DHIA Wins 1st Place in Texas Lawyer’s ‘Best Of 2026’ Awards
We're honored to be chosen by the attorney audience of the Texas Lawyer as a 1st Place winner of the “Best Of” reader's survey for 2026!
A single intern collapsed US cybersecurity. That’s one lesson from the SolarWinds hack. The greater lesson is that the vulnerability was known a year earlier, and nobody took any action.
The news started dripping out in December 2020.
The Pentagon had been hacked. Homeland Security was hacked. The list is extensive:
The hackers had been in these systems for months and nobody knew it.
This was one of the largest breaches in history. But it didn’t happen through sophisticated algorithms using high-powered computers to crack passwords. No, it was a single act of carelessness by one person.
An intern at SolarWinds set a password to solarwinds123 – and that’s how the hackers got in.
“I’m just a small law firm. I’m nobody’s target.” But that’s not true.
The overwhelming majority of cyberattacks hit small and medium size businesses (SMBs). First, because SMBs are easier targets due to less sophisticated security. Second, because there are more SMBs than Fortune 1000 companies. There are exactly 1000 companies in the Fortune 1000. After exhausting this list, hackers must look for volume. And the data shows it.
Small dry cleaners have been the victim of ransomware attacks. A mobile snow cone stand faced thousands of dollars in liability from a data breach. One fact is inescapable.
Attorneys handle privileged information. And that creates an opportunity for malicious actors to extract value from law firms.
But the sensitive information itself isn’t the only reason law firms are common targets for cyberattacks. The legal industry has other specific vulnerabilities:
Don’t neglect the second lesson from the SolarWinds attack.
Who would have guessed in 2017 that one of SolarWinds’ current interns would lay the groundwork for such a devastating attack? The impact was devastating.
Company officials were drug before congressional hearings. It offered little comfort as they testified that the “solarwinds123” password violated their password policy.
The publicity of the attack created customer issues. Now they had to explain to 18,000 current customers what happened and what they were doing about it.
Possibly the greatest sting for any public company hit instantly.
The stock price dropped like a rock from over $23 a share to just over $14 a share. Billions of dollars of market capitalization vaporized as the news hit the wires. And even six months after the revelation of the attack, the stock is still hovering around $17 dollars a share.
Who would have guessed that an intern had that kind of power … the same power any of your employees or contractors have over your business?
The “solarwinds123” password was discovered publicly on the internet in 2019 by an independent security researcher. And he warned SolarWinds of the vulnerability1.
Yes, it could have been prevented. But even after the warning, SolarWinds took no action.
You’ve already been warned. Small and medium sized businesses are the overwhelming victims of cyberattacks. You have privileged and sensitive information that others want to exploit. And you have employees and contractors that will click on malicious links and use ineffective passwords that violate your password policy. Your risk is real.
Will you ignore the issue – like SolarWinds – until it blows up? Or will you heed the warning?
Here are a few resources to help you make your choice:
We also recommend you get our free Ransomware Response Kit and get dedicated Cyber Liability Insurance.
1Former SolarWinds CEO blames intern for “solarwinds123” password leak | CNN Politics
Cyber Liability Risk-Assessment
Key Questions to Ask When Shopping for Professional Liability Insurance
We're honored to be chosen by the attorney audience of the Texas Lawyer as a 1st Place winner of the “Best Of” reader's survey for 2026!
Technology is reshaping the legal field, but success depends on strengthening human connections, not replacing them. As clients demand digital convenience, firms must modernize without losing trust, empathy, or personal service. The future of law belongs to firms that are both tech-savvy and deeply human. Learn how you can achieve both.