Law firms run on two things: billable time and client trust.
In 2026, technology sits underneath both, and the ground is moving fast.
Generative AI went from novelty to daily habit in about a
year. Attackers got more patient and more targeted. Cyber insurers rewrote
their checklists. And clients started asking harder questions about how their
data is protected.
For a firm with 10 to 300 people, that adds up to real
pressure on a small IT footprint. Here are the 10 IT challenges hitting law
firms hardest heading into 2026 and 2027, and what separates the firms that
handle them well from the ones that get caught flat.
1. Shadow AI and the Governance Gap
Generative AI use among legal professionals more than
doubled in a single year, from 31% in 2025 to 69% in 2026, according to the 8am
2026 Legal Industry Report published in the American Bar Association's Law
Practice Magazine.[1]
Lawyers are drafting, researching, and summarizing with tools like ChatGPT,
Gemini, and Claude every day.
The trouble is what sits underneath. That same report found
54% of firms provide no training on responsible AI use and no plans to add it.[2]
When a firm bans AI outright or says nothing, attorneys don't stop using it.
They move to free consumer tools on personal devices, and the firm loses any
line of sight into where client data goes. That is shadow AI, and it puts
privilege and confidentiality directly at risk.
Where the right IT partner helps: The firms getting this right put structure
around AI before they scale it: a written usage policy, a review step before
new tools go live, and clear rules on what client data a tool may touch. A managed IT partner can stand up that framework and give staff
a safe, approved way to use AI.
2. Targeted Ransomware and Longer Dwell Times
Law firms are a high-value target because of what they hold:
M&A intelligence during live deals, litigation strategy before trial, and
decades of confidential client files. Attackers increasingly take their time
once inside, quietly mapping the most sensitive material before they strike, so
the timing does maximum damage.
The exposure is already widespread. In the American Bar
Association's 2023 Legal Technology Survey, its most recent comprehensive
dataset, 29% of firms reported having experienced a security breach, a category
that runs from a lost or stolen device to a full network intrusion.[3]
The same report flags a rise in law firm data breaches specifically, and notes
that affected firms are increasingly named in the class-action suits that
follow.
Where the right IT partner helps: Signature-based antivirus misses this kind
of slow, targeted intrusion. Behavior-based endpoint detection paired with a 24/7 security operations
center catches the activity while attackers are still moving, not after the
files are gone.
3. Cyber Insurance Requirements Keep Tightening
Cyber
liability coverage once felt like a form and a signature. Today it looks
more like a technical audit. Carriers now expect phishing-resistant
multi-factor authentication (MFA) on email, remote access, and cloud admin
accounts, plus endpoint detection, tested backups, and a documented incident
response plan. Firms that cannot show those controls face higher premiums,
coverage sub-limits, or outright denial.
Cost pressure is already pushing firms out of the market.
The ABA found only 40% of firms carry cyber liability insurance, down from 46%
the year before.[4]
Dropping coverage right as requirements tighten leaves a firm exposed on both
sides.
Where the right IT partner helps: Think of security spend as the premium you
pay to keep a known risk within your policy limits. A partner who builds your
controls to match the carrier checklist, and documents them, turns a painful
renewal into a routine one.
4. Confidentiality and Ethics Compliance
A law firm's duty to protect client information is not
optional. ABA Model Rule 1.6 requires reasonable efforts to prevent
unauthorized disclosure, and Rule 1.1 now folds in a duty of technology
competence. State bars are layering their own data-security expectations on
top.
Most firms are underprepared for the moment an incident
actually hits. Only 34% of firms have an incident response plan, and at firms
of 2 to 9 lawyers that drops to 19%.[5]
Without a plan, a bad day becomes a compliance failure.
Where the right IT partner helps: Compliance is mostly about controls and
documentation you can show later. A virtual chief information officer (vCIO) can map your environment to Rule 1.6
expectations, build the incident response plan, and keep the evidence current,
so an ethics question has a clear answer.
5. Clients Are Auditing Your Security
Corporate clients increasingly treat their outside counsel
as an extension of their own attack surface. Outside counsel guidelines,
security questionnaires, and even audits are now part of winning and keeping
work, especially with clients in finance, healthcare, and technology.
This is already common and rising. In the ABA survey, 22% of
firms had been asked by a client to complete a security questionnaire and 27%
to provide a security requirements document, with those numbers reaching 50% at
firms of more than 100 lawyers.[6]
Security has become a business-development issue, not just an IT one.
Where the right IT partner helps: Documented controls and audit-ready
reporting turn a long security questionnaire from a fire drill into a
copy-and-paste exercise, and a credibility win in front of the client.
6. Aging Practice Management and the Cloud Migration
Question
Many firms still run document and practice management on
older on-premise systems that are hard to reach securely from outside the
office and awkward to connect to newer tools. The pressure to move to cloud
platforms is rising, both for anywhere access and because the best AI and
automation features are being built cloud-first.
Migration is where firms get hurt. Move too fast and you
break integrations or lose matter history. Move with no plan and you carry old
risk into the new environment.
Where the right IT partner helps: This is a roadmap problem before it is a
technology problem. A vCIO sequences the migration around your matters and
deadlines, so nothing gets dropped and the new platform is actually more secure
than the old one.
7. Securing a Permanently Hybrid Workforce
Hybrid work is settled, not temporary. Attorneys and staff
work from home, the courthouse, and client sites, often on a mix of firm and
personal devices. Every one of those endpoints is a door into confidential
matter data.
The basics are still not universal. Only 54% of attorneys
report that multi-factor authentication is even available to them, despite
Microsoft's finding that MFA blocks 99.9% of credential-based account attacks.[7]
Security has to follow the people, not the building.
Where the right IT partner helps: Managed, encrypted endpoints, enforced MFA,
and secure remote access let your team work from anywhere without turning
mobility into your biggest exposure. That means more advanced endpoint
protection like Endpoint Detection and Response (EDR) and Managed Detection and
Response (MDR), stricter access controls, advanced email security, regular
security awareness training, and more.
8. Data Retention, E-Discovery, and Information Sprawl
Firms accumulate data for decades: closed matters, email
archives, discovery sets, and duplicate copies scattered across systems.
Retention obligations vary by matter and jurisdiction, and holding everything
forever is both a storage cost and a bigger target if you are breached.
Without a clear information governance policy, most firms
cannot quickly answer a simple question: what do we have, where is it, and who
can see it?
Where the right IT partner helps: A structured approach to retention, access
control, and reliable backup shrinks both your storage bill and the blast
radius of any single incident.
9. Downtime That Stops the Billable Clock
For a law firm, downtime is not an inconvenience, it is
revenue walking out the door. When systems are locked or offline, billable work
stops, partners field anxious client calls instead of doing client work, and
deadlines do not move to accommodate an outage.
Backups are supposed to be the safety net, but they only
help if they survive the attack and actually restore. The ABA's 2023 TechReport
is blunt on this: backups should be engineered to survive a ransomware attack
and tested on a periodic basis, because a backup you have never restored from
is a backup you cannot count on.[8]
Where the right IT partner helps: Proactive maintenance prevents most outages,
and tested backup and disaster recovery makes the rest survivable, so a bad day is
measured in hours instead of weeks.
10. Stretched or Nonexistent Internal IT
Most firms in this range run lean: one overloaded IT person,
an office manager who inherited the job, or no dedicated IT at all. That works
until it doesn't, and it puts the whole firm one resignation or one sick week
away from a gap. Meanwhile the tool stack keeps growing and the security and
compliance bar keeps rising, which is more than a single generalist can carry.
The gap shows up most in the work that never feels urgent
until it is: patching, backup testing, security training, and incident response
planning.
Where the right IT partner helps: A co-managed model gives a solo IT person a
full team of specialists behind them across security, cloud, and strategy, and
gives a firm with no IT a single accountable partner. The goal is to strengthen
your team, not replace it.
The Bottom Line
The through-line across all 10 is that law firm IT stopped
being a back-office cost and became a client-trust and risk issue. AI, cyber
insurance, client audits, and ethics rules all point the same direction: firms
are expected to manage technology deliberately, document what they do, and
prove it on demand.
The firms that treat IT strategically, with proactive
management, a real security posture, and a roadmap tied to how they actually
practice, will spend 2026 and 2027 competing on their work. The ones that stay
reactive will spend it explaining incidents.
Framework IT is a Chicago-based managed IT services firm
that works with law firms and other professional services organizations across
the country. We specialize in IT support, strategy, and security for growing
firms, with a team of more than 40 professionals, most of them engineers based
in the Chicagoland area.
Schedule a conversation with our team to see what managed
IT can look like for your firm: frameworkit.com/discoverycall
About the Author
Adam Barney is President and Managing Partner of Framework
IT, a Chicago-based managed IT services firm he's helped lead for more than 15
years. He and his team of 40+ professionals specialize in IT support, strategy,
and cybersecurity for small and mid-sized businesses. Adam's insights on
business technology have been featured in the Harvard Business Review, the
Washington Post, and Fox 32 Chicago.
Citations
Every
statistic above is sourced to a live page that states it. Verify links are live
before publishing.
[1] Generative AI use among legal professionals
rose from 31% (2025) to 69% (2026). 8am 2026 Legal Industry Report, "AI
for Law Firms," published in ABA Law Practice Magazine as sponsored
content. https://www.americanbar.org/groups/law_practice/resources/law-practice-magazine/2026/march-april-2026/8am-legal-industry-report/
[2] 54% of firms provide no training on responsible
generative AI use and have no plans to add it. 8am 2026 Legal Industry Report,
"AI for Law Firms," published in ABA Law Practice Magazine as
sponsored content. https://www.americanbar.org/groups/law_practice/resources/law-practice-magazine/2026/march-april-2026/8am-legal-industry-report/
[3] 29% of firms reported having experienced a
security breach (a category the report notes includes incidents such as a lost
or stolen device, not only data breaches). American Bar Association, 2023 Legal
Technology Survey Report / 2023 Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[4] 40% of firms carry cyber liability insurance,
down from 46% the prior year. American Bar Association, 2023 Cybersecurity
TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[5] Only 34% of firms have an incident response
plan; 19% at firms of 2-9 lawyers. American Bar Association, 2023 Cybersecurity
TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[6] 22% of firms were asked by a client to complete
a security questionnaire and 27% to provide a security requirements document;
up to 50% at firms of 100+ lawyers. American Bar Association, 2023
Cybersecurity TechReport. https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[7] 54% of attorneys report MFA is available to
them; Microsoft reports MFA blocks 99.9% of credential-based account attacks
(cited within the report). The survey uses the term two-factor authentication
(2FA), which it treats as equivalent to MFA. American Bar Association, 2023
Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/
[8] Backups should be engineered to survive a
ransomware attack and tested on a periodic basis. American Bar Association,
2023 Cybersecurity TechReport.
https://www.americanbar.org/groups/law_practice/resources/tech-report/2023/2023-cybersecurity-techreport/