Back to Industries
IN RE: Your Firm’s InfoSec Program
Matter 2026-LF-001 · Prepared for Mid-Firm Managing Partners

The program that would have made those firms defensible.

Memorandum · statement of purpose

For US mid-firm managing partners, COOs, and firm administrators. After Silent Ransom Group extorted the BigLaw class for $46M+ in 2026, the question a client’s general counsel or a cyber-insurance underwriter will ask is the same one bar counsel would ask after an incident: what did your firm have in place.

New field note · BigLaw’s $46M year, in detail →

§ I. The Docket

A decade of the same question, asked louder.

Law-firm cyber moved from an IT problem into a client-facing procurement question. The FBI issued its second Private Industry Notification on the Silent Ransom Group tactic in May 2026, and every bar counsel and cyber-insurance underwriter now uses it as the yardstick: what did the firm have in place after the profession was warned.

  1. 2016Mossack Fonseca · Panama Papers · 11.5M documents; firm dissolved 2018
  2. 2017DLA Piper · NotPetya paralyzes a global BigLaw for days
  3. 2018ABA Formal Opinion 483 codifies the breach-notification duty
  4. 2020Grubman Shire · REvil $42M demand · 756GB of privileged material stolen
  5. 2023Orrick · $8M class-action settlement · 638K+ downstream individuals
  6. 2025FBI PIN · Silent Ransom Group named as active against US law firms
  7. 2026SRG BigLaw campaign · $46M+ paid across WilmerHale, Goodwin, Weil, and others
  1. 01

    Silent Ransom Group is the active pattern, not a rumor

    In 2026 the group extorted WilmerHale for roughly $18M, Goodwin Procter for $10M, and Weil Gotshal for up to $20M. Some victims never saw a network attack — the operators walked into offices in person, posing as IT contractors. This is the actual, current tactic your peers are answering for.

  2. 02

    The FBI’s May 2026 PIN is now the yardstick

    Bar counsel and cyber-insurance underwriters use the FBI’s second Private Industry Notification as the reference standard. After a warning-of-record from federal law enforcement, “we didn’t see it coming” is not the same defense it was a year ago.

  3. 03

    Mid-firm cyber-insurance renewals are being repriced

    Law.com’s May 2026 mid-market coverage explicitly names mid-firms as the growth segment for these incidents. BigLaw is spending its way into stronger controls, so the pressure is migrating downward. Carriers are already asking mid-firm renewals for the physical-security-at-reception controls the SRG campaign made table-stakes.

  4. 04

    Client SIGs adopt the pattern in a quarter, not a year

    The 2026 outside-counsel-guidelines addenda from F500 clients already include the SRG-specific controls. Every quarter that passes without a documented answer is a quarter a client’s procurement team can point to. The next SIG on your desk is measured against every row of the timeline.

$46M+

Known ransoms paid by BigLaw victims of Silent Ransom Group in 2026.

The Insurer · Aardwolf Security · Aug 2026

200+

Ransomware incidents against US law firms tracked between 2025 and early 2026.

Halcyon ransomware tracking, 2026

$5.08M

Average cost of a 2026 law-firm breach, up 10% year over year.

Halcyon · IBM Cost of a Data Breach 2026

2

FBI Private Industry Notifications on Silent Ransom Group tactics: vishing (May 2025) and physical intrusion (May 2026).

FBI IC3 · 2025, 2026

Bar-Counsel Response PacketAdler & Voss LLP · INQ-2026-014 · Prepared 2026-08-23
MR 1.6(c)
Ex. A
InfoSec policy in effect on date at issue
ON FILE
Ex. B
Evidence the policy was operating
ON FILE
Ex. C
Vendor + MSP + outside-professional register
ON FILE
Ex. D
Tabletop exercise after-action report
ON FILE
Ex. E
Workforce training distribution log
ON FILE
Ex. F
OpenAI API vendor agreement
GAP · REMEDIATION
Illustrative composite · assembles from the live program in under four hours.

§ II. The Complete Response Packet

Day one of an inquiry, on the firm’s terms.

When bar counsel opens an inquiry, when a cyber-insurance underwriter requests a retrospective at renewal, when an F500 client’s outside-counsel oversight team asks for the security posture, the firm has one packet to hand over.

This is what running the program lets a firm produce, in hours instead of weeks.

§ III. What the firm keeps. What it gets back.

