FREE CPD ACCREDITED WEBINAR
Navigating a Cyber Breach
A live breach simulation for law firm leaders.
No jargon. No sales pitch. Just decisions.
Attendees are not visible to each other and cannot be seen or heard.
Founder & Principal Consultant – Cyooda Security
- OVERVIEW
What this webinar is about
A practical, scenario-based session built exclusively for law firm leaders navigating cyber risk.
Cyber incidents rarely unfold neatly. Systems slow down. Alerts start appearing. Staff cannot access files. Partners begin asking questions. Then the ransom note appears.
In this session you will step through a realistic breach affecting a law firm, and the decisions your leadership team would face as it escalates. You will see how quickly a suspected IT issue becomes a full crisis involving legal, operational and reputational risk.
The focus is the first 72 hours, which is the period that usually determines how serious the incident becomes.
- Learning Outcomes
What you will learn
During the session we will work through:
- How a cyber incident actually unfolds inside a professional services firm
- The decisions that cannot wait for a partners' meeting
- Where legal, communications and IT each own part of the response
- Why early evidence preservation determines what you can prove later
- The mistakes firms make in the first 24 hours
- What real investigations reveal that incident response plans do not
You will leave with a clearer view of how a firm should respond when a cyber event becomes a business crisis.
- The Simulation
The Scenario
The session is built around a simulated incident at a mid-sized law firm. You will watch it escalate from early warning signs to ransomware affecting firm systems and, potentially, client material.
Issues explored
- Ransomware reaching practice management and document systems
- What to tell staff, and when
- Potential client data exposure and the notification clock
- Media enquiries and reputational risk
- Decisions on containment, investigation and recovery
- Whether to pay, and who in the firm actually makes that call
You will feel the decision-making pressure a real crisis creates, without the consequences.
- The Method
The Cyooda Colour Code Method™
Built on 30 years of cybercrime investigation and security leadership, the Colour Code Method™ is a proprietary readiness framework assessed across three pillars.
These pillars are assessed across seven domains — from crisis management and communications through to network containment, evidence collection and disaster recovery — using a red, amber, green maturity model that shows at a glance where a firm is prepared and where it is exposed.
About Cyooda Security
Cyooda Security is an independent cybersecurity and digital forensics firm dedicated to protecting Australian law firms.
Founded by John Reeman, former CISO of King & Wood Mallesons, with 30+ years of experience protecting law firms from data breaches, ransomware, and cyber espionage.
NSW Master Security Licence No. 000110701 · Former CISO, King & Wood Mallesons · IRAP Assessor
John Reeman
Founder & Principal Consultant
Rehearse it once, before it counts.
Wednesday 26 August 2026, 10:00am AEST. 75 minutes on Zoom. Free, and worth 1 CPD point.
Places are limited, and attendees are not visible to each other.