Getting firm-wide agreement on a cybersecurity policy that fits everyone’s needs is complicated. In the age of AI, getting attorneys to comply with the policy is even trickier.
Kevin R. Powers, faculty director of Boston College Law School’s cybersecurity program, said the missing piece in most firms’ buy-in strategy is efficiency.
“If there’s things in place that hamper you efficiently getting your job done, everyone’s going to find a workaround,” Powers said. “‘I’m going to use my Gmail account … or I’m not going to use the VPN. This is slowing me down. I’m at a hotel. I don’t care. I’m going to use this.’”
This has implications for privilege issues as well.
“I’m working in my law firm, I’m at my desk, I’m looking at files, everything’s protected by attorney-client privilege [and] work product. I take that [work] and I put it in an outside tool. Guess what? I just violated all that,” Powers said.
Scott D. Anderson, managing partner at Verrill, agreed.
“There’s almost nothing you can put into a prompt in ChatGPT that is meaningful that won’t include some level of confidential information, even if it’s, ‘hey, I’m just asking for a friend,’” he said. “It doesn’t work that way.”
Cameron G. Shilling, founder of the privacy, cyber, and AI practice at McLane Middleton, describes getting buy-in as an enablement problem.
“Success comes from enabling individuals to do what they need to do using the applications and the safeguards that have been employed,” he said.
Firms lose compliance when they stop listening, he added.
“They just don’t listen, and so they provide alternative applications or alternative mechanisms to do things that are either not as effective or don’t provide as high quality of a result,” Shilling said.
This is also true for AI security.
“If a firm is not going to be willing to provide its workers with the type of application like Claude or ChatGPT that plugs into other applications, that’s when you’re going to end up with unauthorized use of applications, data migration off of firm devices, and shadow IT,” Shilling said.
Anderson agreed that problems can be avoided by giving attorneys tools worth using. At his firm, AI tools were vetted and a policy was built around client confidentiality before applications were rolled out.
Verrill also ties buy-in to something concrete: The firm tracks training completion and shares that data with prospective clients as part of RFP responses.
“Once the lawyers understood that our overall firm [training participation] was going to be part of responses to RFPs and might actually impact our ability to get new work, the buy-in went up,” Anderson said.
Implementation, training and buy in
While every firm differs, experts say that at a minimum a policy should cover three fundamentals: strong baseline access controls, clear rules for new tools like AI, and regular training that’s frequent and specific, demonstrating that cybersecurity is a priority.
Anderson noted that AI use and compliance often differs based on seniority: associates need little encouragement, while senior partners need a lower-stakes entry point.
To address that, he’ll suggest using something like ChatGPT to find a place to eat on vacation.
“Then they come back and they’re like, ‘oh my goodness, Scott, I can’t believe how cool these tools are,’” Anderson said.
Powers stressed the importance of emphasizing that compliance and training is part of attorneys’ job.
“Don’t just have a written policy and not do anything with it,” he said. “[There has to be] real training, [and] the lawyers’ [training] should be different from the receptionists, the secretaries, the timekeepers.”
Who delivers the training matters too, Powers said.
” You want to bring someone in who’s going to have everyone pay attention,” he added.
Anderson said Verrill’s training is comprehensive.
“We’ve rolled out a significant educational campaign that includes videos that come with the vendor that we’ve selected. We’ve got monthly all attorney lunches, and the IT group led by our CIO has been bringing examples forward. We also do special town meetings with all of the staff,” he said.
Shilling agreed that education is key, but added, “mistakes that get punished are probably the next thing that’s going to motivate people to figure out how to do this the right way.”
“The adoption of email in law took at least five years, maybe a decade,” he noted. “In AI, we’re talking about a two-year curve, or less.”
Not every policy earns buy-in. Anderson described a strict clean-desk requirement, part of a certification Verrill was pursuing, that attorneys rejected outright, leading the firm to choose SOC 2 compliance (Systems and Organization Controls 2), an audit standard for how a company handles data security, instead.
“That was a non-starter discussion with our lawyers,” Anderson said. “So we said, ‘all right, let’s go with SOC 2. They can keep piles of paper on their desk.’”
There’s no policy that ensures absolute security, Powers cautioned.
“[But] you want to get [your firm] in a place where … you’ve made your risk analysis and you get everyone bought in,” he said. “If it’s not doable, why have that policy? Because no one’s going to follow that.”
