Law Firm Cybersecurity Protection (2026): The Complete Guide to Protecting Client Data, Wires, and Privilege
What cybersecurity protection a law firm actually needs in 2026 — the eleven controls that stop real attacks, what each costs, how the ABA, FTC Safeguards Rule, SEC Reg S-P, and outside counsel guidelines define 'reasonable,' and a 90-day rollout plan with the testing evidence insurers accept.

Cybersecurity protection for a law firm is not a product you buy. It is a small set of controls that block the attacks that actually happen to firms, plus independent evidence that those controls work — because clients, carriers, and bar regulators all ask for the evidence, not the intention.
Five-minute takeaway: A protected law firm in 2026 has (1) phishing-resistant MFA on Microsoft 365 or Google Workspace, (2) conditional access that blocks legacy authentication and unmanaged devices, (3) an out-of-band callback rule for every wire instruction, (4) endpoint detection and response on every device that touches matter data, (5) immutable, tested backups, (6) patching of everything facing the internet, (7) a secured client portal and intake form, (8) encrypted file sharing instead of email attachments, (9) legal-pretext phishing simulation and role-based training, (10) a written information security program (WISP) and incident response plan, and (11) independent external testing that produces a report a carrier and a corporate client will accept. Budget for a 25-attorney firm typically lands between \$28,000 and \$70,000 per year all-in, and the testing component starts around \$199/month on a continuous platform versus \$8,000–\$25,000 for a one-time manual engagement.
What "protection" legally means for a law firm
Four separate authorities converge on the same standard, and none of them accepts "our IT company handles it" as an answer.
ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. Rule 1.1, Comment 8 makes technology competence part of competence itself. ABA Formal Opinions 477R and 483 translate that into a fact-specific analysis: sensitivity of the information, likelihood of disclosure absent safeguards, cost of safeguards, and difficulty of implementing them. Cheap, standard controls that a firm skipped are exactly what an ethics analysis flags after a breach.
The FTC Safeguards Rule applies to firms that are "financial institutions" under GLBA — which reaches many firms doing real estate closings, tax planning, estate and trust work, collections, and certain lending or financial-services support. Covered firms need a designated qualified individual, a written risk assessment, access controls, encryption, MFA, an incident response plan, vendor oversight, and either annual penetration testing plus biannual vulnerability assessment, or continuous monitoring in place of that schedule.
SEC Regulation S-P, as amended in 2024, pushes incident-response and customer-notification obligations down through service providers to broker-dealers, RIAs, and funds — which is how the requirement lands on the firms serving them through outside counsel guidelines.
Outside counsel guidelines (OCGs) are, in practice, the strictest of the four. Corporate clients increasingly require MFA, encryption at rest and in transit, annual third-party testing with a summary report, breach notification inside 24–72 hours, subcontractor flow-down terms, and the right to audit. A firm that cannot produce a current testing report loses panel spots — quietly, without ever being told why.
The eleven controls that constitute real protection
1. Phishing-resistant MFA on email and every remote entry point
Credential theft is still the number-one initial access vector against firms, and SMS or push-approval MFA is routinely defeated by real-time proxy phishing kits and MFA fatigue. Move partners, admins, finance, and anyone touching escrow to FIDO2 security keys or passkeys first. Cost: roughly \$25–\$60 per key, one-time, plus licensing you likely already own.
2. Conditional access and legacy authentication shutdown
Block legacy protocols (IMAP, POP, basic auth), require compliant or hybrid-joined devices for mailbox access, restrict sign-ins from countries the firm does not practice in, and set short session lifetimes for privileged accounts. Token theft only pays off when the stolen token is accepted from anywhere; conditional access is what stops that.
3. A written, enforced wire-verification rule
Every change to wire instructions is verified by voice callback to a number already on file — never a number in the email, and never by replying to the thread. Two-person approval above a threshold the firm sets. This single procedural control prevents the most expensive category of loss most firms will ever face, and it costs nothing but discipline.
4. EDR on every device touching matter data
Managed endpoint detection and response, including partner laptops and any personal device permitted into the environment. Typical cost: \$5–\$12 per endpoint per month, more with 24/7 managed response.
