Securing Buy-In: How Law Firms Engage Attorneys in Cybersecurity Policies

0
1

Key Takeaways

  • Attorneys will bypass cybersecurity policies if they perceive them as obstacles to efficient work.
  • Providing vetted, user‑friendly tools (including AI applications) that meet confidentiality requirements is essential for compliance.
  • Effective buy‑in stems from training that is role‑specific, frequent, and delivered by engaging instructors, coupled with measurable accountability (e.g., tracking training completion for RFP responses).
  • Leadership must listen to practitioners’ needs; policies that ignore workflow realities lead to shadow IT and privilege breaches.
  • A baseline policy should enforce strong access controls, clear rules for emerging technologies like AI, and ongoing, tailored education to demonstrate that security is a firm priority.

The Challenge of Gaining Firm‑Wide Agreement
Getting every lawyer to accept a cybersecurity policy is already a complex task, and the rise of artificial intelligence has made it even more difficult. Kevin R. Powers, faculty director of Boston College Law School’s cybersecurity program, observes that the core obstacle is not the policy itself but the perception that it hampers efficiency. When security measures slow down daily work, attorneys instinctively look for shortcuts—using personal email, bypassing VPNs, or employing unapproved apps—because they prioritize getting the job done over rigid compliance.

Why Workarounds Threaten Attorney‑Client Privilege
Powers warns that these shortcuts have serious legal repercussions. Moving confidential client files from a firm‑protected environment to an external tool—whether a personal Gmail account or an unauthenticated AI chatbot—instantly jeopardizes attorney‑client privilege and work‑product protection. Even a seemingly innocuous query typed into a public AI model can expose privileged information, turning a convenience‑driven workaround into a potential ethics violation and data‑breach incident.

The AI‑Specific Risk Landscape
Scott D. Anderson, managing partner at Verrill, emphasizes that almost any meaningful prompt entered into a generative‑AI system like ChatGPT will inevitably contain some level of confidential information. The model does not distinguish between “asking for a friend” and drafting a client brief; it processes and may retain the input. Consequently, unless firms supply approved AI tools that are contractually bound to safeguard data, attorneys will resort to unsanctioned platforms, creating shadow IT and uncontrolled data migration.

Buy‑In as an Enablement Problem
Cameron G. Shilling, founder of the privacy, cyber, and AI practice at McLane Middleton, reframes the issue: achieving compliance is less about policing and more about enabling lawyers to do their work securely. When firms provide the right applications—those that integrate with existing workflows and include built‑in safeguards—attorneys have little incentive to seek alternatives. Shilling stresses that listening to users is critical; ignoring their feedback leads to ineffective workarounds and diminished results.

Avoiding Shadow IT Through Approved AI Tools
Shilling notes that if a firm refuses to supply attorneys with vetted AI applications that can plug into other software (e.g., Claude or ChatGPT with enterprise‑grade security), the result will be unauthorized use, data leakage, and the proliferation of shadow IT. By contrast, offering approved, confidential‑aware AI tools reduces the temptation to use consumer‑grade alternatives and keeps data within the firm’s controlled environment.

Verrill’s Approach: Vetting, Policy, and Accountability
Anderson describes how Verrill tackled the problem by first vetting AI applications for confidentiality compliance, then building a firm‑wide policy around those vetted tools before rolling them out. To reinforce buy‑in, the firm tracks training completion and shares those metrics with prospective clients as part of request‑for‑proposal (RFP) responses. When lawyers realized that their participation in cybersecurity training could directly influence the firm’s ability to win new business, engagement rose significantly.

Core Elements of an Effective Cybersecurity Policy
Experts agree that, at a minimum, a firm‑wide policy should address three fundamentals: strong baseline access controls, clear and specific rules for emerging technologies such as AI, and regular, role‑tailored training that demonstrates cybersecurity as an ongoing priority. Anderson points out that training needs differ by seniority—associates may adopt new tools quickly, while senior partners often require low‑stakes, relatable entry points (e.g., using ChatGPT to find a restaurant on vacation) to see the technology’s value before applying it to client matters.

Training Delivery and Reinforcement
Powers stresses that training must be more than a static document; it needs to be interactive, frequent, and delivered by someone who can capture the audience’s attention. At Verrill, Anderson’s team combines vendor‑provided videos, monthly attorney lunches led by the CIO, and special town‑hall meetings for all staff. Shilling adds that accountability—such as consequences for mistakes—can further motivate proper behavior, noting that the learning curve for AI adoption in law is expected to be far shorter than the decade‑long transition to email.

Learning from Policy Missteps
Not every policy resonates with attorneys. Anderson recounts a failed attempt to enforce a strict clean‑desk rule as part of a certification effort; lawyers rejected it outright, viewing it as an unnecessary hindrance. The firm pivoted to SOC 2 compliance, a widely recognized audit standard for data security, allowing lawyers to keep paper piles on their desks while still meeting rigorous security benchmarks. This example underscores the importance of aligning security requirements with realistic workflow expectations.

The Limits of Any Policy and the Goal of Risk Management
Powers cautions that no policy can guarantee absolute security. Instead, the aim should be to reach a state where the firm has completed a thorough risk analysis, implemented proportionate controls, and achieved genuine buy‑in from everyone. If a policy is unattainable or ignored, it creates a false sense of security and can expose the firm to greater risk. Ultimately, effective cybersecurity in the AI era hinges on balancing protection with usability, listening to the people who must live with the rules, and continuously adapting training and tools to meet evolving threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here