The 12 Cybersecurity Protections Every Law Firm Should Have in 2026
A 25–50 employee law firm should have at least 12 layers of cybersecurity protection: phishing-resistant multi-factor authentication, managed endpoint detection, email security, Microsoft 365 hardening, device encryption, restricted administrator access, continuous vulnerability management, tested backups, security awareness training, vendor controls, an incident response plan, and 24/7 security monitoring.
Installing antivirus software and turning on basic multi-factor authentication is no longer enough. Law firms store confidential communications, financial records, personally identifiable information, case strategy, discovery materials, contracts, and credentials for courts and legal applications. One compromised account can expose several systems at once.
The goal is not to purchase the largest possible collection of security products. It is to build a coordinated security program that can prevent attacks, detect suspicious activity, contain incidents, and restore operations without unnecessarily slowing down attorneys and staff.
1. Require Strong, Phishing-Resistant Multi-Factor Authentication
Multi-factor authentication, or MFA, requires a user to provide more than a password before accessing an account. It should be required for every attorney, employee, administrator, contractor, and outside user who can access firm systems.
At a minimum, enable MFA for:
- Microsoft 365 and firm email
- Practice-management and document-management platforms
- Remote-access services
- Cloud file storage
- Accounting and billing applications
- Legal research platforms
- Backup administration portals
- Network and firewall administration
- Domain registration and website management
- Any application containing client or financial information
Not all MFA methods provide equal protection. Text messages and approval prompts are generally better than using a password alone, but they can still be defeated through social engineering, fraudulent account recovery, SIM swapping, or repeated approval requests.
Firms should move higher-risk accounts toward phishing-resistant authentication methods such as passkeys, hardware security keys, certificate-based authentication, or properly configured Windows Hello for Business. Start with partners, administrators, finance personnel, and anyone who can access large volumes of client information.
Warning signs that MFA is not properly managed
- Some employees are exempt because MFA is considered inconvenient.
- Shared accounts are still in use.
- Former employees remain registered for authentication.
- Users approve login prompts without verifying them.
- Administrators use the same accounts for email and system administration.
- No one reviews sign-in logs or unusual authentication activity.
911 IT can help law firms strengthen identity security as part of a broader managed cybersecurity strategy.
2. Protect Every Computer With Managed Endpoint Detection and Response
Traditional antivirus primarily looks for known malicious files. Modern attacks may use legitimate administrative tools, stolen credentials, scripts, cloud services, and built-in operating-system features that do not look like conventional malware.
Endpoint detection and response, commonly called EDR, continuously monitors computers and servers for suspicious behavior. A managed service can investigate alerts, isolate a compromised device, block malicious activity, and help determine how far an attacker may have traveled.
Every firm-managed device should have:
- Endpoint detection and response
- Automatic operating-system updates
- Application patching
- Disk encryption
- Screen-lock policies
- Managed firewall settings
- Restricted local administrator privileges
- Remote management and support
- A documented owner and assigned user
This includes desktops, laptops, servers, and computers used by remote attorneys. A device should not be considered protected simply because it is located outside the office or used by a senior partner.
Do not overlook personal devices
When personal devices are allowed to access firm email or files, the firm needs a written bring-your-own-device policy. At minimum, access should be conditioned on appropriate authentication, encryption, screen locking, software updates, and the ability to remove firm data when an employee leaves.
A personal laptop that cannot be monitored, updated, or remotely secured should not have unrestricted access to confidential client information.
3. Secure Email Against Phishing, Impersonation, and Payment Fraud
Email remains one of the easiest ways for an attacker to reach a law firm. A convincing message may impersonate a partner, client, court, vendor, opposing counsel, or financial institution. It may request a password reset, contain a fraudulent document-sharing link, or change payment instructions.
