Ransomware Playbook for Orange County Law Firms
By Tom Hermstad · HD Tech

What should an Orange County law firm's ransomware playbook actually include?
A ransomware playbook for an Orange County law firm must cover three phases: before an attack (access controls, encrypted backups, MFA on case management systems), during an attack (isolation, evidence preservation, and a pay-or-don't-pay decision filtered through California Bar ethics guidance), and after an attack (breach notification under California's civil code, ABA professional responsibility obligations, and root-cause remediation). "Call your IT guy" is not a plan. Ransomware response is a legal, technical, insurance, and communications exercise — and law firms carry some of the highest-stakes client data in any industry.
By Tom Hermstad, Founder & CEO, HD Tech
It's 9 a.m. on a Tuesday. A staff member walks into your office and says the words you never want to hear: "Files are encrypting. I can't open anything."
Your case management system is frozen. Client files are locked. The ransom note is already on the screen.
Here's what separates firms that recover from those that don't: a written plan, tested backups, and a response team that knows exactly what to do before that call ever comes in.
You don't need a reminder that client confidentiality is sacred. You live it every day. What you might not have is a written plan for the day ransomware locks every client file, freezes your case management system, and forces a fast decision — one that determines whether your practice survives.
That gap is where firms get hurt. Not just in recovery costs, but in the trust of clients who handed you their most sensitive information. And in the legal industry, trust is the product. Clients choose firms based on reputation. They stay based on confidence. A ransomware event that leaks sealed depositions or settlement details doesn't just cost you money — it costs you the cases you haven't signed yet, and the referrals that were coming.
That scenario isn't theoretical. According to CISA and its international partners, ransomware remains one of the most significant threats facing professional services organizations. Legal firms are a high-value target. You hold confidential, time-sensitive data. Attackers know that a firm in the middle of litigation — or a deal closing — will feel maximum pressure to pay fast and ask questions later.
Here's what works. Let's get you ready.
Why law firms are a ransomware target worth planning around
Client files are worth money. Not just to you — to the people trying to steal, expose, or encrypt them.
A managing partner's firm might hold sealed depositions, financial records, immigration documents, custody files, and settlement agreements. A transactional shop carries due diligence packages, wire transfer instructions, and acquisition details that would be devastating in the wrong hands.
That's before you factor in the ethical dimension. California attorneys have duties of competence, confidentiality, and supervision that extend to technology. A breach isn't just a business problem — it's a professional responsibility problem.
Unlike a retailer, a law firm can't absorb extended downtime quietly. Deadlines don't pause for ransomware. Courts don't grant continuances because your email is encrypted.
Think about what one missed filing deadline costs. Recovery fees, malpractice exposure, and client relationship damage — all hitting at once. Understanding the real cost of a ransomware attack in Orange County means counting every layer of that impact.
Managed IT isn't a cost center — it's the infrastructure that lets you keep your word to clients. When your systems are secure and your backups are clean, you can look a prospective client in the eye and say your firm takes data protection seriously. That's not a marketing line. It's a differentiator that wins business, survives Bar inquiries, and holds up under client scrutiny when a competitor's breach makes the news. The firms that invest in a real security posture aren't just avoiding disaster — they're building a competitive advantage that clients can feel.
It's not if. It's when. So let's build the plan.
Phase 1 — Before the attack: controls that actually protect a law firm
Most "cybersecurity tips for law firms" lists are generic. Lock your screens. Use strong passwords. Update your software. That's table stakes. Here's what a real pre-attack posture looks like for a legal practice.
I genuinely love this part of the work. There is something deeply satisfying about walking into a firm, mapping their exposure, and watching a managing partner's shoulders drop when they realize — for the first time — that they actually have a plan. That's why we do this.
Require MFA on every system that touches client data
Multi-factor authentication — MFA, meaning a second verification step beyond your password — is one of the most impactful controls you can put in place today. CISA-aligned ransomware guidance lists MFA as a foundational control. Stolen credentials are a leading entry point for ransomware — not a sophisticated technical exploit.
For law firms, MFA needs to be active on:
- Your case management platform (Clio, MyCase, PracticePanther, or whatever you use)
- Microsoft 365 or Google Workspace email and document storage
- Remote access tools, including any VPN or remote desktop connections
- Your billing and accounting systems
- Any cloud storage where client files live
If a staff member's password gets phished, MFA stops the attacker from using it.
Encrypt client files at rest and in transit
File encryption means that even if an attacker steals your data before triggering the ransomware — a tactic called double extortion — those files are unreadable without the decryption key.
Double extortion is when attackers copy your files first, then lock them. They now have two ways to pressure you: decrypt or expose.
