Subnet Blog

Why Law Firms Need Cyber Resilience — Not Just Cybersecurity

Written by Ben Luks | 2 September 2026, 05:40:06 Z

Law firms have good reason to invest heavily in cybersecurity. They hold confidential client information, commercially sensitive documents and privileged communications. Their people exchange information with clients and external parties constantly, while email, document management systems, practice management platforms and cloud applications have become fundamental to everyday legal work.

But there is an important question that can get lost when the focus is primarily on preventing cyberattacks: What happens if something still gets through?

No security environment can guarantee that every malicious email will be blocked, every compromised credential detected immediately or every employee will make the right decision every time.

That's why law firms increasingly need to think beyond cybersecurity alone. They need to think about cyber resilience.

Cybersecurity and Cyber Resilience Aren't Quite the Same Thing

Cybersecurity is largely concerned with protecting systems, information and users from cyber threats. Cyber resilience goes a step further.

It asks whether the firm can anticipate, withstand, respond to and recover from an incident while continuing to perform its most important functions.

That distinction matters. A firm could have strong endpoint protection, multi-factor authentication, email security and other preventative controls in place and still experience an incident.

A user account could be compromised. A malicious attachment could evade detection. A third-party service could be disrupted. An attacker could exploit a vulnerability before it is patched.

The measure of the firm's preparedness then changes. It is no longer simply: “Did our security stop the attack?” It becomes: “How quickly can we understand what happened, contain it, recover and keep serving our clients?”

Prevention Still Matters — But It Is Only the First Layer

None of this makes prevention less important. Law firms should still be working to reduce the likelihood that an incident occurs in the first place. That can include strong identity controls, multi-factor authentication, email security, endpoint protection, appropriate access controls, vulnerability management, security awareness and keeping systems appropriately patched.

But prevention shouldn't be treated as an impenetrable wall. Cybercriminals only need one successful route into an environment. Defenders have to manage many. A resilient approach therefore assumes that preventative controls will sometimes be tested — and asks what happens next.

A useful way to think about this is: Prevent. Detect. Respond. Recover. Each layer matters.

Detection: Would You Know Something Had Happened?

Some cyber incidents are immediately obvious. Others aren't. An attacker who gains access to a legitimate user account may deliberately avoid causing disruption. Instead, they may observe email conversations, search for sensitive information or wait for an opportunity to manipulate an existing transaction.

Similarly, malicious activity on an endpoint or unusual access to cloud information may not necessarily result in an immediate outage. That makes visibility critical.

Law firms need ways to identify unusual behaviour across identities, endpoints, applications and information. The important question isn't whether the firm collects security alerts. It's whether somebody can recognise which alerts actually matter.

If an employee's account suddenly signs in from an unusual location, begins accessing information differently or displays other suspicious behaviour, how quickly would somebody notice? And once they did, would they know what to do next?

Response: Who Takes Control When Something Goes Wrong?

This is where cyber resilience becomes an organisational issue rather than simply a technology issue. Imagine suspicious activity is detected at 8:30 on a Monday morning. 

  • Who makes the decision to disable an account?

  • Who determines whether other systems may have been affected?

  • Who investigates what information was accessed?

  • Who coordinates with leadership?

  • Who considers whether clients, insurers, legal advisers or other parties need to be involved?

  • And who keeps the rest of the firm operating while all of this is happening?

Those questions are much easier to answer before an incident than during one. A documented incident response plan can help establish responsibilities, escalation paths and decision-making processes in advance.

But a document sitting in a folder isn't enough. The people involved need to understand their roles, and ideally the plan should be exercised before it is needed for real.

Recovery Is a Cybersecurity Capability Too

Backups are sometimes treated as an IT operational issue rather than a cybersecurity control. That distinction has become increasingly difficult to maintain.

If ransomware encrypts critical information, systems are damaged or data is otherwise made unavailable, the firm's ability to recover becomes part of its security posture.

But having a backup isn't the same as being recoverable. Law firms should understand what information and systems are protected, how frequently backups occur, whether backups are sufficiently isolated from the production environment and how quickly critical services could realistically be restored.

Most importantly: Has recovery actually been tested? An untested backup provides reassurance. A tested recovery process provides evidence. For a law firm, the difference can determine how quickly lawyers regain access to the information and systems they need to service clients.

Start With the Systems the Firm Cannot Practise Without

Not every application is equally important. A useful resilience exercise is to ask leadership and IT a deceptively simple question: If our technology environment went down tomorrow morning, what would we need back first?

Email and communications may be near the top of the list. So might document management, practice management, identity services, client files, financial systems or particular applications used by specific practice areas.

The exact answer will vary between firms. What matters is that the priorities are understood before recovery is required.

That allows IT teams to design recovery priorities around business impact rather than discovering during an incident that leadership and IT had very different assumptions about what was most critical.

Cyber Resilience Also Depends on People

Technology is only part of the resilience equation. A law firm might have capable internal IT staff who understand its systems exceptionally well. But that can introduce another risk: How much critical knowledge sits with one person?

  • Who understands the Microsoft 365 environment?

  • Who manages the security tools?

  • Who knows how the backup environment is configured?

  • Who has access to critical administrative accounts?

  • Who would lead the technical response to a cyber incident?

  • And what happens if that person is unavailable when the incident occurs?

This isn't an argument against internal IT teams. Quite the opposite. Strong internal IT capability is enormously valuable. But resilience means ensuring the organisation isn't dependent on one person's availability, knowledge or access when something goes wrong.

For some firms, that may mean documenting critical knowledge and cross-training internal staff. For others, it may involve a co-managed IT or security model that gives the internal team access to additional expertise and support when required. The objective is the same: Remove single points of failure wherever you reasonably can — including human ones.

Client Trust Doesn't Disappear During a Cyber Incident

Law firms operate on trust. Clients provide information because they expect their legal advisers to handle it appropriately. They also expect their lawyers to remain available when something important is happening.

A cyber incident can put both expectations under pressure simultaneously. That means resilience isn't only about restoring servers or closing security alerts. It's also about maintaining confidence.

  • How will the firm communicate if normal email is unavailable?

  • Who decides what clients need to know?

  • Can lawyers continue accessing the information required to work on urgent matters?

  • How will leadership communicate internally?

  • What happens if an incident lasts hours rather than minutes — or days rather than hours?

These are business continuity questions as much as cybersecurity questions. And for law firm leadership, that's precisely why cyber resilience deserves attention beyond the IT department.

Four Questions Worth Asking

You don't need to be a cybersecurity specialist to start assessing your firm's resilience. Leadership can begin with four questions:

  1. Prevent: What controls reduce the likelihood of a successful cyber incident?
  2. Detect: How would we know if an identity, device or system had been compromised?
  3. Respond: Who takes control, and does everyone know their role?
  4. Recover: Which systems need to come back first, and have we proven that we can restore them?

If any of those questions is difficult to answer, that doesn't necessarily mean the firm has poor cybersecurity. It identifies where resilience may need more attention.

The Goal Isn't to Guarantee Nothing Will Ever Go Wrong

There is a natural temptation in cybersecurity to measure success by the absence of incidents. But no organisation can guarantee that it will never be targeted, never encounter a vulnerability or never have a user make a mistake. A more useful objective is to build an environment where one successful attack doesn't automatically become a business crisis.

That means preventing what you can. Detecting what gets through. Responding before the damage spreads. Recovering the systems and information the firm depends on. And ensuring the organisation has the people, processes and technology to keep operating throughout.

For law firms, that is what cyber resilience ultimately means. Not simply protecting the firm from an incident — but being prepared to keep practising when prevention isn't enough.