Law firms are high-value ransomware targets — client files, settlement documents, and medical records have significant value on the dark web. The ABA's 2023 Legal Technology Survey found that 29% of law firms reported a security breach, yet most small firms still operate without basic technical safeguards. This checklist covers the gaps most commonly exploited, with documentation guidance for each.
All laptops and workstations have full-disk encryption enabledABA Model Rule 1.6 requires reasonable measures to protect client information. An unencrypted laptop with case files is a bar complaint waiting to happen. BitLocker (Windows) or FileVault (Mac) must be enabled and verified.Most common gap
Client documents shared with clients via encrypted portal — not email attachmentsUnencrypted email is not considered reasonable protection for sensitive case documents. Use a client portal, ShareFile, or encrypted email service for sensitive materials.
Encryption status verified quarterly — not just assumedBitLocker can be silently disabled by a Windows update. Run a status check and document the results.
Proactive hardware monitoring on servers and critical workstationsDrive failures give warning signs before they fail completely — monitoring tools catch them before they become emergencies. A server failure the morning of a mediation is preventable.High impact
Verified daily backup with off-site or cloud copyBackup must be verified — not just running. Test a restore quarterly and document the result. On-site-only backups are destroyed in the same event as your primary system.
Recovery time objective documented — how long can the firm operate without systems?Most small firms can tolerate 4 hours of downtime. Document your tolerance and ensure your backup/recovery solution can meet it.
MFA enabled on email, practice management software, and document storageEmail account takeover is the most common entry point for law firm breaches. MFA on email alone prevents the majority of attacks. Clio, MyCase, and most practice management tools support MFA — enable it.Most common gap
Departed staff access revoked same dayFormer employees, paralegals, and contractors with active access to case management systems is a common gap. Document your offboarding checklist and verify access is removed.
Workstations lock automatically after 10 minutes of inactivityAn unlocked workstation in a conference room or common area is a breach waiting to happen. Configure automatic lock via Group Policy or system settings.
Secure remote access to case files from court, depositions, and client sitesIf attorneys access case files from personal devices or public Wi-Fi without a secure connection, that traffic is unprotected. Use a properly configured cloud solution or secure remote desktop — not an ad-hoc file share.
Personal devices accessing firm systems meet minimum security standardsIf attorneys use personal laptops or phones for work, those devices need MFA, encryption, and current OS patches — or they need to be excluded from firm systems.
Written IT security policy exists covering data handling and incident responseFlorida Bar Ethics Opinion 12-3 addresses confidentiality obligations in the context of technology. A written policy demonstrates reasonable measures. It doesn't need to be long — a 2-page document is sufficient.
Staff know what to do if they click a phishing link or suspect a breachThe most important breach response step is speed. Every staff member should know: stop, don't try to fix it, call IT immediately.
ABA ethics note: Model Rule 1.6(c) requires lawyers to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." The ABA has clarified that "reasonable efforts" includes technical safeguards proportional to the sensitivity of the data. Client medical records, settlement negotiations, and financial information are high-sensitivity data requiring stronger controls than general correspondence.
Date completed
___________