For a California law firm, encryption also matters legally. Here's the plain-English version of California Civil Code §1798.82: if an unauthorized party accesses your clients' unencrypted personal information, you must notify them. Encrypted data triggers a different analysis — confirm the specifics with outside counsel, because the facts of each incident determine the outcome.
Either way, encryption is a baseline for any firm handling sensitive client records.
Do offline backups actually protect a law firm from ransomware?
Your cloud backup is not a ransomware recovery plan. Ransomware is well-documented to target connected backup systems before triggering the encryption event. The Canadian Centre for Cyber Security's ransomware playbook calls offline backups a non-negotiable control.
For a law firm, that means:
- Backups that are air-gapped — meaning physically disconnected from any network — or separated by strict access controls
- Backups that are tested — someone has actually restored from them, not just assumed they work
- Retention policies that let you roll back to a clean state that predates the attack
If you haven't tested a backup restore recently, you don't have a backup. You have a belief.
This is where the "nephew solution" breaks down. Has anyone actually restored your client files under pressure at 2 a.m. — confirmed the data is intact, in sequence, and usable — before a ransom clock is counting down? That's the difference between a belief and a plan. A ransomware event combined with a breach notification clock and malpractice exposure isn't a Wi-Fi problem. It's a triple-threat crisis. And it requires a seasoned response team.
Document your decision authority in advance
Who has authority to pull the firm offline if ransomware is suspected? Who calls the cyber insurance carrier? Who notifies the managing partner in the middle of the night? Who communicates with clients if data was exposed?
These decisions can't be made in real time by people who are panicking. Write it down. Print it. Keep a physical copy somewhere that isn't on your network.
This is exactly where the Lifeguard Loop™ earns its value — the Listen & Learn phase maps your firm's escalation paths, names decision-makers, and puts everything in writing before you ever need it. Effective ransomware planning requires pre-identified stakeholders, pre-authorized contacts (including an external incident response firm), and a documented chain of command — all in place before you need them.
How does AI-assisted monitoring help law firms catch attacks faster?
According to the IBM Cost of a Data Breach Report 2024, organizations using security AI and automation reduced the breach lifecycle by about 100–108 days on average compared to those that did not — a meaningful advantage that can determine whether an attack is contained or catastrophic.
That window is everything.
AI-powered monitoring tools — think of them as automated tripwires running around the clock — watch your network traffic and user behavior in real time. When something looks wrong (a user account accessing hundreds of files at an unusual hour, or data moving to an unusual location), the system flags it and isolates the threat before it spreads.
The threat changes. So do we — and AI-assisted monitoring is now a core part of how the Relentless Response Engine™ catches attacks early enough to matter.
Network segmentation — keep case management isolated
If your case management system, email, billing software, and file storage all live on the same flat network, ransomware that gets in anywhere can reach everything. Segmentation keeps those systems separated so a compromise in one area doesn't automatically spread to all of them.
Ask your IT provider directly: "If ransomware hits a staff workstation, can it reach our client files?" The answer should not be "probably not."
Phase 2 — During the attack: a decision tree for the critical early window
The call comes in. Someone opened something they shouldn't have. Files are encrypting. Systems are going dark. Here is what happens next — in order.
This is where most firms freeze. Here's how you don't.
Step 1: Isolate immediately
Speed is everything here. Every second the ransomware runs, it reaches more systems — and more client files.
- Disconnect affected systems from the network.
- Physically unplug ethernet cables.
- Disable Wi-Fi on affected devices.
The goal is to stop ransomware from spreading to systems that are still clean.
Do not shut systems down first. Powered-on systems preserve volatile memory — RAM — that forensic investigators need to understand how the attack entered and how far it traveled. Disconnect, then preserve.
Step 2: Activate your incident response contacts — in parallel
While isolation is happening, make these calls at the same time:
- Your cyber insurance carrier — notify your carrier promptly. Delay can affect coverage. Your carrier may also have a pre-approved incident response firm ready to deploy.
- Your external IT or managed security provider — if you're running the HD Tech Relentless Response Engine™, we're already watching for anomalies. This call is confirmation, not discovery. This is the moment preparation pays off — and when a managing partner calls and we already have the picture, that's the whole reason we built this.
- Outside legal counsel — someone outside the crisis who can advise on notification obligations, privilege, and documentation from the first moment.
Step 3: Do not touch the ransom note yet
- Screenshot it.
- Do not click any links.
- Do not communicate with the attackers yet.
The ransom note contains information your forensic team needs to see in its original state. The decision about whether to pay comes later — after you know whether your backups are intact.
