Skip to content
All resources
CybersecurityJuly 14, 2026·7 min read

Law Firm Cybersecurity: The Duty You Already Have

Your ethics rules already require reasonable safeguards for client information. Here is what that means in practice, and where the real risks sit.

By Cohesive Security

Lawyers do not need a lecture on confidentiality. It is the profession’s oldest habit, and every attorney reading this already treats client information as something held in trust rather than merely stored.

What is less obvious is the translation. The duty is familiar; the controls that satisfy it in 2026 are not, and the gap between “we take confidentiality seriously” and “we could demonstrate reasonable safeguards if asked” is where small firms tend to sit. This is about closing that gap without turning your practice into an IT project.

One caveat up front. We are not lawyers and this is not legal or ethics advice. Every state adopts its own version of the rules discussed below, so check your own jurisdiction’s language and your bar’s guidance before relying on any of it.

Key takeaways:

  • The obligation is not new. Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information, and technological competence sits in the comment to Rule 1.1.
  • Reasonableness is a process, not a product. Nobody requires you to own a specific tool; they expect you to have assessed risks and acted on them.
  • Closing and settlement funds are actively targeted. The FBI names real estate attorneys and title companies among the participants reporting this fraud.
  • In a small firm everyone can usually see every matter. Conflicts screening is an access control question, and most firms run it on the honor system.

Your ethics rules got there first

The framework already exists, which is genuinely useful: you are not being asked to adopt someone else’s security standard, you are being asked to meet one your profession wrote.

Model Rule 1.1, at comment 8, ties competence to keeping abreast of the benefits and risks of relevant technology. Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.

Two ABA ethics opinions put detail on that. Formal Opinion 477R, issued in 2017, concluded that a lawyer may generally transmit information relating to a representation over the internet without violating the rules where reasonable efforts have been taken to prevent unauthorized access, while noting that special precautions may be required where the nature of the information demands a higher degree of security. Formal Opinion 483, issued the following year, addressed what happens after a breach, concluding that a lawyer has an obligation to communicate with current clients about a data breach where material client information is known or reasonably suspected to have been accessed.

The word carrying the weight in all of this is “reasonable”. It is deliberately not a product list. What it describes is a process: understand where client information lives and how it moves, assess what threatens it, put proportionate measures in place, and keep that current. A sole practitioner and a forty-lawyer firm can both be reasonable, and the answer looks different in each.

The wire that only moves once

If you handle closings, settlements, or any client funds, this is the risk that should have your attention, because the money is gone in minutes and the duty attached to it is not the ordinary business duty.

The FBI is explicit that this fraud targets the legal side of property transactions. Its guidance on business email compromise states that the scam “targets all participants in real estate transactions, to include buyers, seller, real estate attorneys, title companies, and agents”, with perpetrators timing a fraudulent request to change the payment method or the receiving bank account. The email arrives at exactly the right moment in the matter, worded exactly the way your firm words things, because someone has been reading the correspondence.

The control is unglamorous and it works: verify every change to payment instructions by voice, on a number you already had on file, never one supplied in the message asking for the change. The FBI’s own recommendation is to use secondary channels or two-factor authentication to verify requests for changes in account information. Put it in writing as firm policy, apply it to partners as well as staff, and tell clients at the start of a matter that your wire details will never change by email. That last step protects them from an impersonation of you.

The mechanics of how attackers get inside the conversation in the first place are worth understanding, and we walked through them in how business email compromise actually works. You can also check in a few seconds whether someone can send email as your exact domain, using our email security checker.

Everyone can see everything

Walk into most small firms and any staff member can open any matter. That is convenient, and it quietly undermines two things at once.

The first is ethical screening. When a conflict requires a wall around a matter, that wall has to be real, and in a shared drive with open permissions it is a request rather than a control. The second is the size of the damage when one account is compromised. If a single paralegal’s credentials open the whole document management system, one phishing email exposes every client you have rather than the handful that person works on.

Matter-based access is not exotic. It means the document system reflects who works on what, and access is granted rather than assumed. It takes an afternoon to design and it changes what a bad day looks like.

The questionnaire from your corporate client

This one is a business development argument as much as a risk one. Corporate clients increasingly send outside counsel guidelines with security requirements attached: encryption, breach notification timelines, access restrictions, sometimes an audit right or a questionnaire that reads like a vendor assessment.

Firms that can answer these quickly win work. Firms that cannot either lose it or agree to terms they are not actually meeting, which is a worse position than declining. If you are receiving these, treat the requirements as the specification they are, and get your answers straight before signing rather than after.

The rest of the practical list

Briefly, because these are the ones that come up in every firm we look at:

Mobile devices. Privileged material sits in email on personal phones. Those devices need a passcode, encryption, and a way to remove firm data if the phone is lost or the person leaves.

Your practice management vendor secures their platform, not your firm. Cloud document and practice systems are generally well run. That protection stops at their front door: your workstations, mailboxes, and sign-ins are yours, and that is where incidents start.

Email retention. Know what your policy is and whether it matches your obligations, rather than discovering the answer during discovery.

Sign-in security. Multi-factor authentication on email and remote access, and it is worth knowing that not all MFA is equal if the firm’s email is what stands between an attacker and every client file.

Staff working from home. Fine, and common, provided it happens on managed machines rather than a family laptop.

Where a firm usually needs help

Most of the above a firm can do itself, and a partner with an interest in technology often does. What tends not to survive contact with a busy practice is the maintenance: the patching, the access reviews when people join and leave, the training, the documentation that proves your safeguards were reasonable on the date something happened.

That continuity is what we carry for the law firms we work with, alongside the security controls themselves and the documentation side that turns a set of practices into something you can show a client or a bar committee.

If you would like an honest read on where your firm stands, that is a free assessment: what is exposed, what your outside counsel guidelines would fail today, and what we would fix first. Or email hello@cohesivesecurity.com with a question.

#legal#confidentiality#wire fraud#compliance#access control

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.