
Law Firm Cybersecurity Risks: What Florida Bar Rules Require | GoCo
Law firm cybersecurity risks go beyond your engagement letter - see what Florida Bar Rules 4-1.6 and 4-5.3 already require. ⚖️ Learn more.
Law firm cybersecurity risks rarely start with a sophisticated attacker. They start with an IT vendor who was never asked to sign a confidentiality agreement, a login with no second factor, or a duty to safeguard client information that everyone assumes is being met without anyone having checked. A firm's engagement letter protects the client relationship - it says nothing about whether the firm's own systems would hold up under a real incident. Below are the practices that most directly change what a breach costs a law firm, and the specific professional-conduct obligations most firms assume are already handled.
What Law Firm Cybersecurity Risks Actually Cost
Legal services carry an average breach cost of $5.08 million per incident (IBM Cost of a Data Breach Report, 2024 figures - IBM's 2026 report does not break out a separate legal-services category, so this is the most recent primary figure available). IBM prices a breach primarily by records compromised, at roughly $192 per record - which is why a small firm's real exposure looks nothing like a large practice's, even handling similar matters. Six factors move that number up or down more than any others: security AI and automation (-$1.93M), a written AI usage policy with access controls (-$670K when present), detecting and containing an incident inside 200 days (-$1.33M), encryption at rest and in transit (-$213K), a recent review of vendor security practices (-$227K), and staying current on the compliance requirements that apply to you (-$201K). Each section below is one of those levers, or a professional-conduct obligation that compounds them.
Multi-Factor Authentication and Same-Day Access Removal
Stolen or reused credentials remain one of the most common ways attackers get into a network in the first place - a password alone is rarely enough friction to stop someone determined to get in. MFA on every account that can reach client files closes that gap directly. The quieter version of the same risk is offboarding: an associate, paralegal or contractor who changes roles or leaves the firm but keeps access for days or weeks. Every login a former employee could still use is a login your firm isn't watching. Pair MFA with a same-day access-removal checklist owned jointly by HR and IT, not left to whoever remembers.
Encrypting Client Files at Rest and in Transit
Encryption doesn't stop every attack, but it changes what an attacker gets when one succeeds - the difference between a breach of exposed case files and a breach of unreadable ones. A firm that encrypts client data at rest (document management systems, laptops, backups) and in transit (email, file transfers, client portals) is directly reducing both its exposure and its real breach cost, and it's a concrete way to demonstrate the "reasonable efforts" a firm's duty of confidentiality requires.
Incident Response and How Fast You Detect a Breach
The gap between when a breach happens and when it's caught and contained is one of the largest cost drivers IBM measures. A written incident response plan matters less for the document itself than for what it forces you to know in advance: who gets called first, which systems get isolated, and how you'd notify affected clients if you had to. If you've never tested that plan, you don't know your real response time - you know your assumption about it.
Vendor and Third-Party Risk Review
Every firm accumulates vendors: the practice-management platform, the document management system, the e-discovery tool, the cloud backup provider, the IT managed service provider itself. Each one that can reach client data is a door into your systems that isn't yours to lock. Reviewing vendor security practices - not just collecting a signed contract, but confirming what they actually do - is worth up to $227K in avoided breach cost according to IBM's 2026 data, and it directly supports a firm's duty to supervise the nonlawyers it relies on.
Staying Current on Regulatory Compliance
Compliance requirements don't hold still: state breach-notification laws vary and are periodically updated, professional-conduct guidance on technology competence continues to evolve, and client-imposed security requirements (particularly from institutional and corporate clients) tend to get stricter, not looser. "Current" doesn't mean a policy from a few years ago - it means someone owns the question of what changed and when your practices were last checked against it.
Vendor Confidentiality Agreements and Your Duty to Supervise
Florida Bar Rule 4-5.3 requires attorneys to make reasonable efforts to ensure nonlawyers they retain - including IT vendors and managed service providers - act in a way compatible with the lawyer's own professional obligations. In practice, that means every IT vendor with access to client data needs a contract that includes confidentiality terms specific to that duty, not a generic services agreement. If your firm's IT vendor contract has never been reviewed against this specific requirement, that's a supervision gap, not a technology gap.
"Reasonable Efforts" Safeguards Under Rule 4-1.6
Florida Bar Rule 4-1.6 requires a lawyer to make reasonable efforts to prevent unauthorized access to, or disclosure of, information relating to the representation of a client. "Reasonable efforts" isn't a fixed checklist - it's assessed against the sensitivity of the information, the cost and difficulty of safeguards, and the extent to which safeguards would interfere with the representation. A firm that can document what it does - and why those measures are proportionate to what it protects - is in a fundamentally different position than one that has never written any of it down.
Florida's 30-Day Breach Notice Deadline, and What to Do Next

Florida's Information Protection Act (Fla. Stat. § 501.171) requires notifying affected individuals within 30 days of discovering a breach involving their personal information - a deadline that only helps if a firm has a written procedure ready before an incident, not one improvised during it. These law firm cybersecurity risks share a pattern: MFA, encryption, a tested response plan, reviewed vendors, current compliance, supervised IT vendors, documented reasonable efforts, and a notice procedure you've actually planned for. The firms that hold up under a real incident are the ones that checked.
Could you show a client, or the Bar, that your firm's efforts were reasonable?
Rule 4-1.6 and Florida's 30-day notice deadline do not wait for a convenient moment, and neither do attackers going after firms that hold privileged client data. The firms that come out well are the ones that documented their safeguards before anything happened.
In a short meeting, our team will walk through where you stand today, which gaps carry the most risk, and what to fix first. Pick a time that works for you.
Book your meeting with our team
Because better decisions start with better understanding.
Good Company IT
GoCo
You are in Good Company