Cybersecurity Basics for Small Law Firms
Category: Cybersecurity
Resource Type: Topic Guide
Last Updated: September 2026
Reading Time: 8 minutes
By Eric Helms, GSEC
Founder, Helmlight Consulting LLC
Category: Cybersecurity
Resource Type: Topic Guide
Last Updated: September 2026
Reading Time: 8 minutes
By Eric Helms, GSEC
Founder, Helmlight Consulting LLC
Cybersecurity threats continue to become more sophisticated, but many of the ways law firms get compromised are still surprisingly ordinary.
An old account that was never disabled. A computer that has not been updated. An administrator account without strong multifactor authentication. A backup nobody has ever tested.
This guide covers some of the cybersecurity basics small law firms should make sure are in place before worrying about more advanced security tools.
In this guide you'll learn:
Why basic cybersecurity controls still matter
Which accounts should receive the most protection
Why software updates are a security issue
How administrator accounts can create unnecessary risk
Why MFA should protect critical systems
What role backups and restore testing play in cybersecurity
Why technology ownership and documentation matter
Practical steps your firm can take now
Cybersecurity can sound complicated.
Vendors discuss artificial intelligence, advanced threat detection, zero trust, security monitoring, and many other technologies.
Those tools can be useful.
But a law firm can still have serious problems if the basics are not covered.
For example:
A former employee still has an active account
An old laptop has stopped receiving security updates
A Microsoft 365 administrator account is protected only by a password
Nobody knows who controls the firm's domain name
Important files are being synchronized to the cloud but have never been restored from backup
Before adding more technology, make sure the foundation is sound.
Every active account is another possible way into a firm's systems.
When an employee, contractor, vendor, or temporary worker no longer needs access, that access should be removed.
Old accounts can be particularly easy to overlook because nobody may notice if they remain active for months or years.
Pay attention to accounts for:
Microsoft 365 or Google Workspace
Practice/case management systems
Cloud storage
Accounting software
Remote access
Website and hosting administration
Domain registration
Backup systems
Vendor portals
Your firm should have a simple process for reviewing access when someone joins, changes roles, or leaves.
Software updates do more than add features.
Many updates fix security vulnerabilities that attackers may already know how to exploit.
Important systems and devices to keep current include:
Windows, macOS, Android, iOS, and iPadOS
Web browsers (Firefox, Chrome, Edge, and Safari)
Microsoft 365 and Office applications
Adobe software
PDF tools
Practice/case management applications
Remote-access software
Routers and other network equipment
Security software
Automatic updating can help, but firms should not assume that every application updates itself successfully.
Periodically confirm that important devices and software are actually receiving updates.
Administrator accounts can make major changes to computers and cloud systems.
That makes them especially valuable to an attacker.
A compromised administrator account may allow someone to:
Create new users
Reset passwords
Change security settings
Access sensitive information
Disable protections
Alter email rules
Delete data
Add unauthorized applications
Whenever practical, attorneys and staff should use standard accounts for routine work rather than administrator accounts.
Administrative privileges should be limited to the people who genuinely need them.
Administrator accounts should also receive the strongest available authentication protection.
A password by itself may not be enough to protect an important account.
Multifactor authentication, or MFA, requires another form of verification in addition to the password.
MFA is especially important for:
Microsoft 365
Google Workspace
Practice/case management systems
Cloud storage
Accounting and financial systems
Remote access
Backup systems
Domain and website administration
Not all MFA methods provide the same level of protection.
Where supported, authenticator apps, passkeys, or hardware security keys are generally stronger choices than relying only on SMS text messages.
The important first step is making sure MFA is enabled wherever sensitive information or administrative access is involved.
Backups are not just a disaster-recovery issue.
They are also part of cybersecurity.
Ransomware, account compromise, accidental deletion, and malicious activity can all make information unavailable.
Your firm should know:
What information is backed up
Where backups are stored
How frequently backups are created
How long backups are retained
Who can access them
Whether backup systems are protected from the same accounts and credentials used for everyday work
Whether attackers who compromise the primary environment could also delete or encrypt the backups
A backup is much less useful if an attacker who compromises the firm’s systems can also reach and destroy the backup copies. Whenever possible, backups should be stored separately from primary systems and protected with their own access controls.
