Person using Acer laptop displaying Tribunal de Justiça website with an open book on a wooden table.

10 Signs Your Law Firm's Cybersecurity Is Falling Behind

October 05, 2026

Most firms don't get breached because they ignored security. They get breached because their defenses stopped keeping pace with the threats while everyone was busy practicing law.

The warning signs are usually there long before an incident. For a firm of 10 to 300 people with a small IT footprint, they're easy to miss. The figures below come largely from the American Bar Association's 2023 Legal Technology Survey, its most recent comprehensive dataset, paired with current cost and threat data.

Here are 10 signs your firm's cybersecurity may be falling behind heading into 2026 and 2027. If several sound familiar, it's time for a closer look.

1. Multi-Factor Authentication Isn't Turned On Everywhere

Multi-factor authentication (MFA) is the cheapest, highest-impact control a firm can turn on, and Microsoft's own data shows it stops 99.9% of credential-based account attacks. Yet only 54% of attorneys report having MFA available.[1]

If MFA isn't required on email, remote access, and cloud admin accounts, a single stolen password is all an attacker needs. Partial coverage is a false sense of safety.

Where the right IT partner helps: A partner can enforce phishing-resistant MFA across every account and application, not just the ones that were easy to set up, and document it for your cyber insurer.

2. Nobody Can Find (or Has Ever Tested) Your Incident Response Plan

Only 34% of firms have an incident response plan, and at firms of 2 to 9 lawyers that drops to 19%.[2] Without one, a bad morning becomes a compliance failure.

An incident response plan is your road map for the hours after an attack: who to call, what to shut down, when to notify clients and regulators. Writing it during the incident is too late.

Where the right IT partner helps: A virtual chief information officer (vCIO) can build the plan, assign the roles, and run a tabletop exercise so the first time your team uses it isn't during a real breach.

3. Antivirus Is the Only Thing Standing Between You and Ransomware

Law firms are high-value targets because of what they hold: deal intelligence, litigation strategy, and decades of confidential files. Attackers increasingly take their time once inside, mapping the most sensitive material before they strike.

Signature-based antivirus was built for a different era and misses this kind of slow, targeted intrusion. When a breach does land, it takes organizations an average of 241 days to identify and contain, the global mean IBM reported for 2025.[3]

Where the right IT partner helps: The upgrade is advanced endpoint protection like Endpoint Detection and Response (EDR) and Managed Detection and Response (MDR), backed by a 24/7 security operations center that catches activity while attackers are still moving, not after the files are gone.

4. Your Last Security Assessment Was Years Ago, or Never

Only 29% of firms have had a full security assessment performed by a third party.[4] You can't fix what you can't see, and your own staff have a vested interest in the results.

An outside assessment uses fresh eyes and scanning tools to find the gaps that internal habit glosses over. Many cyber insurers and corporate clients now expect one.

Where the right IT partner helps: A partner can run an independent assessment against a recognized framework, then hand you a prioritized plan instead of a list of scary findings with no fix.

5. Your Staff Have Never Had Real Phishing Training

Most breaches still start with a person clicking something. Social engineering is especially dangerous around financial transactions, where a convincing email can redirect a wire or a settlement.

The ABA's own guidance is that firms should run cybersecurity awareness training at least once a year, covering current threats and attack methods. Many firms do it once at onboarding, or never.

Where the right IT partner helps: A partner can run quarterly security awareness training and mock phishing campaigns, then route the people who fail into more coaching, which turns your staff into a human firewall instead of the weak link.

6. Your Cyber Insurance Renewal Keeps Getting Harder

Only 40% of firms carry cyber liability insurance, down from 46% the year before.[5] Dropping coverage right as requirements tighten leaves a firm exposed on both sides.

Coverage used to be a form and a signature. Now it's a technical audit: carriers expect MFA, endpoint detection, tested backups, and a documented incident response plan, or they raise premiums, cut limits, or decline.

Where the right IT partner helps: Think of security spend as the premium you pay to keep a known risk within your policy limits. A partner who builds your controls to match the carrier checklist, and documents them, turns a painful renewal into a routine one.

7. Attorneys Are Using Consumer AI Tools With No Policy

53% of legal professionals say their firm has no AI policy or they're unaware of one, and 54% of firms provide no training on responsible AI use.[6]

When a firm stays silent, attorneys don't stop using AI. They paste client material into free consumer tools on personal accounts, and privilege walks out the door. High use of shadow AI added an average of 670,000 dollars to the cost of a breach in IBM's 2025 research.[9]

Where the right IT partner helps: A partner can stand up an AI usage policy, an approval step for new tools, and clear rules on what client data a tool may touch, so staff get a safe, sanctioned way to use AI.

8. Clients Are Auditing You and You're Scrambling to Answer

Corporate clients increasingly treat outside counsel as an extension of their own attack surface. In the ABA survey, 22% of firms had been asked to complete a security questionnaire and 27% to provide a security requirements document, reaching 50% at firms of more than 100 lawyers.[7]

If every client security request sets off a fire drill, security has become a business development problem, not just an IT one.

Where the right IT partner helps: Documented controls and audit-ready reporting turn a long questionnaire into a copy-and-paste exercise, and a credibility win in front of the client.

9. Your Backups Aren't Tested and May Not Survive Ransomware

The ABA's guidance is blunt: backups should be engineered to survive a ransomware attack and tested on a periodic basis, because all the backups in the world won't help if you can't restore.[8]

Many firms trust a green checkmark that says the backup ran and have never actually performed a test restore. Modern ransomware specifically hunts for and encrypts backups, so a backup that isn't isolated may already be compromised.

Where the right IT partner helps: A partner can move you to immutable, isolated backups and run scheduled test restores, so recovery is something you've proven rather than something you hope works.

10. One Person, or Nobody, Owns Security

At a lot of firms, cybersecurity is a side job for the office manager or the one attorney who likes computers. That works until that person is on vacation, leaves, or simply can't keep up with threats that change weekly.

Security is now a full-time discipline that runs around the clock. A part-time owner can't monitor at 2am, and attackers know most firms aren't watching then.

Where the right IT partner helps: A partner gives you a whole team and 24/7 monitoring instead of a single point of failure, plus a vCIO who owns the strategy so security stops depending on one person's spare time.

The Bottom Line

None of these signs means your firm is careless. They mean technology outran a setup that was fine a few years ago, which is the normal path for a busy firm with a small IT footprint.

The good news is that every one of these is fixable, and most fixes cost far less than a single incident. The firms that handle 2026 and 2027 well are the ones that treat security as an ongoing discipline with clear ownership, not a box checked once at renewal.

That's the work Framework IT does for law firms every day: layered defenses, tested recovery, documented controls that satisfy insurers and clients, and a team that owns it around the clock. Framework IT is a Chicago-based managed IT services firm founded in 2008, with a team of more than 40 professionals, most of them engineers who live in the Chicagoland area. We help law firms and other professional services organizations with IT support, strategy, and security, and with putting structure around AI so it can be used safely.

If a few of these signs hit close to home, schedule a conversation with our team for a straight assessment of where your firm stands: frameworkit.com/discoverycall

About the Author

Adam Barney is President and Managing Partner of Framework IT, a Chicago-based managed IT services firm he's helped lead for more than 15 years. He and his team of 40+ professionals specialize in IT support, strategy, and cybersecurity for small and mid-sized businesses. Adam's insights on business technology have been featured in the Harvard Business Review, the Washington Post, and Fox 32 Chicago.

Citations

Every statistic above is sourced to a live page that states it. Verify links are live before publishing.

[1] 54% of attorneys report having multi-factor authentication (two-factor authentication, in the survey's wording) available; Microsoft data shows MFA stops 99.9% of credential-based account attacks. ABA 2023 Cybersecurity TechReport / 2023 Legal Technology Survey. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[2] 34% of firms have an incident response plan; 19% at firms of 2-9 lawyers and 19% for solo attorneys. ABA 2023 Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[3] The global average time to identify and contain a breach was 241 days in 2025 (the lowest in nine years); global average breach cost was 4.44 million dollars. IBM 2025 Cost of a Data Breach Report. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai

[4] 29% of firms have had a full security assessment performed by a third party. ABA 2023 Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[5] 40% of firms carry cyber liability insurance, down from 46% the prior year. ABA 2023 Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[6] 53% of legal professionals say their firm has no AI policy or are unaware of one (Clio 2025 Legal Trends Report, via 2Civility); 54% of firms provide no training on responsible AI use (8am 2026 Legal Industry Report, ABA Law Practice Magazine). https://www.2civility.org/2025-clio-legal-trends-report/ ; https://www.americanbar.org/groups/law_practice/resources/law-practice-magazine/2026/march-april-2026/8am-legal-industry-report/

[7] 22% of firms had been asked by a client to complete a security questionnaire and 27% to provide a security requirements document, reaching 50% at firms of more than 100 lawyers. ABA 2023 Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[8] The ABA advises that backups be engineered to survive a ransomware attack and tested periodically with test restores. ABA 2023 Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/

[9] A high level of shadow AI added an average of 670,000 dollars to breach costs; 97% of organizations with an AI-related incident lacked proper AI access controls. IBM 2025 Cost of a Data Breach Report. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai