Cybercrime – How you respond matters episode artwork

EPISODE · Feb 26, 2025 · 19 MIN

Cybercrime – How you respond matters

from Risk on Air

In this episode, host Julian Morrow is joined by Malcolm Heath, Lawcover’s Practice Risk Manager, to unpack a five-letter word that could feel like a four-letter one: CYBER. The key question isn’t just how to prevent a cyber-attack but also how to respond when it happens—because how you respond can make all the difference. Transcript: Cybercrime – How you respond matters Additional Resources lawcover.com.au

Episode metadata supplied by the publisher feed · Published Feb 26, 2025

Embed this episode

NOW PLAYING

Cybercrime – How you respond matters

0:00 19:58
of MATCHES

TRANSCRIPT · AUTO-GENERATED

This is Riscon Air by Lore Cover. Today's episode, Cyber Crime, How You Respond, Matters. Welcome to Riscon Air, I'm Julian Morrow, and I'm joined today by Malcolm Heath, Lore Cover's Practice Risk Manager, to discuss a five-letter word that could also be a four-letter word. Cyber, it's a huge area of concern for all businesses, but particularly law firms.

It's listed in many surveys as the biggest operational challenge that law firms are facing, and that something firms across the spectrum have to be absolutely focused on, isn't that right, Mal? That is exactly right, Julian. Now, how big a challenge is cyber for law firms at the moment? Interesting question.

On one hand, it's an enormous challenge, because of the size and scale and ongoing nature of this crime, yet at the other end of the spectrum, it's actually very manageable to minimise the impacts of cyber crime. So, on the scale of this enormous crime that's really only 10 years old now, and really for the legal profession in Australia about eight years old, in terms of professional negligence claims, such as a new area of crime, at the top end it's a huge issue, but we can manage it fairly effectively with fundamental improvements in what we do. And, essentially, you say minimising the risk, I think there was a time where perhaps we thought, oh, well, that might happen to someone else, but it's not going to happen to me. Really, you have to approach things on the basis that it is going to happen to all of us at some point, and you've got to get the processor systems and the mindset in place for what it does.

Yeah, that's really important to think of the mindset. I think that's the first part to understand the size and scale of it, and also to understand that I have to change. And if I've already changed, I have to keep on changing and improving, because we can't get to Basecamp 1 and think we've done it, we're finished. And that actually happened with a firm who had a cyber attack and was found out that they did their training some years ago, and nothing since.

And they left vulnerable as a consequence of lack of follow-up. So it may have been a tick box exercise to do that initial training. We've done that, that's fantastic. We're all aware now.

And we went for those easy traps that they did. Isn't that interesting? Because the top types of cybercrime that are reported are pretty familiar. It's email compromise, particularly business email compromise, and online banking fraud.

But the techniques within those categories are changing all the time. And so the training that you got last time might not equip you for what the scammers are up to these days. Very true. The psychological aspects are getting more sophisticated.

The techniques are improving, and that's where we have to adjust and remind ourselves, never to think on top of it. And is this something that you're actually seeing at a claims level at Law Cover Now? Yes, it's ongoing. We still see the business email compromise issues.

We still hear from the principles I never thought they're going to be after me, or my firm. I'm a small law firm. Why would they be after me? And that they sort of personalised it, which is a mistake rather than thinking.

The criminals are looking for vulnerabilities in systems. And that's what they're after, rather than after Julian Morrow or Mountain Heath. And teaching from what you're saying there, you're seeing the risks popping up at firms of all sizes. Absolutely, and particularly smaller firms who may be more vulnerable in the belief that they're not after my firm.

Or they're operating on a tight budget and are not investing appropriately in IT security and in the education. So let's talk about what you should do. If you find yourself in a situation that you know there's been a breach, or you just think there might have been one, how should a practitioner in that very, very unwelcome place respond? Yeah, and that's very important to think we may have, rather than being definitive.

Let's be a little bit proactive and do an investigation where we think there's unusual activity. Yeah, so if you're in that really unwelcome position, past your practitioner or a practice manager or anyone in a law firm respond? Firstly, they should contact their IT service providers. Depending on the size of the firm, they may have an internal IT team or their external provider.

And these are the days now for the smallest of firms to have an IT support service available and contactable. And also they can notify of a potential problem under the law cover group's side-risk insurance policy. That's the policy that coincides with the law cover professional and deputy insurance policy. So for a firm that's opening up for the first time, they will have their professional and deputy insurance policy, but automatically there's a foundational level of cover with the side-risk insurance policy.

If the firm's renewing the same process, they renewing their professional and deputy insurance, automatically that side-risk insurance policy comes into play. Foundational level of cover, but very important, and there's a number there which is so important to note, which is 1-800-427-3-2. 1-800-427-3-2, or 1-800- disappoint to it, was 1-800-4 breach. Now you can call that straightaway, yeah?

The lines are open now. Yes you can. And that can be very supportive. It can immediately relieve the pressures on this list, knowing that there's technical expertise at hand, either through their competent IT provider or through the side-risk policy to discuss a process going forward.

