ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Cybersecurity Month for Law Firms: Five Habits Worth Building Now

October is a good prompt for a firm security reset. Five habits for law firms that cost little and reduce real risk, from MFA to incident rehearsal.

3 min readBy Counsel Cyber Team

October is widely observed as Cybersecurity Awareness Month, and CISA and its partners publish public guidance around it. For a law firm, it is a convenient prompt to stop and ask whether your security habits match the sensitivity of what you hold. You are custodians of confidential client information, financial details and strategy, which makes you an attractive target and, under Model Rule 1.6(c), a lawyer with a duty to make reasonable efforts to protect it.

You do not need a large budget to make progress. Five habits, done consistently, cover a large share of the risk for small and mid-size firms.

1. Enforce multifactor authentication everywhere

Stolen passwords remain a leading way into email and cloud systems. Multifactor authentication stops many of those attempts even when a password leaks.

  • Turn it on for email, practice management, document management, remote access and banking
  • Prefer authenticator apps, security keys or passkeys over text messages where you can
  • Include partners. Exemptions for senior people are exactly where attackers look
  • Review the list of accounts without MFA each quarter

2. Treat email as the front door

Email is where phishing and wire fraud start. Basic hygiene goes a long way:

  • Filter and scan attachments and links
  • Flag external senders and lookalike domains
  • Alert on new forwarding rules and unusual sign-ins
  • Require a phone callback for any change to payment instructions

3. Train people in small, frequent doses

One annual video is better than nothing but is quickly forgotten. Short monthly reminders, simulated phishing messages, and a culture where staff can report a suspicious email without embarrassment work better. Model Rules 5.1 and 5.3 address supervision, and training is a practical way to show reasonable oversight of lawyers and nonlawyer staff.

Make reporting easy. A single "report phishing" button gets more reports than an email address nobody remembers.

4. Patch and inventory

You cannot protect what you do not know you have. Keep a current list of computers, servers, network devices, cloud applications and who owns each. Then:

  • Apply operating system and application updates on a schedule
  • Replace devices that no longer receive security updates
  • Retire accounts and software nobody uses
  • Review who has administrator rights

Unpatched internet-facing systems and forgotten accounts are common footholds for attackers.

5. Rehearse the bad day

An incident response plan nobody has read is a document, not a capability. Spend an hour a year on a tabletop exercise with partners and your IT provider. Pick a scenario, such as a compromised partner mailbox or ransomware on the file server, and walk through it:

  1. Who is in charge and who makes decisions?
  2. Who do we call first: IT provider, cyber-insurance carrier, outside counsel?
  3. How do we communicate if email is down?
  4. What would we tell clients, and when?
  5. Which systems come back first?

ABA Formal Opinion 483 discusses lawyers' obligations when they learn of a data breach, and 477R discusses securing client communications. Reading them with your ethics counsel before an incident is far easier than after.

Pick one this week

Trying to do everything in a month leads to doing nothing. Choose the habit where your firm is weakest, assign an owner, and set a date. Then record what you did, because clients and cyber-insurance carriers increasingly ask for evidence, not just assurances. If you need to rank them, start with multifactor authentication and the email controls, since those address the most common attack paths.

A note on culture

Technology helps, but the strongest protection is a firm where a paralegal feels comfortable telling a partner that a request looks wrong. Partners set that tone. When leaders follow the same rules and thank people for raising concerns, security stops feeling like an obstacle and becomes part of how the firm works.

Where Counsel Cyber fits

Counsel Cyber works only with law firms, so our assessments are built around the way firms actually operate. If you would like a baseline of where your firm stands on these five habits, we offer a straightforward security review with a prioritized list of next steps.