Do not assume that storing information in OneDrive, SharePoint, Google Drive, Dropbox, or another cloud service automatically provides the type of backup your firm expects.
The important question is:
If this information disappeared today, how would we get it back?
A backup that has never been tested is still an assumption.
Restore testing helps confirm that:
Backups actually contain recent information
Recovery credentials work
Deleted files can be restored
Someone knows how the process works
Recovery will not depend entirely on one person
You do not necessarily need to perform a full disaster-recovery exercise.
Even restoring a small sample of files can uncover problems before an emergency occurs.
Small firms sometimes rely on outside vendors, web developers, former employees, or individual attorneys to establish important technology accounts.
Over time, nobody may be completely sure who controls them.
Your firm should know who owns and administers:
The domain name
DNS settings
Business email
Microsoft 365 or Google Workspace
Cloud storage
Practice/case management systems
Website hosting
Backup services
Security tools
Billing accounts
Recovery email addresses and phone numbers
Critical business systems should ultimately be controlled by the firm rather than depending entirely on one outside person.
Good cybersecurity does not require a giant technical manual.
But important information should not exist only in someone's memory.
Basic documentation might include:
A list of important technology systems
Who administers each system
Where billing information is maintained
Who owns critical accounts
Where recovery information is stored
Which users have administrative access
How backups are accessed
Who should be contacted if something goes wrong
Documentation becomes especially important when an employee leaves, a vendor changes, or the person who normally handles technology is unavailable.
Email is one of the most important systems in most law firms.
It is also a frequent target for attackers.
A compromised email account may expose:
Client communications
Attachments
Password-reset messages
Financial information
Calendar information
Internal discussions
Attackers may also use a compromised mailbox to impersonate an attorney or redirect payments.
At a minimum, firms should:
Require MFA
Remove old accounts promptly
Review suspicious forwarding rules
Protect administrator accounts
Train users to recognize phishing attempts
Have a process for reporting suspicious messages quickly
You do not need to be a cybersecurity expert to ask useful questions.
Start with these:
Are there any accounts belonging to former employees or vendors?
Are all computers receiving security updates?
Is important software being kept current?
Who has administrator access?
Are administrator accounts protected with MFA?
Is MFA enabled on email and other critical systems?
Do we know what information is being backed up?
When did we last test restoring something?
Who owns our domain name?
Who controls our website administrator account?
Who controls our Microsoft 365 or Google Workspace environment?
Are recovery email addresses and phone numbers current?
Do we have basic documentation of our technology environment?
If several of those questions are difficult to answer, that is a good place to start.
You can improve your firm's cybersecurity without replacing every system or buying a complicated security platform.
Start with a few practical steps:
Review active user accounts and remove access that is no longer needed.
Confirm computers and important applications are receiving updates.
Identify everyone with administrator access.
Enable strong MFA on critical accounts.
Confirm what data is actually being backed up.
Restore at least one file from backup.
Verify who controls the firm's domain, email, website, and cloud services.
Document important accounts, administrators, vendors, and recovery information.
Review these basics again whenever staff, vendors, or major systems change.
Small law firms do not need every advanced cybersecurity product on the market.
But they do need the basics to work.
That means knowing who has access, keeping systems updated, protecting important accounts with MFA, maintaining recoverable backups, controlling critical technology accounts, and documenting enough information to respond when something changes.
The goal is not perfect security.
The goal is to make common problems harder to cause, easier to detect, and easier to recover from.
Cybersecurity Downloads and Checklists — Practical reference materials for small law firms.
If you are not sure which of these protections your firm already has in place, Helmlight can help you review your current technology environment and identify practical next steps.
You do not need to know exactly what kind of service you need before reaching out.
Technology should support your law practice—not distract from it.
We believe the best technology decisions begin with understanding. By sharing practical knowledge and real-world guidance, we hope to help solo attorneys and small law firms build a stronger technology foundation with confidence.
If you're ready to apply these ideas to your firm, explore our services or tell us what’s going on. We’re happy to discuss your firm’s technology goals and help determine the right next step.
Follow us for IT guidance and security updates for small law firms
© 2026 Helmlight Consulting LLC. All rights reserved.