Pumpkin
    Cybersecurity for Law Firms
    Security

    Cybersecurity for Law Firms

    By Aaron WatersApril 21, 2026Updated August 15, 20266 min read

    Cybersecurity for law firms is a different problem than it is for everyone else, because the thing at risk is privilege. A breached retailer loses card numbers and apologizes. A breached law firm exposes litigation strategy, settlement postures, and communications clients believed were confidential in the strongest sense the law offers. Courts and bar regulators have made the expectation plain: reasonable security is part of the job now. So the practical question is what reasonable looks like for a firm of ten or forty lawyers with no security department. The answer is smaller than the vendors claim, and more specific.

    Why the other side wants your files

    Law firms concentrate value. Merger terms before they're announced. Litigation strategy the opposing party would pay real money to read. Intellectual property, settlement numbers, the personal finances of whoever's getting divorced. One mid-sized firm can hold sensitive files for a hospital, a bank, a startup, and a school district at the same time, which makes it a more efficient target than any one of its clients.

    And the profession's relationship with technology doesn't help. Plenty of firms still run on systems nobody has patched in years, guarded by passwords chosen in a hurry a decade ago. Attackers know both facts.

    The 42 million dollar example

    If you want the ceiling on how bad this gets, it has a name. Grubman Shire Meiselas & Sacks, the entertainment law firm whose client roster was the entire point, got hit by the REvil ransomware crew, which encrypted the firm's files and stole copies first, then demanded $42 million. That's the modern shape of ransomware. The encryption is almost a distraction. The theft is the pressure, because it turns every choice into a bad one: pay, and you're trusting extortionists to delete their only asset. Refuse, and your clients' private files go up for auction. Every good option expired before the demand arrived, back when the intrusion was still preventable.

    The wrong lesson here is "we're not Grubman, so we're fine." The crews that hit ten-lawyer firms run the same playbook with smaller numbers, and a $400,000 demand does to a small practice roughly what $42 million does to a famous one. The prevention layer is unglamorous: patched systems, monitored machines, someone who actually owns the infrastructure and checks it. That's what competent law firm IT support looks like in practice. Firms tend to buy it afterward.

    What reasonable efforts actually means

    The ABA's Formal Opinion 477R says lawyers must make reasonable efforts to secure client information, and what counts as reasonable moves with the technology. In practice, a defensible floor looks like this.

    Encrypt everything that holds client data. Laptops get full-disk encryption, so a machine left in a cab is an inconvenience instead of a notification event. Files get encrypted where they're stored, whether that's the server in the closet or somebody's cloud. Email gets encryption for anything sensitive, and the truly sensitive documents move through a secure portal instead of email at all. If you're not sure where your gaps are, our client data encryption service starts by finding them.

    Then control who can open which matters. A firm where every user can browse every matter has exactly one security boundary: the weakest password in the building. Matter-level access means a compromised paralegal account exposes that paralegal's matters, and stops there. The full discipline of retention, access control, and encryption is its own topic, and it's the backbone of everything else on this page.

    The login layer

    Multi-factor authentication on email, the document system, remote access, and anything with a client name in it. Attackers rarely break into law firms; they log in, using credentials somebody handed over on a fake page. A second factor turns most stolen passwords into paperweights. It's a lunch-hour project per system, which is exactly why insurers and a growing number of corporate clients now ask about it in writing.

    The email that costs the most

    Phishing built for law firms is specific. Fake filings from opposing counsel. "Scheduling changes" from a judge's chambers. A client emailing new wire instructions the day before closing. That last one is business email compromise, and it drains trust accounts, which is about the worst sentence in legal practice.

    One policy blocks most of it: money never moves, and payment details never change, on the strength of an email alone. Verification happens by phone, on a number you already had, before anything else happens. No exceptions for urgency. Urgency is the tell.

    Working from the courthouse, the kitchen, the airport

    Lawyers work everywhere, which is fine, and they access firm systems from hotel Wi-Fi, which isn't. Remote access should run through a VPN or a zero trust setup that verifies every request. Devices that touch client data should be managed by the firm, encrypted, and wipeable from a distance when one goes missing. And the printed deposition on the kitchen table deserves the same policy attention as the digital copy, even though nobody enjoys writing that memo.

    When it happens anyway

    A law firm breach carries obligations most businesses never face. You'll need to assess whether privilege was compromised, notify affected clients individually, possibly report to the bar depending on jurisdiction, and think hard about conflicts if the breach touches active litigation. Those judgments can't be made well for the first time at 2am. Decide now who leads, who calls outside counsel, and what happens in the first 24 hours after a breach, because the early hours decide whether the thing is contained or compounding.

    New tools, old duty

    E-discovery platforms, research databases, practice management, and now AI drafting assistants. Every vendor that touches client files inherits your confidentiality problem without inheriting your duty, and the newest vendors deserve the hardest questions. Before anything sees client data, someone should ask where it's stored, whether it trains anyone's models, and what happens to it when you leave. Our guide to assessing AI vendor security has the full question list.

    The short version

    Encrypt everything, gate access by matter, verify money movement by phone, manage the devices, and rehearse the bad day. None of it requires a chief information security officer. All of it requires a decision. The rest of the picture, checklists and insurance and compliance included, is in our cybersecurity guide for firms, written for firms that measure security budgets in thousands, not millions.