How law firms win attorney buy-in on cybersecurity policies

IN BRIEF
- Kevin R. Powers highlights efficiency as key to policy buy-in
- Verrill tracks training completion to boost attorney compliance
- McLane Middleton emphasizes enabling users to adopt safeguards
Kevin R. Powers, faculty director of Boston College Law School’s cybersecurity program, said the missing piece in most firms’ buy-in strategy is efficiency.
“If there’s things in place that hamper you efficiently getting your job done, everyone’s going to find a workaround,” Powers said. “‘I’m going to use my Gmail account … or I’m not going to use the VPN. This is slowing me down. I’m at a hotel. I don’t care. I’m going to use this.’”
This has implications for privilege issues as well.
“I’m working in my law firm, I’m at my desk, I’m looking at files, everything’s protected by attorney-client privilege [and] work product. I take that [work] and I put it in an outside tool. Guess what? I just violated all that,” Powers said.
Scott D. Anderson, managing partner at Verrill, agreed.
“There’s almost nothing you can put into a prompt in ChatGPT that is meaningful that won’t include some level of confidential information, even if it’s, ‘hey, I’m just asking for a friend,’” he said. “It doesn’t work that way.”
Cameron G. Shilling, founder of the privacy, cyber, and AI practice at McLane Middleton, describes getting buy-in as an enablement problem.
“Success comes from enabling individuals to do what they need to do using the applications and the safeguards that have been employed,” he said.
Firms lose compliance when they stop listening, he added.
“They just don’t listen, and so they provide alternative applications or alternative mechanisms to do things that are either not as effective or don’t provide as high quality of a result,” Shilling said.
This is also true for AI security.
“If a firm is not going to be willing to provide its workers with the type of application like Claude or ChatGPT that plugs into other applications, that’s when you’re going to end up with unauthorized use of applications, data migration off of firm devices, and shadow IT,” Shilling said.
Anderson agreed that problems can be avoided by giving attorneys tools worth using. At his firm, AI tools were vetted and a policy was built around client confidentiality before applications were rolled out.
Verrill also ties buy-in to something concrete: The firm tracks training completion and shares that data with prospective clients as part of RFP responses.
“Once the lawyers understood that our overall firm [training participation] was going to be part of responses to RFPs and might actually impact our ability to get new work, the buy-in went up,” Anderson said.
Implementation, training and buy in
While every firm differs, experts say that at a minimum a policy should cover three fundamentals: strong baseline access controls, clear rules for new tools like AI, and regular training that’s frequent and specific, demonstrating that cybersecurity is a priority.
Anderson noted that AI use and compliance often differs based on seniority: associates need little encouragement, while senior partners need a lower-stakes entry point.
To address that, he’ll suggest using something like ChatGPT to find a place to eat on vacation.
“Then they come back and they’re like, ‘oh my goodness, Scott, I can’t believe how cool these tools are,’” Anderson said.
Powers stressed the importance of emphasizing that compliance and training is part of attorneys’ job.
“Don’t just have a written policy and not do anything with it,” he said. “[There has to be] real training, [and] the lawyers’ [training] should be different from the receptionists, the secretaries, the timekeepers.”
Who delivers the training matters too, Powers said.
” You want to bring someone in who’s going to have everyone pay attention,” he added.
Anderson said Verrill’s training is comprehensive.
“We’ve rolled out a significant educational campaign that includes videos that come with the vendor that we’ve selected. We’ve got monthly all attorney lunches, and the IT group led by our CIO has been bringing examples forward. We also do special town meetings with all of the staff,” he said.
Shilling agreed that education is key, but added, “mistakes that get punished are probably the next thing that’s going to motivate people to figure out how to do this the right way.”
“The adoption of email in law took at least five years, maybe a decade,” he noted. “In AI, we’re talking about a two-year curve, or less.”
Not every policy earns buy-in. Anderson described a strict clean-desk requirement, part of a certification Verrill was pursuing, that attorneys rejected outright, leading the firm to choose SOC 2 compliance (Systems and Organization Controls 2), an audit standard for how a company handles data security, instead.
“That was a non-starter discussion with our lawyers,” Anderson said. “So we said, ‘all right, let’s go with SOC 2. They can keep piles of paper on their desk.’”
There’s no policy that ensures absolute security, Powers cautioned.
“[But] you want to get [your firm] in a place where … you’ve made your risk analysis and you get everyone bought in,” he said. “If it’s not doable, why have that policy? Because no one’s going to follow that.”
Share this story, choose a platform
Brought to you by BridgeTower Media
Free Weekly Newsletter
Recommended content
Technology and the Law A new kind of AI-related hazard surfaces: The “prompt injection”
Technology and the Law: A new kind of AI-related hazard surfaces: The “prompt injection” By Jennifer Ellis Two lawyers in [...]
Serving Clients: Clarifying your value: A practical approach to personal branding
Serving Clients: Clarifying your value: A practical approach to personal branding By Brenda Plowman In today’s legal landscape, most partners [...]
Why Your Legal Data Isn’t Ready for AI
Legal data readiness is critical for AI adoption. A September session highlights why siloed, inconsistent data hinders AI's effectiveness in legal departments.
5 things we wish every lawyer would inform us about a referral
Lawyers who make the best referrals accurately relay all the particulars about a case; that includes what they don’t know [...]
Tips for keeping doomsday language out of client communications
Anxiety levels for both lawyer and client can be kept in check by tempering the words you use when discussing [...]