So not only have you formally notified you're in touch with someone who deals with these issues all the time, they can give you the practical advice that you might need and probably is feeling a little bit more calm than you are when you call. That's exactly right. Very good point to it about that pressure when we're anxious. Yeah, well, you've alluded to the fact that this has been an active area of claims for law cover.

Could you give us a sense of what sort of situations it's been that have happened within a law firm that have led to a claim bank name? Over the last 12 months, we've seen an elevation in telephone fraud in personation fraud, whereby the impersonator is allegedly calling from the Law Firm's Bank. And they're speaking to the partner, they've been directed through to the partner, and they are talking about identification of unusual activity in the law firm's trust account. Right, so the scam is, it sounds like you're being alerted to unusual activity in the account, but in fact, the call itself is the scam.

That's exactly right. So the scam is talking about a scam. And when we mention trust account peculiarities, uncertainties to a solicitor, Red flags, and heart rate escalation. Making me nervous just talking about it now.

It's making me get goosebumps about it too. Heart rate may be from a normal resting pulse or working at the desk pulse, leading up towards 200, 220 with that type of information. Now the behavioral response, when we hear this, it's connected as an extreme disaster for the law firm, we are then thrown into a state of anxiety. And it's at that particular point that the fraudster is able to do their best work because of the panic that's building.

And when we're panicked, we don't think straight, and we do actions that we would never normally do in a calm state of alertness. You can see that essentially the fundamental purpose of the scam is to get you into that state as quickly as possible, because most scams are the result of human error. And when we are anxious, maybe even panicking, that's when those errors are most likely to happen. That's exactly right.

And the fear that comes into play is fear driven for the practitioner is significant, and they want it to stop. It's also a real challenge, isn't it? Because your intuitive response in a situation like this would be, well, I need to speak to the bank, or you might feel like you are speaking to the right person while you're being scammed. So how do you deal with that?

Yeah, this is the thing where it seems when we're talking about the cold light of day, I would never do that. I wouldn't fall for that. I would always hang up and call the name myself, which is exactly what should be done. But when we're in a panic state, it's really fight or flight.

And this is to try and stop the problem that's occurring in the law firm's trust account with clients, funds, potentially going elsewhere. And so this is the point of call who's helping. They've alerted us to the problem. They're here to help.

It seems to me because what we're talking about is if it's actually happening, an emergency. But what you just said there is that good practice is probably to put the phone down and call back. Isn't that introducing an element of delay into an emergency scenario amount? That's right.

Because it allows you to collect your thoughts and think of the process in a crisis. We're not going on your leave. Take a whole day and look at it next time. That's right.

But give yourself a moment and put a break in that in the cycle of worry. Exactly. It's a pause. It's important to pause and treat it like, okay, this is a crisis.

I'm a first aid responder. So I'm not going to run over to the victim because my running across the road puts me in immense danger. And then I cannot help that person that I actually went out to try and help. So I've defeated the entire purpose.

It's far better for me to look around and check my own safety. And when I understand that it's clear, I can walk across to that victim whilst thinking about the process I'm going to take in triage whilst comfortably getting up my phone and dialing triple O and thinking about the location to report where I am as well and going over to the person who's injured. So there's a whole variety of calm thinking that we can do to better manage a crisis. So it's very hard to transfer that thinking into a calm office environment.

But that's the discipline and the changing behaviours that we need to think about when we have those left of field calls. And it's also a situation where different people are going to respond in different ways. And to extend the analogy, if you go into an emergency department at the hospital, what you see and what those departments rely on is teamwork. More than one person being involved is the same apply to cyber risks for lawyers now.

Absolutely. It's a great analogy to look at the team and the support that's available. So that is your IT security. It's another colleague within the firm.

If you are a sole practitioner operating by yourself and you don't have a colleague in the firm or your IT team, you can contact another colleague that you've got a trusted relationship in and one that you know is a sound rational thinking colleague. Make sure you call your bank's fraud team. Or if you're nearby, if you're a suburban firm, walk to your bank and go to the bank and speak to them there. Minutes will not be the difference between total disaster and far better management.

Yeah, yeah. And often it's about making sure that there's an independent line of communication initiated by the practice themselves, not something that's coming in externally because that's where these games come from. Exactly. We need to be street smart and aware.

Not totally suspicious of everybody and everything, but that awareness when there is something left to feel. And putting in place steps in the process, simple opportunities to take that breath to pause and to restart communications in a way that you can internally say, yeah, I know that this is actually going to be a safe communication. How do you think law firms are going now? I mean, terms of prepping themselves for these sorts of scenarios and then dealing with the possible or actual cyber crisis when it comes.

There is a gigantic spectrum of well. Some are doing it excellently. They're at the best practice level and others are still back 10, 15 years in their IT security and they're thinking about their systems and processes in their firm. And that's driven by a number of factors that can come into play.

