Also on CyberFence: CyberFence's industry directory for other professions · CyberFence for Teams for business VPN with BAA and SSO .
If you run a small law firm — solo, boutique, or a partnership of a dozen attorneys — you carry an obligation that most other small businesses do not. Every client communication is privileged. Every discovery file, sealed motion, and settlement negotiation is confidential by professional rule, not just by preference. The American Bar Association's Model Rule 1.6(c) requires reasonable efforts to prevent the unauthorized disclosure of client information, and courts have made clear that "reasonable" now means competent technical safeguards, not just a locked file cabinet.
The FBI has been warning small and mid-sized US law firms for years that they are being targeted specifically because they hold sensitive corporate M&A material, litigation strategy, and settlement figures — often with weaker cybersecurity than the enterprise counterparties they represent. This guide walks through what a small law firm actually needs to install to meet the modern bar and how a US-operated VPN fits into that stack.
Why small law firms are on the target list
Three factors put small law firms in front of both criminal ransomware operators and nation-state espionage groups:
- You hold aggregated privileged data — attorney-client communications, deposition transcripts, sealed pleadings, expert reports, and settlement figures. Any one client file is valuable; a firm holds hundreds.
- You have wire-transfer authority — real estate closings, trust accounts, and settlement disbursements move meaningful money through firm accounts. Business email compromise (BEC) attacks against law firms have been a top FBI complaint category for years.
- You operate from mixed environments — home offices, court hallways, deposition suites, client sites, hotels during trial travel. Every one of those is an untrusted network.
The Silent Ransom Group (also tracked as Luna Moth) has been actively targeting US law firms, even conducting in-person impersonation attempts on some. Ransomware crews like BlackCat, LockBit, and their successors have hit dozens of named US firms. This is not a theoretical risk.
Baseline privileged-data protection in ten minutes
CyberFence is a US-operated VPN with AES-256-GCM encryption, DNS-level phishing blocking, and zero logs — installed on every attorney's laptop and phone, it protects every client login and file transfer.
Start Your Free TrialWhat ABA Model Rule 1.6(c) and Formal Opinion 477R actually require
The ABA has stated repeatedly, most explicitly in Formal Opinion 477R (updated in Formal Opinion 498 on virtual practice), that lawyers must take "reasonable" steps to safeguard client information when transmitting it electronically. What counts as reasonable depends on the sensitivity of the information, the cost of protection, and the availability of the technology.
In 2026, an encrypted VPN costs roughly the price of one lunch per month. That means "cost" is no longer a defense. The bar for reasonable technical safeguards on any device that touches privileged material now includes, at minimum:
- Full-disk encryption on every laptop and phone (built into modern macOS, Windows, iOS, and Android).
- Strong multi-factor authentication on email, practice-management, and file storage.
- Encrypted transmission of client data — which is precisely what a VPN provides on top of HTTPS, especially on untrusted networks.
- Blocking of known phishing and malware sites at the DNS layer.
- Timely software patching and endpoint protection.
- Backups sufficient to recover from ransomware without paying.
Nothing on that list is exotic. All of it is table stakes.
The three attack paths most likely to hit a small law firm
1. Business email compromise around a real estate closing or settlement
The attacker compromises a paralegal or attorney's email account — often via credential phishing on a lookalike Microsoft 365 login page — and then quietly watches. When a wire is about to move, the attacker sends new "corrected" wire instructions from the compromised inbox. Funds go to the attacker.
CyberFence's Web Shield blocks known phishing domains at the DNS level, so the fake Microsoft 365 login page fails to load in the first place. Combined with mandatory MFA on your Microsoft 365 tenant, this is the single highest-leverage defense you can put in place for the BEC problem.
2. Ransomware from a compromised remote endpoint
Attorneys work from home. Home networks have weak or shared Wi-Fi passwords, and the router firmware has often not been updated in years. If any device on the home network is compromised — a cheap smart camera, a kid's laptop — the attacker can move laterally, install remote access malware on the attorney's work machine, and eventually deploy ransomware across the firm's shared drives.
A VPN treats your home network as untrusted. All traffic from the attorney's laptop leaves the house encrypted, so a compromised neighbor device sees nothing useful. Combined with disk encryption and current endpoint protection, this closes the most common ransomware pivot path against remote-first firms.
3. Interception of privileged material on courthouse, hotel, or client Wi-Fi
You take depositions in hotel conference rooms. You review privileged material during trial in courthouse Wi-Fi. You reply to a partner from a client's guest network. Every one of those is an untrusted network shared with strangers. HTTPS protects most modern legal-tech tools, but DNS lookups, metadata, and any tool that falls back to plaintext can leak.
A VPN wraps every packet in AES-256 encryption from your device to the VPN server, so a nearby attacker sees only encrypted noise — even the domain names you are looking up are hidden inside the tunnel.
What a small firm should actually deploy
Here is a defensible baseline for a firm of 1 to 20 attorneys:
- CyberFence on every attorney and staff device — laptop, phone, tablet. Set to auto-connect. This covers privileged material in transit anywhere anyone works.
- MFA on Microsoft 365 or Google Workspace — mandatory for every user, no exceptions for partners. Prefer app-based or hardware key over SMS.
- MFA on your practice-management system — Clio, MyCase, PracticePanther, or whichever platform holds your matter list and time entries.
- MFA on your document management — NetDocuments, iManage, SharePoint, or Dropbox for Business.
- MFA on your trust account bank login — and a written wire-transfer verification policy: any change to wire instructions is confirmed by phone at a known number, not by return email.
- Automatic full-disk encryption on every device — FileVault (Mac), BitLocker (Windows), on by default on iPhone and modern Android.
- Immutable, off-site backups — a ransomware-resistant backup of matter files that cannot be encrypted from the attorney's own credentials.
- CyberFence Breach Monitor on every firm email address — you want to know within hours if a vendor breach exposes staff credentials, so you can force a password reset before the credentials are used against you.
What to tell a client, insurer, or ethics counsel who asks
Being able to answer this question in one paragraph is defensible practice and a competitive advantage:
"Every firm device is protected by full-disk encryption and a US-operated VPN with AES-256-GCM encryption, so client material is encrypted in transit and at rest across every network we work from — home, court, hotels, client offices. We require multi-factor authentication on every system that touches client data, block known phishing and malware domains at the DNS layer, verify wire-transfer instructions out of band by phone, and monitor firm email addresses against known credential breaches. Our VPN provider keeps zero logs of our browsing activity."
That paragraph aligns with ABA Model Rule 1.6(c), most state bar guidance, and the technical safeguards clause that keeps showing up in engagement letters from sophisticated corporate clients.
Firm-wide protection, one subscription
CyberFence is $7.99/mo per user monthly, or $88.21/yr annually — $7.35/mo, save 8%. That includes the VPN, Web Shield DNS blocking, Breach Monitor, and support from a US-based team. Firm plans are available for teams.
See Pricing and Start Free TrialBottom line
Small law firms are targeted precisely because they hold aggregated privileged material and often lag enterprise clients on technical safeguards. The ABA's guidance and the technical safeguards clauses in modern engagement letters have converged: encrypted transmission on every network, MFA everywhere, DNS-level phishing blocking, and out-of-band wire verification. A US-operated VPN is the piece that covers the "encrypted transmission on every network" requirement in one install per device — and gives you a straightforward, defensible answer the next time a client, insurer, or state bar auditor asks how you protect their confidences.
Want to go deeper? Read how CyberFence protects other regulated industries , the CyberFence Teams product page , or CyberFence plans and pricing .