Most law firm cybersecurity advice is a generic checklist: strong passwords, back up your data. It reads like every managed-IT blog, and it doesn’t get into lawyer-specific cybersecurity risks.
This guide does something different. It walks through how a motivated adversary actually collects against a target firm — either an OSINT (open-source intelligence) researcher finding information your site is inadvertently leaking, or a hacker probing your site’s security — and only then pivots to the fix. Your website, your team's LinkedIn profiles, the metadata inside your published PDFs, the wireless networks your office broadcasts to the street: nearly everything in these fourteen chapters is something an outsider can already see, map, or look up. Security starts with looking at yourself the way they do.
Each chapter anchors to the professional duties you already owe your clients under the rules of professional conduct. For the American reader: the ABA Model Rules — competence (Rule 1.1, Comment 8), confidentiality (Rule 1.6(c)), and supervision (Rules 5.1, 5.3) — and the Standing Committee's formal opinions. For the Canadian reader: the Federation of Law Societies' Model Code, whose 2019 technological-competence commentary is expressly tied to the confidentiality duty. Since "reasonable efforts" is the standard for safeguarding client information in both countries, knowing what an adversary sees is where reasonable efforts can be strengthened.
The fourteen chapters
