Cybersecurity

Law Firms and Cloud Security

Cloud tools move faster than security policy at most law firms, and the rules of professional conduct don't leave room for that gap. This piece looks at what's actually putting client data at risk and what closes it.

Blog Post

7 minute read

Sep 10, 2026

Cloud adoption in the legal industry moved quickly. Firms shifted document management, practice management, and e-discovery to cloud platforms because the tools work better and clients expect faster turnaround.

Security practices didn't always move at the same pace.

Law firms and cloud security are no longer separate conversations a firm can have independently. The tools and the protections around them have to be planned together.

That gap carries more weight in legal than in most industries. Attorneys hold information other people would pay to see: merger details before they go public, litigation strategy, trade secrets, financial records tied to estate planning or family law.

A breach at a law firm isn't only a financial event. It can trigger review under the rules of professional conduct that govern every practicing attorney, since client confidentiality is an ethical obligation, not just a business practice.

The scope of the problem shows up in the American Bar Association's own numbers. In its 2023 Cybersecurity TechReport, 29% of responding firms reported experiencing a security breach, up from 27% the year before.

Only 34% had a formal incident response plan in place, down from 42% the prior year. The share of firms carrying cyber liability insurance dropped from 46% to 40% over the same period.

Coverage and preparation moved in the wrong direction while risk moved in the other.

Data is the world’s most valuable currency, and you need to protect your firm. Find out how hackers think in Impact’s webinar, How to Hack Your Business.  

Cyber Threats to Law Firms Look Different Than in Other Industries

Most cyberattacks are opportunistic. Attackers scan for open doors and take whatever they find behind them.

Law firms face that same baseline risk, plus something else. Attackers know a firm's cloud environment often holds sensitive data belonging to dozens of clients at once. That concentration makes law firms a more efficient target than most.

Phishing remains the most common entry point, and it works for a simple reason. Attorneys and staff handle a high volume of email from unfamiliar senders as part of normal casework, so a convincing message blends in more easily than it would in a lower-volume inbox. 

39% of firms reported a breach in the past year

Ransomware groups have taken notice too. Legal work depends on continuous access to case files and client records, which gives a firm a strong incentive to pay quickly rather than rebuild from backups under deadline pressure.

The shift to cloud-based tools adds a layer attorneys don't always think about. Cloud vendors and their legal clients share responsibility for security, and the line between them isn't always obvious.

Cloud providers secure their own infrastructure, but configuration, access permissions, and user behavior stay with the firm. A misconfigured sharing setting or an account without multifactor authentication can undo the security the platform itself provides.

Law Firm Security Requirements Come From the Rules of Professional Conduct, Not Just IT Policy

Security in a law firm isn't optional in the way it might be framed elsewhere. Model Rule 1.1 requires attorneys to maintain competence in the technology they use to represent clients.

Model Rule 1.6(c) goes further, requiring reasonable efforts to prevent unauthorized access to or disclosure of client information.

"Reasonable" doesn't mean perfect. Comment 18 to Rule 1.6 lays out the factors that determine what's reasonable for a given firm: the sensitivity of the information, the likelihood it could be exposed without added safeguards, the cost and difficulty of those safeguards, and how much they'd interfere with representing clients effectively.

A solo practitioner and a 200-attorney firm won't meet that standard the same way, but both are held to it.

The ABA has issued formal guidance on how this applies in practice, including Formal Opinion 477R on securing client communications, Formal Opinion 483 on a lawyer's duties following a data breach, and Formal Opinion 498 on safeguards for virtual practice.

Most state bars have issued their own opinions on cloud computing specifically, and requirements vary by jurisdiction. Firms with attorneys licensed in multiple states need to account for more than one standard.

What Law Firm Data Protection Looks Like in the Cloud

None of this requires abandoning cloud tools. It requires treating security as part of how those tools get implemented, not an afterthought layered on top.

Multifactor authentication is the clearest example. It's available on nearly every cloud platform firms already use, yet only 54% of firms in the ABA survey had it enabled.

Turning it on closes off one of the most common paths attackers use to get into an account, and it costs nothing beyond the time to set it up.

Access controls matter just as much. Not every person at a firm needs access to every matter, and cloud platforms make it straightforward to limit permissions by role or by case team.