A law firm’s email-security program should include:
- Advanced spam, malware, and phishing filtering
- Attachment and link inspection
- Impersonation and lookalike-domain detection
- External sender identification
- Domain protections using SPF, DKIM, and DMARC
- Restrictions on automatic email forwarding
- Alerts for unusual inbox rules
- Monitoring for suspicious sign-ins
- A separate verification process for financial requests
Use a two-channel verification rule
Any request to change wiring instructions, payment information, payroll details, direct deposit, or account ownership should be verified through a second communication channel. Do not use the phone number included in the suspicious message. Call a previously verified number or speak directly with the person involved.
This process should apply even when the request appears to come from a partner or long-standing client. Attackers rely on urgency, authority, confidentiality, and familiarity to persuade employees to bypass normal procedures.
4. Harden Microsoft 365 Instead of Relying on Default Settings
Microsoft 365 can support secure legal work, but purchasing licenses does not automatically create a secure environment. Identity policies, administrative roles, sharing permissions, retention settings, audit logs, and application access all require deliberate configuration.
A law firm should review at least these Microsoft 365 controls:
- MFA for all users
- Phishing-resistant authentication for privileged accounts
- Conditional Access policies
- Separate administrator accounts
- Blocking of legacy authentication
- Restrictions on external file sharing
- SharePoint and OneDrive permission reviews
- Mailbox forwarding and inbox-rule monitoring
- Mobile-device and application controls
- Audit logging and alerting
- Data retention and deletion policies
- Recovery procedures for deleted or altered cloud data
Conditional Access can apply different requirements based on factors such as the user, device, location, application, and level of risk. For example, a firm might require a managed device and stronger authentication before allowing access to sensitive files.
Review 911 IT’s cloud services for help managing Microsoft 365 security, collaboration, remote access, and cloud data protection.
5. Encrypt Laptops, Portable Devices, and Sensitive Data
Encryption helps protect information when a device is lost, stolen, or accessed without authorization. Every firm-owned laptop should use full-disk encryption, and recovery keys should be securely stored and managed.
Encryption should also be considered for:
- Portable storage devices
- Backups
- Mobile devices
- Confidential email messages
- Files transferred to clients or third parties
- Cloud storage containing sensitive information
Encryption is only one layer. A stolen laptop may still create risk if it was left unlocked, used weak authentication, contained active sessions, or allowed access to cloud platforms without additional verification.
A 911 IT client specifically valued knowing that information on a stolen computer would be unusable to the thief. That is the practical result a law firm should expect from correctly implemented device protection.
6. Remove Unnecessary Administrator Access
Administrator privileges allow a user or program to install software, change security settings, access protected areas, and alter the computer. These capabilities are useful for IT management but dangerous for everyday work.
Attorneys and employees should generally use standard accounts for email, document work, legal research, billing, and web browsing. Administrative access should be limited, separately authenticated, monitored, and used only when necessary.
Law firms should also:
- Create separate accounts for administrative work.
- Remove administrator rights from ordinary users.
- Disable inactive and former-employee accounts promptly.
- Avoid shared administrative credentials.
- Use unique credentials for vendors and contractors.
- Review privileged access at least quarterly.
- Protect backup and security tools with separate credentials.
This limits the amount of damage that can occur when a password is stolen or an employee accidentally launches malicious software.
7. Patch Vulnerabilities and Maintain an Accurate Technology Inventory
A firm cannot protect systems it does not know it owns. Maintain an inventory of computers, servers, network devices, cloud platforms, software, vendors, domains, and administrative accounts.
Each item should have:
- An assigned owner
- A business purpose
- A support or renewal date
- A patching responsibility
- A replacement or retirement plan
- A record of who can access it
Security updates should be prioritized according to risk. Internet-facing systems, actively exploited vulnerabilities, remote-access tools, browsers, operating systems, and security products generally require faster action than low-risk internal applications.
Set measurable patching targets
Instead of saying that systems are “updated regularly,” establish written timeframes. For example, a firm might require critical, actively exploited vulnerabilities to be addressed within a few days and other high-risk updates within a defined number of weeks.
