ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Security Awareness Training That Attorneys Will Actually Complete

Lawyers are busy and skeptical of compliance training. Learn how to design short, relevant security awareness sessions that change behavior and earn buy-in.

3 min readBy Counsel Cyber Team

Ask a firm administrator about security awareness training and you will often hear the same frustration: attorneys postpone it, click through the videos, and complain about phishing simulations. Yet human error remains a central factor in many breaches, which is why insurers, clients and regulators ask about training.

The solution is not more training but better training: shorter, relevant to legal work, and visibly supported by firm leadership.

Why attorney training is different

Attorneys bill by the hour, handle urgent matters and are trained to be skeptical. A 45-minute generic module on "password hygiene" feels like a poor use of time. Training lands when it connects to things lawyers care about: client confidentiality, professional responsibility, court deadlines, and avoiding embarrassment.

Principles for training that works

Keep it short and frequent

Five- to ten-minute sessions each month tend to outperform a single annual marathon. People retain more, and you can respond to current threats.

Use legal-specific scenarios

Replace generic examples with ones lawyers recognize:

  • A fake e-signature request that appears to come from opposing counsel
  • An email that appears to come from a client changing wire instructions before a closing
  • A "court notice" with a link
  • A request from the "managing partner" to buy gift cards or process an urgent payment
  • A shared document link that asks for Microsoft 365 credentials

Tie it to professional obligations

Frame training around duties the ABA has described: Rule 1.1 technology competence, Rule 1.6(c) reasonable efforts to protect client information, and supervision duties under Rules 5.1 and 5.3. That makes training part of professional practice, not an IT chore.

Get leadership participation

When managing partners complete training first and talk about it, everyone else follows. When partners are exempt, the message is clear. Report completion rates by practice group at partner meetings.

What to cover

  1. Phishing recognition: sender details, urgency, unusual requests, links, and attachments
  2. Payment fraud: verifying any change in payment instructions by phone using a known number
  3. Passwords and MFA: password managers, why unexpected MFA prompts are alarms, and never sharing codes
  4. Safe handling of client data: where to store files, how to share securely, avoiding personal email and unapproved apps
  5. Travel and remote work: public Wi-Fi, device locks, screen privacy
  6. AI tools: what is approved and what must never be pasted into an unapproved tool
  7. Reporting: how to report a suspicious email or mistake, quickly and without blame

Phishing simulations: use them wisely

Simulated phishing emails can measure and improve awareness, but they work best when they are:

  • Realistic, but not humiliating or deceptive about personal topics such as bonuses
  • Followed by immediate, brief coaching for those who click
  • Tracked as trends, not as a list of people to punish
  • Paired with an easy "report phish" button, because reporting rate matters as much as click rate

A culture where staff feel safe reporting a mistake is worth more than any simulation score.

Measure what matters

Useful metrics include completion rates, reporting rates for suspicious messages, repeat-clicker trends and time between a suspicious email arriving and being reported. Avoid declaring success based on completion alone.

Handle the resisters

  • Offer a flexible schedule, including mobile-friendly modules
  • Have a supervising partner follow up personally
  • Link completion to account access or compliance reviews, as a last resort
  • Explain the why with examples from the legal world, using hypotheticals rather than naming real victims

Document everything

Keep training content, dates, attendance and simulation results. Insurers and clients often ask for them.

One more practical tip: schedule training around the firm's calendar rather than against it. Avoid trial weeks and filing crunches, offer sessions at lunch or as short recorded modules, and let attorneys complete them on a phone between meetings. Removing friction does more for completion rates than any reminder email.

Support from Counsel Cyber

We provide security awareness training and phishing simulations tailored to law firms, with short sessions designed for busy lawyers. Ask us for a sample program for your firm.