It's a lack of awareness or understanding, financial pressures. We can't invest in appropriate IT security and support services. We are in denial stage and there's a whole spectrum in between. And what about basic stuff like password security and multi-factor authentication?

Is it big and small doing well on that front? Mixed. Like everything mixed. And so it is imperative to have password protection, complex passwords and they're changed on a regular basis across all endpoints of the law firm's computer system, not forgetting our handheld devices.

If we are operating work from our handheld devices, the security level on those should be as robust as the law firm's computer system as well. Virtual private networks are important. Free Wi-Fi days, public Wi-Fi should be dismissed. And password protection Wi-Fi, multi-factor authentication is very important as well on all outputs.

And we are still seeing when there's been a business email compromise that many firms still haven't implemented multi-factor authentication across all their law firm's computer system's endpoints. So it allows simple entry. Once the criminal has accessed the firm, we know that business email compromise, they'll go into Microsoft Outlook Rules, they'll change the rules, redirecting emails as read and into an archive box or a delete box or another sub-inbox that the solicitor or support staff member never really looks at. Then they've got all the time that they need to read and manipulate information within that email change addresses.

They can put in rules to redirect the client's email to their email that they want to use. And in recent examples, that has happened where the criminal is liaising directly with the client of the law firm. The client thinks they're liaising with the law firm, but those emails are no longer even reaching the law firm in the archive box. They've been redirected by the Microsoft Office Rules that have been manipulated by the criminal.

Sometimes phoning the client periodically throughout a transaction, knowing that it's the client's phone number that you've got from the original file, not from the one in the email, to confirm information, to give them an update. In the scenario I've just been talking about, they may say that I've sent you all that information and you've responded. And there's the red flag straight away saying, well, actually, no, I haven't received anything and I haven't responded. And you know then that there's a potential problem and then can make the appropriate investigations rather than if we are solely relying on email communications as our only source of communication with the client, that's now much higher risk than it used to be.

And a timely reminder there, Malcolm, that looking out for the best interests of a client involves not just thinking about your own systems and people, but also your client's systems and people because of breach on either end could be disastrous. That's right. So we're seeing many firms improving their own security systems, their education and training and implementing all the appropriate things. And that's fabulous.

Are they having the conversation with their clients about cyber risk? Simply, you know, some simple mechanisms like if I've been directed to transfer $700,000 into a law firm's trust account, why don't we do a test $10 before I potentially send $700,000 to a criminal's account? You know, it's that type of thinking that we need to change simple things to look at better protections. You know, one small firm saw a practitioner right on top of saying, yes, you know what I do, I always meet my clients face to face.

So there's the perfect client identifications and would provide the client with a code word. That can be a simple way. So when they call, when it's to do with critical information transfers such as funds transfers. And essentially, it seems like a way that you can be improving both your cybersecurity, but also the relationship with the client.

You're making it more human and personal in a way which is good for the broader relationship while you're minimizing your cyber risk. That's so correct. Yes, it does take time, but there's an investment in that time that it takes and it's providing a higher security level for your clients and giving greater confidence to your clients. We've been focusing on, if you like, the psychology and mental preparedness required for these sorts of situations, but it's worth probably also mentioning the changing regulatory environment as well as an increasing intertwining of cybersecurity issues and privacy issues and regulation as well.

Any comments on that? Yeah, there's a raft of legislation coming through changes in the Privacy Act. There's still the $3 million threshold which alleviates some of the responsibilities for smaller organizations to have to report on notifiable data breaches. However, that's likely to change the great majority of our firms who we ensure have turnovers of less than $3 million.

And they will need to be on the front foot about responsibilities in notifying. Yes, a recent changes to the Privacy Act, the cybersecurity legislation went through, but this is a very active area. Prospect that there will be more changes along the lines and something that you really are going to be making sure that you're up to date within your knowledge. Yes, and I think the important point which you touched on earlier was it's a collective.

We can't try and deal with this individually. The criminals work in clusters and groups and communities. They're sophisticated and clever. And if we try and defend this alone, we will be targeted and keep on learning and look at it in a positive light.

There are always opportunities that we can get a competitive advantage if I'm working on my firm's security and confidential information and I'm looking at encrypted services and I'm able to communicate the level of competencies to my clients to give them a higher level of confidence themselves. That may put me in a far better position going forward. Well, Malcolm, it's been fascinating discussing the latest cyber risks and how to respond to them. Something tells me the conversation will need to continue.

So let's have another chat another time. Thanks, Jordan. Thanks very much. And of course, there are plenty of cyber resources on the Lore Cover website, go to lawcover.com.au or if you do need to get in touch by phone anytime of the day or night because you've experienced the possible breach, that number again is 1-800-4-breach or 1-800-427-3222.

Thanks for listening to Risk on Air by Lore Cover. And to stay up to date, join us for the next episode on Current Risks in Legal Practice.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Risk on Air?

This episode is 19 minutes long.

When was this Risk on Air episode published?

This episode was published on February 26, 2025.

Can I download this Risk on Air episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!