ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Your Law Firm's Security Awareness Training: What Actually Works

Annual slide decks rarely change behavior. Here is how to build a security awareness program for attorneys and staff that is short, relevant and sustained.

3 min readBy Counsel Cyber Team

Almost every firm has done some version of security training: a video once a year, a sign-in sheet, a certificate. Then someone clicks a phishing link anyway. The problem is not that people are careless. It is that infrequent, generic training does little to change habits.

Effective programs are shorter, more frequent, more relevant to the law firm environment, and supported by leadership. Here is how to build one.

Principles That Work

Keep it short and frequent

A few minutes each month is better than an hour once a year. People retain what they see often. Short lessons also fit billable schedules, which helps attorney participation.

Use examples from the legal world

Generic content about "your bank account" does not connect. Use scenarios that match daily work: a fake e-signature request, a message from a client changing wire instructions, a court-looking notice, a "document shared with you" notification, a request from the managing partner for gift cards or an urgent payment.

Teach what to do, not just what to avoid

Telling staff to "be careful" is vague. Give them clear actions: hover over links, verify by phone, report using the report button, never approve an MFA prompt you did not initiate.

Make reporting easy and safe

The most valuable behavior is reporting a suspicious message quickly, including after a mistake. If staff fear punishment, they hide incidents and attackers gain days. Make reporting a one-click action and thank people who use it.

Include everyone, starting with partners

Attorneys with the most access and authority are valuable targets. Exempting partners signals that the rules are optional and leaves the firm's weakest link untouched.

Topics to Cover

  1. Phishing and credential theft, including fake login pages
  2. Business email compromise and wire verification
  3. MFA fatigue and why you never approve unexpected prompts
  4. Password hygiene, using a password manager and unique passphrases
  5. Safe handling of client data, including email, file sharing and printing
  6. Working remotely, including public Wi-Fi and home networks
  7. Physical security, such as visitors, unattended screens and paper files
  8. AI tools, and what may or may not be entered into them
  9. Reporting incidents, with names and numbers
  10. Social engineering by phone, including callers claiming to be IT or a bank

Build the Program

Start with a baseline

A simulated phishing exercise, run kindly, shows where you stand. The goal is learning, not shaming. Avoid publishing individual results.

Set a calendar

  • Onboarding training for new hires during week one
  • Short monthly or bi-monthly lessons
  • Quarterly simulated phishing tests with varied difficulty
  • Annual refresher covering policy updates
  • Ad-hoc alerts when a real threat circulates

Track and report

Measure completion rates, reporting rates and repeat clickers, and review trends with firm leadership. A rising reporting rate is a good sign even if click rates fluctuate.

Follow up with support

If someone repeatedly struggles, offer additional coaching rather than discipline. Pair the training with technical controls so that one click does not equal a disaster.

Link Training to Ethics and Insurance

The ABA's Model Rules 5.1 and 5.3 address supervisory responsibilities for lawyers and nonlawyer staff, and Rule 1.1, Comment 8, refers to understanding technology risks. Training records help demonstrate reasonable efforts. Cyber insurance applications and client questionnaires frequently ask whether training and phishing simulation occur, and how often. Confirm with your state bar how your jurisdiction applies these rules.

Common Mistakes

  • A single annual session
  • Content that is too technical or too generic
  • Punishing people who click
  • No simulation or follow-up
  • Excusing senior attorneys
  • Not updating content as new scams appear

What Training Cannot Do

Training reduces risk but cannot eliminate it. Everyone makes mistakes when busy. That is why technical safeguards, such as MFA, email filtering and endpoint monitoring, belong beside awareness efforts.

Support From Counsel Cyber

Counsel Cyber delivers short, law-firm-specific awareness training with simulated phishing and reporting tools, and provides completion records you can share with clients and insurers. If your program is a once-a-year video, we can help you build something more effective.