Legal Services

The Wire Instructions Your Client Received May Not Have Come From You

Law firm security is not an IT problem with an ethics footnote. It is an ethics obligation with an IT dependency - and the loss that actually happens to small firms is a redirected closing wire, not a headline ransomware event.

Confidentiality and data security are different things. You can satisfy one and fail the other. Your malpractice carrier and your clients are now asking about both.

The operational reality

What Makes Legal Services Different

Your duty runs to the client, and it is enforceable by the Bar. The Florida Bar publishes ethics opinions on exactly the technology questions firms ask - cloud storage of client files, the data on a leased copier before it goes back, and generative AI (Florida Bar ethics opinions). Those opinions ask for due diligence you can describe, not a product you bought.

Trust accounts make you a payments target. Real estate closings, settlements, and escrow disbursements move on emailed instructions. Business email compromise against an IOLTA disbursement is the highest-severity incident type for a small firm, and it is a verification process failure rather than a missing security tool.

Your practice management platform decides your controls. Clio, MyCase, PracticePanther at the small end; Aderant or Elite 3E at the large end; NetDocuments or iManage for documents - or, in many firms under ten attorneys, a shared drive. The vendor configuration you never opened is your access control policy.

There is no natural owner. One to fifteen attorneys, no IT staff, and the de facto administrator is a paralegal or the managing partner. Any requirement to designate a responsible person lands on someone with a full caseload.

Your clients now audit you. Corporate clients push their own vendor requirements down to outside counsel as questionnaires - multi-factor, encryption, retention, breach notification terms. Firms lose engagements over the answers, not the rates.

Frameworks

Your Compliance Landscape

Most of what governs a law firm is professional responsibility rather than a security standard. The frameworks below attach because of the work you do, not because you are a law firm.

Almost always applies

  • The structure most cyber insurance applications and client questionnaires are built on (NIST CSF). Useful as your organizing framework even though nothing requires it.

Applies in some cases

  • The Safeguards Rule reaches non-bank businesses engaged in financial activity (16 CFR Part 314). Firms doing closings, settlement services, or tax-adjacent work should have that determination made deliberately, by counsel, rather than assumed away.
  • You become a Business Associate when you receive protected health information while representing a covered entity (HHS on business associates). This is matter-specific. A firm with three healthcare clients does not need an enterprise HIPAA program; it needs BAAs and controls scoped to those matters.
  • Family law, custody, and criminal defense files routinely contain substance use disorder treatment records, which carry consent restrictions stricter than HIPAA (42 CFR Part 2).
  • Applies where the firm has access to criminal justice information systems - municipal prosecution and some defense work. The FBI publishes the current Security Policy (CJIS Security Policy).
  • Education law and special education practices holding student records from district clients (FERPA at the Department of Education).
  • Card retainers make you a merchant (PCI SSC).
  • Almost always a demand on you rather than something you obtain. Corporate clients ask outside counsel to evidence controls; the practical answer is a documented program, not a certification.
  • EU-connected matters (Regulation 2016/679) and California matters (California AG on CCPA) bring data subject and processor obligations into the engagement.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Failure patterns

What Usually Goes Wrong

  • A closing wire is redirected. The instructions look right, the thread looks real, and the funds are gone within hours. Call-back verification to a number from the file - not from the email - is the control that stops it.
  • "The cloud vendor handles security." The Bar's due-diligence expectation is about where the data lives, who can compel access to it, and whether you can get it back. That is a vendor review, and it produces a document.
  • Departed access lingers. Paralegals, contract attorneys, and temps keep credentials to the document system months after the last matter closed.
  • The leased copier goes back with the drive in it. Court filings, discovery, and probate documents live on that device.
  • An associate pastes client facts into a public AI tool. Almost no small firm has a written policy on this, which makes it a personnel question with no rule behind it.
  • The cyber insurance renewal comes back conditional on multi-factor everywhere, endpoint detection, and immutable backups. Firms find out at renewal, or worse, at claim.
  • A client sends a security questionnaire and the firm has nothing to send back.
  • Everything is privileged, so everything feels protected. Privilege is a rule of evidence. It does not encrypt anything.

Our services

How We Work With Legal Services

  • Cyber Risk Management

    Multi-factor across email and the practice management platform, endpoint detection, and email controls tuned for the impersonation attempts that precede a wire fraud.

