
Law Firm Cybersecurity: Confidentiality as a Professional Obligation
Client data concentrated by matter, partners who resist controls, and clients who now audit their outside counsel.
GuardsArm Team
Security Experts

Law firms hold concentrated, high-value confidential information: transaction documents before announcement, litigation strategy, investigation material, personal information of clients and their counterparties. Attackers understand that the firm is frequently the softest route to a client's secrets.
Confidentiality is also a professional obligation rather than a commercial preference, which changes the character of a breach.
Two things make law firms distinctive
Matter-level confidentiality. Access should be scoped to the matter, not granted broadly across the firm. Ethical walls between teams acting on conflicting matters are a professional requirement, and in many firms they are enforced socially rather than technically.
A technically enforced ethical wall — where the document management system actually prevents access — is both a better control and far easier to evidence when a client or regulator asks.
Partner resistance. Partners are owners, they are busy, and they are frequently exempted from controls the rest of the firm follows. That inverts the risk model: the people with the broadest access have the weakest controls.
What clients now require
Corporate clients audit their outside counsel. Security questionnaires, outside counsel guidelines with security schedules, and occasionally on-site assessment are now routine for firms serving large clients.
Common requirements:
| Requirement | Typical firm gap |
|---|---|
| MFA for all users, including partners | Partner exemptions |
| Encryption at rest and in transit | Ad-hoc email of documents |
| Matter-level access restriction | Firm-wide document access |
| Breach notification within a stated period | No defined process |
| Annual penetration testing | Never done, or a scan |
| Security awareness training | Informal or absent |
| Subcontractor and e-discovery vendor controls | Unassessed |
Failing a client security review is a commercial event, not just a compliance one. Firms increasingly lose panel positions over it.
Trust account and payment fraud
The highest-frequency direct loss. The pattern is consistent: an attacker monitors a compromised mailbox during a transaction, then sends revised payment instructions at the moment funds are due, often from a lookalike domain or from the genuine compromised account.
Controls that work:
- Out-of-band verification of every payment instruction change, using a number held on file rather than one in the email
- A firm rule that instructions are never accepted or changed by email alone, stated to clients at engagement
- Mailbox rule monitoring, since attackers create forwarding and auto-delete rules to hide their presence
- Client warning at engagement, which both protects them and demonstrates care
See BEC defence.
Practical controls partners will accept
The trick is choosing controls with low friction and high value:
- MFA with a good authenticator, not SMS, and no exemptions
- Single sign-on, which reduces the password burden rather than adding to it
- Managed devices with encryption and remote wipe, including personal phones with firm email
- Matter-based access in the document management system, configured once
- Secure client portals instead of emailing documents, which clients increasingly prefer anyway
- Phishing simulation and short training, with partners included
Point five is worth pushing: it removes a large category of exposure and improves the client experience, so it is one of the few security changes that can be sold on its merits rather than on risk.
E-discovery and the vendors around a matter
A litigation matter pulls in e-discovery providers, document review teams, experts, agencies and sometimes co-counsel. Client data spreads across organisations the firm does not control, for the duration of a matter and frequently long after it.
Practical controls:
| Control | Detail |
|---|---|
| Assess before engagement | Security terms in the engagement, not after data moves |
| Transfer securely | Portals, not email or unencrypted media |
| Scope the data | Send what the matter requires, not the whole collection |
| Set deletion terms | With a date, and confirmation |
| Track where data went | A register per matter — few firms have one |
The last row is the gap. Firms rarely know, matter by matter, which third parties hold client data. When a client asks — and clients increasingly do — the inability to answer is itself the finding.
Responding to a client security questionnaire
These arrive regularly and consume partner time badly. The efficient approach is to build one maintained answer set covering the questions that recur: MFA coverage, encryption, access control, backup and recovery, incident response, training, testing, subcontractor management and insurance.
Keep it current, keep the supporting evidence with it, and have one person own it. Firms that rebuild answers each time both waste hours and give inconsistent responses across clients, which is noticed.
Where to start
Check whether your partners are exempt from MFA. In most firms that have not looked recently, some are. It is the highest-value single control, the exemptions are usually historical rather than deliberate, and closing them takes an afternoon.
GuardsArm works with professional services firms on assessment and client assurance. See legal sector solutions or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


