Many small firms assume attackers only go after banks and hospitals. In reality, criminals pick targets based on the value of the data, the money in motion and how hard the defenses look. A law firm often scores well on the first two and, historically, poorly on the third. This post explains what makes firms attractive and what to do about it.
What attackers want from a law firm
Money in motion
Law firms regularly handle large sums: real estate closings, settlements, escrow and retainers. Criminals know that a single redirected wire can be worth more than weeks of other fraud. The FBI's Internet Crime Complaint Center has consistently described business email compromise as among the costliest categories of cybercrime it tracks, and real estate transactions are specifically mentioned in its guidance.
Confidential information
Firms hold merger plans, litigation strategy, intellectual property, personal financial records and medical details. That information can be sold, used for insider trading, or used to pressure the client or the firm. Even a small firm may hold the one document an attacker wants about one of its clients.
Access to other targets
A firm that works with larger organizations may be a stepping stone. Attackers sometimes compromise a smaller supplier or advisor in order to reach its clients, using the trusted relationship to send convincing messages.
Leverage for extortion
Ransomware groups encrypt systems and often steal data first. A law firm faces pressure not just from downtime but from the threat of publishing client confidences. That is why paying or not paying is a hard decision, and why prevention and recovery planning matter.
How attackers usually get in
Most successful attacks use common techniques, not exotic ones.
- Phishing and credential theft. A convincing email leads to a fake login page that captures a password.
- Weak or reused passwords without multi-factor authentication.
- Unpatched software on servers, VPNs and firewalls that have known vulnerabilities. CISA regularly publishes lists of vulnerabilities that are being actively exploited.
- Compromised vendors or accounts that have trusted access.
- Exposed remote access, such as a remote desktop service reachable from the internet.
- Mistakes, such as misdirected email or overshared links.
Why smaller firms are exposed
Small and mid-size firms often have the same data as large ones but fewer dedicated security staff. Attorneys are busy and practice under deadlines, which makes them vulnerable to urgent-sounding messages. Many firms also have grown organically, with a mix of old servers, cloud tools and personal devices that nobody has fully inventoried.
Controls that block the most common attacks
You do not have to buy everything. A well-chosen baseline addresses a large share of real-world risk.
- Multi-factor authentication on email, remote access, practice management and administrator accounts
- Email security that filters phishing, impersonation and malicious attachments
- Endpoint detection and response with someone watching the alerts around the clock
- Prompt patching of operating systems, applications, firewalls and VPN devices
- Tested, immutable backups that cannot be erased from a compromised network
- Least-privilege access, so a single account cannot reach everything
- Security awareness training with simulated phishing
- Payment verification procedures for wire instructions
- A written incident response plan with contacts and roles
NIST Cybersecurity Framework 2.0 organizes this work into functions: govern, identify, protect, detect, respond and recover. It offers a useful way to check that a program is balanced and not heavy on just one area.
The duty angle
Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information, and ABA Formal Opinion 483 discusses obligations when a breach occurs. Confirm the specifics with your state bar. Beyond ethics, clients and insurers increasingly expect these controls and ask for evidence of them.
Where to begin
- List your critical systems and where client data lives.
- Check MFA on every one, and close gaps.
- Confirm backups are immutable and test a restore.
- Review who has administrator access.
- Schedule staff training and a phishing simulation.
- Write down who to call when something goes wrong.
None of this requires an enterprise budget. It requires deciding to treat security as part of running the practice, not an afterthought.
Counsel Cyber focuses on law firms specifically. If you would like to know where your firm stands against these basics, we can walk through them together in a short security review.