| Professional Services Firms Face Record Cyber Attacks SonicWall Finds SonicWall Research Finds Professional Services Firms Overruled by Their Own Cybersecurity Gaps as Attackers Target the Sectorâs Privileged Data SonicWall today released its 2026 Professional Services Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report, revealing that law firms, accountancies, consulting practices, engineering firms and managed service providers generated 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry SonicWall tracks, and that 460 organizations in the sector are actively detecting ransomware campaigns, the broadest exposure of any vertical. Every year, attacks look more sophisticated. In most ways they are; AI has made them faster, cleaner, and harder to spot at a glance. But the underlying methods have not changed. Attackers are still walking through the same unlocked doors. In professional services, those doors are open by design. Client portals, document management platforms, billing systems and collaboration tools are built to be accessible, and that accessibility is also the vulnerability. âProfessional services holds the kind of data that carries built-in leverage,â said Michael Crean, SonicWall SVP of Managed Services. âClient records tied to active legal matters, financial transactions, privileged communications, and for MSPs, administrative credentials into dozens of other organizationsâ networks. We're not talking about harmless background data. For the client, it represents massive financial, legal, and reputational risk. Attackers know this value, and the data bears that out.â SonicWallâs Professional Services Protect Brief draws on data from SonicWallâs global network of more than one million security sensors to document the specific attack patterns, exploitation vectors and ransomware campaigns defining the professional services threat landscape in the first half of 2026. Key Findings from the 2026 SonicWall Professional Services Protect Brief An MSP Breach Is Never Just One Breach