1. Identity and email
Require MFA, minimize administrator access, protect account recovery, secure email domains, detect suspicious mailbox activity, and give staff a clear process for escalating unusual messages.
Law Firm Cybersecurity
A small law firm needs more than security software. A defensible baseline connects identity, email, devices, client information, payment verification, backups, vendors, incident response, staff behavior, and cyber insurance expectations to clear owners and evidence that the controls are actually operating.
A small law firm should establish strong identity and MFA controls, secure email and devices, independently verify payment changes, protect and recover client data, manage vendors, patch systems, train personnel, monitor for suspicious activity, maintain an incident-response process, and periodically verify that those safeguards still operate as intended.
Require MFA, minimize administrator access, protect account recovery, secure email domains, detect suspicious mailbox activity, and give staff a clear process for escalating unusual messages.
Manage firm devices, keep software current, use endpoint protection, encrypt sensitive data where appropriate, control file sharing, remove stale access, and define secure remote-work practices.
Independently verify new or changed payment instructions, use dual review for material transfers, protect finance workflows, and document exceptions so a compromised email account cannot authorize money movement by itself.
Maintain recoverable backups, monitor critical activity, prepare an incident-response process, know who to contact after fraud or compromise, and test recovery and response rather than assuming the plans will work.
Every recurring safeguard should have a named owner who knows what must be done, how often it occurs, what requires escalation, and who reviews the result.
Do not mark a control complete because a tool was purchased or a policy exists. Define the configuration, coverage, workflow, exceptions, and operating evidence required for the control to be considered implemented.
Examples include MFA coverage, device inventories, endpoint status, patch reports, access reviews, backup tests, training records, vendor reviews, incident exercises, and remediation tickets.
Reassess security after major staffing, technology, vendor, office, insurance, client, or threat changes, and establish a recurring review instead of waiting for an incident.
A checklist can reveal missing areas, but it does not prove that controls are properly designed or operating. The firm still needs to verify coverage, investigate exceptions, document evidence, and prioritize gaps based on its actual risks and client obligations.
Last reviewed August 10, 2026. This checklist uses current CISA small-business security guidance and FBI/IC3 business email compromise guidance. Firms should adapt controls to their actual systems, risks, and professional obligations.
Use these resources to move from a practical security baseline into business email compromise prevention, evidence preparation, and a structured security assessment.
Use the Smart Security Snapshot to identify critical security risks and build a practical 90-day roadmap. If cyber insurance is the immediate trigger, review the Cyber Insurance Readiness service.