top of page

When IT and Attorneys Speak Different Languages, Firms Pay the Price

NopalCyber
44 minutes ago
2 min read

Law firms have a communication problem that's quietly becoming a security problem. In a new piece for ALA Legal Management magazine,  NopalCyber Founder and Chairman Ram Vasudevan argues that the gap between IT leaders who understand a firm's cyber risk and the partners who control its budget is where security failures actually begin, and closing it is no longer optional.


The stakes have risen sharply. Corporate clients now embed detailed security requirements into outside counsel guidelines, and firms that can't speak fluently about their own infrastructure risk quietly losing business. ABA Model Rules on competence and confidentiality now require lawyers – not just IT staff – to take technologically informed steps to protect client data. Insurers have grown far less forgiving too: Vasudevan points to real cases where carriers rescinded cyber policies after discovering that security controls attested to on applications, like multifactor authentication, weren't actually in place everywhere, leaving firms to absorb losses insurance was supposed to cover.


The root problem, he writes, is that IT and legal teams are trained to solve different problems in different vocabularies. Security teams speak in threat models and vulnerability ratings; lawyers are trained to evaluate specific, actionable requests. A vague appeal to "improve our security posture" asks partners to do analytical work someone else should have finished, and budgets stall as a result.


Vasudevan offers three fixes that firms can implement immediately: require a one-page, plain-language brief before any technical request reaches a partner committee; run tabletop breach simulations so leadership feels the stakes firsthand; and reframe requests around business metrics and revenue at risk, not technical jargon.


Firm administrators and COOs, he argues, are best positioned to serve as the translator between both worlds.


Read the full article here: Why IT Needs Get Lost in Translation.

 
 
Cropped_edited.png

Cybersecurity
Blog

bottom of page