Skip to main content
Just-TechFall 2026 · Issue No. 1

The Quarterly Briefing

Technology insight for the legal aid community · Published by Just-Tech


From the founder

Dear Legal Services Leader,

For over a decade, Just-Tech has been a trusted technology, business, and service delivery partner to legal aid organizations and regional and national collaboratives. Our team members have deep roots in legal services and work across the full range of provider needs: delivering day-to-day technology management and user support in provider offices, advancing engineering, privacy, and security, leading improvement projects for individual providers and statewide coalitions, and building AI and non-AI products that are intuitive, secure, and privacy-first. We also stay active nationally through conference leadership, community forums, national resource development, and online engagement.

Until now, we’ve shared what we learn mainly through individual conversations and communications. Based on community feedback, we’re launching The Quarterly Briefing exclusively for clients and partners. It won’t replace those conversations. Instead, it offers a more comprehensive, consistent, and accessible way to stay current on issues affecting client services and provider operations, and to explore them further on your own timing so you can act proactively rather than reactively.

Drawing on our teams’ breadth of experience and their current and historical perspective, each Briefing will share:

  • Insights from our daily work across the legal services community
  • Emerging technology opportunities from our research and development
  • Risks and mitigation strategies that protect client data, security, and business continuity

Since this is our first issue, we especially welcome your feedback, as we want this to become a resource you value for years to come. We’ve invested significantly in the Briefing, so please share it with colleagues in your organization. If you’d like to share it with people outside your organization, let us know and we’ll work to make that happen.

Thank you.

John Greiner, Esq.
Founder of Just-Tech


Security

Attackers are posing as IT support

The biggest threat to legal organizations right now does not involve malware at all. It involves a phone call, and it is working.

Someone calls or emails an employee, says they are from IT, and asks for something an IT provider might plausibly ask for: approving an MFA prompt, installing a remote access tool, sharing a screen for a minute.

And it works more often than anyone would like. Earlier this quarter a large law firm disclosed a breach affecting roughly 37,000 people that started when an employee sent documents to someone posing as IT support. The FBI has warned that law firms are being targeted with this exact playbook, sometimes including attackers who show up in person as IT contractors when the phone call fails.

Credential theft and identity compromise account for over half of observed threats against legal organizations this year.

Industry threat reporting puts credential theft and identity compromise at over half of observed threats against legal organizations this year. Your technical defenses can be excellent and none of them will stop a person from being persuaded.


Case Management

LegalServer 5 is coming, and it is bigger than an upgrade

The transition now has official dates. LegalServer 5 has been open for preview and testing since November 2025. Starting October 2, 2026, every user can preview LS5 and switch back and forth with LS4, with a site administrator override for organizations that want to control the pace. On January 1, 2027, new LS4 feature development stops, with only security issues and material failures addressed from there. And April 2, 2027 is the working retirement date: once LS4 is retired it will no longer be available, and LegalServer has said it will adjust that date only for compelling reasons.

On paper that makes the move a software transition. In practice, most organizations open the hood and find years of accumulated workarounds, one-off customizations, and processes nobody ever wrote down, all of which have to be sorted out before staff can work in the new system. The extra months are not a reason to wait. The organizations that started early are treating this as a rare chance to simplify how work actually flows, and the October 2 preview toggle means staff will start forming opinions about LS5 whether or not there is a plan. The ones that wait will be doing the same work on a deadline.


Budget

IT costs are changing shape

Two things worth building into next year’s budget. The shift from on-premise servers to cloud services means IT spending is now a recurring operating cost that grows with headcount, not a capital purchase every five to seven years. Plan for it that way.

And hardware is getting more expensive: a global shortage of memory chips, driven largely by AI data center demand, is pushing up computer prices and analysts expect it to run into 2027. If a device refresh is in your plans, budget more than last time.


What We’re Seeing

Patterns from across the environments we support, in aggregate.