Client retention. Carrier renewal. Bar-counsel readiness. Partner hours.

A policy set and a live vendor register sound tactical. What they actually buy the firm is strategic — every one of these shows up in a client SIG response, a carrier renewal, a bar-counsel inquiry, or a monthly partner meeting that used to run twenty-five minutes and now runs fifteen.

Retain

Your F500-client retainer

Outside-counsel-guidelines cyber addenda are increasingly retainer-conditional. If the firm can't answer the 30-question SIG in ten business days with sourced, dated evidence, the retainer moves to a firm that can. Every SIG the platform answers is a retainer defended.

Preserve

Your cyber-insurance pricing

After Silent Ransom Group paid $46M+ across BigLaw in 2026, cyber-insurance carriers (CNA, Brit, Beazley, Chubb) are repricing mid-firm renewals against the same controls set. Firms that walk in with a FAIR-quantified posture packet and a tabletop artifact don't get quoted at 2x. Flat premium is the outcome you're paying to preserve.

Save

Fifteen partner hours a week

Every hour the platform pulls evidence, drafts SIG responses, and keeps the vendor register current is an hour a partner isn't. Fifteen hours a week returned to matter work, client meetings, and the judgment calls that only a partner can make.

Answer

Bar counsel in hours, not weeks

If an inquiry lands, the Response Packet assembles from the live program in under four hours. Reconstruction from email threads under a 24-hour clock is not a defense a bar counsel accepts; a dated packet is.

Protect

The firm's reputation, before the trade press writes about it

Peer-firm incidents make the ABA Journal and Law360 the week they happen. The story a reporter can write about your firm is shaped by what your program can produce that afternoon. The difference between "documented same-day response" and "the firm is investigating" is the difference between a story that ends and one that runs for six months.

Learn

Where the firm actually stands against peers

Halcyon and Law.com publish quarterly mid-firm posture benchmarks. The managing-partner dashboard surfaces the firm's position against peers of the same head count and practice mix, so partner-meeting decisions come with a reference point instead of a guess.

F500 client SIG lands

Moment 01
???

3 days of reconstruction
from email threads

Sourced answers,
dated, defensible

The client’s procurement team asks for the security posture; the firm returns evidence sourced from the live program — not reconstructed from email under a ten-day clock.

Cyber-insurance renewal

Moment 02
1×2×

Premium doubles
or policy denies

1×1×

Flat renewal on a
FAIR-quantified packet

Cyber-insurance carriers (CNA, Brit, Beazley, Chubb) reprice mid-firm renewals against the 2026 SRG controls set. A FAIR-quantified packet with Loss Exceedance Curve + tabletop + MSP-oversight evidence attached is what keeps the premium where it was.

MSP requests root access

Moment 03
?

MSP compromise
months later

24h

Disclosure clock on;
intel watches peer hits

The MSP joins the governed register with a written agreement and a 24-hour disclosure clock. The platform’s incident-detection feed (CVE databases, government advisories, security news, vendor status pages) auto-declares matching incidents against the register — so when an MSP compromise hits the wires, it’s in the firm’s queue before it’s in the news.

Suspected breach at 8 PM

Moment 04
?

Which clients are
in scope?

OP 483

Client-by-client list,
state-bar layered

Formal Op 483 triggers a client-by-client notification duty. The list assembles from the live matter data with material-sensitivity per client and state-bar layers already mapped, so the ethics-committee review is looking at a workflow, not a scramble.

§ IV. Contents of the Program

The full deliverable inventory.

Every deliverable is exportable in the format a client SIG asks for, a cyber-insurance underwriter scores, or a bar counsel would request in an inquiry.

