Latest / Tech Talks With Kinsoft / Legal Practice Board of Western Australia Data Breach
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Today we're
- 0:02unraveling a topic that's really become non -negotiable
- 0:05for pretty much every professional out there,
- 0:07cybersecurity. The online world is buzzing, definitely,
- 0:10but unfortunately that also means, you know,
- 0:13a big jump in cybercrime. We're going to explore
- 0:15what these threats mean for you specifically
- 0:17using a pretty significant real -world case study.
- 0:20Our goal is to cut through the noise, really,
- 0:23and give you the essential insights so you can
- 0:25be informed and prepared. Yeah. And what's really
- 0:28striking is just how fast these threats change.
- 0:31Right. They're always shifting, looking for new
- 0:33online opportunities. We'll connect that to how
- 0:35businesses, especially professional services
- 0:37like, say, law practices are affected and what
- 0:41measures actually seem to work. Exactly. We'll
- 0:44look closely at a recent very public cyber incident
- 0:47in the legal sector. We'll get into the nitty
- 0:49gritty of what went down and then importantly,
- 0:52pivot to why having the right kind of cyber insurance
- 0:55is. Well, it's not really optional anymore. So
- 0:58let's start with the bigger picture. We're seeing
- 1:01this clear trend. Cybercrime is definitely rising,
- 1:04especially here in Australia. Criminals are getting
- 1:06smarter, focusing online, and it's causing, you
- 1:09know, major disruption, real losses. It's much
- 1:13more than just a small hassle. And that brings
- 1:15up a really important point. What do these losses
- 1:17actually look like for a practice? It's not just
- 1:20the obvious stuff. I mean, sure, there are the
- 1:22immediate costs, investigation, IT fixes to get
- 1:24systems back up, rebuilding from backups, finding
- 1:27the vulnerability, all that. But then there are
- 1:29these huge first -party losses. That's things
- 1:32like lost income because you can't operate, extra
- 1:34expenses just to keep things afloat during the
- 1:36interruption. These costs, the ones the business
- 1:39itself suffers, they're often overlooked, but
- 1:41honestly, they can be devastating. Resilience.
- 1:44is key. Right. And to really see what this looks
- 1:46like in practice, let's dive into a specific
- 1:48case, a very public one involving the Legal Practice
- 1:51Board of Western Australia, the LPBWA. They had
- 1:55a major cyber incident. And it turned out to
- 1:57be a group calling themselves Direwolf. Direwolf.
- 2:00Yeah, they're relatively new, but pretty aggressive.
- 2:03They actually state their motive is just money.
- 2:06They say no morals, no political stance, no LGBT.
- 2:10And they use these double extortion techniques.
- 2:12Double extortion. What does that mean exactly?
- 2:14Well, it means they don't just lock up your data
- 2:16with ransomware and demand money to unlock it.
- 2:19They also steal a copy of your data before they
- 2:22encrypt it. Then they threaten to publish that
- 2:24stolen data online if you don't pay up. Wow.
- 2:27So they hit you twice, operationally and reputationally.
- 2:30Exactly. It massively increases the pressure,
- 2:32especially for businesses that handle sensitive
- 2:34client information. I think law firms, accountants,
- 2:37the reputational damage can be huge. Okay. So
- 2:40let's unpack the LPBWA incident itself. How did
- 2:43it unfold? Well, they detected unusual activity
- 2:46on their network. That was on Wednesday, May
- 2:4921st, 2025. That discovery led them to, you know,
- 2:53act fast. They took some systems offline right
- 2:55away, including their main website services,
- 2:58basically to contain the problem. And what happened
- 3:01right after that? How did they keep operating?
- 3:03They had to switch to manual workarounds. Think
- 3:06about that. Processing applications, renewals
- 3:08for practicing certificates all by hand or through
- 3:11less efficient methods. That must have been incredibly
- 3:13disruptive for the practitioners relying on that.
- 3:16Absolutely. It shows the immediate real world
- 3:18impact on just day to day operations, slows everything
- 3:22down. Then things escalated. They found out some
- 3:25information had actually been disclosed publicly.
- 3:27That was Tuesday, May 27th. What kind of data
- 3:31are we talking about? What got out? Their investigation
- 3:33confirmed it was limited corporate correspondence.
- 3:36It had some minimal contact information, a bit
- 3:39of operational and resourcing information, and
- 3:41crucially, banking information for the board
- 3:43itself. And a very small number of third parties.
