When a cyber incident strikes a law firm, the first hour is often the difference between a contained disruption and a full‑scale crisis. In those early moments, decisions are made quickly, sometimes emotionally, and often without the benefit of a formal plan. Yet this is exactly when clarity matters most.
Cyber Attacks and Law Firms
Law firms face a unique kind of pressure during a breach. Client confidentiality raises the stakes. Matter data sits across multiple systems. Staff may be working remotely or on personal devices. And every minute of downtime affects billable work, deadlines, and client trust. That’s why the first hour needs to be handled with discipline, even if the situation feels chaotic.
The First Ten Minutes: Stop the Bleeding
The very first step is simple: isolate the problem. If a computer is behaving strangely, disconnect it from the network. Pull the Ethernet cable, turn off Wi‑Fi, and leave the machine powered on. Shutting it down can erase evidence your IT team will need later.
At the same time, alert whoever handles your IT — whether that’s an internal lead or an outside provider. Don’t wait until you “have more information.” Early notification is your best chance at containing the issue.
Finally, send a quick message to staff telling them to pause activity. You don’t need a long explanation. A short, direct instruction: “Please stop using firm systems until further notice” is enough to prevent the incident from spreading through active sessions.
Minutes Ten to Twenty: Contain the Damage
Once the immediate threat is isolated, the next step is understanding what’s affected. You’re not diagnosing the malware or trying to fix anything. You’re simply identifying which systems appear compromised: email, case management, shared drives, cloud accounts, or remote access tools.
With that rough picture in place, begin locking down access. Change passwords for critical systems, especially administrative accounts. If your firm uses multi‑factor authentication, this is where it pays off. If it doesn’t, this is where you’ll feel the absence.
Remote access should be disabled temporarily. Many attacks begin with stolen credentials used through VPNs or remote desktop tools. Closing those doors early prevents attackers from moving deeper into your environment.
Minutes Twenty to Forty: Stabilize and Document
This is the point where the adrenaline starts to settle and the work becomes more methodical. Start keeping a simple log of what’s happening. Write down who reported the issue, when it began, what systems appear affected, and what actions have been taken so far. It doesn’t need to be formal. It just needs to exist. Later, clients, insurers, or regulators may ask for this timeline.
Check your backups — not to restore them, but to confirm they’re available and intact. Restoring too early can make things worse, especially if the attacker is still active.
You should also communicate with staff again, this time with a bit more context. Let them know what’s happening, what you need from them, and when they can expect an update. Clear communication prevents rumors, panic, and accidental mistakes.
Minutes Forty to Sixty: Prepare for Full Response
By now, your IT team should be engaged and beginning forensic work. They’ll look at logs, analyze suspicious files, and determine whether data was accessed. Their findings will guide the next steps.
This is also when you begin thinking about client notification. Not every incident requires it, but law firms have ethical obligations that go beyond typical business requirements. If there’s any chance client data was exposed, you’ll want to consult your IT provider and, if necessary, your malpractice carrier.
Finally, decide whether to activate your full incident response plan. If you don’t have one, the past hour has effectively become your plan. That’s not ideal, but it’s common — and it’s fixable.
Throughout this period, keep documenting. Every decision, every observation, every action. It’s tedious, but it’s invaluable later.
What Not to Do In a Cyber Attack
There are a few actions that consistently make incidents worse. Don’t reboot the affected machine; it wipes volatile evidence. Don’t try to “clean” the infection yourself; many attacks include secondary payloads that activate when tampered with. Don’t communicate with attackers. And don’t assume cloud systems are safe simply because they’re hosted elsewhere. If credentials were compromised, everything is potentially in play.
Why Law Firms Struggle in the First Hour
Most guidance online is written for enterprise IT teams with full‑time security staff. Small and mid‑sized firms operate differently. They rely on outsourced IT, hybrid work environments, and a mix of legacy and cloud systems. They need practical, plain‑language steps that work even when the managing partner is the one making the first call.
This playbook is designed for exactly that scenario.
How WCA Technologies Helps Firms Prepare
The firms that handle incidents best are the ones that prepare before they need to. WCA Technologies works with law practices to build incident response plans that match their workflows, run tabletop exercises that don’t disrupt operations, strengthen cybersecurity controls, and ensure compliance with legal‑industry standards. Preparation turns panic into procedure — and procedure protects your clients, your reputation, and your business.
For more information, contact WCA Technologies or call us at 212-642-0980.

