Law Firm Cybersecurity Checklist: 10 Practical Steps for 2026

A plain-language cybersecurity checklist for law firms in 2026 - MFA, encryption, email risk, vendor review, and a written security plan.

March 11, 2025
Written By:
Justin Neiman
Glowing shield protecting a law office laptop and client folders from phishing emails

Law firms hold exactly what attackers want: identity documents, financial records, settlement details, and privileged communications - all concentrated in small offices that rarely have an IT department. You don't need an enterprise security budget to be a hard target. You need a short list of habits, applied consistently. Here is the 2026 version of that list.

1. Turn on multi-factor authentication everywhere

If you do only one thing on this page, do this. MFA on email, your practice-management system, your file-sharing tools, and your bank blocks the vast majority of account-takeover attacks. Prefer an authenticator app over SMS codes where you can.

2. Get client files out of email

Email is where law-firm breaches start: it's unencrypted at rest in two places you don't control (your sent folder and the client's inbox), and attachments live there forever. Move client document exchange to a secure portal with access controls and an audit trail, and make "never as an email attachment" a firm policy.

3. Use a password manager - firm-wide

Reused passwords are how one breached shopping site becomes your breached case files. A password manager makes unique passwords the path of least resistance. Pair it with MFA and most credential attacks stop working.

4. Encrypt every device that leaves the office

Laptops and phones get lost and stolen more often than servers get hacked. Full-disk encryption (BitLocker on Windows, FileVault on Mac) plus a device PIN turns a stolen laptop from a reportable breach into an inconvenience.

5. Train for today's phishing, not 2015's

Modern phishing is clean, well-written, and increasingly AI-generated - fake counsel requests, spoofed payoff instructions, "updated wire details." Train staff on one rule above all: any request to move money or change payment details gets verified by phone at a number you already have. Run this refresher twice a year.

6. Patch and update automatically

Most exploited vulnerabilities are old ones with fixes available. Turn on automatic updates for operating systems, browsers, and practice software, and retire anything the vendor no longer supports.

7. Back up like you'll be ransomed

Assume ransomware will eventually reach one of your machines. Keep an automatic, encrypted, versioned backup that lives somewhere your office network can't overwrite - and actually test a restore once a quarter.

8. Control who can see what

Not everyone at the firm needs every matter. Use per-matter or per-client access controls, review them when staff change roles, and cut access the same day someone leaves. An audit log that shows who accessed which file, when, answers the question every client asks after an incident.

9. Review your vendors once a year

Your security now includes your e-signature tool, your cloud storage, your IT contractor, and your copier company. Once a year, list every vendor that touches client data and confirm what they store, whether it's encrypted, and how you'd get your data out.

10. Write it down: you need a written security plan

Every step above belongs in one short document: what data you hold, what could go wrong, what safeguards you run, and who does what when something breaks. If your practice prepares tax returns or fiduciary filings, this isn't optional - the FTC Safeguards Rule requires a Written Information Security Plan (WISP), and the IRS checks for one when it issues preparer credentials.

Don't start from a blank page. We publish a free, fillable WISP template - verified against IRS Publication 5708 and the FTC Safeguards Rule - that you can complete in an afternoon: download the free WISP template. No email gate on this checklist; the template download takes one form.

The common thread

Nine of these ten items are about controlling where client data lives and who can reach it. That's also the case for a client portal over email attachments: encrypted storage, per-client access, an audit trail, and nothing sensitive sitting in inboxes. If your firm still exchanges documents by email, that's the first fix worth making.

Header green dot shapeHeader green dot shape

Ready to dive in?
Request your free trial today.

Simple and Fast Client File Sharing.

arrow up icon

Law Firm Cybersecurity Checklist: 10 Practical Steps for 2026

Opinion

A plain-language cybersecurity checklist for law firms in 2026 - MFA, encryption, email risk, vendor review, and a written security plan.

Post by
Justin Neiman
Publish Date:
July 16, 2026
Glowing shield protecting a law office laptop and client folders from phishing emails

Law firms hold exactly what attackers want: identity documents, financial records, settlement details, and privileged communications - all concentrated in small offices that rarely have an IT department. You don't need an enterprise security budget to be a hard target. You need a short list of habits, applied consistently. Here is the 2026 version of that list.

1. Turn on multi-factor authentication everywhere

If you do only one thing on this page, do this. MFA on email, your practice-management system, your file-sharing tools, and your bank blocks the vast majority of account-takeover attacks. Prefer an authenticator app over SMS codes where you can.

2. Get client files out of email

Email is where law-firm breaches start: it's unencrypted at rest in two places you don't control (your sent folder and the client's inbox), and attachments live there forever. Move client document exchange to a secure portal with access controls and an audit trail, and make "never as an email attachment" a firm policy.

3. Use a password manager - firm-wide

Reused passwords are how one breached shopping site becomes your breached case files. A password manager makes unique passwords the path of least resistance. Pair it with MFA and most credential attacks stop working.

4. Encrypt every device that leaves the office

Laptops and phones get lost and stolen more often than servers get hacked. Full-disk encryption (BitLocker on Windows, FileVault on Mac) plus a device PIN turns a stolen laptop from a reportable breach into an inconvenience.

5. Train for today's phishing, not 2015's

Modern phishing is clean, well-written, and increasingly AI-generated - fake counsel requests, spoofed payoff instructions, "updated wire details." Train staff on one rule above all: any request to move money or change payment details gets verified by phone at a number you already have. Run this refresher twice a year.

6. Patch and update automatically

Most exploited vulnerabilities are old ones with fixes available. Turn on automatic updates for operating systems, browsers, and practice software, and retire anything the vendor no longer supports.

7. Back up like you'll be ransomed

Assume ransomware will eventually reach one of your machines. Keep an automatic, encrypted, versioned backup that lives somewhere your office network can't overwrite - and actually test a restore once a quarter.

8. Control who can see what

Not everyone at the firm needs every matter. Use per-matter or per-client access controls, review them when staff change roles, and cut access the same day someone leaves. An audit log that shows who accessed which file, when, answers the question every client asks after an incident.

9. Review your vendors once a year

Your security now includes your e-signature tool, your cloud storage, your IT contractor, and your copier company. Once a year, list every vendor that touches client data and confirm what they store, whether it's encrypted, and how you'd get your data out.

10. Write it down: you need a written security plan

Every step above belongs in one short document: what data you hold, what could go wrong, what safeguards you run, and who does what when something breaks. If your practice prepares tax returns or fiduciary filings, this isn't optional - the FTC Safeguards Rule requires a Written Information Security Plan (WISP), and the IRS checks for one when it issues preparer credentials.

Don't start from a blank page. We publish a free, fillable WISP template - verified against IRS Publication 5708 and the FTC Safeguards Rule - that you can complete in an afternoon: download the free WISP template. No email gate on this checklist; the template download takes one form.

The common thread

Nine of these ten items are about controlling where client data lives and who can reach it. That's also the case for a client portal over email attachments: encrypted storage, per-client access, an audit trail, and nothing sensitive sitting in inboxes. If your firm still exchanges documents by email, that's the first fix worth making.

Justin is a software engineer that loves breaking the mold, always pressing current frameworks to the limit. He's a father, avid PC builder, and keen to all things whisky.