惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Martin Fowler
Martin Fowler
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
C
Check Point Blog
H
Help Net Security
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
P
Proofpoint News Feed
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
雷峰网
雷峰网
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Vercel News
Vercel News
S
SegmentFault 最新的问题
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
博客园_首页
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏

City AM

As it happened: Stocks mixed as Trump warns takes ‘two to tango’ on Iran peace As it happened: Stocks mixed as Trump warns takes ‘two to tango’ on Iran peace Replace Reeves if Starmer goes, voters tell Labour Right to Buy has been a huge success, of course the left hates it Regional bond revolution risks making Britain more unequal and less prudent Labour may not agree with Blair, but the public does… The world can’t keep consuming more than it produces If performance matters more than privilege then prove it Wayve: London robotaxis will make passengers forget there’s no driver Mandelson Files add insult to injury, but the patient was already beyond saving Blackstone Raises its Largest Asia Private Equity Fund at $13.1 Billion Pension master trusts join forces to tackle outdated transfer systems Iran ‘pulls out of talks with US’ and threatens to strike Israel Anthropic files for IPO as race with OpenAI heats up ‘Be more Trumpian’ – Mandelson discussed dire economy and ‘lack of verve’ with key Starmer ally Deloitte UK appoints first chief AI officer in drive for ‘AI-enabled’ services Private credit is crowded — but disciplined capital still knows where to look Squash players turn to social media to cash in on LA Olympic Games opportunities Interactive Brokers Integrates AI into Client Portfolios – Informed by Agentic Technology, Controlled by the Client WWEX Group and Auctane Complete Merger, Creating Leading Logistics Provider ShipStation Global Sadiq Khan: London tech boom can weather ‘dizzying’ AI risks New mixed gender trophy introduced for coming Hundred season Labour voters lead AI adoption as public remains split on impact North Highland Names Anthony Shaw Global Chief Executive Officer Vyond Appoints SaaS Industry Veteran Scott Ernst as Chief Executive Officer Winston Taylor Completes Historic Transatlantic Combination M&S chief’s pay slashed by £3m after cyberattack turmoil Inside Celonis, the German tech unicorn that won over a fifth of the FTSE 100 Stop and think before asking for a bigger salary Brits back Blair’s growth calls – yet are squeamish over welfare cuts
Professional services firms the
Maria Ward-Brennan · 2026-06-19 · via City AM

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
law firms, are the "current flavour of the month" for cyberattacks

Professional services firms, particularly law firms, are the “current flavour of the month” for cyberattacks, driven by the valuable client information the sector guards.

Speaking to City AM, Holly Waszak, head of cyber claims advocacy at Marsh, said: “We’re seeing insurers come to us with law firms on their books, and they are trying to engage with clients as much as possible to forewarn them.”

Due to the nature of the work professional services firms carry out, they are seen as high‑value, information‑rich targets for cybercriminals. Firms hold all sorts of highly confidential information on file for clients, from M&A deals and trade secrets to contentious employment matters, exposing firms of all sizes to these threats.

Waszak highlighted that, because of this sensitive information, groups such as the ‘silent ransom’ collective, which includes Luna Moth and Chatty Spider, instead focus on quiet data theft rather than noisy encryption.

“They are using phishing tactics… so, calling these kinds of employees, partners, saying ‘we really need to access your computer, it’s your IT help desk support, can you give me remote access’.”

“Once they’ve got that access, they are immediately exfiltrating data, and they’re not bothering with deploying ransomware or encrypting data. They are simply exfiltrating whatever they can… then working out what they’ve got, and then extorting their victims, such as ‘we have all of this data from your clients, and you do not want this to be leaked, so here is our demand’,” she added.

This isn’t a new attack for law firms. Back in 2023, magic circle firm Allen & Overy (now A&O Shearman) was targeted by the notorious LockBit ransomware group, which threatened to leak data stolen from a small number of the firm’s storage servers. Most recently, Stewarts Law reported incidents in which criminals impersonated the firm, sending fraudulent emails and faxes to the public to exploit its brand identity.

Firms urged to focus on incident response plans

For firms, the question is no longer whether they will be targeted, but how well they respond when they are. Waszak describes it as “not a matter of when, it’s if, and response is key”.

Leaders are urged to develop incident response plans that name decision‑makers, insurers, forensic providers, external counsel, and PR advisers, and that are rehearsed. “The incident response plan isn’t a stale document on a shelf,” she warned; tabletop exercises are essential to “flex those muscles”.

Waszak also argued that culture is as important as controls, as staff have to feel safe admitting a mistake quickly: “Anyone could do it, anyone can make that mistake,” she says, but the real danger is when employees stay silent and “threat actors can lurk on the systems for months”.

Last year, the headlines were lit up by cyberattacks targeting the most notable businesses on the high street, including M&S. This led to a wave of boardrooms shifting their attitudes towards cyber security, sparking demand for insurance coverage.