Client Confidentiality Ends at Your Firewall

July 22, 2026  |  Technology

by:admin July 22, 2026 0 Comments

Every attorney understands confidentiality as an ethical obligation. Fewer have thought about it as a technical one.

The duty is familiar and absolute: client information stays private. What has changed is that the duty now depends almost entirely on systems most firms have never examined. You can conduct every conversation carefully, shred every document, and maintain perfect discretion in public — and still have client files sitting on a server that anyone with a stolen password could reach from anywhere in the world.

Privilege protects information from disclosure in legal proceedings. It offers no protection whatsoever against someone simply taking it.

Why firms this size get attacked

There’s a persistent assumption in smaller practices that attackers are interested in large firms with large matters. The economics point the other way.

A single small firm may hold financial disclosures from a dozen divorces, medical records attached to injury claims, business terms from commercial matters, and personal details for every client it has ever represented. That’s a concentrated collection of exactly the information attackers monetise, and it sits behind defenses that are typically far lighter than a large firm’s.

There’s also leverage that most businesses don’t offer. A manufacturer facing encrypted files loses production. A law firm facing the threat of published client files faces something closer to an existential problem, and attackers price accordingly. Confidentiality isn’t a feature of the service — it is the service.

Then there’s money in motion. Firms handling real estate closings, settlements, and trust accounts move funds on a predictable schedule, and a compromised email account gives an attacker visibility into exactly when.

The attack that costs firms the most

It isn’t ransomware, though that gets the attention.

It begins with a fake login page — a message about a shared document, a password expiry notice, a court filing alert. Someone enters their credentials during a busy afternoon and nothing visible happens. The attacker now has legitimate access to a real mailbox.

Then they wait, and read. They learn which matters are approaching closing, how the firm communicates with clients, who authorises payments, and how the partners write. Some set up quiet mail rules so their activity stays invisible to the account’s actual owner.

At exactly the right moment — a settlement disbursement, a property closing — they send updated wire instructions from that genuine firm address, inside a conversation that has been running for weeks. Everything about the message is authentic except its purpose. The funds leave before anyone notices, and the firm frequently only learns what happened when a client calls to ask why the money hasn’t arrived.

Real estate and settlement practices are hit hardest by this, because large transfers on known schedules are precisely what the attack is designed to intercept.

Two things stop most of it. Multi-Factor Authentication prevents the account access in the overwhelming majority of cases. And a verification habit — confirming any change to payment instructions by telephone, using a number already on file rather than one supplied in the email — catches what gets through. The second costs nothing at all and is worth adopting today, regardless of anything else.

Where professional responsibility enters

This is the part that separates a law firm’s exposure from an ordinary business’s.

Rules of professional conduct require competence in safeguarding client information. That obligation doesn’t specify particular technologies, but it does distinguish between a firm breached despite reasonable defenses and a firm breached because basic measures were never in place.

The practical consequence is that the review following an incident asks what you had done, not merely what happened. A firm that can show enforced MFA, tested backups, documented training, and monitored systems is in a materially different position from one that can show good intentions.

There’s a related consideration around notification. California’s requirements are among the more demanding in the country, and for a firm the disclosure may extend beyond affected individuals to opposing parties and courts, depending on the matters involved. The notification becomes a public record of the incident, which is a difficult document to have circulating in a market where firms refer work to one another.

The controls that actually matter

The reassuring reality is that most successful attacks exploit a small number of gaps, and closing them isn’t complicated.

Multi-Factor Authentication on every account, with no exceptions for partners. Those accounts hold the broadest access and their messages carry the most authority, which is exactly why they’re targeted. Partial coverage is what attackers look for.

Email threat filtering, since nearly every incident begins with a message. Good filtering removes most of them before anyone has to exercise judgment about a plausible-looking invoice at five o’clock on a Friday.

Endpoint detection and response, which watches for suspicious behaviour rather than recognising known threats. This is how ransomware gets caught during the weeks an attacker spends mapping a network before triggering encryption.

Secure client file sharing. Email attachments are the wrong mechanism for privileged documents — no access control, no audit trail, and copies scattered across mailboxes indefinitely. A proper portal gives clients a better experience and gives the firm a record of what was shared with whom.

Verified, off-site backups. A backup that has never been restored is an assumption. Ransomware specifically hunts connected backup storage, so where the copy lives matters as much as whether it exists. Our backup and disaster recovery service is built around exactly that.

Our cybersecurity services run these as one coordinated layer, and our managed IT services keep them monitored — because MFA coverage drifts as staff join and leave, and a control nobody reviews stops being effective within months.

The question clients have started asking

Something has shifted quietly over the past few years.

Corporate and institutional clients increasingly send security questionnaires to outside counsel. Some now require evidence of specific controls before engagement. Insurers ask the same questions at application and again at renewal — and the application is a legal document, with claims having been reduced where a firm attested to controls it didn’t actually have.

Consider two responses to the same questionnaire. One firm writes that it takes confidentiality seriously and uses strong passwords. Another states that MFA is enforced firm-wide, backups were tested on a specific date with documented results, staff complete training quarterly, and systems are continuously monitored — and attaches the records.

The second firm wins that engagement. Increasingly, the first never reaches the conversation at all.

That’s the shift worth noticing. Security has moved from something firms do quietly to something they may need to demonstrate in order to win work.

A note for smaller practices

There’s an assumption that a three-attorney firm needs less than a thirty-attorney firm. In scale, obviously. In requirements, considerably less so.

A solo practitioner handling family law holds the same categories of sensitive information as a larger firm — financial disclosures, custody matters, circumstances clients would be distressed to see exposed. The confidentiality obligation doesn’t scale with headcount, and a client’s expectation certainly doesn’t. Neither does the security questionnaire, which has no small-firm version.

What does change is how easily this gets fixed. Enforcing MFA across a five-person firm is an afternoon’s work. Establishing a payment verification habit is a single conversation everyone actually remembers. Getting backups tested and replicated off-site is a straightforward project.

The disadvantage smaller firms face isn’t cost. It’s that nobody’s job includes thinking about any of this — and in Placerville and the surrounding foothill communities, where specialist support has historically been thin, that gap tends to persist longer than it should.

Where to start

Three questions will establish where your firm stands. Ask whether MFA is enforced on every account including partners. Ask what date the last actual restore test happened. Ask what your procedure is when a client’s payment instructions change.

Vague answers to any of those tell you where to begin, and none of them are expensive to resolve.

RJ PRO Tech Group works with Placerville law firms to make confidentiality hold at a technical level as well as an ethical one, with a Help Desk that responds in minutes when something needs attention during a filing week.

Schedule a complimentary IT assessment for your Placerville firm. We’ll show you exactly where your exposure sits — before someone else finds it

Categories:

Get Access To Your Free White Papers

Enter your details and we’ll take you straight to the download page.