Reviewing who has access to what on a regular schedule, rather than only when someone leaves the firm, closes gaps that build up quietly over time.

An incident response plan belongs on that same list. Firms with a plan in place respond faster and with less confusion than firms improvising during an active incident, but only about a third of firms have one.

Building the plan before it's needed, and testing it, is the difference between a contained incident and a prolonged one.

Vendor due diligence closes the loop. Before moving a system to the cloud, firms should understand exactly what the provider secures and what stays the firm's responsibility, in writing.

That shared responsibility model is standard across cloud providers, but it only works if both sides understand where the line falls.

The financial stakes back this up. The global average cost of a data breach reached $4.44 million in 2025, and firms handling privileged, high-value information have less room to treat that number as someone else's problem.

Third-Party Vendors Extend the Attack Surface Beyond the Primary Cloud Provider

A firm's cloud security isn't defined by one platform. Practice management software, e-discovery platforms, billing systems, and client portals each hold a slice of the same sensitive data, often through a different vendor with its own security posture.

The 2023 MOVEit Transfer vulnerability made that risk concrete. Attackers exploited a flaw in file-transfer software used by multiple law firms, exposing privileged communications and client financial and medical information at firms that had no direct security failure of their own.

Vendor due diligence has to extend past the primary cloud provider. Security questionnaires, contractual breach-notification clauses, and visibility into a vendor's own subprocessors close a gap internal controls can't reach alone.

The same logic applies to AI-enabled legal tools, which are becoming a standard part of the tech stack. Contracts should specify whether client data trains a vendor's models, and who reviews AI-generated work before it reaches a client or the court.

Key Takeaways

Law firms hold concentrated, high-value data that makes them efficient targets, and cloud adoption has expanded the attack surface without a matching increase in security policy at most firms.

Client confidentiality is an ethical obligation under Model Rules 1.1 and 1.6(c), not only a business or IT concern, and several ABA formal opinions define what "reasonable" security looks like.

Multifactor authentication, scheduled access reviews, a tested incident response plan, and clear vendor due diligence are practical, low-cost steps that close the most common gaps.

Security requirements vary by state bar, so firms with attorneys licensed in multiple jurisdictions should confirm they're meeting each one.

Wrapping Up on Law Firms and Cloud Security

Cloud platforms aren't the risk. Unmanaged access, missing multifactor authentication, and the absence of a response plan are the risk, and all three are fixable without slowing down the work attorneys need cloud tools to do in the first place.

Firms who treat security as part of their ethical obligation to clients, rather than a separate IT project, tend to close these gaps before they turn into a breach.

None of this is a one-time project. Threats change, vendors change, and the tools a firm relies on today will look different in two years.

Treating cloud security as a standing part of how the firm operates, reviewed on a regular schedule rather than after an incident, is what keeps the rest of this guidance current.

When clients give you their data, they’re also giving you their trust. Find out how hackers think and how you can protect sensitive data in Impact’s webinar, How to Hack Your Business

Andrew Mancini headshot

Andrew Mancini

Content Writer

Andrew Mancini is a Content Writer for Impact's in-house marketing team, where he plans content for the Impact insights hub, manages the publication schedule, drafts articles, Q&As, interview narratives, case studies, video scripts, and other content with SEO best practices. He is also the main contributor on a monthly cybersecurity news series, The Security Report, researching stories, writing the script, and delivering the report on camera.

Read More About Author

Tags

CybersecurityDigital TransformationMitigate Cyber RisksLegal

Share

Additional Resources

An image of a cloud behind multiple internet capable devices with a bunch of metrics and data flows displayed

Blog Post

Creating a Cloud Transformation Strategy

A cloud transformation journey includes several steps including: assessment, goal setting, research, migration, optimization, expansion, and ultimately – transformation.

FPO

Elevate Your Business Today

Speak to one of our experts about how you can apply innovative strategies and solutions to your business.

Get Started

Business Tech Insights Straight to You

Subscribe to our newsletter and get all our insights, videos, and other resources delivered to your inbox.

Subscribe Now

Impact Insights

Sign up for The Edge newsletter to receive our latest insights, articles, and videos delivered straight to your inbox.

More From Impact

View all Insights