Why Law Firms Are Ditching 'Spot the Fake' Training for Verification Routines
As artificial intelligence makes deepfake voices and video impersonations nearly indistinguishable from real ones, law firms are discovering that teaching staff to "spot the fake" is no longer a viable defense strategy. Instead, security experts are pushing a fundamentally different approach: building organizational cultures where any unusual request, no matter how convincing, triggers the same calm verification routine every single time.
The shift reflects a hard reality. Deepfake technology has advanced so rapidly that visual glitches, robotic voices, and poor grammar, once reliable warning signs, are disappearing. A Hong Kong-based employee at a major engineering firm learned this the hard way in January 2024, when a deepfake video call convinced him he was speaking with his company's London-based CFO. He executed 15 secret wire transfers totaling $25 million before the fraud was discovered.
This is not an isolated incident. Deepfake-driven identity fraud has surged by 3,000 percent over the past year, according to an Onfido identity fraud report, with gambling and gaming industries experiencing an 80 percent jump in fraud attempts alone. Deloitte has warned that generative AI could push overall fraud losses as high as $40 billion by 2027 if organizations do not adapt their defenses.
What Should Modern Cybersecurity Training for Law Firms Actually Cover?
The traditional "spot the phishing email" approach is no longer sufficient. Instead, law firms need training that addresses the psychological vulnerabilities that attackers exploit, regardless of how convincing the technology becomes. This means focusing on the core elements that make social engineering work in the first place.
- Trust in authority: Attackers impersonate partners, executives, and trusted colleagues to bypass normal skepticism.
- Urgency and panic: Requests framed as time-sensitive or crisis-driven push people to act without verification.
- Helpfulness: Employees naturally want to assist colleagues and clients, making them vulnerable to requests that seem legitimate.
- Specific attack vectors: Training should cover phishing, smishing (SMS-based phishing), vishing (voice-based phishing), AI-generated voice and deepfake impersonation, business email compromise, suspicious payment requests, fraudulent password-reset attempts, and new-client scams.
Beyond these core elements, law firms should ensure their training covers how to safely handle confidential client data, the firm's verification and escalation procedures, and how to report a mistake quickly without fear of blame.
How to Build a Verification Routine That Works Against AI Deception
The most effective defense against deepfakes and AI-powered social engineering is not detection; it is a simple, repeatable process that works even when the message looks professional and the voice sounds convincing. Security experts recommend a four-step verification routine that every employee should follow automatically when they encounter an unusual request.
- Pause when a request is urgent, unusual, secret, or financially sensitive: Train staff to recognize these red flags as signals to slow down, not speed up.
- Avoid using the contact information supplied in the suspicious message: Instead, independently verify the request through a known phone number, company directory, or internal channel.
- Require a second approval before acting on high-stakes requests: Financial transactions, credential changes, and access to sensitive files should never be approved by a single person based on an unsolicited request.
- Escalate without fear of being blamed for slowing the request down: Organizations must create a culture where pausing to verify is expected behavior, not insubordination.
The Federal Bureau of Investigation (FBI) has identified common patterns in vishing schemes that law firms should train staff to recognize. These include unexpected calls from new numbers, immediate requests to move communication to a secondary platform, urgent instructions involving money or credentials, pressure to bypass normal approval steps, and requests for multi-factor authentication codes.
Why Financial Workflows Require Extra Scrutiny
Adversaries routinely target financial processes because they represent areas where urgency and authority can override normal skepticism. Wire transfers, settlement funds, vendor payments, trust-account instructions, and bank-detail changes are all high-value targets. Law firms should implement mandatory verification steps for any new or changed payment instructions, set approval thresholds for high-risk transactions, and never accept multi-factor authentication codes or password changes through unsolicited requests.
Documentation is equally important. Firms should clearly define who can authorize exceptions to standard procedures and make "stop and verify" an expected behavior in every financial workflow.
How Should Law Firms Prepare Intake Staff for New-Client Scams?
Intake teams face a unique risk. Prospective clients may send emails with malicious attachments, weaponized Office documents, or links designed to compromise employee workstations. Law firms should provide intake staff with a simple checklist for verifying unexpected links, attachments, and file-sharing invitations before opening them. This allows the firm to stay safe without disrupting legitimate client intake.
The goal is to create a process that is both secure and efficient, so that legitimate business does not suffer while fraudulent attempts are blocked.
What Does an Effective Escalation Process Look Like?
Simple escalation procedures are one of the most underrated defenses against social engineering. Law firms should establish a clear security-reporting channel for suspicious emails, calls, login prompts, and requests, with named after-hours contacts so there is always someone to reach. Equally important is the authority to pause payments and access changes until they can be independently verified, along with fast account-lock and credential-reset procedures when compromise is suspected.
Perhaps most critically, firms must adopt a no-blame reporting process. Employees should report mistakes immediately rather than hiding them, knowing they will not face punishment for catching a potential attack.
Why Role-Based Training Matters More Than Generic Modules
Adversaries ultra-personalize social engineering attacks to increase the likelihood they will succeed. An attack on a law firm's finance department will look very different from one targeting intake teams. Finance teams face payment changes, wire fraud, and vendor impersonation, while intake teams encounter new-client attachments and fake file-sharing links. This means training should be context-based, with each major role group assigned realistic threat scenarios they are most likely to encounter.
Generic, one-size-fits-all training modules are less effective because they do not reflect the actual threats employees face in their day-to-day work.
How Can Law Firms Test Their Defenses?
The principle "practice makes perfect" applies directly to tightening defenses against AI social engineering. Law firms should augment security awareness training with regular tabletop exercises, simulated calls, role-play, and discussions around situations the firm could realistically encounter. For example, firms can divide teams into pairs where one person plays the attacker and calls requesting a confidential file, money transfer, or bypass of the usual verification process. Running even a five-minute drill using a fake urgent voice request can reveal whether staff actually follow the verification process or revert to old habits.
These exercises are not about making employees feel bad when they fail; they are about building muscle memory for the right response.
What Are Organizations Doing to Engage Employees Year-Round?
While Cybersecurity Awareness Month in October has traditionally been the focal point for security training, research shows that human risk is concentrated but constantly changing. Living Security's 2026 State of Human Risk Report found that 74.8 percent of risky behavior traces to the riskiest 10 percent of the workforce, yet two in three people in this year's riskiest 10 percent were not on last year's list.
This finding reinforces the need to engage employees and manage risk continuously throughout the year, not just during October. Living Security has expanded its 2026 Cybersecurity Awareness Month program with two new interactive experiences designed to help employees practice critical security behaviors in realistic scenarios.
The first experience, called "Verified," is a live 30-minute game-show challenge where employees navigate increasingly convincing AI-powered threats. Across three interactive rounds, participants evaluate scenarios involving deepfake video, cloned voices, phishing, smishing, impersonation attacks, and AI-powered automation. Rather than teaching employees to rely on visual glitches or robotic voices, the experience focuses on contextual warning signs such as unexpected urgency, changes to normal processes, unfamiliar communication channels, and unusual requests for money, credentials, or sensitive information.
The second experience, "Trust No One," is a team-based investigation where employees retrace a sophisticated fraud attempt that nearly resulted in financial loss. As teams investigate, they discover how cybercriminals combined publicly available information, business email compromise techniques, AI-generated voice cloning, and impersonation to create a convincing request from a trusted colleague. Throughout the investigation, participants practice three critical behaviors: slow down before acting, verify information and identities through a trusted channel, and trust evidence and established processes, not assumptions.
"Technology is changing rapidly, but one principle remains constant: verify before you trust," said Ashley Rose, CEO and Co-Founder of Living Security. "These experiences give employees hands-on opportunities to recognize deception, question assumptions, and practice the behaviors that reduce human risk."
Ashley Rose, CEO and Co-Founder of Living Security
The key insight underlying all of these approaches is that as attacks become more technologically sophisticated, simple human behaviors, such as independently verifying an unexpected request, remain powerful defenses. Law firms do not need to make everyone a deepfake expert. What they need is a culture where unusual requests trigger the same calm verification routine every time, regardless of how convincing the voice or video appears.