  • Governance, Risk & Compliance (GRC)

    The written incident response plan, the vendor and BAA inventory, the hardware retirement process, and an AI use policy - the artifacts your carrier and your clients ask for.

  • Third-Party Assessments

    Due diligence on your cloud and document vendors, and completed answers when a corporate client sends outside counsel a questionnaire.

  • Helpdesk Support

    Support that understands a hearing date is not a reschedulable event and that the firm has no internal IT to escalate to.

  • Fractional CIO, CTO & CISO

    Someone who owns security decisions so the managing partner does not, and who can brief the partnership in plain language.

  • Digital Forensics & Incident Response

    Wire fraud and email compromise response - mailbox forensics, containment, and the timeline you will need for the carrier and the client.

Questions people ask

Frequently Asked Questions

Do law firms have to comply with HIPAA?
Only where the firm acts as a business associate - that is, receives protected health information while performing services for a covered entity. It is matter-driven rather than firm-wide. HHS publishes the business associate definition and the required contract terms at hhs.gov/hipaa.
Do I have to tell my clients if the firm was hacked?
Two obligations run in parallel. Professional responsibility governs what you owe the affected client, and the Florida Bar publishes guidance in its ethics opinions. Separately, Fla. Stat. §501.171 requires notice to affected Florida residents within 30 days of determining a breach of personal information. Consult ethics counsel on the first; the statute text is on flsenate.gov for the second.
Can lawyers use Dropbox or Google Drive for client files?
Cloud storage is not prohibited. What is expected is due diligence you can describe: where the data resides, who else can access or compel it, how it is protected, and whether you can retrieve it if the relationship ends. The Florida Bar has addressed cloud computing in its ethics opinions - read them at floridabar.org/etopinions.
Is it acceptable to email clients unencrypted?
It depends on the sensitivity of the content and the client's informed expectations. The higher-risk case is not the routine status email - it is anything containing account numbers or payment instructions, which should not be transmitted or acted on by email alone.
What do I do before returning a leased office copier?
Treat it as a storage device, because it is one. The Florida Bar has issued an ethics opinion on the confidentiality obligations attached to devices with retained data. Practically: a documented sanitization step in the lease-return process, with a certificate you keep.
Can I use ChatGPT to draft legal documents?
The Florida Bar has published an ethics opinion addressing generative AI and lawyers' duties around confidentiality, supervision, and competence. The firm-level answer is a written policy naming approved tools and what may never be entered into them - most firms this size do not have one yet.
Does my malpractice insurance cover a cyberattack?
Professional liability and cyber liability are different policies covering different losses, and social engineering or funds transfer fraud is frequently a separate, sub-limited coverage. Read the funds transfer endorsement specifically, before you need it.
Do solo attorneys get targeted?
Wire fraud attempts are opportunistic and driven by transaction visibility, not firm size. A solo practitioner handling residential closings is a more attractive target than a large firm doing appellate work, because the money moves and the approval chain is short.
A client sent us a security questionnaire. What do we send back?
They typically ask about multi-factor authentication, encryption at rest and in transit, access reviews, backup and recovery, incident response and notification timelines, subcontractor lists, and cyber insurance limits. The answers should come from documents that already exist. Building the answers and the documents at the same time is what makes this painful.
Is my firm required to have multi-factor authentication?
No general rule imposes it on all firms. In practice it is imposed by your cyber insurer at renewal, by corporate clients in engagement terms, and by the reasonable-safeguards expectation behind your confidentiality duty. Treat it as required and you will be right in every case that matters.

Florida & the Treasure Coast

Legal Services on the Treasure Coast

Florida gives firms a shorter breach clock than most states. Fla. Stat. §501.171 sets 30 days for notice to affected Florida residents, with notice to the Department of Legal Affairs above the statutory threshold. Firm ethics obligations sit on top of that, and the Florida Bar publishes its guidance at floridabar.org/etopinions.

The Treasure Coast profile raises the wire fraud exposure specifically: high second-home and retirement transaction volume across Martin, St. Lucie, and Palm Beach counties means real estate and estate planning practices are routinely moving significant funds for clients who are often out of state and communicating entirely by email. That combination - remote client, large transfer, email-based instruction - is the exact pattern these attacks are built around.

[NEEDS: client proof for this vertical]