InfoSec policy set · twelve templates
MR 1.6(c) reasonable-efforts policy authored, owned by a named partner. Confidentiality, incident response, vendor oversight, physical security, remote work, AI use.
Policy management
Vendor + MSP + outside-professional register
Every relationship with client-matter access flagged. Agreement + security questionnaire captured. Breach-disclosure clock tracked. One export when a client's GC asks.
Vendor register
Industry threat-intelligence feed
Silent Ransom Group / Luna Moth / UNC3753 flagged against the register in near-real time. Notification timing from the platform, not from a news cycle.
Vendor incident intel
Tabletop exercise + participant-tracking artifact
Facilitated tabletop with actual partners and associates. Participants, date, scenario, after-action findings captured. What a carrier and a bar counsel each want to see.
Executive reporting
One-page training PDFs
Physical-security-at-reception, vishing-verify, MSP-risk-signals, incident-report-within-24-hours. What a partner drops on a staff-meeting agenda in five minutes.
Training library
Formal Op 483 notification workflow
Client-by-client list from live matter data. Material-sensitivity classification per client. State-bar and statutory layers mapped, ready to run.
Incident workflow
Client SIG / OCG response library
The 30-question client addendum answered from live evidence. Every response sourced, dated, defensible. Reusable across every F500 client sending the same question set.
Security questionnaires
Cyber-insurance renewal packet · FAIR
FAIR-quantified breach scenarios with Loss Exceedance Curve, control attestation, mapped to what CNA / Brit / Beazley / Chubb actually ask after the 2026 payout year.
Executive reporting
Managing-partner dashboard
Outstanding client SIGs, expiring agreements, policies due for re-adoption, next tabletop date. One-glance view for a monthly firm meeting.
Executive intelligence

§ V. The program’s cadence

The platform runs the cadence. The firm signs off where it counts.

The InfoSec program is a running operation, not a lawyer’s side project. Most of it happens without pulling anyone off matter work. The rest lands in the right role’s queue at the right frequency — MSP or IT support, firm administrator, managing partner. Nobody has to build anything from scratch on a Tuesday.

Frequency
On autopilot
The firm signs off
Continuous
Evidence collection from every integration (Okta, Duo, Clio, iManage, NetDocuments, Barracuda, MSP RMM)
Industry threat-intel scan against the vendor register
—
Daily
Vendor incident signals auto-declared into the response queue
MSP / IT support reviews the day's declared incidentsMSP / IT support
Weekly
Client SIG / OCG response drafts assembled from live evidence
Firm administrator approves SIG responses before they go back to the clientFirm administrator
Monthly
Managing-partner dashboard updated with SIG status, register drift, upcoming renewals
Register-drift flags for expiring agreements and new vendors
Managing partner reviews dashboard as a fifteen-minute agenda itemManaging partner
Quarterly
Framework attestations re-projected against evidence drift
Facilitated tabletop exercise with the firm's actual partners and associatesFirm-wide
Managing-partner oversight attestation signedManaging partner
Annual
Cyber-insurance renewal packet assembled the quarter before the renewal date
Policy-review schedule fires on its cadence
Renewal packet sign-off and carrier submissionFirm administrator
Policy re-adoption voteManaging partner + partnership

§ VI. Terms of Engagement

Eight weeks in. Then the cadence takes over.

Pricing lives on the pricing page. What follows is the one-time stand-up sequence: five phases across eight weeks, then § VI’s cadence carries the program forward.

01
Weeks 1 – 2
Intake + policy adoption
Managing partner signs off the policy set. First vendor-register import from the firm's practice-management stack.
02
Weeks 3 – 4
Full register populated
Every vendor, MSP, and outside professional captured with agreement + disclosure clock per row.
03
Week 5
First tabletop scheduled
Scenario tuned to the live threat conditions (MSP compromise via vishing in the 2026 kit).
04
Week 6
Training library staged
First one-page PDF distributed. Attestation tracking on.
05
Weeks 7 – 8
First SIG dry run
Response library exercised against a real client addendum. Renewal packet drafted if a renewal is in scope.
Steady state
Cadence @ § VI
Mid-crisis ruleFirms arriving with a client SIG in hand or a cyber-insurance renewal quoted at 2× get the artifacts unblocking the immediate deadline first. Everything else on the timeline follows.

§ VII. Counsel of Record

A real vCISO on the engagement.

Retained counsel · Ultra tier and above

A real vCISO. Not “book time with our partner network.”

Client outside-counsel-guidelines cyber-addendum negotiation. Malpractice-carrier questionnaire response prep. Bar-counsel inquiry response readiness with a dated artifact chain. Tabletop facilitation with your actual partners in the room. MSP oversight and outside-professional agreement redlines. Ultra tier includes 4 hours per month of vCISO consulting; the Fractional CISO SKU adds a dedicated 8-hour-per-week engagement.

§ VIII. How your firm’s data stays yours

Scoped to your firm. Auditable by anyone you point at it.

A firm choosing an InfoSec platform is choosing a subprocessor for privileged material. The four things below are how we hold that responsibility.

