Cybersecurity for Law Firms: Where to Start

By Yonatan Hoorizadeh CISSP, CISM, CRISC, AAISM
Published By: Purple Shield Security
Published: August 10, 2026
Last updated: August 10, 2026
Start by mapping where client data lives, then enforcing phishing-resistant multi-factor authentication on email and the document management system, then writing an incident response plan that names who calls whom. Those three moves close most of the exposure that ethics rules, cyber insurers, and corporate client questionnaires all ask about. Everything else sequences behind them.
Where should a law firm actually start with cybersecurity?
Start with an inventory, not a purchase. Before a firm signs a managed services contract or buys another agent, it needs to know which systems hold client matter data, who can reach each one, and what happens if a partner's mailbox is taken over at four o'clock on a Friday. Firms that skip this step buy controls for problems they do not have and miss the ones they do.
Here is the practical version. A managing partner should be able to answer three questions in about thirty seconds:
Where does client data actually live, including the places nobody approved?
Who inside the firm can see across matters they are not staffed on?
Who do we call first, by name and phone number, if a client file shows up on a leak site tonight?
Most firms under a hundred attorneys cannot answer all three. That is not a character flaw, it is a staffing reality. Nobody at a thirty-lawyer litigation boutique was hired to own this, so it drifts to whoever is most comfortable with technology, which is usually the office administrator or an outside IT provider. Both are useful. Neither is accountable in the way the ethics rules and the client contracts now assume someone is.
The right starting point also scales with size, and the sequencing genuinely differs:
Solo through nine attorneys: phishing-resistant MFA on email and cloud storage, a tested backup restore, and a two-page written incident response outline listing the carrier, the forensics contact, and the notification counsel. That is a real program at that size.
Ten to forty-nine attorneys: add a data map, a document management permission review, an annual risk assessment, and a named external incident response firm you have actually spoken to.
Fifty to one hundred fifty attorneys: formalize the program against a framework, put someone with real authority in the security seat, and build the evidence package that corporate clients ask for. This is the band where fractional CISO services usually make the most sense.
Above one hundred fifty attorneys: the question shifts from whether to have security leadership to whether it should be full time, and the answer usually becomes yes.
The gap between those bands shows up clearly in the ABA's own survey data. The ABA Legal Technology Survey Report has consistently found that incident response planning tracks almost perfectly with headcount, running around twelve percent among solos and roughly eighty percent at firms with a hundred or more attorneys. The threat actors targeting the legal sector do not observe that dividing line.
Why are law firms targeted more heavily than businesses their size?
Law firms concentrate other people's secrets. A single intrusion at a thirty-attorney firm can reach merger terms, litigation strategy, tax records, and health information belonging to hundreds of clients. Attackers are not after the firm's balance sheet. They are after leverage over everyone the firm represents, which is why both espionage crews and extortion crews treat the legal sector as a shortcut.
The most instructive recent example is not a ransomware headline. Between January and May 2026, Mandiant investigated a data theft extortion campaign run by the threat cluster UNC3753, also tracked as Luna Moth, Chatty Spider, and Silent Ransom Group, against dozens of US professional, legal, and financial services organizations. According to Google Threat Intelligence Group, the attackers called employees on the phone, posed as internal IT helpdesk staff, and talked them into starting a screen sharing session or installing a legitimate remote management tool.
Once inside, the operators ran keyword searches directly against the firm's document management system, hunting for folders containing W-2, W-9, and 1099 forms, audit files, corporate client agreements, and Social Security numbers. Mandiant reported that in many cases the full sequence, from first contact through theft and extortion demand, happened inside a single business day, and that in recent incidents the search and staging phase took under an hour. The extortion email typically arrived within thirty minutes of the attackers leaving, carrying a three-day deadline and a threat to call the firm's clients directly.
It escalated further. Google Threat Intelligence Group noted, corroborating an FBI Cyber FLASH alert, that when remote social engineering failed, individuals showed up at offices in person claiming to be IT technicians and attempted to copy data straight to USB drives.
Here is the part worth sitting with. That entire chain never touched a firewall. Every tool used was software the firm already licensed or could download without triggering an alert. GTIG's own assessment is that voice-guided social engineering lets attackers "bypass robust technical perimeters, web security gateways, and MFA configurations." A firm that reads that campaign write-up and responds by shopping for another security product has diagnosed the wrong problem. The control that breaks that chain is a published procedure requiring out-of-band verification of anyone claiming to be IT, plus a rule that nobody escorts an unscheduled technician to a workstation. Those are governance decisions, and they cost nothing except the willingness to make them.
The espionage side of the picture is quieter and slower. In October 2025, Williams and Connolly told clients that a nation-state affiliated actor had exploited a zero-day vulnerability to access a small number of attorney email accounts, part of what CNN and others reported as a broader campaign against US firms. Google Threat Intelligence Group separately reported that the BRICKSTORM campaign, which prioritized legal services among its targets, ran with an average dwell time of 393 days. Meanwhile, Coveware data compiled by DeepStrike put professional services, the category that contains law firms, at 18.9 percent of ransomware incidents in the fourth quarter of 2025, the single largest share of any sector.
Two different adversary profiles, two different tempos. One is in and out before lunch. The other has been reading your mail since the last presidential election cycle. A security program built only for the fast one will never find the slow one.
What do the ethics rules actually require?
The Model Rules require reasonable efforts, not perfect security, and that distinction is where firms get into trouble in both directions. Model Rule 1.6(c) obliges a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of information relating to a representation. A firm breached despite genuine effort has not violated the rule. A firm that never made the effort has, whether or not it was ever breached.
Three ABA opinions do most of the work here. Formal Opinion 477R, issued in 2017, applied the confidentiality duty to electronic communication. Formal Opinion 483, issued October 17, 2018, extended it to breaches and cyberattacks. Formal Opinion 512, issued July 29, 2024, applied the same framework to generative artificial intelligence. Comment 8 to Model Rule 1.1 supplies the underlying obligation that lawyers keep abreast of the benefits and risks of relevant technology.
Formal Opinion 483 is the one every firm leader should read in full, because it sets the standard that a bar committee will later apply. The opinion places the ethical violation not at the moment of the breach but earlier, holding that the problem arises when a lawyer fails to make "reasonable efforts to avoid data loss or to detect cyber-intrusion" and that failure causes the breach. It also imposes an affirmative sequence after an incident: act promptly to stop the intrusion, evaluate to the extent reasonably possible what data was accessed or lost, and notify current clients where material client information is involved, with enough detail for the client to make informed decisions about the representation.
Then there are Rules 5.1 and 5.3, on supervision of lawyers and nonlawyer assistance. These are the rules most firms quietly ignore, and they are the reason "our IT company handles security" is not an answer. The supervision duty runs to vendors. It cannot be delegated back to the vendor being supervised. If the same company that sells the firm its security stack is also the company that tells the firm whether the stack is adequate, no supervision is occurring in any meaningful sense. A litigator would spot that conflict in a client's vendor arrangement immediately.
One more point that gets missed. The reasonable-efforts standard is evidentiary. It is judged after the fact by people who read documents: a bar disciplinary committee, a malpractice carrier's coverage counsel, a client's general counsel, sometimes a plaintiff's lawyer. None of them can see the effort you made. They can only see the artifacts. Which means the practical translation of Rule 1.6(c) for a law firm is this: can you produce dated records showing you assessed the risk, made decisions, and acted on them. A risk assessment is not paperwork. It is the exhibit.
State rules govern, not the Model Rules, and jurisdictions vary. Check your own state's version and its ethics opinions before assuming the ABA guidance is the ceiling.
What changes if the firm practices in California?
California adds two layers. The State Bar's guidance on artificial intelligence is moving from advisory toward binding, and the California Privacy Protection Agency's cybersecurity audit regulations took effect on January 1, 2026. Most small firms will not trigger the audit thresholds themselves. Firms that advise businesses which do will be answering their clients' auditors either way.
The CPPA cybersecurity audit rule
Ropes and Gray described the CPPA regulations that took effect January 1, 2026 as the first comprehensive cybersecurity audit obligations of their kind among state privacy laws. The trigger requires that a business first fall under the CCPA and then meet one of several additional conditions: processing personal information of 250,000 or more California consumers or households, processing sensitive personal information of 50,000 or more consumers, or deriving half or more of annual revenue from selling or sharing personal information. Certification deadlines phase in by revenue, with the largest businesses certifying first and the remainder phased in through 2030.
What the audit examines will look familiar to anyone who has done a client questionnaire: multi-factor authentication, encryption, access controls, network monitoring, incident response planning, employee training, and data disposal. Two details matter more than the control list. The auditor must be independent, and the findings cannot rest primarily on management's own assertions. And an executive with direct responsibility for cybersecurity compliance signs the certification, under penalty of perjury.
That signature line is the sleeper clause, and it applies well beyond law firms. It presumes an accountable executive exists. At most organizations below a certain size, including most law firms under a hundred and fifty attorneys, no such person is on the org chart. There is an administrator, an outside IT provider, and a partner who is good with computers. Nobody in that group can credibly sign a perjury-backed attestation about control effectiveness. This is precisely the gap that fractional CISO services were built to fill, and it is also why the person signing should not work for the vendor that sold the controls.
California's AI guidance is hardening into rules
The State Bar of California's Committee on Professional Responsibility and Conduct first published its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law on November 16, 2023. The Board of Trustees approved updated revisions on May 14, 2026, which address agentic artificial intelligence, meaning systems that carry out multi-step tasks without being prompted at each step.
The direction of travel is toward enforceability. On August 22, 2025, the California Supreme Court directed the State Bar to consider folding those guiding principles into the Rules of Professional Conduct themselves, and COPRAC circulated proposed amendments for public comment that closed in May 2026. Advisory guidance you can debate. Rules of Professional Conduct carry disciplinary authority.
The California guidance is unusually direct about the security question. It instructs lawyers to confirm that any generative AI system adheres to security, confidentiality, and data retention protocols, and frames that as something to verify with an IT or cybersecurity professional rather than assume. On agentic tools specifically, the guidance warns that poorly configured systems may "unintentionally disclose confidential information (including across different matters)" and expose privileged material. Read that clause carefully. It is describing a permissions problem inside the document management system, not a flaw in the AI tool, which means the fix is an access review rather than a software purchase.
Separately, California Civil Code section 1798.82 governs breach notification, and it operates independently of the ethics duty to notify clients. A California firm dealing with a breach is running two notification analyses at once, on different clocks, with different triggers.
What does a real law firm risk assessment cover?
A useful risk assessment produces a ranked list of specific exposures tied to named systems and matters, not a color-coded spreadsheet of generic threats. For a law firm it starts with a data map, moves through matter-level access in the document management system, and ends with an honest answer to whether the firm could reconstruct what an attacker touched. That last one is where most assessments quietly fail.
The NIST Cybersecurity Framework 2.0 is the right backbone for a firm of almost any size, largely because of the Govern function added in the 2.0 release. Govern asks who decides, who is accountable, and how risk decisions get made and recorded. For law firms, which are partnerships rather than corporations and often have no single decision maker for operational spending, that function does more work than any technical control.
A law firm assessment worth paying for inventories the systems that actually hold matter data:
Document management: iManage, NetDocuments, SharePoint, or in smaller firms a network share nobody has audited since it was set up
Email and identity, including every mailbox with delegate access and every OAuth-connected application
Practice management and billing, which hold client contact data and trust account details
E-discovery repositories, which routinely contain more third-party personal data than the firm's own client files
Client portals and secure file transfer tools, including the ad hoc ones partners set up for a single deal
Backups, and specifically the date of the last successful restore test rather than the existence of a backup job
Vendors with standing access, from the IT provider to the court reporting service
The single most common finding at firms under a hundred attorneys is that everyone can see everything. Matter-level segregation was never configured, or it was configured and then eroded through years of "just give her access, she is covering the hearing." That is an ethics problem, an insurance problem, and, as the UNC3753 campaign showed, the difference between one compromised paralegal account and the wholesale theft of a client roster.
Log retention deserves its own line, and it is the point I would most want a managing partner to take away. In the BRICKSTORM investigations, Mandiant reported that the 393-day average dwell time exceeded victims' log retention periods, so the artifacts showing how the attackers first got in were simply gone. Now hold that against Formal Opinion 483, which requires a firm to evaluate what data was accessed. If your logs roll off at thirty days and an intruder was resident for six months, you cannot perform the evaluation the ethics opinion requires. Log retention is not an IT budget line at a law firm. It is a professional responsibility control, and almost nobody treats it as one.
The output should be evidence, not assurances. Regulators, insurers, and client general counsel have all converged on the same posture: show me the MFA enrollment report, the restore test result, the tabletop summary, the permission review date. Risk assessment services that stop at a maturity score and a slide deck have not produced anything a firm can hand to a client's procurement team.
How do you protect client confidentiality when the client is auditing you?
Corporate clients now audit their outside counsel, and the security questionnaire is where a firm's program stops being an IT topic and becomes a revenue topic. Banks, insurers, health systems, technology companies, and private equity backed operators send questionnaires, outside counsel guidelines naming specific controls, and increasingly requests for SOC 2 or ISO 27001 evidence. Firms that produce artifacts quickly keep the matter.
Outside counsel guidelines have grown teeth. In insurance defense particularly, carrier guidelines now specify multi-factor authentication, endpoint detection, encryption standards, breach notification windows frequently set at twenty-four to seventy-two hours, annual attestations, and third-party audits, with panel counsel status conditioned on compliance. Corporate general counsel push their own regulatory obligations downstream the same way, which is how a firm that has never heard of the CCPA ends up contractually bound to controls written for it.
Recorded Future found that only around thirty percent of firms report ever having been asked to complete a client security questionnaire. That number tends to get read as reassurance. Read it the other way. Audits concentrate where the valuable work is. If your firm has never received one, you are either not doing the regulated-client work you want to be doing, or you are about to receive your first one, from your largest client, with a two-week turnaround.
There is a boundary here that firms should hold, and it is an ethics boundary rather than a negotiating posture. Fox Rothschild's published guidance on the outside counsel guidelines problem gets it right: a firm can reasonably agree to complete periodic security questionnaires and assessments, and to provide executive summaries of audits, an ISO 27001 certificate, or a penetration test summary. What a firm should not agree to is letting a client conduct a physical audit of systems that hold other clients' data, or handing over a full audit report or complete penetration test results. Granting Client A inspection rights over infrastructure holding Clients B through Z is not a commercial concession, it is a confidentiality breach with respect to everyone else.
The practitioner move is to build a standing evidence package before the questionnaire arrives: a current network and data flow summary, MFA coverage report, the last penetration test executive summary, the incident response plan table of contents, the most recent tabletop date, vendor list with access levels, and a short written security overview a partner can send without a scramble. Firms that assemble this once answer future questionnaires in days.
One more thing nobody catches until it is too late. Someone should read the security clauses in outside counsel guidelines before the billing partner signs them. Firms routinely commit to twenty-four hour breach notification windows while running thirty-day log retention and no monitoring, which is a contractual promise the firm has no technical ability to keep. That is a discoverable fact after an incident.
What cloud security means for a law firm in practice
For most firms the cloud is Microsoft 365 or Google Workspace, a document management platform, and a handful of legal SaaS tools. The risk is almost never the provider's infrastructure. It is configuration: overshared links, guest accounts that outlived the matter, connected applications with mailbox access nobody approved, and personal laptops reaching corporate virtual desktops.
The UNC3753 campaign is again the clearest illustration. Mandiant documented intrusions where the operators established screen sharing sessions on targets' personal bring-your-own-device laptops and used those personal machines to reach corporate virtual desktop infrastructure through native Windows 365 or Citrix clients. From there they crawled OneDrive folders and mapped network drives, then ran keyword searches inside the document management system. A conditional access policy limiting virtual desktop and VPN authentication to firm-owned devices would have broken that chain before it reached the first client file.
The cloud work that actually reduces law firm risk is unglamorous:
Sweep external sharing across OneDrive, SharePoint, and Teams and remove anonymous links and guest accounts left over from closed matters
Audit OAuth-connected applications with mail or file access, because a consented app survives a password reset and most firms have never looked at the list
Check every mailbox for forwarding and inbox rules, the classic sign of a compromise nobody noticed
Restrict virtual desktop and remote access authentication to managed devices
Require MFA on the document management system itself, not just on the network perimeter around it
Run a real restore test on the document repository and time it, because recovery time is the number that determines whether ransom is even a question
Firms tend to buy cloud security as a product when the finding is almost always a permissions decision someone made three years ago and then left the firm. A quarterly access review, done properly, outperforms another agent. That said, cloud security services earn their keep when a firm has genuinely outgrown manual review, typically once multiple platforms and hundreds of external collaborators are in play.
How should a firm govern AI without banning it?
A ban does not work, because associates and paralegals will use consumer AI tools on their phones and never mention it. What works is a short written policy naming approved tools, prohibiting client data in anything not on the list, and requiring a documented verification step before AI output reaches a filing or a client. That combination satisfies both Formal Opinion 512 and California's guidance without freezing the practice.
ABA Formal Opinion 512 addresses competence, confidentiality, communication with clients, candor toward tribunals, supervisory responsibilities, and fees. Two points from it deserve emphasis. Lawyers must understand how a given tool handles the data they put into it, including whether inputs may resurface in another user's output. And boilerplate consent buried in an engagement letter is not adequate where informed client consent is actually required.
Now the point that most law firm AI guidance misses entirely, and it is the one that connects this section back to the risk assessment.
AI assistants layered over a document management system inherit its permissions. They do not create them. If everyone in your firm can see every matter in the DMS, a Copilot-class assistant will cheerfully surface Matter A's privileged strategy memo to the associate working Matter B, and it will do so through an interface designed to make retrieval effortless.
This is exactly what the California guidance is pointing at when it warns about agentic systems disclosing confidential information across different matters. The remedy is not an AI control. It is the matter-level permission cleanup already sitting in the risk assessment. Firms are buying AI governance tooling to solve a problem whose fix is a document management permission review they have deferred for four years. Do the permissions first, then turn on the assistant. Doing it in the other order builds a very efficient confidentiality incident.
Beyond that, an AI program for a law firm needs four things and not much more:
An approved tool list, with vendor diligence covering data retention, whether inputs train the model, subprocessors, data location, and deletion on request
A hard rule that client confidential information goes only into approved, contractually covered tools
A verification and citation-check step before any AI-assisted work product goes to a court or a client, logged so it can be shown later
A shadow AI check, because the tool nobody told you about is the one holding your data
AI security governance for law firms is genuinely different from AI governance elsewhere, because the confidentiality duty attaches to all information relating to the representation regardless of source, which is a broader category than the personal data most AI policies are written around.
What makes incident response different at a law firm?
Two things, and both are structural. The firm's own breach triggers a client notification duty under Model Rule 1.4 as interpreted by Formal Opinion 483. And the firm cannot credibly serve as its own breach counsel. Every firm knows how to advise a client through an incident. Very few have accepted that when the victim is the firm, the same discipline has to be imported from outside.
Start with the clock. In the UNC3753 campaign the extortion email arrived within thirty minutes of exfiltration and carried a three-day deadline, with an explicit threat to contact the firm's clients directly. That is not enough time to decide who is in charge, whether the carrier needs to approve the forensics vendor, or whether the managing partner or the general counsel signs the client letter. Those decisions have to be made in advance or they get made badly.
Then the privilege problem, which is where law firms are strangely careless about themselves. Forensic reports produced during an incident are far more defensible as work product when the engagement runs through outside breach counsel rather than directly from the firm to the forensics vendor. Firms advise clients to structure it that way routinely. When it is their own incident, partners often assume privilege attaches automatically because they are lawyers, and it does not work like that. Recorded Future has separately flagged the added exposure that arises under Federal Rule of Evidence 502 when incident reports get shared with regulators.
There is also a conflicts question no vendor will raise. The breach counsel on your cyber carrier's approved panel may be a direct competitor in your practice area, or adverse to you in a pending matter. Sorting that out at nine on a Saturday night, while an extortion clock runs, is not a plan. Identify two acceptable breach counsel options now and confirm they are on the carrier's panel.
A workable law firm incident response plan is short and names people:
Who declares an incident, and who can authorize taking systems offline during business hours
Carrier notification contact, policy number, and the reporting deadline the policy actually imposes
Pre-identified breach counsel and digital forensics firm, ideally on retainer, with conflicts cleared in advance
The decision tree for client notification under Model Rule 1.4 and Formal Opinion 483, separate from the state statutory analysis
Draft client communication templates reviewed by whoever owns the firm's ethics questions
Trust account and wire controls, since business email compromise remains the fastest route from a compromised mailbox to real money. The FBI's Internet Crime Complaint Center reported 2.8 billion dollars in business email compromise losses in 2024, and law firms move client funds constantly
Then run one tabletop a year against a scenario that matches what is actually happening. Not a generic ransomware exercise. Try this one: a paralegal gets a call at four on a Friday from someone claiming to be your IT provider, about a data migration issue. She starts a screen share. Walk the room through the next ninety minutes. That exercise, run once, does more for a firm's readiness than a year of policy revision, and incident response services are worth engaging specifically to facilitate it.
When does a law firm need a fractional CISO?
A firm needs security leadership before it needs more security tools, and below roughly a hundred and fifty attorneys a full-time chief information security officer is rarely justifiable. A fractional CISO, also called a vCISO or virtual Chief Information Security Officer, puts an experienced security executive in the seat for a defined number of hours each month. For most mid-market firms that is enough to own the work that has no other owner.
What the role actually holds:
The risk assessment cadence and the remediation roadmap that comes out of it
Client security questionnaires and outside counsel guideline reviews, including which asks to decline and why
Vendor security evaluation, which is the Rule 5.3 supervision obligation performed by someone competent to perform it
The incident response plan, the tabletop, and the relationship with breach counsel and forensics before an incident
AI governance, tool approval, and the permission work underneath it
Cyber insurance application accuracy, which matters because misrepresenting a control on an application can void the coverage the firm is counting on
Reporting to the partnership in language partners can act on, which is a distinct skill from running the controls
The honest trigger list, if you want a decision rule rather than a sales pitch. Engage fractional CISO services when two or more of these are true:
You have received more than one client security questionnaire in the past year
You sit on insurance defense panels with security clauses in the guidelines
You handle protected health information as a business associate, or financial data subject to GLBA
Your cyber insurance renewal asked questions nobody at the firm could answer with evidence
You advise businesses that are themselves subject to the CPPA audit rule, and you would rather not be the weakest link in their vendor review
You are adopting AI tools that touch matter data
You are merging, acquiring a lateral group, or being diligenced by anyone
One structural point, because it decides whether any of this works. The party assessing controls should not be the party selling them. An IT provider evaluating whether the firm needs more of that provider's stack has a conflict any litigator would identify in a client's contract within seconds. Under Rules 5.1 and 5.3 the firm supervises its vendors, and supervision performed by the supervised party is not supervision. Keep vCISO services and managed IT in separate hands. Purple Shield Security operates that way deliberately, with no product resale and no referral fees, because a firm needs the assessment to be an assessment.
On cost, run the comparison honestly. It is not fractional CISO versus nothing. It is a fraction of a security executive's fully loaded compensation versus the combined cost of the matters that go elsewhere after an unanswered questionnaire, the insurance premium that reflects an unprovable control set, and the incident nobody had a plan for.
The first 90 days, in order
Sequencing matters more than completeness. A firm that does the first thirty days properly is meaningfully safer than a firm that starts everything at once and finishes nothing. Each phase below is scoped so a firm without dedicated security staff can actually complete it.
Days 1 to 30: find the data and close the front door
Build a one-page data map: every system holding client matter data, who owns it, who can reach it
Enforce MFA on email, the document management system, remote access, and every cloud admin account, using an authenticator app or hardware key rather than SMS
Audit every mailbox for forwarding rules and review connected OAuth applications
Sweep external sharing links and guest accounts in Microsoft 365 or Google Workspace and remove what is stale
Confirm who owns backups and when a restore was last actually tested, not merely scheduled
Write down the incident call list: carrier, forensics, breach counsel, IT provider, with names and mobile numbers
Days 31 to 60: fix access and publish the human controls
Run a document management permission review and re-establish matter-level segregation, starting with your most sensitive practice areas
Restrict virtual desktop and VPN authentication to firm-managed devices
Publish an out-of-band verification procedure covering anyone claiming to be IT, any vendor requesting remote access, and any change to payment or wire instructions, then tell every employee it exists
Set a visitor and technician escort policy at the front desk, verified against a scheduled work order
Issue a two-page AI use policy with an approved tool list and a verification requirement
Extend security log retention past a year for identity, email, and document management systems
Days 61 to 90: build the evidence and rehearse
Complete a risk assessment mapped to NIST CSF 2.0, including the Govern function, and rank findings by client impact
Finalize the incident response plan with named external parties and conflicts cleared in advance
Run one tabletop using a vishing scenario, and write down what broke
Assemble the client questionnaire evidence package so the next request takes days rather than weeks
Review the security clauses in outside counsel guidelines for your five largest client relationships against what the firm can actually deliver, and renegotiate the ones you cannot
Decide who owns security going forward, by name, with hours and authority attached
Frequently asked questions
Does a 12-attorney firm really need a fractional CISO, or is a managed IT provider enough?
A managed IT provider and a fractional CISO do different jobs. The provider runs the systems. The CISO decides what risk the firm accepts, answers client questionnaires, owns the incident plan, and evaluates the provider. At twelve attorneys you may only need a few hours a month, but you do need someone who can perform the Rule 5.3 supervision of the vendor, and that cannot be the vendor. If you have never received a client security questionnaire and handle no regulated data, a well-run annual risk assessment plus a written incident plan may be sufficient for now.
What do we have to do if we discover a breach involving client data?
ABA Formal Opinion 483 sets out the sequence: act promptly to stop the intrusion, evaluate as far as reasonably possible what data was accessed or lost, and notify current clients where material client information relating to their representation was involved. That ethics duty is separate from and usually broader than statutory breach notification, which in California runs through Civil Code section 1798.82. Engage outside breach counsel before the forensics vendor so the investigation has the best available work product protection, and check whether your outside counsel guidelines impose a shorter notification window than the statute does. Many now require notice within twenty-four to seventy-two hours.
Do the CPPA cybersecurity audit rules apply to my law firm?
Probably not directly, and that is the common misread. The rule applies to businesses that fall under the CCPA and then hit an additional threshold, such as processing personal information of 250,000 or more California consumers or households, or sensitive personal information of 50,000 or more. Most law firms will not reach those volumes on their own data. The exposure is indirect: your CCPA-covered clients are now being audited on their vendor security, and outside counsel is a vendor with copies of their most sensitive records. Expect the questionnaire even if you never file a certification.
Can our associates use ChatGPT or Copilot on client matters?
It depends entirely on the contractual terms behind the specific deployment, not on the brand name. Consumer tiers that may use inputs for training are inappropriate for client confidential information. Enterprise agreements with contractual commitments on retention, training, and subprocessors can be workable, subject to the verification duty. Before enabling any assistant that reads your document management system, fix matter-level permissions first, because the assistant inherits whatever access already exists and makes cross-matter disclosure faster, not less likely. Log the verification step for anything headed to a court.
How long should a law firm keep security logs?
Longer than thirty days, and a year is a defensible floor for identity, email, and document management systems. The reason is not technical. Mandiant found that BRICKSTORM intrusions averaged 393 days of dwell time, exceeding most victims' retention windows, which meant investigators could not determine how the attackers got in. Formal Opinion 483 requires a firm to evaluate what an intruder accessed. If the logs are gone, you cannot perform that evaluation, and telling a client you do not know is a materially worse conversation than telling them what happened.
Where to go from here
Cybersecurity for law firms is not a product problem. The 2026 attack chain that hit dozens of US firms ran entirely on software those firms already licensed, and the controls that would have stopped it were procedures nobody had written down. The ethics rules ask for reasonable efforts and evidence of them. Clients ask for artifacts. Insurers ask for proof. None of that requires a large budget. It requires someone whose job it is to own the answers.
If your firm is trying to figure out where to start, or you have a client questionnaire on your desk with a deadline attached, Purple Shield Security works with law firms on exactly this: risk assessments that produce evidence, incident response plans that name people, AI and cloud governance that fits how a practice actually runs, and vCISO services for firms that need the seat filled without a full-time hire. No product resale, no referral fees, no stack to sell you. Start a conversation and we will tell you plainly what your first ninety days should look like.
Sources
Threats to the Defense Industrial Base, BRICKSTORM dwell time, Google Cloud Threat Intelligence
Chinese Hackers Breached Law Firm Williams and Connolly via Zero-Day, SecurityWeek
ABA Formal Opinion 483, Lawyers' Obligations After an Electronic Data Breach or Cyberattack
ABA issues first ethics guidance on a lawyer's use of AI tools, Formal Opinion 512
California's CCPA Cybersecurity Audit Rule Takes Effect, Ropes and Gray, January 2026
Understanding CCPA Cybersecurity Audits: Thresholds and Timelines, Sheppard Mullin
The Hidden Cascade: Why Law Firm Breaches Destroy More than Data, Recorded Future



