Practicing law at the speed of technology: How Cole, Scott & Kissane made speed the standard
Cole, Scott & Kissane cut investigation time from more than an hour to under seven minutes, and freed its analysts for the high-value vulnerability work that always got pushed aside.
The Challenge
Thirty minutes is an eternity
In 2025, Jason Thomas was already calling the traditional SOC a legacy model. A year later, Jason feels that his beliefs are confirmed. He wasn’t willing to accept a 30+ minute window to understand whether a threat actor was working within his environment.
"Thirty minutes to an hour is like an eternity in the security space, especially if there's a potential breach or a threat actor in your environment."
Cole, Scott & Kissane, Florida's largest law firm, with more than 550 attorneys across 12 offices, used a legacy MDR provider for security operations and saw a 30-minute to one-hour response time and lacked comprehensive coverage. Jason's analysts were left to absorb the difference.
Efficiency is the operating model, and technology is where Jason and his team are able to innovate. The legal industry also tends to be conservative on technology adoption, which is exactly what makes technology a competitive advantage for CSK.
That instinct for innovation set the terms for what had to change.
The Decision
The question was whether to hire
Their legacy MDR provider was slow to respond, and its coverage had gaps, including CrowdStrike Identity alerts. Jason saw two ways to transform security operations: hire more people to cover what the MDR missed, or use AI for more of the process.
But his team was already bogged down in manual analyst work. Adding people would have relieved some of the alert triage without freeing anyone for the work that mattered more, like vulnerability management.
Jason keeps a constant eye on evolving technology, constantly evaluating what is new to market in security. He saw 7AI as a potential answer to the challenge his team was facing.
Speed made the decision clear
Security at CSK was working. Jason's team keeps looking for the next edge, and a lot of the firm's success runs on the technology behind the lawyers.
Because he hadn't set out to find a new partner, Jason didn't know what his evaluation criteria would be.
“Going into the evaluation, we didn't yet have clear criteria. As a new market category, we were exploring the potential of the technology to solve our challenges. But it didn't take long to figure out after doing the POC. The biggest thing for us has always been the speed of response time."
Compared to their legacy MDR, the results were clear. Who got to the alert first? Who got to it fastest? Who got to every alert? The answer was 7AI every time.
A decision this size would normally have gone to a formal comparison test. The POC had already answered the question.
"Normally we would have done a bake-off, but in this case I was pretty confident."
That confidence held up in practice. When a penetration test ran against the environment, 7AI flagged the activity and correctly identified the first alert as malicious.
The partnership worked the same way. When Jason's team asked for connectors their previous provider had passed on, the answer was yes.
Super flexible. 'Hey, it would be nice if we had this,' and I understand security vendors can't do everything. But if it makes sense for one customer, it usually makes sense for other customers. And the answer was always yes from 7AI. The team was always willing to add features quickly.
The work that always took a backseat
We started looking at 7AI and in my mind, it totally makes sense, this is the future. The proof is in the pudding. It doesn't take very long. Within the first few weeks you're going to see the value. This is not like an ERP implementation.
With 7AI implemented, alert investigation time went from more than an hour to under 7 minutes. This offloaded a lot of the Tier 1 work that someone on Jason's team would have to look at. CrowdStrike Identity alerts, which had gone uncovered, are now investigated alongside everything else.
That freed his team for the work that had been waiting, like vulnerability remediation. It gets pushed to the side because it is voluminous and time-intensive, and security alerts will always take top priority. With 7AI handling those, his team could finally get to it.
Proof at the scale that matters
From the analysts
The engine speaks for itself
Ask Jason's analysts what stands out, and they go straight to the investigation engine. They describe it as self-sufficient in understanding the environment. It explains its reasoning in language anyone on the team can follow, arrives with response plays and remediation guidance already built in, and lets an analyst expand any line item, a hash or an endpoint, into the underlying telemetry without leaving the investigation. When they want to ask it something directly, there is a chat function for that too.
Sounds like a messaging problem
Sounds like a messaging problem. That fear is valid, but it's also how you message it. This is going to make your life easier. We're not here to reduce staff. We're trying to make you more efficient and make your job more enjoyable.
Jason puts the responsibility on leadership. Fear travels from the top down, so CISOs are the ones who have to tell their teams what AI gives them back. The trick is separating tasks from roles. The Tier 1 queue was never anyone's career.
What comes next
AI defense isn't optional anymore
The attack surface itself is moving. In May 2026, researchers reported hundreds of thousands of unsafe or suspicious artifacts across public AI model repositories, including models capable of arbitrary code execution, alongside a coordinated campaign of malicious agent skills. The infrastructure security teams are adopting has itself become a target.
"If we have the tools, then guess what, the threat actors have the same tools. So we have to match, if not beat, the speed at which they're coming at us."
Jason had been watching this category closely long before any of it reached his environment, sorting what was legitimate from what was not. That is what makes his read useful. He has seen enough of the market to know the difference.
The takeaway
Those days are long gone
CSK's answer was to treat security the way it treats everything else in the business, as a technology problem with a technology answer. That is the part any firm can copy.
"The current generation of lawyers want all the tools. They want to be more efficient. They don't want to be a pencil-and-paper kind of place anymore. Those days are long gone."
For Jason, the question of whether the technology is ready is already settled.
See for yourself
Hear the full conversation
Jason Thomas joined 7AI's Lior Div and Nate Burke live at Black Hat 2025 to talk about bringing AI into a law firm years ahead of the curve. They cover the culture shift it takes, how to move talent to the work people enjoy, and why he already sees the traditional SOC as a legacy model.