Law firms are built on trust. Every client matter involves confidential communications, privileged documents, financial records, and personally identifiable information (PII). That makes law firm cybersecurity both an IT priority and a professional responsibility.
The threat is real. According to the ABA Cybersecurity TechReport 2023, 29% of law firms reported a security breach, while the Verizon 2024 DBIR found that the human element was involved in 68% of breaches.
Today, cybersecurity and data privacy go hand in hand. Protecting client data and complying with evolving privacy requirements are now essential responsibilities for every law firm.
Why Law Firms Are Prime Targets for Cyberattacks
Law firms are attractive targets because they store highly valuable information in one place, including confidential client communications, financial records, intellectual property, litigation strategies, and trust account data. A single breach can expose hundreds or thousands of sensitive files.
Common threats include Business Email Compromise (BEC), ransomware, phishing, and credential theft. According to the FBI Internet Crime Complaint Center (IC3) 2023 Report, BEC caused nearly $2.9 billion in reported losses, making it the costliest category of cybercrime.
The consequences extend far beyond financial losses. A data breach can trigger breach notification obligations, malpractice claims, regulatory scrutiny, and reputational damage. Clients also expect firms to demonstrate strong data protection and cybersecurity practices before entrusting them with sensitive matters.
For small and midsize law firms, three security priorities provide the greatest protection:
- Strong identity protection through multi-factor authentication (MFA) and modern access controls.
- Secure document management systems, such as iManage or NetDocuments, combined with encryption and role-based permissions.
- A tested incident response plan supported by managed security monitoring, reliable backups, and ongoing employee security awareness training.
These foundational controls significantly reduce both operational risk and ethical exposure without requiring an enterprise-sized security team.
Your Client-Data Obligations: What the Rules Actually Require
Cybersecurity obligations for lawyers are not based on a single regulation. Instead, they come from a combination of ABA Model Rules, Formal Opinions, state breach notification laws, and contractual security requirements imposed by clients. Together, they establish that protecting client information is a professional obligation, not simply a technical best practice.
ABA Model Rules and Formal Opinions
Over the past decade, the American Bar Association has clarified that lawyers are expected to understand technology risks, implement reasonable safeguards, supervise vendors, and respond appropriately when security incidents occur.
| ABA rule or opinion | Year | What it requires? |
|---|---|---|
ABA Model Rule 1.1, Comment 8 | Current | Lawyers have a duty of technology competence and should understand the benefits and risks of relevant technology. |
ABA Model Rule 1.6(c) | Current | Attorneys must make reasonable efforts to prevent the unauthorized disclosure or access of confidential client information. |
ABA Model Rules 5.1–5.3 | Current | Partners must supervise lawyers, staff, and third-party vendors to ensure compliance with professional obligations. |
ABA Formal Opinion 477R | 2017 | Firms should assess when encryption or additional security measures are necessary for client communications based on the sensitivity of the information. |
ABA Formal Opinion 483 | ABA Formal Opinion 483 2018 | Law firms have a duty to monitor for data breaches, stop and mitigate attacks, investigate their impact, and notify current clients when appropriate. |
What “reasonable efforts” actually mean?
The ABA intentionally avoids requiring specific technologies because cyber threats change constantly. Instead, ABA Model Rule 1.6(c) expects law firms to assess their risks, implement appropriate safeguards, and review them regularly.
In practice, “reasonable efforts” typically include multi-factor authentication (MFA), device encryption, reliable backups, phishing protection, regular patching, and access controls for confidential client data. Firms should also evaluate the security of third-party vendors, including cloud platforms, legal software, and managed IT providers.
These responsibilities extend beyond attorneys. Under ABA Model Rules 5.1–5.3, managing partners must also oversee employees and vendors with access to client information. Regular cybersecurity training, vendor due diligence, documented security policies, and a tested incident response plan all help demonstrate that the firm is meeting its ethical obligations while reducing cyber risk.
State and Regulatory Requirements Every Law Firm Should Know
The ABA Model Rules establish ethical responsibilities, but they are only part of a law firm’s cybersecurity obligations. Firms must also comply with state breach notification laws, client security requirements, and industry-specific regulations where applicable.
