A law firm sells two things at once: the legal work itself, and the confidence that whatever the client told the lawyer will not end up anywhere else. A divorce agreement, a labor investigation, a dispute between business partners — all of it reaches a lawyer because the lawyer promises to keep it secret. Losing that secret is not just an IT problem. It breaks the reason the firm exists in the first place.
According to The State of Ransomware 2026, a report by security firm Sophos based on 2,158 respondents across 17 countries surveyed between January and March 2026, 56% of the ransomware attacks recorded succeeded in encrypting the attacked organization's files — 41% were stopped before that. And the amount demanded tracks the size of the target: among organizations with revenue under USD 50 million, the median ransom demand was around USD 140,000.
For whoever decides at a small or mid-size firm, that number matters for a direct reason: it is not the large firm with its own IT department that carries the most risk. It is the lean firm, where the client's case lives on the laptop of whoever is handling it, with no one watching it full time.
Where the client's case actually lives
In practice, a client's documents rarely sit in one safe place. They sit in a local folder on the lawyer's computer, in a copy sent by e-mail, sometimes on a USB drive carried to a hearing. Every extra copy is one more place where the data can be lost, shown to the wrong person, or simply disappear when the computer crashes.
Much of that material fits what the law calls sensitive data. According to the frequently asked questions published by Brazil's National Data Protection Authority (ANPD), sensitive personal data covers racial or ethnic origin, religious belief, political opinion, union membership, health, sexual life, or genetic and biometric data. A medical report in a health-plan lawsuit, an exam in a labor dispute, a family history in a custody case: all of that crosses the desk of an ordinary law firm, carrying the higher duty of care the law reserves for this kind of information.
A client's document can disappear along with a broken hard drive, but the case deadline does not disappear with it. A filing due by 11:59 p.m. on a specific day does not wait for the computer to turn back on, and it does not wait for someone to remember where the latest version of the text went. Missing a deadline because of an IT problem is not like losing an e-mail: it can cost the very right the client hired the firm to defend.
CERT.br, the center that receives voluntary reports of network security incidents in Brazil, has updated its statistics monthly since 1999. That steady stream of reports shows that data loss and unauthorized access are not a rare exception — they are part of daily life for anyone who works on a computer, and a law firm is no exception just because it handles cases instead of products.
Why the usual approach falls short
The usual way small firms handle this is to call someone only when the computer stops working. While everything runs fine, no one checks whether the backup actually exists, whether it actually opens, or whether the antivirus installed three years ago is still up to date.
Another common version is relying on the intern or the partner who happens to know more about technology to fix whatever goes wrong — with no time, training, or formal responsibility for it. It works until the day that person is on vacation, in a hearing, or has no idea where to start with a file that will not open anymore.
A third version is protecting the case with nothing more than an e-mail password. A password alone does not stop someone who found it out from logging in, reading the case file, and continuing to read it for days without anyone noticing.
What has to be in place
A firm prepared for this scenario does not rely on luck or good intentions. It relies on mechanisms that keep working even when no one is watching.
Automatic backup of everything, including the laptop of whoever works outside the office. A client document that exists on only one machine is a document that can disappear in a crash, a theft, or a virus.
Regular testing of that backup, not just the backup itself. A backup no one has tried to restore is an assumption, not a guarantee — and the day to find out it does not work cannot be the day the deadline is due.
Secure remote access for working from a hearing, a courthouse, or home. This replaces the USB drive carried in a pocket and avoids leaving a client's document on whatever computer happens to be nearby.
A second confirmation step beyond the password, on e-mail and on the firm's systems. Even if someone finds out the password, that second step keeps the account closed.
One single person responsible for the firm's IT, instead of whichever intern is around or a different vendor for every problem. Someone who already knows the whole environment responds faster than someone learning the firm from scratch in the middle of an emergency.
Every issue logged with its cause and its fix, so the same problem — a lost file, e-mail down, a computer too slow to work with — does not keep happening without explanation.
This is how Skills IT works: with tested backup, secure remote access for whoever works outside the office, and one single person responsible for IT, instead of improvised fixes.
What changes once the firm is prepared
The gain is not a nicer-looking system. It is staying operational on the day something goes wrong. A firm with a tested backup loses a few hours restoring a file; without one, it can lose the whole case, or its deadline.
Predictable cost also weighs on the decision of whoever runs the firm. Trading "pay a lot in an emergency, with no estimate beforehand" for a fixed monthly cost, with an estimate before any larger purchase, turns an unpredictable problem into a budget line a partner can actually plan around.
There is also a gain that shows up in no number: client trust. A firm that can explain, in one sentence, how it protects a case and the documents handed over conveys exactly the professionalism that client confidentiality promises. A firm that stumbles over that question has already lost a bit of that trust, even if nothing has gone wrong yet.
Only 1 in 3 smaller organizations hit by ransomware managed to stop the attack before their files were encrypted.
Questions to bring to the firm's next meeting
Before assuming "this won't happen here," it is worth asking what exists today for the day it does.
- Where is tomorrow's filing, right now? If the answer is "on someone's laptop," that laptop needs the same protection as the firm's server.
- When was the last time anyone actually tried to restore a backup? If the answer is "never," the firm does not know whether it has a backup or just an assumption.
- If the computer holding the case crashes tonight and the deadline is tomorrow, what does the firm do? Without a ready answer, the fix will be improvised under pressure.
- Does a document with health, personal, or family data get any extra care? This kind of document shows up more often than expected at an ordinary practice, and the law treats it with more rigor.
- If a client asks who else had access to their case, can the firm answer on the spot? That ready answer is, in practice, client confidentiality actually working.




