Most law firms do not fail at cybersecurity because they ignored it. They fail because they bought a few tools, never agreed on what "good enough" looks like, and have no way to tell whether the pieces fit together. A baseline fixes that. It is a short, written list of controls that every attorney and staff member can count on, whatever the size of the firm.
The list below is deliberately practical. None of it requires a large budget, and most items can be verified in an afternoon. Treat it as a starting point for a conversation with whoever manages your IT.
The ten controls
Identity and access
- Multi-factor authentication on everything that matters. Email, practice management, document management, remote access, and any banking portal. Prefer authenticator apps or hardware keys over text messages where you can.
- Unique accounts and least privilege. No shared logins. Staff get access to the matters and systems their role requires, and nothing more. Administrator rights should be rare and separate from daily accounts.
- A password manager. It removes the pressure to reuse passwords and gives you a way to share credentials without pasting them into email.
Devices and software
- Managed, patched endpoints. Every laptop and desktop should receive operating system and application updates on a schedule, with someone responsible for confirming they actually installed.
- Modern endpoint protection with monitoring. Traditional antivirus catches known threats. Endpoint detection and response, watched by people who can act at 2 a.m., catches behavior that looks like an attack in progress.
- Full-disk encryption. A lost laptop should be an inconvenience, not a reportable event.
Email and data
- Email filtering and authentication. Most intrusions begin with an email. Filtering, link protection, and properly configured sender authentication reduce what reaches your people.
- Tested, separate backups. Backups that live on the same network as your servers can be encrypted by the same ransomware. Keep at least one copy isolated, and prove you can restore from it.
People and process
- Regular security awareness training. Short, frequent sessions with simulated phishing work better than an annual slideshow. Include a clear, blame-free way to report suspicious messages.
- A written incident response plan. Know who calls whom, who has authority to disconnect systems, and when you notify your insurer, clients, and counsel.
Why a baseline matters for law firms specifically
Law firms hold confidential client information, handle large sums in trust accounts, and operate under deadlines that make people click quickly. Attackers know this. The ABA's Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and ABA Formal Opinion 477R discusses what reasonable efforts can look like depending on the sensitivity of the information. How your own state bar treats these questions is something to confirm with the bar directly, but a written baseline is the kind of evidence of reasonable effort that is easy to show and hard to argue with.
Cyber insurance applications and client security questionnaires increasingly ask about the same items. A firm that has the ten controls documented can answer those requests faster and with more confidence.
How to use this list
Start with a simple grading exercise. For each control, mark it as in place and verified, in place but unverified, or missing. Be honest about the middle category. Many firms discover that MFA is "on" for most accounts but not for a long-standing shared mailbox, or that backups run nightly but nobody has tried a restore.
Then rank the gaps by how much damage they could cause and how quickly you can close them. MFA gaps and untested backups usually come first. Training and incident planning are cheap and can proceed in parallel.
Common mistakes to avoid
- Treating the baseline as a one-time project instead of a quarterly review.
- Buying tools without assigning someone to read their alerts.
- Exempting partners from controls because they find them inconvenient. Attackers target partners precisely because their accounts have the most access.
- Assuming a cloud vendor handles everything. Vendors secure their platform. Configuration, user accounts, and data handling remain your responsibility.
Making it stick
Write the baseline down in one or two pages, have the managing partner sign off on it, and review it every quarter. A short review meeting with whoever runs your IT is enough: what changed, what failed, and what is next.
Counsel Cyber works with law firms across Texas, Arkansas, Louisiana, Oklahoma and Kansas, and a baseline review is a common first conversation. If you would like a second set of eyes on where your firm stands against these ten controls, we are glad to walk through it with you.