5. Immutable, tested backups
Backups that ransomware cannot encrypt or delete, with a restoration test performed and documented at least twice a year. An untested backup is a hypothesis, and carriers now ask directly whether restoration was tested and when.
6. Patch what faces the internet, fast
VPN appliances, firewalls, remote-access gateways, file-transfer tools, and the firm website's CMS and plugins. Exploited edge devices remain a top ransomware entry path. Critical internet-facing patches inside 72 hours; everything else on a documented monthly cycle.
7. Client portal and intake form security
The portal is the highest-risk surface a firm operates because it is intentionally exposed and it holds matter documents. The recurring findings are broken access control (changing a document or matter ID returns another client's file), missing rate limits on intake and login, insecure direct object references in download links, and file-upload handling that allows dangerous types. None of these are found by a network scan — they require application testing.
8. Encrypted sharing instead of email attachments
A portal or secure-link service with expiring links, per-recipient access, download logging, and revocation. The access log doubles as evidence when a client asks who saw what.
9. Legal-pretext phishing simulation and role-based training
Generic "your package is delayed" simulations teach a firm nothing. Effective programs use legal pretexts: court e-filing notices, opposing counsel document links, client wire updates, e-signature requests, and vendor invoice changes. Quarterly at minimum, monthly for finance and intake staff, with completion records retained as evidence.
10. A WISP and an incident response plan that names people
The WISP documents the risk assessment, controls, vendor oversight, and review cadence. The IR plan names the breach counsel, forensics firm, carrier hotline, and internal decision-maker — before the incident, because the first hour is when privilege is either preserved or lost. Engage forensics through counsel to protect the investigation under privilege.
11. Independent testing that produces usable evidence
Self-attestation is not evidence. What insurers and corporate clients accept is a third-party report: scope, methodology, findings with severity, remediation status, and retest confirmation. This is the control that converts a firm's security work into panel eligibility and better renewal terms.
What law firm cybersecurity protection costs in 2026
| Component | Solo–10 attorneys | 10–50 attorneys | 50–200 attorneys |
|---|---|---|---|
| Identity hardening (MFA keys, conditional access) | \$500–\$2,500 one-time | \$2,500–\$8,000 | \$8,000–\$25,000 |
| EDR / managed detection | \$1,200–\$4,000/yr | \$4,000–\$18,000/yr | \$18,000–\$70,000/yr |
| Backup and recovery | \$1,000–\$3,500/yr | \$3,500–\$12,000/yr | \$12,000–\$40,000/yr |
| Security awareness + phishing simulation | \$300–\$1,200/yr | \$1,200–\$6,000/yr | \$6,000–\$20,000/yr |
| Continuous testing platform | from \$2,400/yr | \$6,000–\$12,000/yr | \$12,000–\$40,000/yr |
| One-time manual pentest (alternative) | \$5,000–\$12,000 | \$8,000–\$20,000 | \$18,000–\$45,000 |
| WISP + IR plan authoring | \$2,000–\$6,000 | \$4,000–\$12,000 | \$10,000–\$30,000 |
Ranges reflect typical US market pricing observed in 2026 engagements and public vendor list pricing; your quotes will vary with scope, application count, and whether the firm has an in-house IT function.
For context on the other side of the ledger: a wire diversion in a real estate or settlement practice routinely runs six figures, and a ransomware event of any size costs a firm weeks of billable disruption before a single notification letter goes out.
A 90-day protection rollout
Days 1–15 — See the actual attack surface. Run an external assessment of every domain, subdomain, portal, and mail configuration. Inventory who has admin rights in Microsoft 365. Identify which internet-facing systems are unpatched. You cannot protect an asset you have not enumerated, and most firms discover forgotten marketing subdomains and legacy portals in this step.
Days 16–30 — Close the identity gap. Phishing-resistant MFA for partners, admins, finance, and intake. Disable legacy auth. Turn on conditional access. Remove standing global-admin rights and replace them with just-in-time elevation.
Days 31–45 — Stop the money loss. Publish the wire-verification callback rule in writing, train finance and paralegals on it, and add banner warnings on external email. Configure impersonation and lookalike-domain protection.