For example, the Illinois Personal Information Protection Act (PIPA) requires organizations to notify affected individuals following certain data breaches involving personal information. Firms serving clients in regulated industries may also need to support compliance with frameworks such as HIPAA, the General Data Protection Regulation (GDPR), or the California Consumer Privacy Act (CCPA).
Corporate clients often impose additional security requirements before engaging outside counsel. Security assessments commonly evaluate encryption, backups, incident response, vendor management, and employee cybersecurity training. As a result, strong data security and data privacy practices have become both a compliance requirement and a competitive advantage for modern law firms.
The 6 Most Common Cyber Threats to Law Firms
Every law firm faces cyber risks, but some threats appear far more frequently than others. Understanding how these attacks work allows firms to prioritize the security controls that provide the greatest protection.
| Threat | Common attack path | Recommended control |
|---|---|---|
Business Email Compromise (BEC) | Stolen email credentials, fake wire transfer requests | Multi-factor authentication, callback verification, email security |
Ransomware | Phishing emails, compromised remote access, unpatched systems | Endpoint Detection and Response (EDR), tested backups, patch management |
Phishing & credential theft | Malicious emails, fake login pages | Security awareness training, MFA, email filtering |
Insider threats | Employee mistakes or malicious actions | Least-privilege access, monitoring, offboarding procedures |
Third-party vendor compromise | Compromised cloud software or service providers | Vendor risk assessments, contractual security requirements |
Lost devices & remote work | Unencrypted laptops or mobile devices | Full-disk encryption, mobile device management, remote wipe capabilities |
1. Business Email Compromise (BEC)
Business Email Compromise remains one of the most damaging attacks targeting legal practices. Criminals impersonate attorneys, clients, lenders, or title companies to convince employees to transfer funds or change payment instructions. Since many firms routinely manage escrow accounts and sensitive financial transactions, even one successful fraudulent wire transfer can result in substantial losses.
Strong email authentication, multi-factor authentication, and a mandatory callback procedure for wire transfer requests are among the most effective defenses against BEC.
2. Ransomware
Ransomware attacks have evolved beyond simply encrypting files. Modern attackers frequently steal confidential documents before encrypting systems, threatening to publish sensitive client information if the ransom is not paid. This “double extortion” approach creates legal, ethical, and reputational consequences in addition to operational downtime.
A layered defense - including Endpoint Detection and Response (EDR), offline backups, rapid patch management, and continuous monitoring - significantly reduces the likelihood and impact of ransomware incidents.
3. Phishing and Credential Theft
Phishing remains the primary entry point for many cyberattacks. A convincing email may trick an employee into revealing login credentials or downloading malicious software, allowing attackers to gain access to email accounts, document repositories, or cloud applications.
Regular employee training, phishing simulations, and MFA dramatically reduce the success rate of these attacks. Because the human element continues to play a role in most security incidents, ongoing awareness programs are just as important as technical controls.
4. Insider Threats
Not every security incident originates from an external attacker. Employees, contractors, or former staff members may accidentally expose confidential information through poor security practices, or intentionally misuse sensitive data.
Role-based access controls, detailed audit logs, and prompt account deactivation when employees leave the firm help minimize insider risk while protecting confidential client information.
5. Third-Party Vendor Compromise
Most modern law firms rely on cloud-based legal software, document management systems, accounting platforms, and managed service providers. While these vendors improve efficiency, they also become part of the firm’s overall security posture.
Managing partners should conduct due diligence before selecting vendors and confirm they maintain appropriate certifications, security controls, and incident response procedures. Regular reviews help ensure third-party providers continue meeting security expectations throughout the relationship.
6. Lost Devices and Remote Work Risks
Hybrid work has become standard across much of the legal industry, but it also increases risk. Lost laptops, unsecured home networks, and personal mobile devices can expose confidential client information if they are not properly protected.
Every device accessing firm resources should use full-disk encryption, strong authentication, automatic locking, and remote wipe capabilities. Combined with secure VPN access and cloud-based document management systems such as iManage or NetDocuments, these controls help maintain client confidentiality regardless of where attorneys are working.
The Managing Partner’s IT Security Checklist
Knowing the risks is only the first step. Managing partners should also ensure the firm has practical safeguards in place across people, technology, and processes. The checklist below covers the security controls that provide the greatest protection for small and midsize law firms.

Identity and Access
- Enforce multi-factor authentication (MFA) for email, document management systems, VPNs, and all cloud applications.
- Require employees to use a business password manager with unique passwords for every account.
- Disable user accounts within 24 hours when an employee leaves the firm.
Devices and Data
- Deploy Endpoint Detection and Response (EDR) on every workstation and server.
- Encrypt all laptops, desktops, and mobile devices that store client information.
- Use encrypted email or secure client portals for sensitive communications.
- Protect documents within iManage, NetDocuments, or another secure document management system using role-based permissions and ethical walls.
- Follow the 3-2-1 backup strategy and test backup restoration at least quarterly.
People and Processes
- Conduct annual cybersecurity awareness training supported by regular phishing simulations.
- Implement a mandatory callback verification process before approving wire transfers or changing payment instructions.
- Maintain a documented incident response plan and perform tabletop exercises at least once a year.
- Evaluate the security practices of all third-party vendors before granting access to firm systems or client information.
Assurance and Governance
- Perform an annual cybersecurity risk assessment.
- Review cyber insurance coverage annually and confirm required controls - such as MFA, EDR, and tested backups - remain in place.
- Consider Managed Detection and Response (MDR) or Security Operations Center (SOC) monitoring for continuous threat detection.
If your firm cannot confidently check every item on this list, it’s a strong indication that your cybersecurity program has gaps worth addressing. A professional Network Security Audit can help identify those weaknesses before attackers do, allowing you to strengthen your defenses while demonstrating a commitment to protecting confidential client information.
Incident Response: What a Law Firm Must Do in the First 72 Hours?
No cybersecurity program can eliminate every risk. That’s why every law firm should have a documented incident response plan before a security event occurs. According to ABA Formal Opinion 483 (2018), a firm’s responsibilities don’t end when an attack is detected. Attorneys have an ongoing duty to identify, stop, mitigate, investigate, and determine whether clients must be notified about a security incident.
The first 72 hours after discovering a breach are often the most important. Decisions made during this period can significantly reduce financial losses, preserve evidence, and help the firm meet its legal and ethical obligations.
The first priority is containing the incident. Compromised devices should be isolated from the network to prevent attackers from moving laterally or accessing additional client data. At the same time, the firm should activate its incident response team and notify internal leadership.
Next, engage the appropriate external resources. This typically includes your managed IT provider, digital forensics specialists, legal counsel specializing in data breaches, and your cyber insurance carrier. Many insurers require immediate notification and may recommend approved incident response vendors. Delaying these notifications can affect insurance coverage.
The investigation phase focuses on determining what happened, how attackers gained access, what information was affected, and whether client confidentiality was compromised. Under ABA Formal Opinion 483, firms should evaluate whether current clients must be informed and what steps are necessary to mitigate further harm.
Finally, firms must consider applicable breach notification laws. Because every U.S. state has its own notification requirements, and Illinois firms must comply with the Personal Information Protection Act (PIPA), working with experienced legal and technical advisors is essential to ensure notifications are accurate and timely.
Perhaps most importantly, every incident should end with a lessons-learned review. Updating security controls, improving employee training, and refining the incident response plan help reduce the likelihood of future attacks.
Cybersecurity Costs for a Law Firm: Budget Benchmarks
One of the most common questions managing partners ask is how much they should budget for cybersecurity. While every firm has different requirements, most small and midsize practices should think in terms of ongoing risk management rather than one-time technology purchases.
For firms with 5 to 50 attorneys, a fully managed IT and cybersecurity program typically ranges from $100 to $250 per user per month, depending on the services included. This usually covers managed IT support, endpoint detection and response (EDR), email security, patch management, backup monitoring, Microsoft 365 security, user support, and continuous security monitoring.
