Most law firms believe their cybersecurity is reasonably solid until something happens. By then, the question is no longer whether the firm was protected. It is whether the firm noticed, responded appropriately, and told the people who needed to know.
Recent industry research found that 63 percent of law firms experienced a significant email-based security breach in the past year. Just as concerning, more than half of clients say their firm has never proactively communicated with them about cybersecurity at all.
That gap, between what is actually happening inside law firms and what clients are being told, is where real risk and real reputational damage live.
Graffen: Cybersecurity Built for the Realities of Legal Practice
Not sure where your firm stands on breach readiness or client communication? Graffen helps law firms assess their current security posture, close the gaps that insurers and clients are now asking about, and build a response plan before an incident forces one.
Start with a straightforward security assessment. Contact us now.
Why Law Firms Are Such a Frequent Target
Law firms hold a dense concentration of exactly the kind of information cybercriminals want: privileged communications, financial records, merger and acquisition details, litigation strategy, and personal information tied to clients who often have significant assets. That combination makes firms a high-value target, and attackers know it.
Email remains the most common point of entry. Phishing attempts directed at attorneys and staff are often more sophisticated than the generic scams most people are used to spotting. Attackers research a firm’s active matters, impersonate opposing counsel or clients, and time their messages around real deadlines. A single click from a busy associate or paralegal can be enough to compromise an entire email environment.
Once inside, attackers do not always announce themselves immediately. Some breaches go undetected for weeks or longer, during which privileged communications, case files, and client data may be accessed, copied, or held for ransom.
The Real Problem Is Not Just the Breach. It Is the Silence Afterward.
A breach is a technical failure. Not telling clients about it is a trust failure, and trust failures tend to do more lasting damage to a firm than the technical incident itself.
Here is what that silence typically looks like in practice:
- Firms detecting unusual account activity but not investigating it thoroughly enough to know if data was actually accessed
- Security incidents being handled internally with no formal communication plan for affected clients
- Leadership assuming that disclosure obligations only apply to large-scale, headline-level breaches
- No documented incident response plan, meaning decisions about disclosure get made reactively under pressure
- Clients learning about an incident from a third party, a news report, or another vendor rather than from the firm directly
When clients eventually find out, and they usually do, the firm’s silence becomes the story instead of the breach itself. Clients are more forgiving of an incident that was handled transparently than one that was hidden or downplayed.
What Clients Actually Want From Their Law Firm on Security
The expectation gap here is worth sitting with. Most firms assume clients are not thinking about cybersecurity at all. The data says otherwise. Clients want to know that the firm holding their most sensitive information takes that responsibility seriously, and they want to be told directly if something has gone wrong rather than finding out after the fact.
Firms that get ahead of this build something competitors cannot easily replicate: documented, demonstrable proof that they take data protection seriously. That includes being able to show clients and prospective clients exactly what security measures are in place, having a clear incident response plan ready before it is needed, and communicating proactively rather than only when forced to.
This is not just a client relations issue. It increasingly shows up in new business decisions. Corporate clients are sending detailed security questionnaires before granting outside counsel status, and firms that cannot answer those questions clearly and quickly are losing opportunities they never even knew they were being evaluated for.
Cyber Insurance Has Quietly Raised the Bar
Beyond client expectations, the cyber insurance market has changed the calculus for every law firm carrying a policy. Underwriters are no longer satisfied with a signed attestation form claiming reasonable security measures are in place. Multi-factor authentication, endpoint detection and response, and immutable backups are now baseline requirements before a policy will even be quoted, not optional upgrades.
Firms that have not reviewed their security posture against current underwriting requirements are at risk of renewal surprises: higher premiums, reduced coverage, or denied claims if an incident occurs and the firm cannot demonstrate the controls their policy assumed were in place.
This is one of the clearest, most concrete reasons firms are moving away from informal or part-time IT arrangements toward managed providers who can document compliance in the language insurers and regulators now expect.
“63% of firms reported a significant email-based security breach in the past year.” Integris 2026 Law Firm Trust in Technology Report
That statistic alone should reframe how most firms think about their current security posture. A breach is no longer a rare, unlucky event. For more than six in ten firms, it has already happened. The real differentiator between firms now is not whether an incident occurs. It is whether the firm was prepared, detected it quickly, and handled the aftermath in a way that preserved client trust rather than eroding it.
Closing the Gap Starts With an Honest Assessment
Most firms do not need a complete technology overhaul to close this gap. They need an honest, documented picture of where their current security stands, what their cyber insurance policy actually requires, and what a clear incident response plan looks like if something does happen.
That assessment typically surfaces a familiar set of gaps: multi-factor authentication that is enabled inconsistently across staff, email security that has not been reviewed in years, no documented response plan, and no clear protocol for client communication if an incident occurs. None of these are difficult to fix. They are simply easy to overlook until an underwriter, a corporate client, or an incident forces the issue.
For Law Firms, Cybersecurity Is No Longer Just an IT Issue. It Is a Client Trust Issue.
The firms that will be best positioned over the next several years are not necessarily the ones with the most sophisticated technology stack. They are the ones who took a clear-eyed look at their actual risk, closed the obvious gaps, and built a plan for transparent communication before they needed one.
Your clients are trusting you with information that could damage them significantly if it were exposed. That trust deserves more than a hope that nothing goes wrong. It deserves a documented, proactive approach.
Frequently Asked Questions
How common are data breaches at law firms?
More common than most firm leaders assume. Recent industry research found that 63 percent of law firms experienced a significant email-based security breach in the past year. Law firms are frequent targets because they hold dense concentrations of privileged, financial, and personal client data.
Why are law firms specifically targeted by cybercriminals?
Law firms hold a unique combination of high-value information, including privileged communications, financial records, litigation strategy, and client personal data, often without the same security infrastructure that financial institutions or healthcare organizations are required to maintain. That combination makes firms an efficient target for attackers.
Are law firms required to tell clients about a data breach?
Disclosure obligations vary by state and by the type of data involved, but most jurisdictions have breach notification laws that apply once certain types of personal information are compromised. Beyond legal obligation, proactive communication is also what clients say they expect, even when it is not strictly required.
What does cyber insurance require from law firms now?
Underwriters increasingly require multi-factor authentication, endpoint detection and response, and immutable backups before issuing or renewing a policy. Firms that cannot demonstrate these controls risk higher premiums, reduced coverage, or denied claims if an incident occurs.
What should a law firm’s incident response plan include?
At minimum, a response plan should define who is responsible for detecting and investigating a potential incident, how quickly affected systems are isolated, how the scope of a breach is determined, what regulatory and client notification obligations apply, and who is responsible for communicating with clients and the firm’s insurer.
How can a law firm find out if its current security meets insurer or client expectations?
A structured security assessment is the most reliable way to find out. This typically reviews multi-factor authentication coverage, email security configuration, backup integrity, and the existence and quality of a documented incident response plan, then compares the findings against what insurers and corporate clients are currently asking for.
How does Graffen help law firms with cybersecurity and breach readiness?
Graffen conducts a thorough security assessment of a firm’s current environment, identifies gaps against current insurer and client expectations, and helps build a documented incident response and communication plan. We also help firms implement the specific controls, including MFA, EDR, and immutable backups, that insurers and corporate clients are now requiring.