The exact schedule should reflect the firm’s risk, application compatibility, and operational requirements. Exceptions should be documented, reviewed, and supported by temporary safeguards.
8. Maintain Isolated Backups and Test Real Restorations
A backup report that says “successful” does not prove that a law firm can recover. Backups may be incomplete, corrupted, improperly configured, accessible to an attacker, or too slow to restore within the firm’s required timeframe.
A strong backup strategy should include:
- Multiple copies of important information
- At least one isolated or immutable copy
- Encryption in storage and during transfer
- Separate administrative credentials
- Monitoring for missed or failed backups
- Defined retention periods
- Microsoft 365 data protection where needed
- Regular restoration testing
- A documented recovery sequence
Define two recovery numbers
Recovery Time Objective is the maximum acceptable period a system can be unavailable. Recovery Point Objective is the maximum amount of recently created or changed information the firm can afford to lose.
For example, a firm may decide that email can be unavailable for four hours but that a matter-management system must be restored within two hours. It may tolerate losing no more than 30 minutes of recent work in one system and four hours in another.
Those requirements determine the backup frequency, infrastructure, redundancy, and recovery process the firm needs.
Learn how business continuity and disaster recovery services can protect legal operations from ransomware, equipment failure, human error, and other disruptions.
9. Train Employees With Short, Recurring Security Exercises
Annual security training alone is unlikely to change behavior throughout the year. Law firms should use short, recurring education supported by practical exercises and clear reporting procedures.
Training should cover:
- Phishing and credential theft
- Business email compromise
- Fraudulent payment requests
- Malicious document-sharing links
- Password-manager use
- Safe handling of client information
- Remote-work security
- Lost or stolen devices
- Suspicious login prompts
- Use of public and consumer AI tools
- How to report a suspected incident immediately
Run simulated phishing exercises periodically, but do not use them merely to embarrass employees or generate a compliance report. Use the results to identify departments, workflows, and attack themes that require additional protection.
Make reporting easier than hiding a mistake
Employees should know exactly how to report suspicious activity. The firm should reinforce that rapid reporting is more important than avoiding embarrassment.
An employee who clicks a suspicious link and reports it within two minutes gives the response team a much better opportunity to contain the event than someone who waits two days because they fear being blamed.
10. Control Vendors, Applications, and Outside Access
Law firms depend on cloud applications, legal software vendors, e-discovery platforms, payment providers, consultants, copy and scanning systems, telecommunications providers, and other third parties.
Each relationship can introduce risk. Before giving a vendor access to systems or client information, determine:
- What information the vendor can access
- How access is authenticated
- Whether vendor access is temporary or ongoing
- How the vendor protects and backs up information
- Whether subcontractors are involved
- How security incidents are reported
- How information is returned or deleted when the relationship ends
- Who removes vendor access
Vendor accounts should be unique, limited to the minimum necessary access, protected by MFA, and disabled when no longer required.
The firm should also review new software before employees begin using it. Free file-sharing, transcription, automation, and generative AI tools may collect or retain information in ways that conflict with client expectations or firm policy.
11. Create and Practice an Incident Response Plan
A security incident is the wrong time to decide who has authority, which systems are critical, how clients will be notified, or where backup credentials are stored.
A written incident response plan should identify:
- Who leads the response
- Who has decision-making authority
- How employees report suspected incidents
- How compromised accounts and devices are isolated
- How evidence and logs are preserved
- How outside IT, legal, insurance, and forensic resources are contacted
- How operational priorities are established
- How internal and external communication is approved
- How recovery decisions are made
- How lessons learned become security improvements
The plan should account for several scenarios, including ransomware, stolen credentials, fraudulent payments, lost devices, unauthorized file sharing, email compromise, cloud outages, and accidental data deletion.
