https://www.ocbar.org/

OCL Featured Articles


Posted on: Dec 26, 2018

by Merry Neitlich

They say change is the only real constant. And the changes in the practice of law are increasing with alacrity these days, especially with regard to technology and innovation.

According to Doug Hafford, CEO of Afinety, a legal technology consultancy based in Encino, California, keeping up with technology is a key issue in which most law firms are significantly lagging. Clients these days demand increased use of technology to protect them, their intellectual property, and confidential information. And they are seeking more efficient results on their matters. In addition, Doug points out that technology can assist a firm to run more smoothly, dynamically, and profitably.

Small and mid-sized law firms increasingly find themselves competing with large firms with vast IT budgets. One of the key ways these firms can compete is to surpass the manpower edge of the larger firm through the efficiencies and capabilities of high-value information technology (IT) solutions. According to Doug, the most important and savvy technologies to consider consist of five broad concepts, discussed below.

Mobility

Law firms need to allow attorneys to work remotely in a secure and safe environment. Utilizing this type of technology effectively requires a high level of security because of the ever-increasing sophistication of malware, robots, and other types of attacks. Providing secure remote access removes the tether to the office, allowing a firm to hire outside of its geographic area. Full-time remote users are becoming the norm rather than the exception. Once implemented and secured, the lawyer can work from anywhere using a wide variety of devices. In home and remote offices, courtrooms, and even during travel, an attorney can stay in touch and work on client matters outside the office.

Security

Ransomware has co-opted many law firms’ databases, documents, or financial records. Bad actors use ransomware to extort the firm by threatening to destroy information if they are not paid an amount to an offshore account or some other untraceable location. Law firms can avoid this problem by first using preventative measures to keep obvious phishing attacks from ever reaching the user. Mimecast, for example, offers “targeted threat protection,” which effectively stops phishing, the source of most ransomware. Keeping in mind that nothing is perfect, it is also extremely important to train users to recognize fake emails quickly and easily.

One prevalent scam comes in the form of an email to an assistant, paralegal, or associate. An email arrives on this person’s desk presumably from the managing partner, practice group leader, or an executive committee member. It requests that the recipient wire or transfer funds to an account immediately to pay for some well-defined scam. These emails seem so real because they appear to come from within the law firm itself. Many staff members have been duped into sending a large amount of funds to a fictitious address or place.

Numerous firms now have outside consultants who provide training on avoiding these scams. For example, some of Afinety’s clients take part in Afinety University, which provides this, among other types of common training for law firm staff.

Single-Pane Software

Firms need a “single pane of glass” in which they can see everything they need. Many firms have applications that do not communicate with each other. If information and data are widely scattered, an attorney might have to talk to Ralph to find one type of information or wait until Mia returns from vacation to get access to obtain other data. Does this sound familiar?

There are many solutions available today, such as Prolaw, which offers that “single pane of glass” that can provide the user any information they need, simply by knowing something about the client or matter. There are of course others, such as AbacusLaw, TABS with Practice Master, and some web-based software such as CLIO. These packages can integrate time and billing, accounting, client relationship management, case management, calendaring, and docketing among many other features.

Audit Preparedness

Clients, and not just large corporations, are more than a little concerned about data breaches, and rightly so. Clients have sued, and may continue to sue, their law firms for catastrophic amounts when there has been a significant data breach. And we are seeing more and more of these lawsuits over time.

When firms do business with financial institutions such as banks, investment firms, or insurance providers, these large organizations require their legal counsel to undergo an annual security audit. These audits are often difficult, if not impossible, to pass without significant investment in security technologies. Many firms have turned to large cloud providers, such as Amazon Web Services (or AWS) and Microsoft Azure, who offer highly secure, massively redundant platforms on which to house a law firm’s network. These providers have security certifications and offer features such as In-Motion and At-Rest encryption, Multi-factor authentication, redundant power, internet and storage, as well as strong physical security suites. When choosing this option, it is important to select a provider who knows the legal industry and uses these highly sophisticated cloud platforms. This combination provides the finest security in the world, and the peace of mind that the firm’s data is encrypted and safe from any sort of malfeasance.

Proper Disaster Recovery Planning

Even if your law firm has cloud backup, if your firm is exploited or becomes a victim of ransomware, it can be devastating. Disaster recovery is about much more than getting your data back. Here are some considerations.

Recovery Point Objective (RPO): If your firm is infected, how much data will be lost if you are forced to restore an older backup? Common on-premises backup solutions often have an RPO of 24 or 48 hours of lost work. A cloud network, by comparison, might offer an RPO of one to two hours. So, if a ransomware attack happens, how much data would you lose?

Recovery Time Objective (RTO): Often firms find the cost of cloud backup to be prohibitive, so they choose to limit what is stored there. Keeping this in mind, should an attack happen, or if the firm’s office becomes unavailable, how long will it take to get back to full operation? For on-premises networks, these times are often in the neighborhood of several days to more than a week.

Who Does What?: As important as it is to own technology, your staff and the firm must have a detailed and in-place responsibility plan. If something happens, who does what and when? How does the firm communicate internally and to its clients? A law firm that cannot communicate, or demonstrates a lack of planning, can easily go under without a rather simple emergency plan. Overall, being prepared is crucial because it is not a matter of “will it happen?” “but most likely when?”

Will your firm embrace these new technologies and safety precautions? The prudent thing to do, and the way to instill confidence in clients, is to be prepared.

Merry Neitlich is Managing Partner of EM Consulting, and can be reached at merry@EMconsults.org.

© 2026 Orange County Bar Association, All Rights Reserved. Terms of Use.