Making that call before you have that answer is how firms end up paying a ransom and still losing their data.
Trust, yet verify — especially here. Don't take the attacker's word that your backups are gone. Confirm it with your own team before the ransom conversation goes any further.
Should a California law firm pay the ransom?
There is no universal legal rule prohibiting payment. But this is not a decision you make alone, under pressure, in the early hours of an attack.
Thomson Reuters' guidance on surviving a ransomware attack is clear: the decision should involve legal counsel, your cyber insurance carrier, and a forensics team — not a unilateral call made under artificial time pressure from attackers.
For California attorneys, the ethical frame matters too. Your duty of competence — California Rule of Professional Conduct 1.1 — requires you to stay current on the technology your firm depends on and respond appropriately when it fails. Your duty of confidentiality means a ransom payment doesn't end your obligations. It buys decryption keys. It doesn't erase what the attacker already copied.
Work through this checklist before any payment decision:
- Are your backups intact and restorable? If yes, payment becomes much less compelling.
- Has the scope of data exposure been assessed? Know what was accessed before evaluating your ethical and legal obligations.
- Has your insurance carrier weighed in? Many policies have explicit requirements around payment authorization.
- Has outside counsel reviewed your notification obligations? Payment does not suspend your duties under California's breach-notification law or ABA ethics rules.
Don't pay until you've worked through every item on that list. And if your backups are clean, you have a path forward that doesn't involve funding the attacker.
Phase 3 — After the attack: breach notification, ethics obligations, and getting back to practice
Recovery from ransomware isn't just technical restoration. For a California law firm, the post-attack phase carries legal and ethical obligations that run parallel to the IT work.
Most managing partners want to jump straight to "restore the systems." Understandable. But the firms that come out clean on the other side do the legal and ethical work first — and the technical work right alongside it.
The stakes are real. According to the 2024 Verizon Data Breach Investigations Report, ransomware remains among the most prevalent attack types — and total recovery costs, once you add forensics, legal fees, notification expenses, and lost billable time, can substantially exceed the initial ransom demand. For law firms, where the billing clock never stops and client trust is the product, the full cost of a ransomware event lands harder than in most sectors.
What does California's breach-notification law actually require for a law firm?
If the attacker accessed unencrypted client records, you have a notification problem on top of a recovery problem — and the clock is already running.
California Civil Code §1798.82 requires you to notify affected California residents when their unencrypted personal information is accessed without authorization. The CCPA and the CPRA — California's consumer privacy laws — add a second layer of accountability on top of that.
For law firms, the categories of personal information at issue cover the vast majority of client files: names combined with financial account data, Social Security numbers, driver's license numbers, and medical information. The law requires you to act in the most expedient time possible and without unreasonable delay.
Start with the assumption that notification is required. Then work backward in this order:
- Have forensics confirm what data was actually accessed or exfiltrated — not just encrypted.
- Engage outside counsel to evaluate notification scope and draft client notices.
- Document your response timeline from the first moment of detection. That record is your defense if regulators scrutinize how fast you moved.
This is not the work your IT team does. It requires lawyers. And it starts the day the attack is discovered.
ABA ethics obligations — what managing partners are personally on the hook for
The breach doesn't transfer your obligation to someone else. It amplifies it.
ABA Formal Opinion 483 addresses what lawyers must do when client data is breached. Here's what that means in plain English:
Competence. You don't need to be an IT expert. But you do need to understand the technology your firm depends on — and respond when it fails. You can't hand this off and walk away. That's your license on the line.
Confidentiality. Investigate what client information was exposed. In most circumstances, you're required to notify affected clients. A ransom payment doesn't satisfy this duty. It buys decryption keys — it doesn't erase what the attacker already copied.
Supervision. Managing partners are accountable for how staff and vendors handled client data. If a vendor's system was the entry point, that doesn't transfer your obligation. It compounds it. Your name is on the door. No ego means owning the outcome regardless of who caused it.
Thomson Reuters' ransomware guidance for legal professionals makes this plain: post-attack remediation is a professional responsibility exercise that firm leadership must drive. Keep paddling — even when it's uncomfortable.
Technical restoration — the right sequence
Once forensics has documented the scope and you have a verified clean recovery point, restoration follows a structured sequence. Skipping one step puts you right back at risk:
- Root-cause identification — you can't restore securely until you know how the attacker got in. Restoring to a system with an unpatched vulnerability means the attacker is still inside.
- Credential reset — all passwords, all accounts, firm-wide. Not just accounts on affected systems.
- Restore from verified clean backup — the offline backup you tested before this happened.
- Staged reconnection — bring systems back online in segments. Monitor for reinfection before restoring the next segment.
