Law Firm Cybersecurity Checklist

Short answer: Most data leaks at law firms come not from sophisticated attacks but from four simple gaps: shared or weak passwords, two-factor authentication left off, a departing employee whose access was never closed, and client files kept on personal devices. All four can be closed in about a week without buying software.
The data a law firm holds is valuable to an attacker: dispute information, trade secrets, identity documents. Yet in most firms security is treated as a specialist field and deferred. The gaps that cause the most damage are not matters of expertise but of habit.
The four gaps
| Gap | Symptom | Time to close |
|---|---|---|
| Shared password | A shared email or system account in use | 1 day |
| Two-factor off | Email and cloud accounts protected by password only | 1 day |
| Access not closed | A departed employee's account still active | Same day, with a checklist |
| Files on personal devices | Client documents on a personal phone or USB stick | 1 week, rule plus alternative |
Order of priority: Two-factor authentication gives the highest return on its own. It blocks access even when a password leaks, and enabling it takes minutes.
Passwords and identity
- No shared accounts. With a shared account you cannot tell who did what, the audit trail becomes meaningless, and a departing person's access cannot be cut.
- Use a password manager. A password you can remember is not strong; a strong password cannot be remembered. The answer is storing, not memorising.
- Make two-factor mandatory. Priority order: email, cloud storage, practice management system, banking.
- Prefer app-based codes over SMS, which is more resistant to SIM-swap attacks.
Email: the most used entry point
Most attacks on law firms start with email. Two scenarios are especially common.
Fake service or filing notifications
Emails that appear to come from a court or agency, carrying an attachment or a link. Because they mirror a lawyer's daily workflow exactly, they are more convincing than in most other sectors. The rule is simple: never click a link in an email for filing or service information; go directly to the official system.
Payment redirection
An attacker inside the email thread sends a message changing bank details at the last moment. It appears most often in settlement payments and expense transfers. The rule: bank detail changes are never confirmed by email, only by phone to a known number.
Why these two: Neither exploits a technical vulnerability; both exploit the workflow itself. That is why they are prevented by rules rather than software.
Devices and files
- Disk encryption on. An unencrypted disk in a stolen or lost laptop is a leak in itself.
- Short screen lock timeout. A screen left open in a courthouse or a cafe is the easiest route in.
- No client files on personal devices. Prohibiting is not enough; an accessible alternative has to exist.
- Reduce USB use. It is the one carrier whose loss nobody notices.
Departing employees
The most common form of leak is not an external attack but access that was never closed. A checklist run on the day of departure removes this risk entirely.
- Email account closed, inbox forwarded.
- Practice management account disabled.
- Cloud storage shares removed.
- Court system access and matter links reviewed.
- Physical keys, cards and any payment authorities recovered.
- Shared account passwords changed, where shared accounts exist.
Backup: the only answer to ransomware
Ransomware can halt a law firm completely. A working backup is the only way out without paying.
- At least three copies: the working copy, an automatic backup, and a second backup in a different location.
- The second backup must be offline or immutable; a backup on the network gets encrypted along with everything else.
- Test a restore at least once a year. A backup never restored from is not a backup.
A one-week checklist
- Is two-factor authentication on for every email account?
- Do shared accounts exist, and can they be removed?
- Is a password manager in place?
- Is disk encryption on across all laptops?
- Has the screen lock timeout been shortened?
- Is there a written departing-employee checklist?
- Has the phone-confirmation rule for bank detail changes been communicated?
- Has a backup restore been tested?
Frequently asked questions
What is the most common security gap in law firms?
Not sophisticated attacks but four simple gaps: shared or weak passwords, two-factor authentication left off, a departing employee whose access was never closed, and client files kept on personal devices. All four can be closed in roughly a week without buying software.
If we do only one thing, what should it be?
Enable two-factor authentication. It gives the highest return on its own because it blocks access even when a password leaks, and it takes minutes to set up. Priority order is email, cloud storage, practice management system and banking. Prefer app-based codes over SMS.
How do attacks on law firms usually start?
Mostly by email. Two scenarios are common: a fake service or filing notification that appears to come from a court or agency, and a payment redirection message in which an attacker already inside the thread changes bank details at the last moment. Neither exploits a technical vulnerability; both exploit the workflow, which is why rules prevent them rather than software.
How should a change of bank details be confirmed?
Never by email, only by phone to a number you already know. In payment redirection attacks the attacker is inside the email thread, so a confirmation sent by email reaches them too. This matters most in settlement payments and expense transfers.
What should happen when an employee leaves?
A checklist run on the day of departure: close and forward the email account, disable the practice management account, remove cloud shares, review court system access, recover physical keys, cards and payment authorities. The most common form of leak is not an external attack but access that was never closed.
How do we protect against ransomware?
A working backup is the only way out without paying. Keep at least three copies: the working copy, an automatic backup and a second backup in a different location. The second must be offline or immutable, because a backup on the network gets encrypted along with everything else. Test a restore at least once a year.



