Most firms don't get breached because they ignored security.
They get breached because their defenses stopped keeping pace with the threats
while everyone was busy practicing law.
The warning signs are usually there long before an incident.
For a firm of 10 to 300 people with a small IT footprint, they're easy to miss.
The figures below come largely from the American Bar Association's 2023 Legal
Technology Survey, its most recent comprehensive dataset, paired with current
cost and threat data.
Here are 10 signs your firm's cybersecurity may be falling
behind heading into 2026 and 2027. If several sound familiar, it's time for a
closer look.
1. Multi-Factor Authentication Isn't Turned On Everywhere
Multi-factor authentication (MFA) is the cheapest,
highest-impact control a firm can turn on, and Microsoft's own data shows it
stops 99.9% of credential-based account attacks. Yet only 54% of attorneys
report having MFA available.[1]
If MFA isn't required on email, remote access, and cloud
admin accounts, a single stolen password is all an attacker needs. Partial
coverage is a false sense of safety.
Where the right IT partner helps: A partner can enforce phishing-resistant MFA
across every account and application, not just the ones that were easy to set
up, and document it for your cyber insurer.
2. Nobody Can Find (or Has Ever Tested) Your Incident
Response Plan
Only 34% of firms have an incident response plan, and at
firms of 2 to 9 lawyers that drops to 19%.[2]
Without one, a bad morning becomes a compliance failure.
An incident response plan is your road map for the hours
after an attack: who to call, what to shut down, when to notify clients and
regulators. Writing it during the incident is too late.
Where the right IT partner helps: A virtual chief information officer (vCIO) can build the plan, assign the roles, and run a tabletop
exercise so the first time your team uses it isn't during a real breach.
3. Antivirus Is the Only Thing Standing Between You and
Ransomware
Law firms are high-value targets because of what they hold:
deal intelligence, litigation strategy, and decades of confidential files.
Attackers increasingly take their time once inside, mapping the most sensitive
material before they strike.
Signature-based antivirus was built for a different era and
misses this kind of slow, targeted intrusion. When a breach does land, it takes
organizations an average of 241 days to identify and contain, the global mean
IBM reported for 2025.[3]
Where the right IT partner helps: The
upgrade is advanced endpoint protection like Endpoint
Detection and Response (EDR) and Managed Detection and Response (MDR), backed by a 24/7 security operations center that
catches activity while attackers are still moving, not after the files are
gone.
4. Your Last Security Assessment Was Years Ago, or Never
Only 29% of firms have had a full security assessment
performed by a third party.[4]
You can't fix what you can't see, and your own staff have a vested interest in
the results.
An outside assessment uses fresh eyes and scanning tools to
find the gaps that internal habit glosses over. Many cyber insurers and
corporate clients now expect one.
Where the right IT partner helps: A partner can run an independent assessment
against a recognized framework, then hand you a prioritized plan instead of a
list of scary findings with no fix.
5. Your Staff Have Never Had Real Phishing Training
Most breaches still start with a person clicking something.
Social engineering is especially dangerous around financial transactions, where
a convincing email can redirect a wire or a settlement.
The ABA's own guidance is that firms should run
cybersecurity awareness training at least once a year, covering current threats
and attack methods. Many firms do it once at onboarding, or never.
Where the right IT partner helps: A partner can run quarterly security
awareness training and mock phishing campaigns, then route the people who fail
into more coaching, which turns your staff into a human firewall instead of the
weak link.
6. Your Cyber Insurance Renewal Keeps Getting Harder
Only 40% of firms carry cyber
liability insurance, down from 46% the year before.[5] Dropping
coverage right as requirements tighten leaves a firm exposed on both sides.
Coverage used to be a form and a signature. Now it's a
technical audit: carriers expect MFA, endpoint detection, tested backups, and a
documented incident response plan, or they raise premiums, cut limits, or
decline.
Where the right IT partner helps: Think of security spend as the premium you
pay to keep a known risk within your policy limits. A partner who builds your
controls to match the carrier checklist, and documents them, turns a painful
renewal into a routine one.
7. Attorneys Are Using Consumer AI Tools With No Policy
53% of legal professionals say their firm has no AI policy
or they're unaware of one, and 54% of firms provide no training on responsible
AI use.[6]
When a firm stays silent, attorneys don't stop using AI.
They paste client material into free consumer tools on personal accounts, and
privilege walks out the door. High use of shadow AI added an average of 670,000
dollars to the cost of a breach in IBM's 2025 research.[9]
Where the right IT partner helps: A partner can stand up an AI usage policy,
an approval step for new tools, and clear rules on what client data a tool may
touch, so staff get a safe, sanctioned way to use AI.
