Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Agentic AI is automating cyberattacks on law firms. Here's what MFA, air-gapped backups, and an Omni Audit can do to protect client data.

Agentic AI Is Scaling Cybercrime, What Law Firms Must Do
Insight ai

Agentic AI Is Scaling Cybercrime, What Law Firms Must Do

Sam McKay

Recent security reporting on how agentic AI scales cybercrime describes something a lot of security teams have been dreading for a couple of years now. AI agents that don’t just help a human write a better phishing email. They run the intrusion themselves. They probe for open ports, adapt when they hit a wall, rewrite malware on the fly to dodge whatever detection tool is watching, and keep going without a human operator sitting at a keyboard the whole time. That’s a different threat model than the one most law firms built their security policy around.

If you’re a partner or managing owner at a firm doing $1M to $25M in revenue, this isn’t an IT department problem you can hand off and forget. It’s a client-trust problem, a malpractice-exposure problem, and increasingly a cost-of-doing-business problem that shows up on your insurance renewal.

Why law firms are a specific target, not a general one

Sensitive data is your entire business model. Deal terms, litigation strategy, trust account numbers, medical records in a PI file, custody details in a family matter. Attackers know that a single successful breach at a law firm often yields more usable, sellable, extortable data per gigabyte than almost any other small business vertical.

Most firms in this revenue band still run security like it’s 2015. One shared admin login. No multi-factor authentication on the practice management system. Backups sitting on the same network as production files, which means a ransomware payload that hits your case management server also hits your recovery plan. Agentic AI doesn’t need a skilled human to find that configuration anymore. It can be pointed at thousands of firm websites and email domains overnight and instructed to flag exactly this kind of gap, then act on it without waiting for a human to approve the next step.

Where the exposure actually lives in your daily operations

This is the part most partners miss. The manual workflows you already know are inefficient are also, in most cases, your weakest security perimeter.

Intake forms are collecting sensitive facts about a prospective client’s matter before anyone has even run a conflict check. Those submissions often sit in a shared inbox for hours, especially after 6pm or on weekends, which is exactly the kind of unmonitored channel a spoofed email or a malicious attachment slips through unnoticed. Industry ranges suggest 30-40% of after-hours intake never converts to a real consultation in the first place, and a chunk of that traffic is noise, bots, or worse, testing your response process for weaknesses.

Discovery batches are another soft spot. Junior associates doing first-pass document review at $200-400 an hour of billed time often end up pulling files onto personal laptops or dropping them into a personal cloud drive because the firm’s approved system is slow or clunky. That’s shadow IT, and it’s invisible until something goes wrong. We usually see 4-6 hours per attorney per week disappear into this kind of manual review and admin work that never makes it onto an invoice, and a meaningful share of that time is spent working around systems rather than through them securely.

None of this is a story about careless staff. It’s a story about processes built for a slower, smaller-scale threat than the one now targeting firms your size.

The two things worth doing this week

Security researchers covering the agentic AI threat are converging on the same two recommendations, and they’re not complicated.

Multi-factor authentication on every system that touches client data. Practice management, email, document storage, your VPN if you have one. This is table stakes now, not a nice-to-have. If your firm hasn’t enforced it across every partner and associate login, that’s the first call to make, today, not next quarter.

Air-gapped backups, meaning at least one backup copy that is physically or logically disconnected from your live network. Ransomware that encrypts your production files can’t touch a backup it can’t reach. Firms that skip this step and get hit typically face a choice between paying a ransom or rebuilding from scratch, and neither number is small once you count lost billable days and client notification costs.

Both of these are cheap relative to a breach. Neither requires an enterprise IT budget. They require someone to actually own the task and follow through, which is where a lot of firms this size quietly stall out.

What defense looks like when an agent is doing the watching

Here’s the part that connects back to your actual operations, not just your firewall settings.

An Intake Voice Agent built the right way doesn’t just answer the phone after hours. It verifies the caller against a matter number or existing client record, runs a conflict check before any sensitive fact is captured, and logs the full interaction in a structured record rather than a voicemail file sitting on a server that could be spoofed or intercepted. That closes off one of the softest entry points in most firms, the after-hours inbox nobody is watching.

A Matter Triage Agent reviews incoming form submissions and email attachments before a human ever opens them on a work laptop. It classifies the practice area, scores the fit, and routes a clean one-paragraph brief to the right partner, quarantining anything that looks like an unexpected attachment or a suspicious sender pattern before it reaches a desktop. This is the same agent that solves your intake-delay problem and reduces your exposure to malicious payloads riding in on legitimate-looking client inquiries.

A Document Review Agent performs first-pass review on contracts and discovery batches inside a controlled environment, rather than having files bounce between personal devices and cloud folders of varying security quality. It flags clauses, summarizes positions, and produces an associate-grade memo, all without the raw files ever landing on an unmanaged laptop. That’s the same workflow that used to eat days of a $200-400/hour associate’s time, now handled with a tighter security perimeter as a side effect of the redesign, not an afterthought bolted on later.

This is the pattern worth understanding. Fixing the operational bottleneck and closing the security gap are usually the same project, not two separate ones. You can read more about how these specific builds work on the Omni ops page, and see the broader picture of how voice and ops agents fit together on the Omni overview.

Typical exposure range: Firms in the $1M-$25M revenue band that we've audited commonly show $80,000-$250,000 a year in combined leakage from unbilled review time, missed intake, and security-related downtime or insurance cost creep. The number moves depending on staff count and how manual the intake-to-close workflow still is.

The dollar reality of getting this wrong

A breach at a firm this size rarely stays contained to an IT bill. There’s the incident response cost, often a flat fee that surprises owners the first time they see it. There’s the malpractice insurance renewal that jumps once a carrier learns you’ve had an incident, sometimes for several years running. There’s the billable time lost while partners and staff spend days on containment instead of client work. And there’s the harder-to-quantify cost of a client who finds out their custody file or their deal terms sat exposed for a week and quietly moves their next matter to a competitor.

Set against the $80,000-$250,000 annual leakage band we typically see in firms this size, the cost of getting MFA and air-gapped backups in place, and rebuilding intake and review around agents that verify before they act, is a rounding error. Most of the fix cost is time and discipline, not software spend.

What an Omni Audit actually checks

We built the Omni Audit specifically so a managing partner doesn’t have to sit through a sales deck to figure out if any of this applies to their firm. It runs 60 minutes, over a call, and it produces three concrete things: a leakage estimate specific to your intake and review workflows, a prioritized list of where your exposure sits right now including the security gaps most firms don’t think to check, and a build plan for which agents would close the biggest gaps first.

There’s no deck, no generic industry overview. It’s your numbers, your workflow, your gaps. If you want to see how this looks specifically for legal practices before you book anything, see Omni for law firms walks through what the audit covers and what firms typically find.

If you’d rather start with something you can act on today without a call, we put together an AI Client Intake Checklist for law firms that walks through the