Free cookie consent management tool by TermsFeed Generator Update cookies preferences
Case Study · Legal

Spencer Fane Verifies Systems at Runtime for Data Protection and Breach Prevention

The legal sector saw a record surge in ransomware attacks in 2024, and the FBI issued a 2025 advisory identifying threat groups consistently targeting U.S. law firms' high-value data.

Client trust and firm reputation depend on the confidentiality of sensitive M&A data, IP and patent filings, litigation strategies, privileged communications, and more.

IndustryLegal Services
OrganizationNational, Am Law 200
EnvironmentsWindows & Linux
SolutionInvary's Runtime Integrity
Case Study Focus

Spencer Fane LLP sought continuous assurance that the systems remained trustworthy, both within the office and across a globally mobile workforce. The firm recognized that protecting data and preventing breaches requires more than traditional security tools.

The Problem

Attacks Undetectable by EDR/XDR

Attacks are increasingly engineered to target systems to bypass security tools.

35%

35% of malware bypass EDR/XDR altogether (Mandiant).

50%

Zero-day attacks are increasing 50% year-over-year (Google Threat Analysis Group).

212 days

Traditional security detection fails to surface this class of compromise, allowing breaches to persist undetected with an average dwell time of 212 days (IBM Cost of a Data Breach Report).

Zero Day Undetected10%
Undetected25%
Detected by EDR/XDR65%

Sources: IBM, CrowdStrike, Mandiant, Google TAG, MITRE, and Hackmanac

“At Spencer Fane, safeguarding data is our highest priority. Invary's ability to verify the integrity of our systems at runtime represents a significant advancement in security. By reinforcing the foundation of our security posture, Invary enhances our ability to protect our critical data.”
Wai Sheng Cheng, Information Security & Risk Manager, Spencer Fane LLP
The Problem

Security Decisions Must Rely on Verified Systems

While evaluating Invary's Runtime Integrity, Spencer Fane recognized that while traditional security tools are necessary, they rely on the integrity of the underlying systems. If that foundation is compromised, the telemetry those tools produce cannot be trusted.

Example

An AI-driven attack beneath a firm's security stack can surveil privileged files, exfiltrate data, and persist undetected for months while every tool above reports “all clear.”

“We had strong security tools in place. What we lacked was an independent way to confirm that the systems underneath them remained uncompromised. We needed to move from assuming trust to verifying it.”
Wai Sheng Cheng, Spencer Fane LLP
Deployment

Deployment of Invary's Runtime Integrity

With Invary's Runtime Integrity deployed, Spencer Fane now operates with continuous, independent assurance that the systems remain uncompromised.

The lightweight Invary sensor introduced no performance impact to the firm's existing applications and security stack, and the solution integrated into existing workflows without adding operational burden.

“Invary deployed quickly and cleanly across our environment with minimal lift.”
Wai Sheng Cheng, Spencer Fane

Case Study Results

Confidence in the security stack

Invary validates that detection tools are operating as intended, restoring trust in the telemetry the firm relies on for security decisions.

Force multiplier for a lean team

Automated integrity verification provides advanced assurance without requiring a dedicated SOC or additional analyst headcount.

Verified system integrity

Continuous verification confirms that systems remain in a trusted state, preventing attackers from persisting undetected.

Data protection & trust assurance

Verified system integrity strengthens the firm's ability to safeguard data and prevent breaches, enhancing trust and reducing risk.

System Trust

Invary's Runtime Integrity for System Trust

Powered by NSA-licensed technology, Runtime Integrity attests to the integrity of system state in-memory and exposes unauthorized modification, including zero-days and AI-driven attacks designed to evade traditional tools.

Invary provides independent assurance of system state:

  • verifying your security posture can continuously be trusted and
  • exposing attacks that have evolved to blind and bypass defenses.
Outcomes of Runtime Integrity:
  • Reduced breach risk (avg. cost $9.5M), even against AI-driven attacks
  • Reduced attacker dwell time, from avg. 212 days to hours
  • Increased confidence in existing security tool telemetry
  • Improved operational continuity and reduced downtime
Risk Reduction and Operational Resilience

Strategic Value of Continuous Assurance

Decisions based on unverified systems may lead to persistent compromise, extended dwell time, inefficient incident response, and operational disruption.

Invary's Runtime Integrity enables security leaders' confidence that the firm's systems are in a known-good state and that existing security tools can be trusted.

Zero Day Detection

Reveals advanced kernel-level attacks that evade existing security tools

Data Privacy and Security

Verifies & attests to system integrity and data privacy in real time

Zero Trust Architecture

Applies Zero Trust principles by removing implicit trust of the OS

Audit and Compliance

Provides evidence to enhance efforts: SOC2, FedRAMP, CMMC, ATO, etc

Validate integrity, expose hidden threats, and enhance trust.

Invary provides continuous runtime integrity validation for Windows and Linux systems, detecting unauthorized changes that traditional security tools miss.

Book a Demo