Quick Thought – Law Firms as a Target

I know we’re all familiar with the fact that law firms make an inviting target for hackers, because we all have a ton of information about our clients, and law firms in general are just starting to get better at data security.

I wonder, though, if law firms don’t also make for an inviting social engineering target because we’re all so used to getting strange requests from partners that we don’t even stop and think about why someone would ask us to hand over our passwords, or unlock a door, email documents, etc.

Should we be looking at that culture of not questioning partners when we are doing our due diligence for security concerns?