Impersonation over malware. More account compromise attempts, more phishing, more social engineering. A growing share skips malware entirely in favor of a convincing phone call.

Work data on personal devices. Staff check email, files, and case data from personal phones and laptops with nothing protecting them. A lost device or a departing employee can mean sensitive data sitting outside any managed environment, indefinitely.

Intake friction. Duplicate data entry, inconsistent screening, long intake processes. Demand keeps growing and capacity does not, and the organizations making real progress are fixing the process before buying technology for it.

Appetite for knowledge management. Organizations want their documents, case-related and not, stored securely and actually findable when someone needs them.

Just-Tech in the Field

Verified support, both directions. We rolled out mutual identity verification for sensitive support requests using Traceless, which works with Duo, Okta, and Microsoft Authenticator. When a client calls us with a sensitive request, we verify who they are before acting. They can verify us the same way. Since impersonation is the whole trick, this closes the door it comes through.

Catching what gets through. We have been deploying identity detection and response across client Microsoft 365 environments. A stolen session that already passed MFA looks like a normal login to perimeter tools. This watches behavior instead, flags compromised accounts quickly, and records everything the attacker accessed, so you know what was exposed and what needs to happen next. If we haven’t talked with you about this yet, expect to hear from us soon.

Consulting in the field. Our consulting team is deep in LegalServer 5 planning, intake redesign, and business process analysis with organizations across the community.

Knowledge management grows. Knowledge management projects keep expanding, pairing SharePoint with secure AI so sensitive documents stay protected and staff can actually find them.

The Checklist

Three things worth doing this quarter.

Teach staff what IT will never askNo legitimate IT provider will call out of the blue and ask an employee to install remote-access software, hand over an MFA code, or approve a prompt. Every staff member should know that, and should verify any unexpected request through a channel they already trust, like an existing ticket. Never through a number the caller provides. Put it on the agenda for your next all-staff meeting.

Get off text-message MFAMicrosoft retires SMS and voice-based MFA in Entra ID on February 1, 2027, and the other major platforms are moving the same direction. Anyone whose only MFA method is a text code will simply be locked out when it hits. Find out who that is in your organization now, and start moving them to passkeys or another phishing-resistant method.

Start LegalServer 5 planning nowRetirement has moved to April 2, 2027, but the preview window opens to every user on October 2, which makes this quarter the right time to inventory your customizations, workarounds, and undocumented processes. Assign an owner now, because the inventory takes longer than anyone expects and it goes better without a deadline breathing on it.

Spotlight

JTAI: secure AI, built for legal aid

Most conversations about AI in legal aid stall on the same tension: the tools are clearly useful, and nobody wants client data anywhere near them.

JTAI is our answer to that. It is a secure AI platform built for legal services organizations, and the difference is where the answers come from: your own SharePoint documents, your LegalServer data, your templates and policies, not the open internet. An advocate can ask a plain-language question and get an answer grounded in how your organization actually works. Finding the right precedent takes seconds. Getting oriented on an unfamiliar case type stops requiring a colleague’s afternoon. Everything runs with tenant isolation and US data residency, so the security answer is built in rather than bolted on.

JTAI came out of grant-funded pilots with legal aid organizations and is now available by subscription. The best way to evaluate it is the 30-day guided pilot, which runs on your own real content in a structured scope, so you are judging it against your actual work instead of a demo. If your organization is trying to figure out what responsible AI adoption looks like, we would be glad to help you think it through. More at jtai.law.

Come find us in Cincinnati.

We will be at the Access to Justice Network Conference October 21 and 22, plus the pre-conference day on the 20th. John Greiner and Brandon Slack are both on speaker panels. If you are going, come say hello.


Just-Tech

Questions about anything in this issue?
Your Just-Tech contact or [email protected]. We would much rather plan early than untangle later.
just-tech.com · 1345 Avenue of the Americas, 2nd Floor, New York, NY 10105