Firms who decided to wait to migrate to Microsoft 365 are now at risk.
Extended support for SharePoint Server 2016 and 2019 ended July 14.
The same day, Microsoft shipped what are now the final scheduled security fixes for both.
In the same window, CISA confirmed active exploitation of four SharePoint Server flaws where attackers steal IIS machine keys.
Those keys could let them walk back into a fully patched server.
I know several firms who looked at the risks and decided to wait.
I get it. Migration is expensive, disruptive, and nobody gets promoted for finishing one. There is always a matter, a merger, or a DMS project sitting in front of it.
But the math changed on July 14. Before that date, staying on-prem meant accepting a patch cadence you controlled.
After it, staying means accepting that the next critical SharePoint vulnerability has no fix coming. Not a delayed fix. No fix.
And yes, Subscription Edition is still supported. It is also still a farm you patch, keys you rotate, and servers you keep off the open internet.
This is where it stops being an IT decision.
On-prem SharePoint sometimes holds firms holds matter files, deal rooms, investigation workspaces, and records under litigation hold.
A machine key compromise is not one server. It is potential access to everything the farm serves.
That pulls in breach notification analysis, outside counsel guidelines, insurer notice, and preservation decisions before the technical work is even finished.
So the question for firms still waiting is not "when can IT get to this."
It is "who is signing off on running unsupported infrastructure and what do they tell the client who asks."
First published on LinkedIn. Read the thread and replies.
Ted Theodoropoulos is CEO and co-founder of Infodash and hosts the Legal Innovation Spotlight podcast. He writes about legal AI strategy, law firm technology, and the economics of the law firm business model.