Compared to the financial impact of a successful cyberattack, this investment is relatively modest. A single Business Email Compromise incident can result in hundreds of thousands - or even millions - of dollars in fraudulent wire transfers. According to the FBI IC3 2023 Report, Business Email Compromise generated approximately $2.9 billion in reported losses, making it the costliest category of cybercrime.
Cyber insurance providers also continue raising their security expectations. Today, many carriers require firms to demonstrate core security controls before issuing or renewing coverage. These commonly include:
- Multi-factor authentication (MFA) for all users.
- Endpoint Detection and Response (EDR).
- Tested and recoverable backups.
- Security awareness training.
- A documented incident response plan.
Firms that already meet these requirements often qualify for better coverage and may receive more favorable premiums.
For most smaller practices, partnering with a Managed Service Provider (MSP) is significantly more practical than building an internal cybersecurity team. Instead of hiring dedicated security personnel, firms gain access to specialized expertise, 24/7 monitoring, compliance guidance, and predictable monthly costs that scale as the practice grows.
What is a Managed Service Provider (MSP)?
How RIT Company Supports Law Firms in Chicagoland?
Law firms have unique technology requirements that go well beyond standard IT support. They need secure access to confidential client information, reliable document management, dependable backup and recovery, and cybersecurity controls that align with professional responsibilities.
At RIT Company, we provide IT support for law firms throughout the Chicago area, helping firms protect sensitive client data while maintaining efficient daily operations. Our services combine managed IT, cybersecurity, cloud solutions, and ongoing technical support into a single, proactive approach.
We help legal practices:
- Secure Microsoft 365 and business email against phishing and Business Email Compromise.
- Deploy Endpoint Detection and Response (EDR) across all workstations and servers.
- Support legal document management platforms such as iManage and NetDocuments.
- Configure secure remote work environments with encryption, VPN access, and multi-factor authentication.
- Implement reliable backup and disaster recovery strategies.
- Perform cybersecurity risk assessments and ongoing security monitoring.
Whether your firm has five attorneys or fifty, our goal is the same: reduce cyber risk while allowing your team to focus on serving clients instead of managing technology.
If you’re unsure whether your current security controls meet today’s threats, or your clients’ expectations, our free Network Security Audit provides a practical starting point. We’ll evaluate your infrastructure, identify security gaps, and recommend improvements tailored to your firm’s size and practice areas.
Frequently Asked Questions
- Do law firms need cybersecurity?
Absolutely. Law firms routinely store confidential client communications, financial records, litigation strategies, and personally identifiable information. Protecting that data is both a business necessity and an ethical responsibility under the ABA Model Rules.
- Why do hackers target law firms?
Law firms possess valuable information that can be used for financial fraud, identity theft, corporate espionage, or extortion. Client trust accounts, merger documents, intellectual property, and privileged communications make legal practices attractive targets for cybercriminals.
- What percentage of cyberattacks involve human error?
According to the Verizon 2024 Data Breach Investigations Report, the human element was involved in 68% of breaches. Phishing, stolen credentials, and social engineering remain some of the most common attack methods affecting law firms.
- Are law firms required to report data breaches?
Potentially, yes. Notification requirements depend on the type of information involved and the applicable state laws. In addition, ABA Formal Opinion 483 requires attorneys to evaluate whether current clients should be informed following a security incident.
- What cybersecurity insurance do law firms need?
Most firms should carry cyber liability insurance that covers incident response, legal expenses, forensic investigations, business interruption, ransomware events, and breach notification costs. Before issuing coverage, many insurers require firms to implement controls such as MFA, EDR, and tested backups
- How much should a small law firm spend on cybersecurity?
A reasonable benchmark for a comprehensive managed IT and cybersecurity program is approximately $100-$250 per user per month. While actual costs vary, investing in preventive security is almost always less expensive than recovering from a significant data breach or ransomware attack.
Contact Us Today To Schedule Your Discovery Call
15min discovery call Schedule 15min discovery callOr submit a message
Thank you for contacting us!
We respond within 24 hours