All sectors

Information security for law firms

In a law firm the information is the work itself. A leaked client file is not merely an operational problem: it is a breach of attorney–client privilege, which is a professional duty and not only a technical requirement. Security in a firm is therefore measured first by the ability to show that information was protected, not only by whether the systems stayed up.

What is at stake

  • Client files and transaction documents
  • Partner and fee-earner mailboxes
  • Trust accounts and transfer instructions
  • Case management systems and document servers

The incidents that matter here

  • Mailbox takeover redirecting trust funds mid-transaction (Business Email Compromise)
  • Ransomware on the document server, which halts the firm rather than merely encrypting files
  • Targeted phishing at a named fee-earner, timed to a transaction already in the open
  • Third-party access through an outside supplier or case management platform

Obligations that shape the work

Lawyers are bound by a professional duty of confidentiality to their clients, and at the same time by Israeli privacy law and its Amendment 13, which tightened information-security and breach-reporting duties. In practice this means an incident at a firm requires not only technical handling but a record that can be produced — what was exposed, to whom, and when.

This is general information, not legal or regulatory advice. The obligations that apply to a particular organisation depend on its activity and its regulator.

How we approach it

  • Monitoring focused on identities and mailboxes, where almost every incident in this sector begins
  • Incident response that preserves evidence from the first minute, so what was exposed can be stated with certainty
  • A risk assessment that maps where client files actually live and who reaches them
  • Training built around payment-diversion fraud rather than generic awareness content

// next step

Not sure what the right next step is?

Use the short assessment to identify the areas worth reviewing, or tell us what changed and we will start from there.

Do not send passwords, credentials, API keys, logs or sensitive incident material through the web form.