Sector briefing · legal
Your clients’ secrets are the product. Defend them like it.
A law firm is a high-value target with a small IT budget. You hold privileged
material, complete narratives of other people’s disputes, and
trust-account authority — all in an inbox that a paralegal checks on a
phone. Attackers no longer break in; they log in.
Confidentiality is not a policy you write once. It is a control you either
have or you don’t.
monitoring
Weighted from law-firm business email compromise reporting and
adversary-in-the-middle phishing observations across small and mid-size firms.
Why law firms specifically
Privilege
The secret is the payload
In most breaches, data is a commodity. In a firm, it is a negotiation
position. A merger that has not been announced, a settlement figure, a
plaintiff who has not filed — that is leverage, and it is worth more
than the client’s credit card.
Completeness
Matter files read like a dossier
A single matter folder holds identity documents, medical records,
financial statements and candid internal notes. Nothing needs to be
inferred — the file already explains who matters and why.
Money movement
Trust accounts move real cash
Wire instructions are sent by email, changed by email, and confirmed by
email. That is a fraud channel with a signature block, and it only needs
one replied-to thread.
The obligations you already carry
You do not need a new regulation to justify this work. The duties that make a
breach expensive for a firm are already on the books.
A · Confidentiality
Rule 1.6, in practice
The duty of confidentiality does not stop at your staff. It follows the
information into your email provider, your storage, your vendors and your
backups. You are answerable for what you failed to secure.
B · Competence
Technology is now a duty
Competent representation includes understanding the technology you use to
deliver it — or bringing in someone who does. ABA Formal Opinion 477R
frames reasonable efforts to secure client information in exactly those terms.
C · Notification
Who you must tell, and when
When a breach touches client information, notification duties run to the
client and, depending on your state, to regulators. Deciding that under
pressure is how firms create a second problem on top of the first.
The practical question is not whether a firm has a duty to protect client
information — it plainly does. It is whether you could demonstrate, today,
what you did and when you did it. That is what an incident review or a client
audit asks for.
What we do for firms
Attack-surface review
We map what is actually exposed: mail authentication, remote access,
who holds standing administrative rights, and which third parties can
reach case material.
Session-theft defence
Most firm breaches now arrive as a valid session, not a cracked password.
We harden identity and mail so a stolen cookie stops being a full
compromise.
Matter-file segmentation
An intern’s workstation should not be a path to every client.
We separate access by matter and role so one credential is not the whole
firm.
Breach readiness
A written, tested plan for the first 72 hours — who is called,
what is preserved, what gets notified, and who talks to the client.
Decided calmly now, not during a deadline.
Find out what is actually exposed
A security review starts with a conversation, not a contract. We will tell you
what is reachable from outside before you spend anything on fixing it.