Run a tabletop exercise at least annually
A tabletop exercise walks decision-makers through a realistic scenario without disrupting production systems. For example:
A paralegal reports that files have been renamed, an attorney cannot access a matter folder, and the firm receives an email demanding payment. The managing partner, administrator, IT provider, insurance contact, and legal counsel then work through the actions they would take during the first 15 minutes, first hour, and first day.
The exercise should expose missing phone numbers, unclear authority, inaccessible documentation, recovery assumptions, and communication gaps before a real emergency occurs.
12. Monitor Security Around the Clock
Cyber incidents do not follow office hours. Automated security tools may generate alerts at night, on weekends, or while attorneys are traveling. An alert has limited value when no one is responsible for reviewing it and taking action.
Round-the-clock monitoring should cover the systems most likely to reveal or contain an attack, including:
- Endpoint security alerts
- Microsoft 365 and identity activity
- Suspicious logins
- Firewall and network events
- Backup failures
- Critical vulnerabilities
- Administrative changes
Ask who receives alerts, how they are prioritized, what actions can be taken immediately, and when firm leadership will be contacted. The answers should be documented rather than assumed.
911 IT provides managed IT services with live 24/7 support, proactive monitoring, cybersecurity, and strategic technology management.
Use the NIST Six-Function Framework to Organize Law Firm Security
The NIST Cybersecurity Framework 2.0 organizes cybersecurity risk management into six functions. Law firms can use these functions to verify that their security program is balanced.
Govern
Assign responsibility, establish policies, identify legal and contractual expectations, evaluate third-party risk, and set measurable security priorities.
Identify
Inventory technology and information, understand critical workflows, assess vulnerabilities, and determine the business impact of system failures.
Protect
Implement identity controls, encryption, endpoint security, employee education, secure configurations, patching, and data safeguards.
Detect
Monitor systems for suspicious activity, investigate alerts, review sign-in activity, and identify unauthorized changes.
Respond
Contain incidents, preserve evidence, coordinate decision-makers, communicate appropriately, and execute the incident response plan.
Recover
Restore systems and information, verify integrity, return to normal operations, and improve controls based on lessons learned.
A firm that invests only in protection may still be unprepared to detect, respond to, or recover from an incident. The framework helps leadership examine the entire lifecycle.
A Practical Cybersecurity Example for a 35-Employee Law Firm
Consider a Salt Lake City law firm with 35 employees, Microsoft 365, a cloud-based practice-management platform, remote attorneys, local file storage, and several outside vendors.
A practical security program for this firm might include:
- MFA for all 35 employees
- Phishing-resistant authentication for partners and administrators
- Managed endpoint protection for every computer and server
- Conditional Access for Microsoft 365
- Encrypted firm laptops
- Email impersonation and malicious-link protection
- Monthly security training with periodic phishing exercises
- Continuous patching and vulnerability management
- Restricted administrative privileges
- Secure cloud and local backups
- Quarterly restoration testing
- 24/7 monitoring and incident response
- An annual tabletop exercise
- Quarterly reviews of accounts, risks, and vendor access
The firm does not need to make every employee a cybersecurity expert. It needs to establish safe defaults, make secure behavior straightforward, monitor for failures, and give employees a fast way to obtain help.
What Law Firm Clients Say Matters Most
Customer feedback collected by 911 IT shows that businesses value security most when it produces an operational result: fewer interruptions, immediate access to knowledgeable help, confidence that information is protected, and the ability to continue working.
One legal-services owner described relying on 911 IT to support legal research databases, electronic court filing, email, downloads, and other essential attorney workflows. She emphasized the value of reaching a live technician, receiving patient explanations, and having problems handled remotely.
A partner at another legal-industry client described the benefit of having IT, phone, and hosting services managed by one team that understands the company’s setup. Remote diagnosis reduced downtime and provided peace of mind.
These experiences illustrate an important point: cybersecurity should not exist separately from daily IT support. The same team protecting identities, devices, email, applications, and backups should understand how attorneys actually work and how quickly problems must be resolved.
