Steve Durbin, Chief Executive of ISF, guests on the Legal Owl Podcast, where host John “Jock” Brocas explores emerging cyber risk in the legal industry. Originally published by Legal Owl.
In this first of two episodes, Steve discusses how the cyber landscape has evolved, from the “bits and bytes” governance gaps of his early career to today’s boardroom-level understanding of data value. Uncover practical insights from Steve on why law firms, often reliant on highly sensitive data yet under-defended, have become attractive targets for sophisticated attackers, why the “too small to be targeted” mindset is a dangerous illusion, and why organisations must shift from trying to prevent every attack to preparing to recover from one, amid the growing threat of deepfakes and reputational damage.
It is not about protecting your data. It is about managing the risk.
Key takeaways:
- Law firms rely heavily on sensitive data but often lag behind sectors like banking on defences, making them an easy route into larger client organisations.
- Organisations should assume they will be attacked and focus on recovery, not just prevention.
- Deepfakes, surveillance and careless online behaviour are now major risks, beyond technical vulnerabilities, especially for high-profile partners and executives.
Enhance your listening experience
Follow along with our podcast transcript and discover related ISF resources.