What Attackers See When They Look at Your Law Firm

Your clients trusted you with their most sensitive secrets. Are you protecting them? 40% of US law firms experienced a security breach in 2024. The average cost of breaches for professional-services firms has reached $5.08 million. And nearly two-thirds of firms don’t know what they’re legally required to do after one happens.

Every law firm I speak with handles data that someone, somewhere, desperately wants: Social Security numbers, medical records, M&A strategy, wire transfer instructions, settlement figures, etc. Privileged communications that, if exposed, could hand a regulator exactly what they were looking for or cost a client their competitive position before a deal closes.

In the first half of 2024, 21 US law firms reported data breaches to regulators, nearly matching the total reports filed for all of 2023 (imageOne, 2024). Attackers haven’t suddenly discovered that law firms exist. What’s changed is that the tools to reach your systems have become cheaper, faster, and increasingly automated. For mid-size US firms, that creates an uncomfortable situation: high-value data, with security spending that doesn’t match the value of what’s being protected.

Here’s your quick read brief:

  • 40% of US law firms reported a breach in either 2023 or 2024, with 56% of those losing sensitive client data; yet only 34% have an incident response plan in place (Arctic Wolf, 2024; ABA, 2023).
  • The average breach cost for professional services firms is $5.08 million. 40% of clients would leave after a breach. 37% would pay a premium for a firm with stronger security (IBM/Clio, 2024; Integris, 2025).
  • A cybersecurity breach isn’t just an IT problem: under ABA Model Rule 1.6(c) and Formal Opinion 483, it’s a professional responsibility issue that can trigger malpractice claims and bar disciplinary action.

Your Clients’ Data Is Worth Targeting: Your Security Budget Doesn’t Always Reflect That

A 40-attorney, medical-malpractice practice holds data worth more on criminal markets than most financial accounts. You know what makes a mid-size law firm attractive to attackers? Not its size. That 40-attorney practice may hold health records for thousands of patients, each worth considerably more on criminal markets than a compromised credit card number. An IP firm stores trade secrets whose exposure could cost clients tens of millions in competitive advantage. A transactional practice processes wire transfers regularly, every one of which is a social engineering target. High-value data with constrained security resources: that combination is what the actual threat model looks like, and law firms fit it well.

The notion that only large firms get targeted doesn’t hold up. Taft Stettinius & Hollister, ranked 83rd on the Am Law 100, experienced a ransomware attack that compromised names, addresses, and Social Security numbers of approximately 6,000 individuals (imageOne, 2024). 56% of firms that experienced a breach in the past year lost sensitive client information, not operational data, but the confidential material clients shared, expecting it to stay that way (Arctic Wolf, 2024).

The financial impact at a boutique practice may be smaller in absolute terms than a multimillion-dollar enterprise breach, but relative to cash reserves, it can be just as threatening to the firm’s ability to continue operating. In these cases, the scale of incident doesn’t equal the scale of the impact.

This Isn’t an IT Problem; It’s a Professional-Responsibility Problem.

Most attorneys know their ethical obligation to protect client confidentiality. Far fewer know how specifically that obligation has been defined, or what’s now required the moment a breach happens. My concern here isn’t regulatory exposure in the abstract. It’s the preparation gap that makes the exposure far more likely than it needs to be.

ABA Formal Opinion 483 lays out a specific post-breach sequence: stop the incident, restore systems, investigate its scope, notify affected clients, and preserve evidence for potential proceedings. 65% of surveyed law firms are unfamiliar with those specific obligations (Programs.com, 2025). That’s a striking figure for a profession that professionally manages compliance risk on behalf of others.

Bryan Cave Leighton Paisner agreed to a $750,000 settlement in 2024 after a breach exposed personal data, including Social Security numbers, of more than 51,000 individuals connected to a corporate client (imageOne, 2024). That figure came on top of incident response costs, remediation expenses, and the client conversations that don’t appear in a settlement number. The malpractice dimension follows naturally: a client whose settlement strategy or M&A position was exposed during a breach has a straightforward argument that the firm failed its duty of care.

Here’s the preparation gap I find most telling: 80% of US law firms carry a technology insurance policy, but only 34% have a documented incident response plan (ABA, 2023). Insurance pays after: a response plan acts during. They don’t substitute for each other.

For firms handling health records in medical malpractice, personal injury, or healthcare regulation work, HIPAA business-associate obligations may apply on top of ABA requirements. The potential regulatory overlap rarely gets managed with the same rigor firms apply to litigation risk.

“Reasonable Efforts” Is a Standard Worth Meeting Before You Need It

You don’t need a CISO or a seven-figure security budget. You need four things, done seriously and kept current. My advice to managing partners at 20- to 200-attorney firms is usually the same starting point. Not enterprise infrastructure: a structured baseline with someone accountable for keeping it current.

1. Perform an access audit

Who holds credentials to your document management system, case management platform, and email environment? Former associates, paralegals, and IT vendors with legacy access are the most common discovery. Most firms find credentials they didn’t know existed the first time they look properly.

2. Verify backups

Not whether backups are running, but whether they actually restore. The gap between a backup that completes and one that works under real pressure is exactly what turns a recoverable incident into a catastrophic one. Test restoration of actual files from your most critical systems.

3. Review your incident response plan

One page that your attorneys can follow without IT present is more valuable than a detailed document on a SharePoint no one can locate. It should list who calls whom, in what order, within what timeframe, and where your outside counsel, forensics vendor, and insurance contacts are.

4. Conduct attorney training

A trained attorney who knows to verify a credential reset request through a second channel is a more effective control than most technical tools. This type of training will stop many of the most common types of hacks.

In addition, a co-managed IT arrangement that handles the ongoing technical layer, monitoring, patching, backup verification, and threat detection can stop many of the rest—while your team focuses on your practice.

The ethics compliance piece doesn’t disappear; it gets managed properly alongside the technology instead of deferred until something forces it.

Security Built in Advance Is a Different Conversation Than Security Built in Response

37% of legal clients say they’d pay a premium for a firm with stronger cybersecurity practices. 40% say they’d leave after a breach (Integris, 2025). Those numbers represent a shift in how clients are evaluating firms before signing engagement letters, and it’s only moving in one direction.

The ethics obligations and the market pressures are now pointing at exactly the same investment. Firms that move on this first will have a competitive story to tell. Firms that move after an incident will have a different conversation with their clients entirely.

Get a Second Opinion on Your Security

If you’d like a second opinion on where your firm’s security setup stands, Sagacent Technologies is glad to have that conversation. Start with one question: can your firm describe, right now, what it would do in the first 24 hours of a confirmed breach? If you don’t have the answer on the tip of your tongue, find out how we can help you get there.

Glossary of Terms

  • ABA Formal Opinion 483: The ABA’s specific guidance on what attorneys are legally required to do after a data breach. Think of it as the rulebook your state bar will consult if an affected client files a complaint. It requires stopping the breach, notifying clients, and preserving evidence, in that order, on a documented timeline.
  • Double Extortion Ransomware: A ransomware attack where criminals steal your data before encrypting it, then threaten to publish it unless you pay, on top of the standard ransom for restoring access. For law firms, this means client confidentiality is at risk even if you have working backups, because the threat isn’t loss of access. It’s public exposure of privileged communications or client health records.
  • Incident Response Plan (IRP): Your firm’s documented playbook for what happens the moment a breach is detected. Who calls whom, what gets preserved, who gets notified, and in what order. Only 34% of US law firms have one (ABA, 2023), despite 80% carrying a technology insurance policy that assumes one exists.