8. Clients Are Auditing You and You're Scrambling to Answer
Corporate clients increasingly treat outside counsel as an
extension of their own attack surface. In the ABA survey, 22% of firms had been
asked to complete a security questionnaire and 27% to provide a security
requirements document, reaching 50% at firms of more than 100 lawyers.[7]
If every client security request sets off a fire drill,
security has become a business development problem, not just an IT one.
Where the right IT partner helps: Documented controls and audit-ready
reporting turn a long questionnaire into a copy-and-paste exercise, and a
credibility win in front of the client.
9. Your Backups Aren't Tested and May Not Survive
Ransomware
The ABA's guidance is blunt: backups should be engineered to
survive a ransomware attack and tested on a periodic basis, because all the
backups in the world won't help if you can't restore.[8]
Many firms trust a green checkmark that says the backup ran
and have never actually performed a test restore. Modern ransomware
specifically hunts for and encrypts backups, so a backup that isn't isolated
may already be compromised.
Where the right IT partner helps: A partner can move you to immutable,
isolated backups and run scheduled test restores, so recovery is something
you've proven rather than something you hope works.
10. One Person, or Nobody, Owns Security
At a lot of firms, cybersecurity is a side job for the
office manager or the one attorney who likes computers. That works until that
person is on vacation, leaves, or simply can't keep up with threats that change
weekly.
Security is now a full-time discipline that runs around the
clock. A part-time owner can't monitor at 2am, and attackers know most firms
aren't watching then.
Where the right IT partner helps: A partner
gives you a whole team and 24/7 monitoring instead of a single point of
failure, plus a vCIO who owns the strategy so security stops depending on one person's spare time.
The Bottom Line
None of these signs means your firm is careless. They mean
technology outran a setup that was fine a few years ago, which is the normal
path for a busy firm with a small IT footprint.
The good news is that every one of these is fixable, and
most fixes cost far less than a single incident. The firms that handle 2026 and
2027 well are the ones that treat security as an ongoing discipline with clear
ownership, not a box checked once at renewal.
That's the work Framework IT does for law firms every day:
layered defenses, tested recovery, documented controls that satisfy insurers
and clients, and a team that owns it around the clock. Framework IT is a
Chicago-based managed IT services firm founded in 2008, with a team of more
than 40 professionals, most of them engineers who live in the Chicagoland area.
We help law firms and other professional services organizations with IT
support, strategy, and security, and with putting structure around AI so it can
be used safely.
If a few of these
signs hit close to home, schedule a conversation with our team for a straight
assessment of where your firm stands: frameworkit.com/discoverycall
About the Author
Adam Barney is President and Managing Partner of Framework
IT, a Chicago-based managed IT services firm he's helped lead for more than 15
years. He and his team of 40+ professionals specialize in IT support, strategy,
and cybersecurity for small and mid-sized businesses. Adam's insights on
business technology have been featured in the Harvard Business Review, the
Washington Post, and Fox 32 Chicago.
Citations
Every
statistic above is sourced to a live page that states it. Verify links are live
before publishing.
[1] 54% of attorneys report having multi-factor
authentication (two-factor authentication, in the survey's wording) available;
Microsoft data shows MFA stops 99.9% of credential-based account attacks. ABA
2023 Cybersecurity TechReport / 2023 Legal Technology Survey.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[2] 34% of firms have an incident response plan;
19% at firms of 2-9 lawyers and 19% for solo attorneys. ABA 2023 Cybersecurity
TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[3] The global average time to identify and contain
a breach was 241 days in 2025 (the lowest in nine years); global average breach
cost was 4.44 million dollars. IBM 2025 Cost of a Data Breach Report.
https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
[4] 29% of firms have had a full security
assessment performed by a third party. ABA 2023 Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[5] 40% of firms carry cyber liability insurance,
down from 46% the prior year. ABA 2023 Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[6] 53% of legal professionals say their firm has
no AI policy or are unaware of one (Clio 2025 Legal Trends Report, via
2Civility); 54% of firms provide no training on responsible AI use (8am 2026
Legal Industry Report, ABA Law Practice Magazine). https://www.2civility.org/2025-clio-legal-trends-report/
;
https://www.americanbar.org/groups/law_practice/resources/law-practice-magazine/2026/march-april-2026/8am-legal-industry-report/
[7] 22% of firms had been asked by a client to
complete a security questionnaire and 27% to provide a security requirements
document, reaching 50% at firms of more than 100 lawyers. ABA 2023
Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[8] The ABA advises that backups be engineered to
survive a ransomware attack and tested periodically with test restores. ABA
2023 Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[9] A high level of shadow AI added an average of
670,000 dollars to breach costs; 97% of organizations with an AI-related
incident lacked proper AI access controls. IBM 2025 Cost of a Data Breach
Report. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai