Back to Blog
Industry Specific
4 min read

Law Firm Cybersecurity: Confidentiality as a Professional Obligation

Client data concentrated by matter, partners who resist controls, and clients who now audit their outside counsel.

GuardsArm Team

Security Experts

September 25, 2026

Law firm cybersecurity and client confidentiality

Law firms hold concentrated, high-value confidential information: transaction documents before announcement, litigation strategy, investigation material, personal information of clients and their counterparties. Attackers understand that the firm is frequently the softest route to a client's secrets.

Confidentiality is also a professional obligation rather than a commercial preference, which changes the character of a breach.

The firm is the soft route
To a client the attacker cannot reach directly
Ethical walls are often social
Technical enforcement is better and evidenceable
Clients audit counsel now
Failing a review costs panel positions

Two things make law firms distinctive

Matter-level confidentiality. Access should be scoped to the matter, not granted broadly across the firm. Ethical walls between teams acting on conflicting matters are a professional requirement, and in many firms they are enforced socially rather than technically.

A technically enforced ethical wall — where the document management system actually prevents access — is both a better control and far easier to evidence when a client or regulator asks.

Partner resistance. Partners are owners, they are busy, and they are frequently exempted from controls the rest of the firm follows. That inverts the risk model: the people with the broadest access have the weakest controls.

Partner exemptions invert the risk model
The people with access to the most sensitive matters are the ones most often excused from multi-factor authentication, device management and training. Most exemptions are historical rather than decided, and removing them is the single highest-value change available to most firms.

What clients now require

Corporate clients audit their outside counsel. Security questionnaires, outside counsel guidelines with security schedules, and occasionally on-site assessment are now routine for firms serving large clients.

Common requirements:

RequirementTypical firm gap
MFA for all users, including partnersPartner exemptions
Encryption at rest and in transitAd-hoc email of documents
Matter-level access restrictionFirm-wide document access
Breach notification within a stated periodNo defined process
Annual penetration testingNever done, or a scan
Security awareness trainingInformal or absent
Subcontractor and e-discovery vendor controlsUnassessed

Failing a client security review is a commercial event, not just a compliance one. Firms increasingly lose panel positions over it.


Trust account and payment fraud

The highest-frequency direct loss. The pattern is consistent: an attacker monitors a compromised mailbox during a transaction, then sends revised payment instructions at the moment funds are due, often from a lookalike domain or from the genuine compromised account.

Controls that work:

  • Out-of-band verification of every payment instruction change, using a number held on file rather than one in the email
  • A firm rule that instructions are never accepted or changed by email alone, stated to clients at engagement
  • Mailbox rule monitoring, since attackers create forwarding and auto-delete rules to hide their presence
  • Client warning at engagement, which both protects them and demonstrates care

See BEC defence.


Practical controls partners will accept

The trick is choosing controls with low friction and high value:

  1. MFA with a good authenticator, not SMS, and no exemptions
  2. Single sign-on, which reduces the password burden rather than adding to it
  3. Managed devices with encryption and remote wipe, including personal phones with firm email
  4. Matter-based access in the document management system, configured once
  5. Secure client portals instead of emailing documents, which clients increasingly prefer anyway
  6. Phishing simulation and short training, with partners included

Point five is worth pushing: it removes a large category of exposure and improves the client experience, so it is one of the few security changes that can be sold on its merits rather than on risk.


E-discovery and the vendors around a matter

A litigation matter pulls in e-discovery providers, document review teams, experts, agencies and sometimes co-counsel. Client data spreads across organisations the firm does not control, for the duration of a matter and frequently long after it.

Practical controls:

ControlDetail
Assess before engagementSecurity terms in the engagement, not after data moves
Transfer securelyPortals, not email or unencrypted media
Scope the dataSend what the matter requires, not the whole collection
Set deletion termsWith a date, and confirmation
Track where data wentA register per matter — few firms have one

The last row is the gap. Firms rarely know, matter by matter, which third parties hold client data. When a client asks — and clients increasingly do — the inability to answer is itself the finding.


Responding to a client security questionnaire

These arrive regularly and consume partner time badly. The efficient approach is to build one maintained answer set covering the questions that recur: MFA coverage, encryption, access control, backup and recovery, incident response, training, testing, subcontractor management and insurance.

Keep it current, keep the supporting evidence with it, and have one person own it. Firms that rebuild answers each time both waste hours and give inconsistent responses across clients, which is noticed.


Where to start

Check whether your partners are exempt from MFA. In most firms that have not looked recently, some are. It is the highest-value single control, the exemptions are usually historical rather than deliberate, and closing them takes an afternoon.

GuardsArm works with professional services firms on assessment and client assurance. See legal sector solutions or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.