- 3:47Those third parties were notified directly, of
- 3:50course. Okay. Minimal contact info, some operational
- 3:53stuff, some banking details. Right. And importantly,
- 3:56they confirmed that sensitive personal data like...
- 3:59trust information or residential addresses was
- 4:03not part of that disclosure. That was a key finding,
- 4:05thankfully. But the attackers, Direwolf, they
- 4:08made some big claims, didn't they? Oh, yeah.
- 4:10They claimed they'd stolen a massive 300 gigabytes
- 4:13of data. Classic tactic to scare the victim.
- 4:16They even published a timeline threatening to
- 4:19release samples, then half the files, then the
- 4:21rest over the next month or so. 300 gigs. That
- 4:24sounds absolutely terrifying. It does. And the
- 4:26threat was real. designed to maximize pressure.
- 4:29But, and this is important, the LPBWA kept monitoring
- 4:33very closely. On June 19, someone did post a
- 4:36link supposedly containing data, but the LPBWA
- 4:39reviewed it immediately and confirmed that specific
- 4:42data does not relate to the board. So the attackers
- 4:44might have been bluffing or exaggerating the
- 4:46scope. So verifying the attackers' claims is
- 4:49crucial. Don't just take their word for it. Exactly.
- 4:51And they haven't detected any further related
- 4:53activity since then. It shows the importance
- 4:56of that verification step. What steps did the
- 4:59LPBWA take in response, beyond the technical
- 5:02side? They brought in external experts, worked
- 5:05closely with Cybersecurity Western Australia,
- 5:07and they took a significant legal step, too.
- 5:11They obtained an injunction. An injunction. What
- 5:14does that actually achieve in this context? Well,
- 5:16it's a court order. It legally prohibits anyone
- 5:19from accessing, sharing, or using the impacted
- 5:22data. So if someone tries to publish it or trade
- 5:24it, they're breaking the law. It adds a serious
- 5:27legal weapon to their recovery efforts. Interesting.
- 5:30And what about the direct impact on the legal
- 5:32practitioners themselves? Well, besides the manual
- 5:35forms we mentioned, the Find a Practitioner online
- 5:37search tool was down for a while. That was inconvenient
- 5:40for the public and other lawyers. And they waived
- 5:42late fees for a bit. Yeah, for the June renewals,
- 5:45they waived the late fees because of all the
- 5:46disruption. But those fees came back on July
- 5:491st. OK, so this whole LPBWA case study, it really
- 5:53drives home how vulnerable organizations can
- 5:55be, right? Even statutory bodies. Absolutely.
- 5:58Even organizations you'd think would have robust
- 6:01security. It leads us straight into the critical
- 6:04need for protection and specifically cyber insurance.
- 6:08Right. So thinking about legal practices again,
- 6:11how does this fit with their standard insurance?
- 6:13Like a professional indemnity policy, say, from
- 6:16the LPLC. That's a great question, and there's
- 6:19often confusion here. A standard PI policy, like
- 6:22the LPLCs, does cover certain things. It covers
- 6:25your civil liability related to your legal practice.
- 6:28So if a third party, like a client, sues you
- 6:31for damages because their data was breached due
- 6:33to your firm's mistake, that kind of claim usually
- 6:36falls under the PI policy. Okay, so third party
- 6:38claims like a client suing you. Exactly. But
- 6:41here's the really crucial part, that PI policy
- 6:44generally... does not cover the firm's own business
- 6:47losses, those first -party losses we talked about
- 6:49earlier. Ah, okay. So it wouldn't cover things
- 6:51like? Like the cost of the business being interrupted,
- 6:53the income you lose while you're down, or the
- 6:55cost of retrieving your data, the IT forensics,
- 6:58rebuilding your systems, maybe even regulatory
- 6:59fines. All those costs fall directly on the firm
- 7:02itself. And those costs can be huge. as we saw
- 7:06with the LPBWA needing experts and workarounds.
- 7:09Astronomical, potentially. Imagine being shut
- 7:11down for weeks. Your PI policy might handle the
- 7:14client lawsuit, but it won't pay for getting
- 7:16your own business back up and running or the
- 7:18income lost during that time. That's a massive
- 7:21financial gap. Which explains why we're seeing
- 7:23more firms getting separate cyber insurance,
- 7:26right, to fill that gap. Precisely. It's becoming
- 7:28standard procedure now. Firms are buying cyber
- 7:31insurance cover to supplement their other insurances.