Law Firm Cybersecurity Checklist for 2026
Use this checklist during your next technology review:
- Is MFA enabled for every employee, administrator, vendor, and remote user?
- Are privileged accounts using phishing-resistant authentication?
- Does every computer have managed endpoint detection and response?
- Are laptops encrypted with securely stored recovery keys?
- Are employees restricted from using administrator privileges for everyday work?
- Are Microsoft 365 Conditional Access policies configured and reviewed?
- Are external sharing and mailbox forwarding controlled?
- Are email impersonation, malicious links, and fraudulent payment requests addressed?
- Is there an accurate inventory of devices, applications, vendors, and accounts?
- Are critical vulnerabilities remediated within defined timeframes?
- Are backups isolated from production credentials?
- Has the firm completed a real restoration test within the last quarter?
- Do employees receive recurring security training?
- Is there a documented process for verifying payment changes?
- Are vendor and former-employee accounts removed promptly?
- Does the firm have a written incident response plan?
- Has leadership completed a tabletop exercise within the last year?
- Are security alerts monitored 24/7?
- Does leadership receive a quarterly cybersecurity report?
- Can the firm demonstrate its controls to clients and cyber insurers?
Any answer of “no,” “probably,” or “we assume so” should become a documented action item with an owner and deadline.
Frequently Asked Questions
Is antivirus enough for a law firm?
No. Antivirus is only one component of protection. A law firm also needs identity security, email protection, endpoint detection, encryption, secure cloud configuration, vulnerability management, tested backups, employee education, incident response, and active monitoring.
Does every law firm need 24/7 security monitoring?
A firm handling confidential client information should know who will investigate serious alerts outside normal business hours. The level of monitoring may vary, but critical identity, endpoint, network, and backup alerts should not wait unattended until the next business day.
Should every employee use MFA?
Yes. Attackers may begin with any compromised account and use it to impersonate employees, access shared information, or reach more valuable systems. Stronger phishing-resistant authentication should be prioritized for administrators, partners, finance personnel, and other high-risk users.
Does Microsoft 365 back up all law firm data?
Microsoft provides availability, retention, and recovery capabilities, but firms should evaluate whether those features meet their specific retention, deletion, ransomware, and restoration requirements. Depending on the environment, an additional backup service may be appropriate.
How often should backups be tested?
Critical systems should be restoration-tested on a recurring schedule, often quarterly or more frequently when the recovery requirement is strict. Testing should confirm that information can be restored within the expected timeframe—not merely that a backup job completed.
How often should employees receive cybersecurity training?
Training should occur during onboarding and continue throughout the year. Short monthly or quarterly education, phishing simulations, and timely reminders are generally more useful than relying on a single annual session.
How often should a law firm review cybersecurity?
Leadership should review major risks, unresolved vulnerabilities, backup testing, account changes, incidents, and security projects at least quarterly. Policies and the full security program should also be reviewed annually and after major changes or incidents.
Can strong security make attorneys less productive?
Poorly planned security can create unnecessary friction. Properly designed controls use risk-based access, single sign-on, managed devices, passwordless authentication, clear procedures, and responsive support to protect information while preserving efficient legal workflows.
Build a Law Firm Cybersecurity Plan Based on Evidence
A strong law firm cybersecurity program is not defined by a product list. It is defined by whether the firm can answer five questions with evidence:
- Who is responsible for cybersecurity risk?
- Which identities, systems, and information are being protected?
- How will suspicious activity be detected and contained?
- How quickly can critical legal operations be restored?
- When were those protections last tested?
911 IT helps Utah law firms combine managed IT support, Microsoft cloud expertise, proactive cybersecurity, business continuity, local on-site assistance, and access to live technicians around the clock.
Explore our cybersecurity services, review our guide to six questions law firms should ask their IT provider every quarter, or schedule a 10-minute discovery call to identify the highest-priority risks in your firm.
