A coach and four

07 Sept 2026 technology Print

A coach and four

The latest AI models have the potential to drive a coach and four through cybersecurity safety features. How can Irish law firms stay protected against attack? Tanya Moeller and Paul Delahunty attempt to hold the horses

When securing a law firm against cybersecurity threats, questions are usually asked as to how AI is disrupting the status quo. So, are there any particular actions that a practice manager should take to protect against cyberattacks in the age of AI? 

If you are new to the topic, the question about the impact of AI on cybersecurity is timely.

In April of this year, US-based AI developer Anthropic, best known for its Claude application, launched its new Mythos model, but stopped short of a general release.

It stated that observed capabilities could “reshape cybersecurity” because “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities”. 

Mythos found “thousands of high-severity vulnerabilities, including some in every major operating system and web browser”.

Anthropic feared that it would “not be long before such capabilities proliferate”, while the “fallout – for economies, public safety, and national security – could be severe”.

This prompted a flurry of activity between relevant stakeholders, such as governments, technology companies, national cybersecurity agencies, and regulators (including those operating in the financial sector).

What is relevant is that a widespread analysis of Mythos’s impact on critical IT systems took place across the globe. In Ireland, the National Cyber Security Centre commented that, in the circumstances, the decision not to release its latest model on a general basis was a “responsible approach”.

AI duality

Reflecting on this example, there is an obvious duality in the use of AI for cybersecurity.

On the one hand, AI improves defences against cyberattacks, since it improves continuously, calculates faster than humans can, and doesn’t require sleep.

On the other hand, it is precisely these capabilities that can be exploited by cyber-criminals.

In practical terms, the impact on law firms is immediate. Solicitors use software in a number of ways every day: for practice and client management, communication, processing of information, and online banking.

The two major assets of law firms that make them attractive to cyber-criminals – sensitive information and funds in bank accounts – are at risk if AI can help to transform software applications into a gateway to these assets.

For example, if your laptop gets hacked, cyber-criminals can install keystroke monitoring software, without you realising it, and get your online banking credentials.

If your browser is compromised, they can read the information you send to your bank when logging in via the internet.

Indeed, the UK’s National Cyber Security Centre (NCSC) warned in May that the “most significant AI cyber-development will highly likely come from AI-assisted vulnerability research and exploit development that enables access to systems through the discovery and exploitation of flaws in the underlying code or configuration”.

Irish law firms also need to respond to the fact that the improving capabilities of AI will increase the volume of cybersecurity attacks.

In March, the NCSC (UK) warned that AI “lowers the barrier” for novice cyber-criminals, leading to a “commoditisation of AI-enabled capability” in the cyber-crime market. In this way, “both state and nonstate actors” would be facilitated.

Capability uplift

In addition, where cyberattacks occur, these can become more tailored towards the situation at a quicker pace.

A key risk to law firms is the personalisation of cyberattacks to the unique environment of the situation, in order to trick a staff member into carrying out the wrong action – for example, typing an online banking password into a fraudulent website.

Cyber-criminals can secretly stay in your email account for months, monitoring cases, and then striking with a highly personalised email containing fraudulent bank account details.

The NCSC (UK) found that AI provides “capability uplift in reconnaissance and social engineering, almost certainly making both more effective, efficient, and harder to attack”.

Law firms need to respond by adapting effectively. Speaking at the Oireachtas AI Committee, the Irish NCSC warned that a “potential for an ‘AI gap’” could emerge, “between those organisations that can adapt to this new environment, and those that cannot, or at least not quickly enough”.

In practical terms, adaptation here means that cybersecurity needs to be a top priority for law firms.

All about that baseline 

Those who are new to this topic need to implement a baseline cybersecurity programme without further delay.

In a nutshell, this consists of the following three steps: 

  1. Implement a cybersecurity governance structure: identify and define roles and powers. Who takes overall decisions (budget, timelines, risk appetite)? Who is responsible for IT architecture (hardware and software purchases, installations, and maintenance)? Who is the person who carries out cybersecurity services? Where you are a single practitioner or smaller law firm, unless you have the capacity and knowledge, you will most likely outsource the architecture and security services. However, outsourcing does not relieve you of your responsibility to manage your cybersecurity response. Discuss with your IT provider now how you can improve your defences. Equally, law firms should mitigate the cyber-risks posed by thirdparty providers, including cloud software vendors and managed-IT service providers, and ensure that appropriate outsourcing contracts are in place that cover vendor security obligations and breach reporting. If you are uncertain how to review third-party vendor contracts from this perspective, it may be worth taking legal advice from a trusted colleague in the profession.
  2. Understand your unique vulnerabilities: every law firm suffers structural weak points, be it in the physical environment, in behaviour on the road, in hardware, or in daily operational processes carried out by staff. It is an easy premise to believe that, where AI exploits software as an entry point, only the software needs regular maintenance. In fact, humans are still the weakest link in cybersecurity, and the environment in which software operates is crucial in preventing and mitigating cyberattacks. A robust cybersecurity risk assessment provides your law firm with the transparency it requires to understand where it is vulnerable.
  3. Mitigate your vulnerabilities: once you have clarity where you are exposed, evaluate your responses. Usually this is done on a ‘probability versus impact’ matrix, where the likelihood of a risk occurring is measured against the consequences for your law firm if it did happen. For example, the risk of your entire client database being wiped might seem remote, but if it were to happen, it would be catastrophic were you not to have a functioning backup. As such, a risk mitigation plan sets out how you intend to deal with each risk, on a case-by-case basis, depending on the circumstances. You can accept, mitigate, transfer (by offloading), or avoid a risk. In practice, mitigation measures may include staff training, regular software updates and patching, secure backups, and the use of multi-factor authentication to reduce the risk of unauthorised access to systems and accounts.

Law firms that already have a cybersecurity programme in place are likely to already be on the road to risk mitigation. In the context of recent AI developments, it would be wise now to take stock of your cybersecurity efforts and determine whether you need to adapt your approach.

Prepare for the worst

No cybersecurity programme can eliminate risk entirely, particularly as AI increases the scale and sophistication of cyberattacks. Law firms should, therefore, also prepare for the possibility that an incident will occur.

An incident response and recovery plan should set out who is responsible for responding to a cyberattack, how systems and data can be restored, and when clients, insurers, regulators, or other stakeholders need to be notified.

We recommend that you carry out a dry run during a quiet phase in your practice’s calendar. 

In fact, an additional key building-block to surviving the ‘AI gap’ mentioned above is to achieve a solid ‘cybersecurity maintenance phase’.

This is the ideal status quo for any law firm: your cybersecurity risk-assessment is regularly reviewed, your risk-mitigation plan is flexibly adjusted on a regular basis, and risk-mitigation actions – such as mock incidents, IT updates, patching, and staff training – are carried out at recommended intervals.

As AI challenges traditional cybersecurity protections, your maintenance phase must remain continuously dynamic and responsive.

For the latest updates on cybersecurity developments, continuously check the Law Society’s website at lawsociety. ie/cyber-security.

We are planning to make an introductory guide available after the summer break and present this at the Technology Committee’s conference in November. As this is still some months away, it is strongly recommended that you start preparing now.

Tanya Moeller is an in-house counsel (she has coauthored this article in a personal capacity). Paul Delahunty is chief information security officer at Stryve Secure.

Further Reading

Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland

Copyright © 2026 Law Society Gazette. The Law Society is not responsible for the content of external sites – see our Privacy Policy.