Key Takeaways
- Law firm cybersecurity is really a client confidentiality problem wearing technical clothing.
- You know your professional obligations better than any IT provider does. The useful question is whether your systems actually support them.
- Wire fraud around closings and disbursements is the most realistic threat to most practices, and the defense is a process rather than a product.
- Matter-level access control is the difference between general business IT and IT built for a firm.
- If nobody can say what was accessed during an incident, that is a logging decision made long before the incident.
- In this region, client file custody and hurricane continuity are the same conversation.
Most conversations about law firm cybersecurity start in the wrong place. They start with products, and with a vague sense that the firm should probably be doing more. The better starting point is the thing your practice already runs on, which is client confidence.
Clients hand you material they would not give anyone else. Everything a firm does technically, the software, the training, the backups, exists to keep that arrangement intact. We are an IT company rather than a law firm, so we will not tell you what your professional obligations are. You already know them far better than we do. What we can tell you is where the technology underneath them tends to fall short.
Here is what law firm cybersecurity looks like in practice for a New Orleans firm, and where the gaps usually sit.
Law Firm Cybersecurity Is a Confidentiality Problem, Not Just an IT One
A general business asks whether its data is safe. A firm has to be able to answer a harder question: who could have seen this, and how would we know? That is a different standard, and it changes what the technology has to do.
In practice it means access that is scoped to matters rather than granted to everyone, permissions that reflect the walls a firm needs internally, records of who reached what, and access that is actually removed when someone leaves. Most general small business IT setups do none of this, which is where law firm cybersecurity starts to diverge from ordinary IT, not because anyone was careless, but because a general setup was never asked to.
What Reasonable Protection Looks Like in Law Firm Cybersecurity
There is no universal checklist, and what is sensible for a two-lawyer practice differs from what is sensible for a fifty-lawyer firm. That said, a common core has settled: multi-factor authentication on email and anything holding client files, encryption in transit and at rest, current patching, access that is scoped and revoked, backups that have been tested by actually restoring something, and training that happens more than once.
The part firms underestimate is documentation. Protections you cannot evidence are hard to rely on later, whether the person asking is a client, an insurer or your own management committee. Knowing when controls were last reviewed, who has access to which matters, and when the last restore test ran is the difference between a clear answer and an argument.
The Questions You Will Be Asked After an Incident
Whatever a firm decides to do after a security incident, the decisions get much easier when the answers already exist. This is the part of law firm cybersecurity that is settled long before anything goes wrong. In practice three questions come up immediately: what happened, what was actually reached, and who needs to be told.
The first two are technical, and they are settled long before anything goes wrong. You cannot investigate an incident nobody detected, and you cannot determine what was accessed without logs that were already being kept. Most small firms have neither, which turns a bad week into a guessing exercise at exactly the moment precision matters most.

Wire Fraud and the Closing Table
If law firm cybersecurity has one everyday failure point, this is it. For most practices the realistic threat is not a sophisticated intrusion. It is an email asking to change payment instructions, arriving at exactly the moment a payment is due.
The scale is not speculative. The FBI’s Internet Crime Complaint Center reported more than $55.4 billion in domestic and international exposed losses from business email compromise across incidents reported between October 2013 and December 2023. That figure spans every industry, but the pattern maps precisely onto a closing or a settlement disbursement, where large sums move on a known schedule between parties who coordinate by email.
The defense is unglamorous and mostly procedural. Verify every change to payment details by telephone, on a number you already held, before acting on it. Make it a rule everyone in the firm knows, including whoever is covering reception in August, and make clear that nobody will be criticized for slowing a transaction down to make the call.
Law firm: Scoped to matters, with internal walls reflected in the permissions.
Law firm: Access removed promptly and verifiably, including on shared systems.
Law firm: Enough logging to answer what was reached, kept before you need it.
Law firm: Multi-factor authentication, logging, and a verification step for payment changes.
Law firm: Retention and disposal on a schedule the firm has actually decided.
Why Local Matters for a New Orleans Practice
Law firm cybersecurity in this region carries an extra dimension. Client files have to survive an evacuation, not merely a hard drive failure, and where your matter files live becomes a custody question rather than a convenience one.
The practical test is simple. If your office were inaccessible for two weeks in September, could the firm still meet a deadline, reach clients, and be confident that confidential material stayed protected throughout? Continuity and confidentiality turn out to be the same project.
How We Can Help
Courant has supported small and mid-sized businesses across Greater New Orleans since 1997, law firms among them. Our IT services for law firms are built around the way practices actually work, from matter-level access through to file retention, and our managed compliance services produce the documentation that lets you show what is in place rather than assert it.
Underneath that sit the same foundations every client gets. Our cybersecurity services in New Orleans cover the controls themselves, and our managed IT services in New Orleans handle monitoring, patching, backups and tested restores, which is the part that turns a policy into something real.
We will not advise you on your professional responsibilities. What we will do is make sure the technology under them holds up to scrutiny. If you are not certain it would, schedule a 15-minute consultation and we will walk through where your firm stands, or contact our New Orleans team if you would rather start with a question. You will come away knowing which gaps are real and which are not, which is useful whether or not you ever work with us.
Frequently Asked Questions
What makes law firm cybersecurity different from general business IT?
The standard a firm is held to by its own clients. A general business needs its data to be safe. A firm needs to be able to say who could have seen what, and to show it. That means access scoped to matters, internal walls reflected in permissions, logging kept before it is needed, and prompt removal of access when people leave. Most general setups do none of that.
Where do small firms most often fall short?
Two places. Email, because a compromised mailbox gives an attacker everything including the ability to impersonate the firm. And leavers, because access frequently outlives the working relationship on shared drives, practice management systems and third-party portals that nobody thought to review.
What is the most likely way a small firm gets hit?
A convincing message asking to change payment instructions, usually timed to a closing or a disbursement. It requires no technical sophistication, only knowledge that money is about to move. A telephone verification on a previously held number defeats most of it.
What should we have in place before an incident rather than after?
Detection, so you know something happened. Logging, so you can establish what was reached. And a written plan naming who makes decisions, who contacts clients, and who does the technical work. All three are far cheaper to arrange in advance than to improvise.
How does hurricane season affect this?
It makes file custody part of the same conversation. Client files need to survive the loss of the office, not just the loss of a computer, and the firm needs to keep functioning during a disruption. If nobody has tested restoring your matter files, that is the gap to close first.