- Post-incident review — document what happened, what worked, what failed, and what controls need to change.
The Relentless Response Engine™ applied to a law firm isn't "turn it back on." It's a systematic process: find the root cause, validate the restoration, and close the gap that let the attacker in. Watching a firm execute this correctly — and come out stronger — is one of the most satisfying things we do. Keep paddling through every step.
What does the Change Healthcare breach teach law firms about vendor risk?
The 2024 ransomware attack on Change Healthcare disrupted billing and data access across a large number of organizations that had no direct involvement in the breach. The lesson for law firms: your risk isn't just your systems. It's your vendors.
E-signature platforms, cloud document storage, practice management software, court filing services — if any of them are compromised, your firm's data and operations can be affected regardless of how well you've secured your own network.
Ask these five questions every time you evaluate a vendor:
- Do you have a written incident response plan? Ask them to summarize the key steps — not just confirm it exists.
- When did you last test it? A plan that hasn't been exercised is an assumption.
- Do you carry cyber liability insurance? Ask for the coverage amount and whether it includes third-party liability.
- What is your notification timeline if your systems are breached and our data may be affected? You need a specific answer, not "we'll let you know."
- Have you had any security incidents recently? How they answer this tells you more than the answer itself.
If a vendor can't answer those questions clearly, that's a risk to assess before an attack makes it an emergency. Trust, yet verify isn't a slogan here. It's a vendor-selection discipline.
"Careful attention to detail, solution-oriented services and implementation and fair pricing. We have worked with HD Tech for many years now and are extremely satisfied with their professionalism and capabilities." — Greg Burnight, Principal, APC, Curtis & Burnight, Seal Beach
How HD Tech applies the Relentless Response Engine™ to law firms
I'll be direct: this is the work I built HD Tech to do. There is nothing more satisfying than a law firm that survives a ransomware attack and comes out stronger on the other side.
We work with Orange County law firms as a Cyber Lifeguard — not a break-fix vendor you call after the water is already in the boat. The Relentless Response Engine™ means continuous monitoring, documented escalation paths, pre-authorized response actions, and a tested recovery plan that doesn't start with "let me check if you have backups."
We know before the call happens. We act while the window is still open. Today, that monitoring is AI-assisted — automated systems flag anomalies around the clock, so our team responds rapidly when it matters most.
If your current IT setup can't answer "what happens in the early moments of a ransomware attack at our firm," that's the gap we close.
We've seen how other high-trust industries handle this — from approaches that work in cybersecurity for dental offices to frameworks we've applied across managed IT services in Orange County. Law firms have distinct obligations, but the operational discipline is the same: prepare before, respond fast during, remediate completely after.
Don't be a casualty. Be exceptional.
Frequently Asked Questions
Not automatically — but assume it does and work backward from there. California Civil Code §1798.82 applies when unencrypted personal information is accessed without authorization. The vast majority of law firm client files hit that threshold — financial data, government IDs, medical records. Get outside counsel on the phone the same day the attack is discovered. Don't make that call alone.
Don't pay until you've checked your options. First, verify your backups — firms that pay before checking often pay for nothing. Second, call your cyber insurance carrier before any payment; many policies require authorization. Third, understand that payment doesn't erase your notification obligations or guarantee the attacker deleted what they copied. Get outside counsel and a forensics team in the room before you decide.
ABA Formal Opinion 483 addresses lawyers' responsibilities when client data is breached, covering competence (understand the failure and respond), confidentiality (investigate what was exposed and notify affected clients), and supervision (managing partners are accountable for how staff and vendors handled client data). The breach doesn't transfer your obligation to someone else — it amplifies it. Own the response from day one.
California Civil Code §1798.82 requires notification in the most expedient time possible and without unreasonable delay. What regulators look at is your documented response timeline. Start that documentation the moment you discover the attack — every gap in the record is a liability.
Test your backups. Not set them up — actually restore from them. Every firm I've worked with that recovered quickly had two things: clean offline tested backups and a written response document that named decision-makers before the crisis hit. Most firms that struggled had neither. Find out which category you're in before an attacker does.
Your firm's reputation, your clients' confidentiality, and your professional standing don't get a second chance in a ransomware event. The preparation you do today is the only thing standing between a bad day and a catastrophic one. Keep paddling — because the firms that come out the other side are the ones who refused to stop moving forward.
It's not if, it's when — book your free Cyber Preparation Assessment today. We'll show you exactly where your backup and recovery plan has gaps, what an attacker would find before you do, and what to fix first — so you're not making those decisions under fire.

Tom Hermstad
President & CMO, HD Tech
Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.
