Phishing remains one of the most common ways attackers get into law firms. A convincing email, a rushed click and a stolen password can open the door to client files. Simulated phishing campaigns, where the firm sends harmless fake phishing emails to its own people, are a popular training tool. Done badly, they breed resentment and secrecy. Done well, they build the reflex to pause and report.
This post covers how to run simulations in a law firm, where attorneys are busy, skeptical and unforgiving of anything that wastes time.
What simulations are for
The goal is not to catch people. It is to practice. Think of them as fire drills: you want people to know what to do when the alarm sounds, and you learn where the process breaks down. The most valuable number in a simulation program is not the click rate. It is the report rate, meaning how many people flag the suspicious message to IT.
Set expectations before the first test
- Announce that the firm will run periodic simulations and explain why.
- State plainly that the purpose is learning, not discipline.
- Include partners. Exempting leadership tells everyone the program is about blame.
- Explain how to report a suspicious message, ideally with a single button in the email client.
Surprising people with no warning at all tends to generate anger when they discover the trick. A general announcement does not ruin the effect, since individual tests remain unannounced.
Design realistic, relevant scenarios
Generic lottery or prince emails train people to spot fifteen-year-old scams. Law firms face more targeted lures.
- A document-sharing notice appearing to come from a known platform.
- A fake request from a managing partner to purchase gift cards or approve a payment.
- A message claiming a voicemail or fax is waiting.
- A court or agency notice with an attachment.
- A client sending revised wire instructions.
- A calendar invitation from an unknown outside party.
- An MFA fatigue scenario in which a user is asked to approve a prompt they did not initiate.
Vary difficulty. Beginners should see obvious red flags; experienced staff should see subtle ones.
Use the click as a teachable moment
When someone clicks, show an immediate, short page explaining what the red flags were. Avoid shaming language. A good landing page takes thirty seconds to read and gives two or three specific cues, such as a mismatched sender domain or an unexpected request for credentials.
What not to do
- Do not publish names of people who clicked.
- Do not tie results to performance reviews or compensation.
- Do not send simulations during an actual crisis, a major trial or a holiday rush.
- Do not use scenarios that exploit real fears such as layoffs, family illness or bonuses. These generate anger and distract from the learning.
- Do not repeat the same lure so often that people memorize the test rather than the technique.
Measure what matters
Track these over time:
- Report rate: the percentage who flag the message.
- Click rate: useful, but easier to misread. A rising click rate after introducing harder scenarios may not mean worse behavior.
- Time to report: how quickly the first report arrives. Fast reports let real defenders react to a real campaign.
- Repeat clickers: individuals who may need extra coaching, handled privately and supportively.
Avoid setting an unrealistic target of zero clicks. Real attackers only need one person to be fooled once, so the layered defenses behind your people, such as MFA, email filtering and monitoring, matter as much as training.
Pair simulations with real training
Simulations alone do not teach well. Combine them with short training modules, a ten-minute briefing at a staff meeting and sharing sanitized examples of actual phishing emails the firm receives. People learn more from messages that were actually sent to them last week.
Reward reporting
Celebrate the person who reports the real phishing email. A short note in a staff meeting or a small recognition goes a long way. Reporting must feel safe and appreciated, or it will quietly stop.
Respect professional duties
Model Rule 5.3 and related guidance remind lawyers to supervise nonlawyer staff, and the ABA has emphasized training in its discussion of securing client communications in Formal Opinion 477R. Records showing the firm provides regular training and testing are a helpful part of a defensible security program. Keep summaries of completion and report rates, not individual embarrassments.
How Counsel Cyber can help
Counsel Cyber runs security awareness training and phishing simulations for law firms with scenarios built around legal workflows. If you would like to pilot a program, we are happy to help you set it up in a way your attorneys will accept.