Skip to content
StrikeCyberStrikeCyber
Research

Cyber Security for Law Firms in the USA

June 20, 2026Β·4 min readCyber SecurityIndustry Briefings

Law firms hold an unusual concentration of valuable material. A single firm holds the confidential business of every client it acts for, including transactions not yet public, litigation strategy, regulatory exposure and personal information about executives.

Attackers understand the arithmetic. Compromising one firm is more efficient than compromising each of its clients, and firms are typically defended by an IT function sized for a mid-market business rather than for the value of what they hold.

What Is Actually Targeted

Transactional material. Deal information has direct market value before it is public, and the parties, timing and terms of an unannounced transaction are worth money to people positioned to use them.

Litigation material. Strategy, privileged communications and discovery material are worth obtaining to an opposing party or to someone acting for one.

Client personal and financial data, particularly in practices handling estates, immigration, family and personal injury matters.

The firm as a route to its clients. A firm has legitimate email relationships with client executives, which makes a compromised firm mailbox an unusually effective platform for business email compromise against the client.

Funds in trust. Real estate and settlement practices move client funds, and payment redirection fraud against closings is a persistent and costly pattern.

Ethical Obligations Are Technology Obligations

ABA Model Rule 1.1 comment 8 makes technological competence part of competence: a lawyer should keep abreast of the benefits and risks associated with relevant technology. Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of information relating to representation. Most states have adopted equivalent provisions.

ABA Formal Opinion 477R addresses securing communications, and Formal Opinion 483 addresses obligations after a breach, including the duty to notify affected current clients where client confidential information was or may have been accessed.

The practical effect is that security is not solely a business risk for a firm. It is a professional obligation, and the standard, reasonable efforts, is assessed against what a competent firm would do rather than against what the firm chose to spend.

Client Security Reviews Have Arrived

The commercial driver has changed faster than the regulatory one.

Corporate clients now conduct security due diligence on outside counsel much as they would on any vendor. Outside counsel guidelines routinely include security requirements. Firms are asked for evidence of recent independent testing, for multi-factor authentication attestations, for incident response plans, and increasingly for a SOC 2 report.

The pattern we see is a firm that has an annual test, is asked in March about an environment that changed in February, and cannot answer with current evidence. Losing a matter over a questionnaire is a commercial risk partnerships take seriously once it happens once.

Moving from an annual snapshot to a continuous program is usually the response, because it means the firm always holds current evidence rather than a document with a date on it.

Where Assessments Find Problems

Document management over-permissioning. The most consistent finding. Access to matter folders accumulates as staff move between practice groups, and is rarely reviewed, so lawyers and staff can reach material unrelated to their current work. This matters for ethical walls as much as for security.

Matter-specific infrastructure left running. Client portals, secure file transfer sites and data rooms created for a matter and still live years after it closed, frequently on unsupported software. Firms rarely have a matter-closure process that retires infrastructure.

Exposed and reused credentials. Firm credentials appearing in breach corpora and still valid against remote access, which is a straightforward path in and a straightforward thing to check.

Uneven endpoint management. Partners who travel are consistently the furthest behind on updates and the most likely to work from unmanaged networks and devices.

Email as the weak point. Given that mailbox compromise is the primary route to both client material and payment fraud, email security in firms is frequently weaker than the risk justifies, particularly around phishing-resistant authentication.

What to Prioritize

For a firm without a dedicated security function, the sequence that delivers most is fairly clear.

Phishing-resistant multi-factor authentication on email and remote access, first, because mailbox compromise is the route to nearly everything else. Then a review of document management permissions against current team membership. Then discovery of what the firm actually exposes to the internet, because forgotten matter infrastructure is a recurring finding. Then payment verification procedures for any practice that handles client funds, since redirection fraud requires no technical compromise at all.

Those four address the routes that produce actual incidents in this sector, and none requires a large security budget.

To discuss an assessment or a continuous program for your firm, get in touch.

Frequently asked questions

Why are law firms targeted?

Concentration. A firm holds privileged and commercially sensitive material for every client it acts for, which makes compromising one firm more efficient than compromising each client. Transactional practices are particularly exposed because deal information has direct market value, and litigation practices hold material parties would pay or act to obtain.

What are a lawyer's ethical obligations around technology?

ABA Model Rule 1.1 comment 8 establishes that competence includes keeping abreast of the benefits and risks of relevant technology, and Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of client information. Most states have adopted equivalent language. ABA Formal Opinion 483 addresses obligations following a breach, including notifying affected clients.

Do we have to notify clients after a breach?

Ethically, generally yes where client confidential information was or may have been compromised, per ABA Formal Opinion 483 and state equivalents. Separately, state breach notification laws apply where personal information is involved, and client engagement terms frequently impose their own notification obligations with shorter timelines than the law requires.

What do corporate clients ask for in security reviews?

Increasingly, the same things they ask any vendor: evidence of recent independent testing, multi-factor authentication, encryption, access control over matter files, incident response planning, and sometimes a SOC 2 report or ISO 27001 certification. Outside counsel guidelines now routinely contain security requirements that firms must attest to.

What is the most common finding in law firm assessments?

Document management over-permissioning, where access to matter folders accumulated as staff moved between teams and was never reviewed, so lawyers can reach material unrelated to their current work. It matters both for security and for ethical walls, and it is straightforward to fix once anyone looks.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation