Start Free Trial
Back to Resources
Legal Tech

Your Firm Is a Ransomware Target: What Thai Law and Accounting Practices Need to Know in 2026

A boutique law or accounting firm principal who thinks about cybersecurity at all tends to assume the risk applies to someone else: a bank, a hospital, a large corporation with valuable data at scale. A three-to-fifteen-person professional services practice does not feel like an attractive target. That assumption is wrong, and it is wrong in a specific and dangerous way: a boutique firm is not overlooked because it is small. It is targeted precisely because of what it holds and how it is likely to respond.

Thailand’s cyber threat environment has escalated sharply. Thai-CERT and the Royal Thai Police Cyber Crime Investigation Bureau reported a 42% increase in reported cyber incidents in 2025 compared to 2024, with financial losses from cybercrime exceeding THB 70 billion. Globally, ransomware groups have run sustained, deliberate campaigns against law firms specifically, with more than 200 tracked incidents targeting legal practices in 2025 alone. This is not incidental exposure from a broader wave of attacks. It is a pattern of deliberate targeting, and the logic behind it applies just as directly to an accounting practice holding client financial records as it does to a law firm holding case files.

Why Professional Services Firms Are an Attractive Target, Not an Overlooked One

The reason ransomware groups target law firms and accounting practices specifically comes down to what these firms hold and how they are likely to behave under pressure. A professional services firm holds concentrated, highly sensitive client data: financial records, contracts, litigation files, tax positions, and confidential business information, often for dozens of clients, in one place. This is a richer target per successful breach than many single businesses would offer.

The behavioural factor matters as much as the data itself. A law firm bound by confidentiality obligations to its clients, or an accounting firm holding sensitive financial data it does not want exposed, faces strong pressure to resolve an incident quietly and quickly rather than risk case files or client financial data being published, which is the standard “double extortion” tactic: encrypt the data, and threaten to publish it regardless of whether the ransom is paid. Attackers know this dynamic well. A target that is both highly sensitive to disclosure and less likely to have dedicated security resources than a large corporation is, from an attacker’s perspective, a better return on effort than a well-defended enterprise with a security operations team.

For a boutique firm, this means the absence of a large, valuable-looking IT footprint is not protection. The value an attacker sees is in the data and the client relationships behind it, not in the size of the firm’s server room.

Where Small Firms Are Actually Exposed

The specific entry points that put a boutique professional services firm at risk are rarely exotic. They are the ordinary, everyday gaps that accumulate in a firm that has grown organically without a deliberate security review.

Shadow IT, meaning staff using consumer tools such as personal email accounts, LINE, or personal cloud storage to move client documents because the firm’s own systems are inconvenient, is one of the most common entry points. Every one of these unmanaged channels is a location the firm does not monitor, does not back up, and cannot secure with the same controls applied to its primary systems.

Personal devices used for client work extend the same problem. A staff member’s personal laptop or phone, used to access client email or documents outside the office, is outside the firm’s control and often lacks the security software, patching discipline, and access controls the firm applies to its own equipment.

Unsegmented file storage is the structural issue that turns a single compromised account into a firm-wide incident. If every client’s documents sit in one shared drive accessible to every staff member’s login, a single phished credential gives an attacker access to every client’s files at once, rather than a contained subset. This is the difference between a limited incident affecting one matter and a catastrophic one affecting the entire client base.

What Actually Reduces the Risk

The defences that materially reduce both the likelihood of a successful attack and the scope of damage if one occurs are not exotic or expensive relative to the risk they address.

Multi-factor authentication on every account that touches client data closes the single most common attack vector: a stolen or guessed password used alone. This is a low-cost, high-impact control that many boutique firms have not universally applied across every system in use, particularly older or secondary tools that were adopted informally.

Access segmentation by matter limits what a single compromised account can reach. A structure where staff access is scoped to the matters they actually work on, rather than a blanket grant across every client file, means a compromised credential exposes a bounded set of documents rather than the entire client base.

Regular, tested offsite backups are what determines whether a ransomware incident is a serious operational disruption or an existential one. A firm with current, verified backups stored separately from its primary systems can recover its own operations without paying a ransom, even if the negotiation over stolen data continues separately. A firm without tested backups faces a much starker choice when its systems are encrypted.

Consolidating client data into a small number of governed systems, rather than scattering it across personal drives, inboxes, and messaging apps, reduces the attack surface directly. Fewer places where client data lives means fewer places an attacker can reach, and fewer places the firm has to search when trying to understand what has actually been exposed.

The Overlap With PDPA Breach Notification

A ransomware incident and a PDPA-reportable data breach are frequently the same event. When client personal data is encrypted or exfiltrated in a ransomware attack, the firm is very likely facing the 72-hour PDPC notification obligation covered elsewhere in this series at the same time it is dealing with the operational crisis of the attack itself.

The connection between the two is direct: a firm’s ability to meet that 72-hour deadline depends entirely on having systems that are contained and well-understood enough to investigate quickly. A firm that has already consolidated its client data into a small number of governed systems can answer the scope question, what was affected and whose data was involved, in hours. A firm whose data is scattered across shadow IT and personal devices cannot answer that question quickly at all, which means the security posture question addressed before an incident directly determines whether the regulatory response after one succeeds or fails.

This is why security posture and breach response cannot be treated as separate problems solved at separate times. The security work done now, before any incident, is what makes the response process achievable when an incident does occur.

A Realistic Starting Point for a Boutique Firm

None of this requires a boutique firm to build an internal security team or make an enterprise-scale technology investment. The realistic starting point is an honest inventory: where does client data actually live today, across every system, device, and app in active use, not just the ones the firm intends staff to use. Most firms discover the inventory is larger and messier than assumed, with shadow IT channels that grew informally and were never consciously approved.

From that inventory, the practical priority order is straightforward: enforce multi-factor authentication everywhere client data is accessed, verify that backups exist and actually restore correctly when tested, and begin consolidating scattered client data into fewer, better-governed systems rather than accepting the sprawl as permanent. None of these steps require abandoning tools the firm currently relies on; they require deliberately choosing which systems hold client data and closing off the informal channels that have grown up around them.

FirmFlow and a Smaller Attack Surface

FirmFlow consolidates client documents, correspondence, and matter data into a single governed system rather than scattered across personal drives, inboxes, and messaging apps. Fewer places for an attacker to reach, and a much faster answer to the first question that matters in an incident: what was actually exposed.

For a boutique firm, the practical benefit is twofold. Day to day, a smaller number of governed systems is simply easier to secure well, with fewer entry points to monitor and fewer credentials to protect. If an incident does occur, the firm is in a materially stronger position to assess scope quickly, contain the damage, and meet the notification obligations that a breach of client data triggers. Thailand’s cyber threat environment is not going to become less active, and the firms that are already targeted are not chosen because of their size. They are chosen because of what they hold and how quickly they are likely to fold under pressure. A firm that has already reduced its exposure and consolidated its data is neither.

Read the full guide, it's free

Join thousands of Thai professionals getting practical firm management insights.