CX
Cobrix Solutions
Book Consultation(213) 214-1385

Legal IT & Cybersecurity

For California law firms carrying confidentiality duties a generic IT provider does not understand.

Confidentiality is a professional duty, not an IT preference

ABA Model Rules 1.1 and 1.6 place competence and confidentiality obligations on lawyers that extend to the technology holding client material. Comment 8 to Rule 1.1 makes technological competence explicit, and California imposes its own parallel professional duties.

The consequence most firms underrate: this duty cannot be fully delegated. Engaging an IT provider does not transfer the obligation — it remains the firm’s, which means partners need to understand and be able to justify the safeguards protecting client data. “Our IT company handles that” is not a defensible answer to a bar complaint.

In practice this means access control has to work at matter level rather than firm level, and you need a record of who accessed what. Most small firms have neither, because their systems were configured to make files easy to reach.

Where law firms actually get hit

1

Trust account wire fraud

Attackers clone a partner’s voice or spoof their email to authorise a disbursement. Highest-consequence attack against firms, and it defeats technical controls by targeting people under deadline pressure.

2

Mailbox compromise

A credential without phishing-resistant MFA gives an attacker a partner’s mailbox, and with it every matter discussed by email plus the ability to redirect payments from inside a real thread.

3

Over-broad file access

Firm-wide shares mean one compromised paralegal account exposes every matter, including those subject to ethical walls that exist on paper only.

4

Third-party leakage

Staff moving client documents through consumer file-sharing or AI tools with no confidentiality agreement behind them.

Note what is absent from that list: sophisticated malware. The attacks that succeed against firms are unglamorous and target process gaps, which is why the controls that stop them are mostly configuration and written rules rather than products.

The trust account problem, specifically

Client trust accounts concentrate risk in a way most businesses never face. The money is not the firm’s, the obligation to safeguard it is a professional one, and a successful fraud creates a shortfall the firm has to make good regardless of who was deceived.

The attack pattern is consistent. An attacker gains mailbox access, monitors quietly for weeks, learns the firm’s language and its transaction rhythm, then intervenes at a closing or settlement with revised instructions that arrive exactly when everyone expects them.

Matter-level access and ethical walls

Ethical walls that exist as a memo rather than as permissions are not walls. If a paralegal can navigate to a conflicted matter’s folder, the wall has failed regardless of what anyone was instructed.

In a Microsoft 365 environment this is a configuration exercise rather than a project: matter-scoped SharePoint sites with membership governed through Entra ID groups, permissions inherited rather than set per-file, and access reviewed on a cadence. The benefit extends past ethics — matter-level scoping limits the blast radius when a single account is compromised, which is the more common event.

AI automation for firms, done without breaching confidentiality

Your staff are already using AI tools. In most firms we assess, someone has pasted client material into a consumer chatbot — not maliciously, but because it saved an hour and no policy said otherwise.

The exposure is not hypothetical model behaviour. It is privileged material disclosed to a third party with no confidentiality agreement, unclear retention and no audit trail, which sits badly against Rule 1.6. Several bar associations have now issued guidance on exactly this.

The fix is a sanctioned path easier than the unsanctioned one: tooling operating inside your own tenant under existing protections, a short written AI use policy naming what may never be entered, vendor review before adoption, and a named human accountable for anything reaching a client or a court. See AI automation for law firms and AI automation solutions.

How to evaluate an IT provider for your firm

Most firms evaluate providers on price and response time. Those are the two things every provider claims and neither predicts the outcome. The questions below are harder to answer well, which is exactly why they are worth asking.

Ask for the answers in writing. A provider who will commit to them in an email is a different proposition from one who will only say them on a call.

What the first 90 days look like

Engagements fail most often in the transition, not the steady state — because nobody agreed who owned what while it was moving. This is the shape of a Cobrix onboarding.

1

Weeks 1-2: Assess

We inventory the environment: identities, devices, licences, data locations, vendor access and current configuration. Output is a written findings document with gaps ranked by exploitability, not by severity label. You keep it whether or not you continue.

2

Weeks 3-6: Stabilise

The high-exploitability items first — typically phishing-resistant MFA, removal of standing admin rights, audit logging with deliberate retention, and closing whatever access should have been revoked and was not.

3

Weeks 7-10: Document

The written programme, policies and risk analysis your obligations actually require as artefacts, reflecting your real environment rather than a template with your name inserted.

4

Weeks 11-13: Operate

Steady-state support, review cadence agreed, and the accepted-risk register written down with reasoning so the next audit or renewal has something honest to work from.

Nothing here requires you to replace working systems. Most of it is configuration of platforms you already own, which is why the first 90 days rarely involve capital expenditure.

Related services

For the security layer, see cybersecurity services. For day-to-day support, see managed IT. Deepfake and phishing training is the control that actually stops wire fraud — see security awareness training. If a fraudulent wire has already gone out, act within hours: see incident response. For the regulatory documentation side, see compliance services.

Frequently asked questions

What are a law firm's cybersecurity obligations under the ABA Model Rules?

Rule 1.6(c) requires reasonable efforts to prevent unauthorised disclosure of client information, and Comment 8 to Rule 1.1 makes competence in relevant technology part of the duty of competence. California imposes parallel professional obligations. The practical reading is that a firm must understand and be able to justify the safeguards protecting client data — the duty cannot be fully outsourced to a vendor.

How do we stop deepfake wire fraud on our trust account?

Technical controls alone do not stop it, because the attack targets a person authorising a legitimate-looking transfer. The control that works is a written callback rule: any disbursement instruction is verified by calling a known number on file, never a number in the request, using an agreed passphrase. Pair it with dual authorisation above a threshold and phishing-resistant MFA on every mailbox.

Can our firm use ChatGPT or other AI tools with client matters?

Not consumer versions holding privileged material — there is typically no confidentiality agreement, unclear retention, and no audit trail, which sits badly against Rule 1.6. Tools operating inside your own tenant under existing data protections are a materially different proposition. The workable answer is a sanctioned tool plus a written policy, not a ban that staff quietly ignore.

Do we need matter-level access control in a small firm?

If you handle matters requiring ethical walls, yes — firm-wide file shares make walls unenforceable regardless of what staff were instructed. Even without walls, matter-level permissions limit the damage when one account is compromised. In a ten-person firm this is a configuration exercise in SharePoint and Entra ID rather than a large project.

What do we do if a fraudulent wire has already gone out?

Act within hours. Contact the sending bank immediately and request a recall, file with the FBI's IC3 which can trigger the Financial Fraud Kill Chain, notify your carrier and your malpractice insurer, and preserve the mailbox evidence rather than deleting the fraudulent emails. Recovery odds fall sharply after the first day, and the preserved evidence determines how narrowly you can scope the breach.

Is our practice management system enough for security?

It secures what lives inside it. Most firm data does not — email, local files, mobile devices, and documents in transit to clients and counsel sit outside the practice management system entirely. Treating it as the security boundary is a common and expensive assumption.

What happens to our client data if we change IT providers?

It stays in your tenant under your ownership. Cobrix does not hold your Microsoft 365 environment through an admin account you cannot reach, and we document the handover for an incoming provider. Ask any prospective provider this directly — a vague answer is the answer.

Do we have to notify clients after a breach?

Likely yes, on two separate tracks. California Civil Code 1798.29 and 1798.82 impose statutory notification duties for personal information. Separately, professional responsibility guidance addresses a lawyer's duty to inform affected clients of a breach involving their confidential information. The two run on different logic and should be assessed together with counsel.

Ready to Get Started?

Schedule a free consultation today.