Almost every firm has done some version of security training: a video once a year, a sign-in sheet, a certificate. Then someone clicks a phishing link anyway. The problem is not that people are careless. It is that infrequent, generic training does little to change habits.
Effective programs are shorter, more frequent, more relevant to the law firm environment, and supported by leadership. Here is how to build one.
Principles That Work
Keep it short and frequent
A few minutes each month is better than an hour once a year. People retain what they see often. Short lessons also fit billable schedules, which helps attorney participation.
Use examples from the legal world
Generic content about "your bank account" does not connect. Use scenarios that match daily work: a fake e-signature request, a message from a client changing wire instructions, a court-looking notice, a "document shared with you" notification, a request from the managing partner for gift cards or an urgent payment.
Teach what to do, not just what to avoid
Telling staff to "be careful" is vague. Give them clear actions: hover over links, verify by phone, report using the report button, never approve an MFA prompt you did not initiate.
Make reporting easy and safe
The most valuable behavior is reporting a suspicious message quickly, including after a mistake. If staff fear punishment, they hide incidents and attackers gain days. Make reporting a one-click action and thank people who use it.
Include everyone, starting with partners
Attorneys with the most access and authority are valuable targets. Exempting partners signals that the rules are optional and leaves the firm's weakest link untouched.
Topics to Cover
- Phishing and credential theft, including fake login pages
- Business email compromise and wire verification
- MFA fatigue and why you never approve unexpected prompts
- Password hygiene, using a password manager and unique passphrases
- Safe handling of client data, including email, file sharing and printing
- Working remotely, including public Wi-Fi and home networks
- Physical security, such as visitors, unattended screens and paper files
- AI tools, and what may or may not be entered into them
- Reporting incidents, with names and numbers
- Social engineering by phone, including callers claiming to be IT or a bank
Build the Program
Start with a baseline
A simulated phishing exercise, run kindly, shows where you stand. The goal is learning, not shaming. Avoid publishing individual results.
Set a calendar
- Onboarding training for new hires during week one
- Short monthly or bi-monthly lessons
- Quarterly simulated phishing tests with varied difficulty
- Annual refresher covering policy updates
- Ad-hoc alerts when a real threat circulates
Track and report
Measure completion rates, reporting rates and repeat clickers, and review trends with firm leadership. A rising reporting rate is a good sign even if click rates fluctuate.
Follow up with support
If someone repeatedly struggles, offer additional coaching rather than discipline. Pair the training with technical controls so that one click does not equal a disaster.
Link Training to Ethics and Insurance
The ABA's Model Rules 5.1 and 5.3 address supervisory responsibilities for lawyers and nonlawyer staff, and Rule 1.1, Comment 8, refers to understanding technology risks. Training records help demonstrate reasonable efforts. Cyber insurance applications and client questionnaires frequently ask whether training and phishing simulation occur, and how often. Confirm with your state bar how your jurisdiction applies these rules.
Common Mistakes
- A single annual session
- Content that is too technical or too generic
- Punishing people who click
- No simulation or follow-up
- Excusing senior attorneys
- Not updating content as new scams appear
What Training Cannot Do
Training reduces risk but cannot eliminate it. Everyone makes mistakes when busy. That is why technical safeguards, such as MFA, email filtering and endpoint monitoring, belong beside awareness efforts.
Support From Counsel Cyber
Counsel Cyber delivers short, law-firm-specific awareness training with simulated phishing and reporting tools, and provides completion records you can share with clients and insurers. If your program is a once-a-year video, we can help you build something more effective.