems. They take their time precisely because staying hidden is what makes the final demand effective.
Double extortion
Modern ransomware rarely relies on encryption alone. The attacker copies sensitive data before locking anything, then makes two threats at once: you cannot get your files back without paying, and we will publish your clients' data if you do not. This is double extortion, and for a law firm it is especially damaging. Even a firm with clean backups, able to restore everything, still faces the prospect of confidential client material being leaked. Good backups solve the encryption problem. They do nothing about the data the attacker already took.
What a firm loses when encryption hits
When the encryption does fire, it tends to hit everything the firm runs on at once. Active matters in your practice management system, whether that is LEAP, PracticeEvolve, ActionStep or Clio, become unreadable. Trust account records are locked. Email in Microsoft 365 may be affected. The firm cannot open files, cannot bill, cannot meet court deadlines, and cannot answer clients. Work stops across the whole practice on the same morning, and it stops without warning.
The breach obligations that run alongside
A ransomware attack on a law firm is usually a data breach as well, because the attacker has copied client information. That brings the Privacy Act 1988 and the into play. The firm must assess whether the breach is likely to result in serious harm, and if it is, notify both the affected individuals and the .
This assessment runs at the same time as the technical recovery, and both happen under a clock. You are trying to restore systems, work out exactly what data was taken, and meet your notification obligations, all while the practice is offline and clients are waiting. The firm that has thought about this in advance copes far better than the one discovering its obligations mid-crisis.
Recovery under pressure
Recovery rests on three things. The first is tested offline backups, kept separate from the main network so the attacker cannot reach and encrypt them too. Backups you have never restored from are an assumption, not a safeguard. The second is an incident response plan that names who does what, who you call, and how you communicate with staff and clients. The third is the OAIC assessment described above, which has to proceed in parallel. None of this is calm work. It is done at speed, often over a weekend, with the firm's reputation and cash flow on the line. Preparation is what turns a disaster into a manageable event.
Preventing it in the first place
Prevention is far cheaper than recovery, and the controls that matter are well established.
- on every account, so a stolen password is not enough to get in.
- An uplift, the Australian government's baseline of practical controls, applied across the firm rather than in patches.
- Microsoft Defender configured properly to detect and contain threats inside and on devices.
- Prompt patching of operating systems and applications, since attackers rely on known, unpatched holes.
- Coordinated offboarding, so accounts are disabled the day a staff member leaves and forgotten logins do not linger.
- Monitoring, so the quiet period when an attacker is mapping the network is noticed before encryption begins.
The common thread is that these controls do their work early, during the days or weeks the attacker spends moving around before the demand. That is the window in which a ransomware attack can still be stopped.
Where IronSights fits
Ransomware is both a prevention problem and a response problem, and a law firm has to be ready for both. IronSights works with Australian legal practices to raise their Essential Eight maturity, configure MFA and Microsoft Defender, tighten patching and offboarding, and put monitoring in place so an intrusion is caught early. We also help firms build and test the and breach assessment steps they will need if an attack does land. A security review is a sensible first step: it shows where a firm is exposed today and sets a clear order for fixing it.