- 7:34In fact, the LPLC recognized this gap was so
- 7:37significant, they actually worked with insurers
- 7:39Marsh and Chubb to create an optional commercial
- 7:41cyber policy. It's designed specifically to sit
- 7:45alongside the PI cover and handle those first
- 7:47party losses. That really says something about
- 7:49how essential this type of cover has become.
- 7:52It really does. It underlines that strong cybersecurity
- 7:55isn't just about firewalls and software updates.
- 7:58It's also about financial resilience. The threats
- 8:00are always changing, sophisticated scams, accidental
- 8:03data leaks, even new risks from things like AI
- 8:06being used in practices. Cyber insurance provides
- 8:09that vital safety net for your costs, the first
- 8:13party risks that your PI policy just isn't designed
- 8:15to cover. OK, so given everything we've discussed,
- 8:18the rising threats, the dire wolf example, the
- 8:20insurance gaps. What practical steps can people
- 8:23listening take now to protect themselves and
- 8:25their organizations? Right. Let's get practical.
- 8:28For your organization, it starts with a proactive.
- 8:31multi -layered defense that's more than just
- 8:34antivirus software. It means having robust security
- 8:36frameworks, regular vulnerability testing, like
- 8:39penetration testing, to find weaknesses before
- 8:41the bad guys do. And crucially, having a well
- 8:44-thought -out, tested incident response plan.
- 8:46What do you actually do when something happens?
- 8:48Who do you call? How do you communicate? It's
- 8:50like a fire drill, but for cyber incidents. And
- 8:52training for staff must be key, too. Absolutely
- 8:55critical. Regular, engaging training on spotting
- 8:59phishing emails, understanding social engineering
- 9:01tactics, because often the human element is the
- 9:05easiest way in for attackers. Okay, that's the
- 9:07organization. What about on a personal level,
- 9:10especially if you're worried your details might
- 9:11have been exposed somewhere? Yeah, good point.
- 9:14Even if it's just minimal contact information
- 9:16or banking details, extra vigilance is essential.
- 9:19Ask yourself. Are you really checking your bank
- 9:22account statements and transaction histories
- 9:24regularly for anything suspicious? That's your
- 9:27first line of defense. And if you see something
- 9:29weird? Contact your bank directly. Use the official
- 9:32phone number from their website or the back of
- 9:34your card. Never, ever click a link in an email
- 9:36or text message purporting to be from them. Good
- 9:39advice. What else? Use two -step authentication
- 9:41or multi -factor authentication wherever you
- 9:43possibly can, especially for important accounts
- 9:45like email and banking. Consider hardware tokens
- 9:48if possible. Also, check your credit report at
- 9:52least once a year. It can alert you if someone's
- 9:54trying to open accounts in your name. And the
- 9:56email advice bears repeating. Never click links
- 10:00or open attachments in suspicious emails. Just
- 10:03delete them or call the supposed sender directly
- 10:05to verify. Exactly. It's always safer to verify
- 10:08independently. So the reality is these risks
- 10:10aren't going away. They're constantly changing
- 10:12shape. That's right. It's not a one and done
- 10:15fix. It's a continuous process of assessment,
- 10:17adaptation and vigilance, both at work and at
- 10:20home. You know, considering how fast and clever
- 10:23these criminals are getting online, it's worth
- 10:25asking yourself. How prepared are you, really,
- 10:28for a digital incident? And what steps can we
- 10:31all take, maybe starting today, to build a culture
- 10:33where thinking about mitigating cyber risks is
- 10:36just second nature, like locking your door at
- 10:38night? That's a powerful thought to end on. We
- 10:40really hope this exploration of the recent cyber
- 10:43incidents and the role of cyber insurance has
- 10:45given you some valuable insights and some concrete
- 10:48takeaways. Understanding these threats and knowing
- 10:50how to prepare and respond is just so crucial
- 10:53now. And knowledge is great, but it's most valuable
- 10:56when you actually understand it and apply it.
- 10:57So stay vigilant. Stay informed. And remember,
- 11:00it's a constantly evolving landscape. There's
- 11:02always more to learn. Absolutely. For more information
- 11:05on securing your own digital environment or to
- 11:08discuss your specific security and IT needs,
- 11:10you can head over to www .kinsoft .com .au. That's
- 11:15www .kinsoft .com .au. Thank you for joining
- 11:19us on Tech Talks with Kinsoft. We look forward
- 11:21to sharing more insights with you next time.