A plain-language cybersecurity checklist for law firms in 2026 - MFA, encryption, email risk, vendor review, and a written security plan.


Law firms hold exactly what attackers want: identity documents, financial records, settlement details, and privileged communications - all concentrated in small offices that rarely have an IT department. You don't need an enterprise security budget to be a hard target. You need a short list of habits, applied consistently. Here is the 2026 version of that list.
If you do only one thing on this page, do this. MFA on email, your practice-management system, your file-sharing tools, and your bank blocks the vast majority of account-takeover attacks. Prefer an authenticator app over SMS codes where you can.
Email is where law-firm breaches start: it's unencrypted at rest in two places you don't control (your sent folder and the client's inbox), and attachments live there forever. Move client document exchange to a secure portal with access controls and an audit trail, and make "never as an email attachment" a firm policy.
Reused passwords are how one breached shopping site becomes your breached case files. A password manager makes unique passwords the path of least resistance. Pair it with MFA and most credential attacks stop working.
Laptops and phones get lost and stolen more often than servers get hacked. Full-disk encryption (BitLocker on Windows, FileVault on Mac) plus a device PIN turns a stolen laptop from a reportable breach into an inconvenience.
Modern phishing is clean, well-written, and increasingly AI-generated - fake counsel requests, spoofed payoff instructions, "updated wire details." Train staff on one rule above all: any request to move money or change payment details gets verified by phone at a number you already have. Run this refresher twice a year.
Most exploited vulnerabilities are old ones with fixes available. Turn on automatic updates for operating systems, browsers, and practice software, and retire anything the vendor no longer supports.
Assume ransomware will eventually reach one of your machines. Keep an automatic, encrypted, versioned backup that lives somewhere your office network can't overwrite - and actually test a restore once a quarter.
Not everyone at the firm needs every matter. Use per-matter or per-client access controls, review them when staff change roles, and cut access the same day someone leaves. An audit log that shows who accessed which file, when, answers the question every client asks after an incident.
Your security now includes your e-signature tool, your cloud storage, your IT contractor, and your copier company. Once a year, list every vendor that touches client data and confirm what they store, whether it's encrypted, and how you'd get your data out.
Every step above belongs in one short document: what data you hold, what could go wrong, what safeguards you run, and who does what when something breaks. If your practice prepares tax returns or fiduciary filings, this isn't optional - the FTC Safeguards Rule requires a Written Information Security Plan (WISP), and the IRS checks for one when it issues preparer credentials.
Don't start from a blank page. We publish a free, fillable WISP template - verified against IRS Publication 5708 and the FTC Safeguards Rule - that you can complete in an afternoon: download the free WISP template. No email gate on this checklist; the template download takes one form.
Nine of these ten items are about controlling where client data lives and who can reach it. That's also the case for a client portal over email attachments: encrypted storage, per-client access, an audit trail, and nothing sensitive sitting in inboxes. If your firm still exchanges documents by email, that's the first fix worth making.
Simple and Fast Client File Sharing.
A plain-language cybersecurity checklist for law firms in 2026 - MFA, encryption, email risk, vendor review, and a written security plan.

Law firms hold exactly what attackers want: identity documents, financial records, settlement details, and privileged communications - all concentrated in small offices that rarely have an IT department. You don't need an enterprise security budget to be a hard target. You need a short list of habits, applied consistently. Here is the 2026 version of that list.
If you do only one thing on this page, do this. MFA on email, your practice-management system, your file-sharing tools, and your bank blocks the vast majority of account-takeover attacks. Prefer an authenticator app over SMS codes where you can.
Email is where law-firm breaches start: it's unencrypted at rest in two places you don't control (your sent folder and the client's inbox), and attachments live there forever. Move client document exchange to a secure portal with access controls and an audit trail, and make "never as an email attachment" a firm policy.
Reused passwords are how one breached shopping site becomes your breached case files. A password manager makes unique passwords the path of least resistance. Pair it with MFA and most credential attacks stop working.
Laptops and phones get lost and stolen more often than servers get hacked. Full-disk encryption (BitLocker on Windows, FileVault on Mac) plus a device PIN turns a stolen laptop from a reportable breach into an inconvenience.
Modern phishing is clean, well-written, and increasingly AI-generated - fake counsel requests, spoofed payoff instructions, "updated wire details." Train staff on one rule above all: any request to move money or change payment details gets verified by phone at a number you already have. Run this refresher twice a year.
Most exploited vulnerabilities are old ones with fixes available. Turn on automatic updates for operating systems, browsers, and practice software, and retire anything the vendor no longer supports.
Assume ransomware will eventually reach one of your machines. Keep an automatic, encrypted, versioned backup that lives somewhere your office network can't overwrite - and actually test a restore once a quarter.
Not everyone at the firm needs every matter. Use per-matter or per-client access controls, review them when staff change roles, and cut access the same day someone leaves. An audit log that shows who accessed which file, when, answers the question every client asks after an incident.
Your security now includes your e-signature tool, your cloud storage, your IT contractor, and your copier company. Once a year, list every vendor that touches client data and confirm what they store, whether it's encrypted, and how you'd get your data out.
Every step above belongs in one short document: what data you hold, what could go wrong, what safeguards you run, and who does what when something breaks. If your practice prepares tax returns or fiduciary filings, this isn't optional - the FTC Safeguards Rule requires a Written Information Security Plan (WISP), and the IRS checks for one when it issues preparer credentials.
Don't start from a blank page. We publish a free, fillable WISP template - verified against IRS Publication 5708 and the FTC Safeguards Rule - that you can complete in an afternoon: download the free WISP template. No email gate on this checklist; the template download takes one form.
Nine of these ten items are about controlling where client data lives and who can reach it. That's also the case for a client portal over email attachments: encrypted storage, per-client access, an audit trail, and nothing sensitive sitting in inboxes. If your firm still exchanges documents by email, that's the first fix worth making.