PS ProTech
← All articles

Law firms

A cybersecurity checklist for small law firms

· PS ProTech

Law firms hold exactly what attackers want: privileged documents, settlement figures, deal terms and client funds. Small firms are targeted as often as large ones, because they hold the same kind of information with fewer defenses.

Lawyers also have professional duties here. ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information, and the comments to Rule 1.1 say competence includes keeping up with the benefits and risks of relevant technology. Your state's rules may differ, so check them.

This checklist covers the controls we look for first.

Accounts and access

  1. Multi-factor authentication on email. Most law firm breaches start with a stolen email password. Turn on MFA for every mailbox, with no exceptions for partners.
  2. A password manager for the whole firm. It ends reused passwords and makes it easy to remove access when someone leaves.
  3. Individual accounts only. No shared logins for the practice management or document systems. You need to know who opened what.
  4. Same-day offboarding. When someone leaves, their access to email, documents and client portals ends that day.

Devices

  1. Full-disk encryption on every laptop. A lost, encrypted laptop is an inconvenience. A lost, unencrypted one may be a reportable breach.
  2. Automatic patching. Operating systems, browsers and PDF software updated within days, not months.
  3. Endpoint detection and response. Modern protection that watches for ransomware behavior, on every computer including home machines used for work.

Email and money

  1. Email filtering. Block phishing and impersonation before they reach inboxes.
  2. A call-back rule for wire instructions. Any change to payment details is confirmed by phone, using a number you already have. This one habit stops most wire fraud.

Recovery

  1. Backups you have tested. Back up documents and mailboxes to a separate location, and restore a file every quarter to prove it works.
  2. An incident plan on one page. Who to call, how to isolate a machine, and who decides about notifying clients and your insurer.

People

  1. Short, regular training. Ten minutes a quarter on spotting phishing does more than an annual hour-long video. Keep a record of who completed it.

How to check where you stand

Go through the list and mark each item as done, partly done or missing. For anything marked done, ask how you know. "We have backups" is different from "we restored a file last month".

Clients and cyber insurers increasingly ask these same questions in writing. A firm that can answer them with evidence wins work and gets better insurance terms.

If you would like help closing the gaps, our Secure plan covers every item on this list.

See what it costs for your firm.

Build a plan in two minutes. No call required.