On September 25, Epiq announced it had acquired Canopy, a company whose platform sorts through data exposed in a breach to work out whose information was in it. Three days later, on September 28, Repario announced it was acquiring UnitedLex, bringing together two large legal services providers with more than 2,000 people across the United States, Mexico, India, the United Kingdom, and the European Union.
Neither announcement is likely to have reached your inbox. Both involve companies that, somewhere in the chain, hold law firm data.
That is the part worth pausing on. Legal technology is consolidating quickly, and every acquisition raises the same quiet question for downstream firms: the company you signed with is no longer the company that holds your files. Who does the work, where does the work happen now, and what in your agreement followed the data across?
The risk you inherit without signing anything
Most firm administrators have a reasonably clear picture of the systems inside the building. The vendor picture is usually fuzzier, because it accumulates one engagement at a time. A litigation team brings in an e-discovery provider for a single matter. Accounting adds a billing platform. A partner signs up for a research tool. Five years on, the list of outside parties holding some slice of client information is longer than anyone ever wrote down.
The consequences show up in the incident data. BakerHostetler’s 2026 Data Security Incident Response Report, which covers more than 1,250 security incidents the firm handled in 2025, found that vendors were the cause of 25% of them. Phishing remained the single largest cause at 30%, but a quarter of incidents originated outside the organization and ultimately had to be reported. The report also found class action lawsuits filed in 14% of incidents, up from 9% the year before.
A quarter of incidents originating with a third party is a different kind of exposure than a phishing click. You cannot train your way out of it, and you cannot patch it. It rests on knowing who your vendors are, what they hold, and what they have committed to.
Consolidation puts pressure on all three. When a provider is acquired, the practical details that matter to a firm can shift: which subcontractors touch the data, which country the review happens in, which security commitments survive the transition, and how AI is applied to the material. In the Repario and UnitedLex announcement, both companies went out of their way to address this, stating that client data is protected throughout the full lifecycle and handled in accordance with security, confidentiality, and data-sovereignty requirements each client demands. That is the right commitment to make, and it is also the kind of term a firm should be able to point to in its own agreement rather than read about in a press release.
Epiq’s release conveys the scale involved. The company says it supports more than 1,800 cyber incidents a year and serves more than 87% of breach counsel. When a provider operating at that volume adds an AI-driven review capability, the change reaches a great many firms at once, most of whom will never see an announcement about it.
What we do about it
This is work Innovative Computing Systems takes on directly, because it is exactly the kind of preventable problem that turns into a crisis when nobody owns it.
We build and maintain an inventory of your firm’s technology environment, and that inventory extends beyond servers and laptops to the external systems that hold client data. Knowing what exists removes the guesswork, so decisions about renewals and access are made from a record rather than memory. We keep documentation current as the environment changes, so when a vendor is acquired or a platform adds a capability, there is an accurate record to check against rather than a reconstruction from memory.
In our strategic reviews, we look at the vendor landscape alongside your infrastructure roadmap, so contract renewals, security requirements, and consolidation news get examined on a schedule instead of surfacing at renewal time. When something changes at a provider, we investigate what it means for your environment and bring you the answer along with a recommendation.
Through Managed Intelligence, we help firms set the rules for how AI is used, including in the tools outside firms provide. That covers approved tool guidelines, data protection rules, and the acceptable-use boundaries that should be reflected in what a vendor is permitted to do with your material. When a provider announces an AI capability, your firm already has a position on it instead of forming one under pressure.
And when an external system becomes the source of a problem, we coordinate the response and work through the issue with you. We do not hand it back as a vendor matter.
The reassurance
Vendor consolidation is not slowing down, and no firm is going to stop using outside providers. The goal is to know what is on the list, keep the written commitments up to date, and have someone whose job it is to notice when they change.
Innovative Computing Systems has worked exclusively with law firms since 1989, which means we have watched a great many providers merge, rebrand, and change hands. We know which questions to ask and which answers to get in writing. Your environment stays safe, secure, and reliable, and you can focus your people and your firm instead of tracking press releases. We’ve got your back.
If you want a clear picture of which outside systems hold your firm’s data and what those agreements actually commit to, request a consultation. A Solutions Consultant will follow up to talk through your environment and identify any gaps.