Logically isolated

Each firm is its own organization boundary. SIG responses, Formal Op 483 workflows, tabletop scenarios, and every matter reference the platform captures stay scoped to your firm. No cross-tenant access. Single-tenant isolation available on Enterprise.

Standard controls

Multi-factor authentication required. Role-based access within your firm. End-to-end encryption at rest and in transit. No vCISO Lite staff access to matter content without written authorization from the firm.

Independently verifiable audit chain

Every action your program takes — policy adopted, register updated, tabletop closed, SIG returned — lands on a hash-linked audit chain your own auditor can verify independently. Chain integrity holds without depending on any other vCISO Lite system.

Your subprocessor, on your terms

When your firm signs up, vCISO Lite goes on your own vendor register with a written agreement, a disclosure clock, and a data-subject-request path. A governed row in your program, held to the same terms as any other subprocessor.

Full documentation, security questionnaire, and current attestations · Data Protection →

§ IX. Is this you?

You’re the right fit for vCISO Lite if any two of these are true.

Managing partners and firm administrators don’t three-way shop compliance vendors. Either the firm is carrying enough client-facing pressure that the compliance program is straining what can be run manually, or it’s about to be.

  • Bar counsel opened a compliance inquiry after a client complaint about handling of privileged material.

  • An F500 client just sent a security addendum to your outside-counsel guidelines with 30+ questions.

  • Your cyber-insurance renewal came back at 2x with a physical-security-at-reception ask.

  • Your MSP is requesting root access to workstations and no one is capturing what they will and won't touch.

  • A peer firm was named in the 2026 Silent Ransom Group extortion list published by The Insurer.

  • You share a co-counsel arrangement with a firm that just had a breach.

If the firm is BigLaw with an in-house InfoSec team, a dedicated CISO, and a live IR retainer already on file, an enterprise-GRC platform plus internal staffing is the right shape. If the firm is a solo carrying baseline coverage and no client-facing security asks, the standard requirements from insurance and bar-association guidance are usually enough. The 10-to-200-attorney mid-firm segment sitting between those two, with real client-matter exposure and no full-time CISO, is us.

§ X. Frequently-Raised Questions

What managing partners ask us

  • What actually happens if bar counsel opens an inquiry into the firm?

    The complaint arrives. Bar counsel requests the InfoSec policy in effect on the date of the incident, evidence that the policy was operating, the vendor register, the client-by-client notification actions taken, the tabletop drill records, and the technology-competence education documented for the workforce. Counsel does not want a marketing deck; counsel wants the artifacts, dated, findable. If the firm ran vCISO Lite the day of the incident, those artifacts are already in the platform. If not, the firm reconstructs from email threads and shared drives, under a clock, and hopes what is produced meets the reasonable-efforts bar.

  • We already have an IT consultant or MSP. Why do we need this?

    The IT consultant or MSP runs the technology. vCISO Lite runs the compliance program on top of the technology, so a bar counsel or a cyber-insurance underwriter can look at what the firm had in place before an incident and see a written policy, control-by-control evidence, a vendor register (with the MSP itself as a governed row), and a tabletop artifact. The two roles are complements, not substitutes. Firms that skip the compliance-program layer keep paying for IT and still cannot answer the SIG a client sends them or the questionnaire the carrier sends them at renewal.

  • What size firm is this built for?

    10 to 200 attorneys is the sweet spot. Mid-firms with real client-matter exposure and no full-time CISO. Solos and very small firms often get by on baseline requirements from their existing insurance and bar-association guidance. BigLaw has internal teams and specific tooling. The mid-firm segment is the one Law.com and Halcyon both name as the growth segment for cyber incidents in 2026, and the segment where the fractional-CISO plus platform structure most cleanly maps to what client SIGs are asking for.

  • How fast does the program stand up, and what does month one look like?

    Eight weeks to a fully populated program. Week one is intake with a real vCISO — not a chatbot, not a partner-referral network — walking through what the firm already has and what the platform will produce. Firms arriving mid-crisis (a client SIG in hand or a carrier renewal quoted at 2x) get the artifacts unblocking the immediate deadline first, then the rest on the timeline.

Reasonable efforts in evidence, on a subscription that fits the firm.

The next SIG on Tuesday. The next cyber-insurance renewal in Q4. The next tabletop before year-end. All from one program, all defensible on the day someone asks.