Days 46–60 — Harden the perimeter and the portal. Patch internet-facing systems, then test the client portal and intake forms for access-control flaws. Fix, then retest — a finding without a retest is not remediated evidence.
Days 61–75 — Prove resilience. Restore from backup in a test, document the result and time-to-restore. Run a two-hour tabletop with the managing partner, IT, and breach counsel.
Days 76–90 — Produce the evidence pack. Finalize the WISP and IR plan, gather the testing report with remediation status, training completion records, and vendor due-diligence records. This pack answers the cyber-insurance application and the OCG questionnaire without a scramble.
How to verify protection, not assume it
Ask your IT provider or MSP three questions and require documents, not assurances:
1. Show me the last external test report, its date, and the retest confirming fixes. 2. Show me which accounts still allow SMS or push-approval MFA. 3. Show me the last documented restore test and how long it took.
If any answer is verbal, that control is unverified. Independent testing exists precisely because the party that builds and runs an environment should not be the only party grading it — which is also why carriers and corporate clients specify *third-party* testing in their questionnaires.
Frequently asked questions
Q: What is the minimum cybersecurity protection a small law firm needs? A: Phishing-resistant MFA on email, a written out-of-band wire-verification rule, EDR on every device, immutable tested backups, patched internet-facing systems, and one independent external assessment per year. Those six items eliminate the majority of realistic loss scenarios for a firm under ten attorneys.
Q: Does the ABA require law firms to have cybersecurity? A: The ABA requires *reasonable efforts* under Model Rule 1.6(c), with technology competence under Rule 1.1 Comment 8 and practical guidance in Formal Opinions 477R and 483. There is no prescriptive control list, but the reasonableness analysis weighs the cost of safeguards against the sensitivity of the data — which makes skipping inexpensive, standard controls difficult to defend after an incident.
Q: Is managed IT the same as cybersecurity protection? A: No. An MSP builds and operates the environment; cybersecurity testing evaluates it independently. Most OCGs and insurance applications ask specifically for third-party testing, which the party operating the systems cannot provide for itself.
Q: How often should a law firm be tested? A: Annually at minimum, plus after any material change — a new portal, an office move, a merger, or a migration. Firms handling M&A, IP, healthcare, or financial-services matters should be on continuous monitoring, which also satisfies the FTC Safeguards Rule alternative to the annual-pentest schedule.
Q: Will better protection lower our cyber insurance premium? A: It changes eligibility and terms more reliably than raw premium. MFA coverage, EDR, tested backups, and a current third-party testing report are the controls underwriters score; firms lacking them face sublimits on ransomware and social engineering, higher retentions, or declination.
Q: What should the firm do in the first hour of a suspected breach? A: Contact breach counsel first so the investigation runs under privilege, then the carrier hotline, then preserve — do not wipe — affected systems. Isolate rather than power off, so volatile forensic evidence survives.
How Attorney Armor protects law firms
Attorney Armor is a cybersecurity platform built specifically for law firms — every finding is written in terms of matter sensitivity, ethics obligations, and the evidence your carrier and corporate clients ask for.
- Penetration Testing — external, web application, and client-portal testing with ABA- and Safeguards-aligned reporting your insurer accepts.
- Vulnerability Assessment — continuous attack-surface discovery with findings ranked by exploitability and matter sensitivity.
- Continuous Monitoring — 24/7 asset, credential-exposure, and lookalike-domain monitoring with instant alerts.
- Security Awareness Training — legal-pretext phishing simulation, role-based curricula, and completion evidence.
- Compliance & Insurance Evidence — WISP authoring, framework mapping, and cyber-insurance questionnaire evidence packs.
- Incident Response — IR planning, tabletop exercises, containment support, and notification decision support.
Practice-area programs are scoped separately for solo and small firms, personal injury, estate planning, corporate and M&A, intellectual property, and family law.
Start with the free, non-intrusive external assessment on the home page — it returns your firm's externally visible exposure in about six minutes with nothing to install. See pricing for continuous plans, or review a redacted sample report to see exactly what your partners, insurer, and corporate clients would receive.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


