Cocha Technology, Inc.

Cocha Technology, Inc. IT & Cybersecurity for mid-market enterprises. Texas-based, MBE/WBE/HABE/SBE Certified. Building the .

Cocha Technology is a minority woman-owned cybersecurity consulting firm based in Houston, Texas. We specialize in delivering comprehensive cybersecurity solutions that safeguard businesses from evolving digital threats. With a team of seasoned experts, we help organizations protect sensitive data, ensure regulatory compliance, and fortify their digital assets for long-term success.

New this week: an AI assistant handed over an entire filesystem — SSH keys and all — because someone simply asked it to ...
09/30/2026

New this week: an AI assistant handed over an entire filesystem — SSH keys and all — because someone simply asked it to export a file. No hack. No exploit. Just an agent doing exactly what it was told, with none of the judgment a human would apply.

That's the risk category law firms need to start taking seriously: not what AI might say wrong, but what an AI agent is capable of doing when nobody's checking its permissions.

We break down this incident — plus the AWS credential exposure and legal tech's fast pivot toward agent governance tooling — in our latest post. Worth a read before your next AI rollout.

🔗 https://www.cochatechnology.com/ai-agent-security-risks-law-firms/

Google entered legal AI in August and the word it led with was governance. Meanwhile the public count of AI hallucinated...
09/23/2026

Google entered legal AI in August and the word it led with was governance. Meanwhile the public count of AI hallucinated citations in court filings passed 2,000 documented cases this month.

Those two headlines are one story. Vendors are now selling control planes. Courts are sanctioning missing review steps. And every AI assistant, whoever builds it, inherits whatever permissions your Microsoft 365 tenant already granted.

Vendor governance is necessary. It is not your AI risk mitigation for law firms program. Our new post breaks down the three questions a partner committee can ask this week to find out where your firm really stands.

Read about it here: https://www.cochatechnology.com/ai-risk-mitigation-law-firms-google-legal/

xAI opened Grok Bot to enterprises on September 3, and the free trial means someone at one of your portfolio companies h...
09/18/2026

xAI opened Grok Bot to enterprises on September 3, and the free trial means someone at one of your portfolio companies has probably already started it.

Here's what the coverage mostly skipped: Grok Bot runs on Cursor's infrastructure, most of the controls that matter (network allowlisting, audit logs, Action Recording, computer termination) are Enterprise-only and invisible on the free trial or Teams plan, and Audit Logs and Action Recording are separate settings that don't cover each other.

We wrote up 8 governance controls to confirm before a Grok Bot touches deal data, cap tables, or LP reporting.

Full checklist on our blog https://www.cochatechnology.com/governance-controls-grok-bot-portfolio-checklist/

Microsoft just published a real attack walkthrough: a poisoned MCP tool description quietly turned a routine Copilot Stu...
09/16/2026

Microsoft just published a real attack walkthrough: a poisoned MCP tool description quietly turned a routine Copilot Studio agent into a data exfiltration path, and every individual step it took looked completely normal.

The fix isn't one control, it's four: allowlist your MCP servers, inspect tool metadata the way you'd inspect a system prompt, move DLP down to the tool-call parameter instead of just the prompt, and correlate agent telemetry across the whole chain.

If Harvey, CoCounsel, Copilot, or Lito are live at your firm, step one is knowing exactly which tools they can reach right now. Most firms can't answer that yet.

Full breakdown, plus where this fits into a Zero Trust Assessment, on our blog https://www.cochatechnology.com/local-dlp-claude-copilot-ai-assistants/

Did you miss our live webinar on September 3rd? The full recording is up now. 🎥"Keeping Client Data Safe in the Age of A...
09/11/2026

Did you miss our live webinar on September 3rd? The full recording is up now. 🎥

"Keeping Client Data Safe in the Age of AI" — 60 minutes with Rick Thompson, Steven Combs of Cocha Technology Inc., and moderator Dan Safran, digging into shadow AI, the discoverability of AI-generated drafts, and what a real AI governance framework actually looks like for law firms right now.

