Law firm cybersecurity is the set of habits and controls that keep a firm’s website, email, accounts and client files trustworthy. For clients, it comes down to ten checkable things: the right domain, HTTPS, safe contact paths, verified payment instructions, protected logins, and honest notice if something goes wrong.

Here’s a scene that plays out in some form most weekends in Horry County. It’s past 11 p.m. in Conway. Someone has just been released after a DUI arrest, and they’re in a relative’s car with a cracked phone, searching for a lawyer. They’re scared and tired, and they’re about to hand personal details to a website they found 90 seconds ago.

That person isn’t thinking about law firm cybersecurity. They’re thinking about their license, their job, and whether they’ll be in court on Monday. But every tap they make is a trust decision, whether they notice it or not.

I start from a simple position. You don’t need to be a security engineer to judge whether a firm deserves your information. You need to know what to check. Below are ten things a client should be able to trust, and what a firm can do to earn each one.

Law firm cybersecurity starts at the address bar

1. The domain is the one they meant to visit

Scammers register look-alike domains, swapping one letter or tacking on a word like “legal” or “help.” A client in a hurry won’t catch it. Firms should use one domain everywhere, on business cards, the Google Business Profile, bar directory listings and email signatures, so the real address becomes familiar.

2. The connection is encrypted

HTTPS means data moving between the phone and the site is encrypted on the way. Chrome, Safari and Firefox all flag pages without it. But a padlock doesn’t prove a site is honest. It proves the connection is private. Scam sites get certificates too, which is why the domain check comes first.

3. The contact details match everywhere

The phone number on the site should match the one on the bar listing, the Google profile and the office door. If they don’t, ask before you share anything. For firms, a quarterly sweep of every directory listing takes about an hour and closes a quiet gap.

Secure contact paths: where trust gets tested

For a law firm, one of the most security-sensitive website actions is also one of the most ordinary: a prospective client making contact.

Johnny Gardner Law, for example, provides direct telephone and web-based contact options for people looking for DUI-defense information in Horry County. Someone researching a Grand Strand DUI lawyer may decide whether to call, use a form, or continue reading based partly on whether the site appears legitimate and trustworthy.

From a cybersecurity perspective, that raises several useful questions:

  • Is the site using HTTPS?
  • Is the contact form functioning securely?
  • Is the domain correct?
  • Are users warned against sending unnecessary sensitive information?
  • Are administrative accounts protected?
  • Does the firm have a process for suspicious email?

Those questions apply to almost every professional-services website.

4. The contact form sends data safely

A form should submit over HTTPS, land in a monitored inbox or case system, and not get copied to five personal Gmail accounts. Firms should send themselves a test message every month. A broken form loses a client. A leaky one is worse.

5. They’re told what not to send

The best forms say it plainly: don’t include Social Security numbers, account numbers or the full story of your case here. A name, a phone number and a one-line reason is enough to start. That single sentence of microcopy protects the client and the firm.

6. The phone line reaches the firm

A phone call is still one of the safest first contacts, because it moves the conversation off the web. Clients can confirm the number against a second source, like the bar directory, before they dial.

Email is where law firm cybersecurity usually breaks

The FBI’s Internet Crime Complaint Center recorded $2.77 billion in reported business email compromise losses in its 2024 Internet Crime Report. Law firms make natural targets. They move retainers, settlement funds and real estate closing money, often by wire.

7. Payment instructions never change by email alone

This is the one rule I’d print on every engagement letter: we will never change wiring instructions by email. If a client gets a message saying the account has changed, they should call a number they already have, not one in the message.

If an email changes where the money goes, the answer is a phone call, not a reply.

8. There’s a process for suspicious email

Staff should know exactly who to tell when a message feels off, and they shouldn’t feel foolish for asking. A five-minute check beats a five-figure wire recall. Our phishing briefings walk through the signs that show up most often.

Behind the login screen

In the American Bar Association’s 2023 Cybersecurity TechReport, 29% of responding lawyers said their firm had experienced a security breach. Another 19% didn’t know. That second number worries me more. You can’t fix what nobody’s watching.

9. Administrative accounts are locked down

The website admin panel, email, case management and cloud storage each need a unique password and multi-factor authentication. This month The Hacker News reported a campaign that got into Microsoft 365 accounts using default passwords. That’s a fixable problem. A password manager and an authenticator app handle most of it, and our guides to password security and setting up multi-factor authentication cover the details.

When something goes wrong

10. They’ll hear about it honestly

No firm can promise it’ll never be breached. What clients can expect is candor. ABA Formal Opinion 483 says lawyers must notify current clients when a data breach affects their information. A firm with a written response plan, a short list of who to call, and a clear notice to clients keeps trust even on a bad day.

And if you’re the client and something feels wrong, call the office. That’s not rude. It’s exactly what a careful firm hopes you’ll do. If you think your own email or accounts were touched, our account protection section lays out the recovery steps in order.