fbpx

Cybersecurity for Lawyers: Protecting Client Data When AI Tools Enter the Workflow

How law firms can adopt AI without losing control of confidential information, access security, staff behavior, and cybersecurity risk.

Two legal professionals using a laptop for secure AI workflows and client data protection.

Key Takeaways:

  • How should law firms use AI safely?
  • What cybersecurity risks do lawyers face?
  • How can law firms protect client data?

Is your cybersecurity for lawyers keeping up with artificial intelligence (AI) workflows? It certainly needs to. 

A 2025 American Bar Association (ABA) survey of over 2,800 legal professionals shows increasing AI adoption in the workplace.

Per the study:

  • 31% of legal professionals now use the technology.
  • 54% draft emails and other forms of correspondence with generative AI.
  • 14% use it for legal research, discovery, and data analysis.
  • And many administrators use it to streamline scheduling and billing.

This trend will likely continue in the future, which is a good thing for workplace productivity. 

But it does raise a concern: What happens when someone enters client information into an AI tool without understanding where that data goes, how it is retained, who can access it, or whether it may be used by the AI tool provider?

As you’re likely aware, ABA Formal Opinion 512 makes clear that existing professional obligations continue to apply when using generative AI, including competence, lawyer confidentiality, communication, supervision, and client data protection.

One way to strengthen cybersecurity for lawyers and continue meeting obligations is with clear AI governance around approved tools, permitted data, identity and access management security, staff training, and human oversight.

Here’s all you need to know.

Schedule a Law Firm Cybersecurity Review

Attentus can help you:

  • Review identity and endpoint security
  • Evaluate current AI-related technology risks
  • Strengthen client data protections
  • Identify unmanaged applications or devices
  • Review access, monitoring, and recovery processes
  • Establish a stronger cybersecurity foundation for AI adoption

If you’ve been looking to strengthen your cybersecurity for lawyers, we’re happy to chat. 

Discover Attentus’ Managed I.T. Services for Law Firms.

How Law Firms Can Use AI Safely By Strengthening Cybersecurity for Lawyers

To use AI safely, follow these simple rules:

1. Define What Can (and Cannot) Go Into an AI Tool

ABA Model Rule 1.6 requires lawyers to protect information relating to client representation and to make reasonable efforts to prevent unauthorized access or disclosure.

One way you can do that is by establishing a simple and realistic policy that clearly states acceptable AI use cases and those requiring additional review.

For instance, you could give a green light for low-risk scenarios, such as:

  • Brainstorming generic ideas
  • Formatting non-confidential information
  • Summarizing public information
  • Creating internal templates without client data

But mandate caution when it comes to sensitive things, including:

  • Client documents
  • Case strategy
  • Contracts
  • Discovery materials
  • Personally identifiable information
  • Financial information
  • Medical information
  • Privileged communications
  • Confidential business information

With the do’s and don’ts firmly in place, proceed to vet AI tools.

2. Know What Happens to the Data After Someone Clicks “Submit”

AI tools can introduce unnecessary risk when you don’t fully understand a vendor’s data management practices. 

So, before approving any platform, read the terms of service to understand:

  • What information the provider collects
  • Whether prompts or uploaded files are retained
  • Whether submitted information is used to improve or train models
  • Available privacy and security settings
  • Data-retention options
  • Administrative controls
  • User-access management
  • Authentication capabilities
  • Contractual data protections
  • Where information is processed or stored
  • How data can be deleted
  • Whether the firm can monitor employee use

“Firms must rigorously evaluate the vendor’s data architecture, specifically demanding absolute proof that legal queries and client data are walled off from the vendor’s foundation model training pipeline. Beyond standard SOC 2 compliance, firms should audit how the platform handles token caching and whether the vendor provides indemnification against data spillage or copyright liability,” says Eshaan Jain, senior product manager at T-Mobile via Mphasis and a former enterprise technology leader at Amazon and PwC. 

Ideally, you should choose the option that minimizes your data security and privacy risks.

3. Protect the Accounts That Give Employees Access to Client Data

No matter how carefully your firm regulates AI, adversaries can still get in through compromised email, cloud, or document-management credentials. So, make sure your identity and access management (IAM) security is part of your broader strategy.

Here’s what we recommend:

  • Require every internal user to have a strong password, secure connection, and approved device when logging into your systems. 
  • Add an additional verification step beyond the typical username and password during account login. This is known as multi-factor authentication (MFA). 
  • Give employees access to ONLY the information and systems they need to do their job.
  • Create separate administrator accounts for the people managing I.T.
  • Revoke access to email, files, applications, and other systems immediately when someone leaves the firm.
  • Regularly check who has access to what and remove access when no longer needed.
  • Continuously monitor your network for unusual activity.
  • Limit the number of third-party applications accessing your I.T. environment.

As you work on the IAM layer, don’t forget about endpoint security.

4. Control Endpoints and the Broader Legal I.T. Environment

Whether an employee accesses AI tools through a desktop, laptop, or phone, those devices must be secured to protect client data effectively. 

Here are some best practices to follow:

  • Keep everything updated with the latest security patches. 
  • Install antivirus and endpoint protection.
  • Encrypt devices so data can’t easily be accessed if lost or stolen.
  • Establish secure remote access for employees working outside the office.
  • Backup important information so it can be recovered after an incident.

Most importantly, limit employees to approved software and applications. No one should be able to bypass firm policy simply by opening an unapproved AI website from your company device.

Did you know that Managed I.T. services for law firms can improve AI governance by helping you consistently administer device, identity, software, and security policies? Learn more.

5. Train Attorneys and Staff for AI-Enabled Threats

The human element played a role in 62% of successful cyber attacks, according to Verizon’s 2026 Data Breach Investigation Report (DBIR).

That means building a human firewall may be one of the best ways to strengthen cybersecurity for lawyers. 

But how can you do it most effectively?

Raising awareness about approved tools, prohibited data, when to seek client consent or internal review, and how to report accidental exposure certainly helps. But it’s just one-half of the equation.

The other half is equipping them with the skills to defend against AI-powered phishing and social engineering attacks. 

How do they respond to:

  • Suspicious emails?
  • Unexpected payment requests? 
  • Unusual client or executive communications?

Further, in this era of deepfakes, how do they ensure the person they’re interacting with through a video or audio call is actually who they say they are and not an imposter?

Preparing for these eventualities is key to robust cybersecurity for lawyers.

Have You Read: What Happens When Seeing and Hearing Someone Is No Longer Proof of Identity?

6. Require Human Review of AI Output

Another thing to remember is that AI tools hallucinate. That’s just another way of saying that they can produce inaccurate or misleading information while sounding completely confident.

The ABA puts it upon you to spot such errors and ensure they don’t hinder competent representation. 

In that light, every AI-generated output should go through a second set of eyes before being used for legal research, client advice, contracts, court filings, case summaries, or important communications.

7. Make the Approved Path Easier Than the Unapproved One

Another cybersecurity tip for lawyers is to get ahead of “shadow AI.” This is where employees turn to unsanctioned AI tools because official policies are unclear or approved alternatives are inconvenient.

When shadow AI sprawls, your law firm may end up exposed through unsecure tools you don’t know about. 

“Shadow AI is often created when employees seek out faster ways to accomplish their tasks. Companies should listen to these needs and invest in the tools that their employees want while educating them on the dangers of unapproved software. Simply blocking the use of AI will cause users to turn to other options that the company might not be able to monitor as easily,” says Alan Heimlich, president and attorney at Heimlich Law, PC. 

Here’s how to avoid it:

  • Publish a list of approved AI tools.
  • Explain why certain tools are restricted.
  • Creating a simple process for requesting new tools.
  • Periodically review software and browser access.
  • Update your policy as AI products and features change.
  • Give employees a safe way to report mistakes.

These recommendations will help you create a governed workflow where employees know what they can use, what they can enter, and what to do when something goes wrong.

8. Build AI Into Incident Response

Finally, ensure your broader cybersecurity incident-response plan accounts for when someone accidentally enters confidential client data into an unapproved AI platform or an AI-related account is compromised.

In such a scenario, who do employees contact first and what corrective actions should follow? Make sure the entire process is clearly documented.

How Managed I.T. Supports Safer Legal AI Adoption

Managed I.T. services for law firms  can help you establish consistent technology controls around:

  • Identity and access management
  • Endpoint security
  • Approved applications
  • Device configuration
  • Patch management
  • Monitoring and logging
  • Email security
  • Backup and recovery
  • User onboarding and offboarding
  • Vendor coordination
  • Incident response

And that can considerably alleviate your burden of implementing strong cybersecurity for lawyers.

With that said, your firm’s leadership and legal counsel remain responsible for determining ethical, professional, contractual, and client-specific requirements.

Frequently Asked Questions About Cybersecurity for Lawyers

1. How should law firms use AI safely?

Use approved tools, establish clear data-handling rules, understand vendor practices, secure access, train employees, and require human review.

2. Can lawyers put client information into AI tools?

The answer depends on the tool, circumstances, applicable ethics rules, client expectations, and safeguards. ABA guidance stresses confidentiality and informed evaluation of how the AI platform handles client information.

3. What cybersecurity risks do lawyers face?

Common risks include phishing, ransomware, credential theft, business email compromise, account takeover, accidental disclosure, and insecure technology use.

4. How can law firms protect client data?

Use layered controls across identities, endpoints, networks, email, applications, backups, employee training, vendor management, and incident response.

5. Should law firms ban generative AI?

Not necessarily. A governed approach can establish which tools and use cases are acceptable while restricting higher-risk data and workflows.

6. What should a law firm’s AI policy include?

At minimum, define approved tools, prohibited information, vendor-review requirements, human-review expectations, employee responsibilities, and incident-reporting procedures.

AI Governance Is Now Part of Legal Cybersecurity

As AI becomes part of everyday legal work, client data protection requires coordinated policies, secure identities, managed endpoints, vetted vendors, trained employees, and clear incident procedures.

Establishing these controls before AI becomes fragmented across the organization is key to maximizing efficiency gains while minimizing risks. That’s where Attentus comes in.

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY