StealthTech365

A law firm’s entire value proposition rests on a promise most clients never think to ask about directly: that what they tell their attorney stays between them. That promise used to be enforced with locked file cabinets and a receptionist who knew everyone by voice. It’s now enforced — or not — by firewall rules, email encryption settings, and whether a paralegal’s laptop still has last year’s security patches on it. Firms that haven’t made that translation yet are carrying more risk than their malpractice policy was priced for.

The Confidentiality Duty Didn’t Change, but the Threat Model Did

Model Rule 1.6 and its state equivalents require attorneys to make reasonable efforts to prevent unauthorized access to client information. That obligation predates email, but bar associations have made it unambiguous that it now covers electronic systems, and several state ethics opinions go further and expect firms to understand the security posture of the vendors and cloud platforms they use to store client files. “Reasonable efforts” is a moving target that gets redefined every time a major firm shows up in a breach headline, and the standard courts and disciplinary boards apply keeps climbing.

What makes this different from a typical small-business security conversation is the nature of what law firms hold. A single litigation matter can contain trade secrets, medical records, financial statements, merger terms, and personal information for dozens of people who never signed an engagement letter and never agreed to have their data sitting on a firm’s server. Attackers know this. A law firm isn’t just a target for its own sake — it’s frequently a stepping stone to a wealthier or better-defended client on the other side of a deal or dispute.

digital cyber security lock system highlighting data security encryption, cyber password

Why Law Firms Sit Higher on the Target List Than They Realize

Ransomware groups that specialize in double extortion — encrypting files and then threatening to publish them — have learned that law firms pay faster than almost any other vertical, precisely because the leaked material isn’t just embarrassing, it’s often privileged, and its exposure can taint an entire case or deal. Firms with fewer than fifty attorneys are disproportionately represented in these incidents, not because they’re bigger targets but because they’re softer ones: fewer dedicated IT resources, more reliance on a single generalist vendor, and security practices that haven’t kept pace with the sensitivity of what’s being stored.

CISA maintains ongoing guidance on the cybersecurity threat landscape that’s worth a firm’s general counsel or managing partner actually reading rather than delegating, because the attack patterns hitting professional services firms — credential phishing against partners with wire authority, business email compromise targeting trust accounts, and lateral movement through unsegmented networks — are well documented and largely preventable with the right architecture. A managed cybersecurity program built around these known patterns, rather than generic antivirus and a firewall appliance nobody has touched since installation, closes most of the gap.

When Your Clients Are Defense Contractors, Your Obligations Change Too

A growing number of firms, particularly those doing corporate, employment, or regulatory work for manufacturers and engineering firms in the defense supply chain, are discovering that their client relationships come with security obligations that have nothing to do with bar rules. If a firm receives, stores, or transmits Controlled Unclassified Information on behalf of a client performing under a DoD contract, the flow-down requirements in DFARS 252.204-7012 can reach the firm even though it never signed the prime contract. That clause requires safeguarding covered defense information consistent with NIST SP 800-171 and reporting cyber incidents within 72 hours of discovery — a timeline most firms’ current incident response process, if one exists at all, was never built to meet.

This is where general business cybersecurity advice stops being sufficient. A firm handling CUI for a defense contractor client needs to know what counts as CUI in the first place, and the National Archives’ CUI registry lays out the specific categories and marking requirements that apply. Firms that skip this step tend to discover the gap during opposing counsel’s discovery requests or, worse, during a security questionnaire from the client’s own compliance team asking for evidence of controls the firm assumed it didn’t need. Our compliance team walks firms through exactly this scoping exercise before it becomes a contract-ending problem.

Where Law Firm Networks Actually Fail

Having audited networks across engineering, manufacturing, and professional services clients, the failure patterns in law firm environments are strikingly consistent, and they rarely involve exotic attack techniques. The weaknesses are structural:

  • Shared logins on practice management software. Multiple attorneys and paralegals accessing the same case management account under one credential, which makes access logging meaningless and means a single compromised password exposes every active matter.
  • Unmanaged personal devices. Attorneys reviewing privileged documents on personal phones and laptops that have no encryption requirement, no remote wipe capability, and no separation from home network traffic.
  • Stale user accounts. Departed associates and contract attorneys whose credentials were never disabled, sitting active in the directory for months or years after they left the firm.
  • No network segmentation. Guest wifi, front-office systems, and the servers holding client files all sitting on the same flat network, so a compromised printer or a phishing click on the front desk computer has a direct path to the document management system.
  • Vendor sprawl with no oversight. E-discovery platforms, court filing services, transcription vendors, and cloud backup tools accumulated over years, each with its own access to client data and none of them vetted against a consistent security standard.

None of these require a six-figure remediation budget. They require someone whose job it is to notice them, which is where most solo and small-firm environments fall down — the managing partner is billing hours, not reviewing access logs, and the office manager handling IT tickets on the side has neither the time nor the mandate to run a real audit.

The remediation order matters too. Firms that try to fix everything at once tend to stall out on the biggest, most disruptive item — usually the case management platform migration — while the cheap, fast wins sit untouched. Disabling stale accounts and enforcing unique logins can happen in an afternoon. Segmenting the network and standardizing device management takes longer and benefits from being planned around a slower season rather than bolted on mid-trial.

Email Is Still the Front Door, and Encryption Alone Doesn’t Close It

Business email compromise remains the single most common entry point into law firm networks, and it’s rarely a sophisticated exploit — it’s a well-timed message impersonating opposing counsel, a title company, or a client, asking for a wire transfer detail to be “confirmed” or a document to be “resent.” Firms that have added encrypted email as a checkbox item often haven’t paired it with the controls that actually stop the attack: multi-factor authentication on every mailbox, conditional access rules that flag logins from unfamiliar countries, and staff training that treats a request to change wire instructions as an automatic phone-verification trigger, no exceptions.

Secure file sharing deserves the same scrutiny. Attaching a privileged document to an unencrypted email, or dropping it into a consumer-grade file link with no expiration and no access log, defeats the purpose of every other control the firm has in place. Our team recently laid out the specific configuration choices that matter for secure file sharing in hybrid work environments, and the same principles apply directly to how a firm should be moving discovery productions, closing documents, and client correspondence.

man signing agreement on company data security

Shadow IT Is a Bigger Problem in Law Firms Than Most Managing Partners Realize

Ask a firm’s IT provider how many applications touch client data, and you’ll get a number based on what’s been formally procured. Ask the associates what they actually use day to day, and the real number is usually two or three times higher — a free PDF editor one attorney found convenient, a personal Dropbox account used to move files between office and home, a transcription app downloaded to a phone without anyone in IT ever approving it. Each of these is a place client data can end up outside the firm’s control, outside its retention policy, and outside any audit trail a bar complaint or malpractice claim might require.

We’ve written in more depth about how shadow IT creates hidden security risk in professional environments, and the pattern in law firms tracks closely with what we see in engineering and manufacturing clients: the tools proliferate because the sanctioned alternative is slower or clunkier, not because anyone is trying to cut corners. The fix isn’t a memo threatening discipline — it’s making the approved tools genuinely easier to use than the workarounds, which is a design problem as much as a policy one.

The Case Management Platform You Trust Was Never Audited the Way You Assume

Most firms select their document and case management platform based on features attorneys like — search, integrations with billing software, mobile access — and take the vendor’s security claims at face value. That’s a reasonable starting assumption and a dangerous ending point. Cloud vendors vary enormously in how they handle encryption at rest, backup retention, breach notification timelines, and whether client data is used to train any embedded AI features the platform has quietly added in the last product update.

A cloud transformation engagement done properly starts with mapping exactly where client data lives — not just the primary case management system, but every integration, every backup copy, and every export a paralegal has ever generated for offline review. Firms are often surprised to learn that a five-year-old spreadsheet export sitting in a shared drive carries the same confidentiality exposure as the live record it was pulled from, with none of the platform’s access controls attached to it.

This matters even more once a firm’s own vendors start adding generative AI features to draft summaries, extract clauses, or suggest search results. Those features frequently run on infrastructure the firm never evaluated, and the vendor’s default settings sometimes permit client documents to be processed by a third-party model unless a firm administrator actively opts out. A single missed configuration checkbox during a routine software update can turn a compliant platform into one that’s silently sending privileged text outside the firm’s control, and most firms won’t find out until a client’s own security team asks the question directly.

Backup, Recovery, and Incident Response Timelines That Bar Rules and Contracts Both Expect

A ransomware incident that encrypts a firm’s document management system doesn’t just threaten confidentiality — it can freeze active litigation, blow discovery deadlines, and leave a firm unable to produce documents a court has ordered. Bar associations and courts have shown limited patience for “our systems were down” as an excuse when the firm had no tested recovery plan. A backup and data recovery strategy for a law firm needs to account for immutable, offline copies that ransomware can’t reach, and it needs a documented recovery time that someone has actually tested, not just assumed.

When a breach happens — and across enough firms, eventually one will — the clock starts immediately, and it runs on two separate tracks that most firms have never reconciled. State bar rules generally require notifying affected clients without unreasonable delay once a firm knows client confidences have been compromised. If any of that data touches a defense contractor’s CUI, the DFARS incident reporting clause imposes its own 72-hour reporting window to the Department of Defense, independent of whatever the bar rule requires. A firm without a written incident response plan — one that names who calls outside counsel, who notifies the cyber insurance carrier, and who drafts the client notification — will burn the first 24 hours of that window figuring out who’s in charge, which is exactly the time a competent response can’t afford to lose.

Building a Security Program Sized to the Firm You Actually Run

The instinct at a lot of smaller firms is to either do nothing until something goes wrong, or to try to bolt on enterprise-grade tooling that nobody has the staff to manage. Neither works. A right-sized program for a firm with fifteen to eighty attorneys generally includes a few consistent elements:

  • Multi-factor authentication enforced on every account with access to client data, no exceptions carved out for partners
  • A documented, tested backup and recovery process with offline or immutable copies
  • Endpoint detection on every device that touches the network, including attorney-owned devices used for work
  • Quarterly access reviews that catch stale accounts and shared logins before they become a liability
  • A written incident response plan with named roles, tested at least once a year
  • A vendor review process for any platform touching client data, including the AI features many case management tools have added without firms noticing

Firms that don’t have internal IT leadership capable of running this program on top of daily help desk demands tend to do better with a vCIO relationship — someone who owns the security roadmap, budget conversation, and vendor oversight as a standing responsibility rather than an annual afterthought.

A decade ago, onboarding a new corporate client meant a conflicts search and an engagement letter. Increasingly, it also means a multi-page security questionnaire from the client’s general counsel or procurement office, asking the firm to attest to encryption standards, access controls, breach notification timelines, and sometimes whether the firm has ever undergone a formal security assessment. Firms that treat these as boilerplate to be filled out quickly and forgotten are missing that the answers are frequently contractual representations — meaning a firm that overstates its controls to win the engagement is creating liability that has nothing to do with the underlying legal work.

This shows up most sharply with clients performing under federal contracts, where even routine engagements can touch what the FAR defines as Federal Contract Information. FAR 52.204-21 sets out fifteen basic safeguarding requirements that apply broadly to any contractor or downstream party handling that information, and a firm that’s never mapped its systems against that baseline is guessing when it signs the attestation. For firms whose clients are further along the CMMC pipeline and asking outside counsel to demonstrate third-party validation, the CyberAB marketplace is the authoritative place to confirm whether an assessor or consultant a firm is relying on for that validation actually holds the credential it claims to.

Treating these questionnaires as a recurring compliance function, rather than a one-off form each new business development contact fills out under deadline pressure, is what separates firms that win and keep sensitive corporate work from firms that lose it after the first honest answer to a hard question.

Choosing an IT Partner Who Understands What “Privileged” Actually Means

Not every managed service provider is built for this. A generic IT vendor optimized for retail or hospitality clients treats a law firm’s document server the same way it treats a restaurant’s point-of-sale system, and that mismatch shows up in weak access controls, generic ticket handling that doesn’t account for privilege concerns, and no real understanding of what a bar complaint or a discovery dispute actually requires from IT. Firms with existing internal staff who need specialized oversight without a full outsourcing commitment often start with co-managed IT, layering security expertise and compliance support on top of the team already in place rather than replacing it.

Firms in Massachusetts working under both bar rules and, increasingly, defense-adjacent client requirements have specific regional considerations, and our Boston team works with several firms navigating exactly that overlap. The same is true on the Gulf Coast, where our Tampa and Sarasota teams support firms serving Florida’s growing manufacturing and engineering client base, many of whom are now flowing CMMC-adjacent requirements down to outside counsel without much warning.

Tracking whether any of this is actually working matters as much as building it. Our piece on cybersecurity metrics worth reporting to leadership applies directly to a managing partner trying to answer the only question that matters to a bar disciplinary board or a client’s general counsel: not how many threats were blocked, but how quickly the firm would detect and contain a real incident if one got through.

business meeting - manager discussing work with his colleagues - executive guide to CMMC

Conclusion

Client confidentiality was never just an ethical abstraction — it’s the operational core of what a law firm sells, and the systems protecting it deserve the same rigor a firm applies to conflicts checks and trust accounting. Bar association standards are only going to keep tightening, and firms serving clients in regulated or defense-adjacent industries are increasingly finding those standards layered on top of contractual obligations they never negotiated for directly. Our Legal industry team works specifically with firms navigating both sides of that equation, and our Managed IT Services and Compliance practices exist to close the gap between what a firm assumes is protected and what actually is. You can learn more about our approach on our About page or browse further reading on our Insights hub.

If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.

Scroll to Top