Watch the full recording 🔗https://www.cochatechnology.com/keeping-client-data-safe-ai-risks-webinar/

Anthropic just announced a real shift in how it handles enterprise data for Claude: Enterprise Frontier Safeguards lets ...
09/09/2026

Anthropic just announced a real shift in how it handles enterprise data for Claude: Enterprise Frontier Safeguards lets customers keep AI monitoring data in their own cloud account, under their own encryption keys, reviewed by their own security team instead of Anthropic's.

For law firms handling privileged work, that's a meaningful change in AI agent cloud governance. It's also, as of today, still a beta. Access is request-only. Rollout is phased through this fall. No public configuration guide exists yet.

We broke down what's really documented, what's still missing, and what your firm should verify before requesting access, rather than assuming a beta means a finished product.

Read the full piece: https://www.cochatechnology.com/ai-agent-cloud-governance-anthropic-beta/

The question at ILTACON 2026 wasn't "can AI do the work." It can. The real question legal teams are wrestling with now: ...
09/04/2026

The question at ILTACON 2026 wasn't "can AI do the work." It can. The real question legal teams are wrestling with now: can you prove it did the work correctly, and show your client exactly how?

59% of in-house counsel say they don't know if their outside counsel is even using generative AI on their matters. 43% of firms have no formal AI policy at all.

That gap between adoption and accountability is where real risk lives. AI risk mitigation for law firms isn't a one-time training session anymore, it's a documented, defensible program: approved tools, verification steps, named sign-off, a trail you can reconstruct months later if you need to.

We break down what that looks like in practice, and why the trust gap is now a client requirement, not a courtesy.

Read the full piece: https://www.cochatechnology.com/ai-risk-mitigation-law-firm-trust-gap/

Harvey II launched this week with a feature called Memory, and it changes the AI governance conversation for law firms. ...
08/28/2026

Harvey II launched this week with a feature called Memory, and it changes the AI governance conversation for law firms. It's no longer just "can we trust what the AI produced." Now it's "what does this system remember about us, and who else can see it."

We broke down three gaps most firms' AI policies don't cover yet, plus what to fix before Memory rolls out past the individual preference stage. Read it here: https://www.cochatechnology.com/ai-memory-governance-law-firms/

Microsoft Copilot's mobile app now has a Record feature rolling out to general availability this month. Convenient for a...
08/26/2026

Microsoft Copilot's mobile app now has a Record feature rolling out to general availability this month. Convenient for a lot of jobs. For a law firm, it's a privilege risk sitting in a menu most lawyers haven't noticed yet.

We laid out four risks firms need to address, from consent gaps across jurisdictions to how recordings move through Microsoft's multi model Copilot tenant. Full breakdown here:
https://www.cochatechnology.com/copilot-meeting-recording-law-firms/

Microsoft patched a Copilot vulnerability this week called CoSnitch, and how it was found is the part worth paying atten...
08/21/2026

Microsoft patched a Copilot vulnerability this week called CoSnitch, and how it was found is the part worth paying attention to.

Varonis Threat Labs didn't reverse engineer this one. They asked Copilot direct questions about its own limits, and Copilot's answers eventually gave up an undocumented URL parameter that let a single crafted link pull data from a user's session, including connected apps like Gmail and Google Drive.

Here's the bigger point: this is the third Copilot flaw disclosed this year, after Reprompt in January and SearchLeak in June. A security review done once at rollout isn't enough anymore. Copilot security must be an ongoing monitoring habit, not a launch task.

Full breakdown linked here: https://www.cochatechnology.com/copilot-security-law-firms/

Address

4321 Kingwood Drive Suite 222
Houston, TX
77339

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Alerts

Be the first to know and let us send you an email when Cocha Technology, Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Cocha Technology, Inc.:

Shortcuts

Share