The Short Answer: What Should a Law Firm Do After a Data Breach?
If your law firm has been breached, the first 24 hours often set the tone for everything that follows. Common first steps include confirming the incident, isolating affected systems without wiping them, contacting outside cyber counsel before the forensic vendor to help preserve privilege, notifying your malpractice carrier within their required window (many policies require notice within 24 to 72 hours), and beginning to scope which client data was affected. Client notification under ABA Formal Opinion 483 should happen “as soon as reasonably practicable,” though the exact timing will depend on the facts of the incident and your jurisdiction.
Your IT lead just texted at 6 AM. Something is encrypting files on the document management system. Two dozen client folders are already locked. You have three matters going out this week and a partner meeting at 9.
What happens in the next 24 hours can shape a lot of what follows. The scale of the breach. The malpractice exposure. Whether clients renew. Whether the state bar opens a competence inquiry.
This playbook walks through a practical set of actions many law firms find useful in the first day after a suspected data breach. It is drawn from ABA Formal Opinion 483, real law firm response experience, and the requirements many cyber insurance policies now impose. Every firm’s plan should be tailored to its own size, practice areas, jurisdictions, and existing systems.
What Counts as a Data Breach at a Law Firm?
A data breach is any unauthorized access, disclosure, alteration, or destruction of confidential information. For a law firm, that includes client files, work product, trust account data, personnel records, and personally identifiable information.
Not every incident is a breach. A single failed login is not. A phishing email nobody clicked is not. Ransomware encryption, credential theft with confirmed access, unauthorized file exfiltration, and lost or stolen unencrypted devices holding client data all are.
The distinction matters because ABA Formal Opinion 483 and state notification laws only trigger once a breach has actually occurred. Definitions of “breach” vary by state statute (see the National Association of Attorneys General resources for state-by-state references). Many firms adopt the working practice of treating an incident as a breach until forensic evidence proves otherwise.
Hour 0 to 1: Confirm and Contain
The first hour is usually about slowing the attacker down without destroying evidence. The specific steps below apply to most firms, though the right sequence can vary depending on your infrastructure and staff.
- Confirm the alert with a second source. One system alert can be a false positive.
- Note the exact time you first knew. This timestamp anchors every notification deadline.
- Isolate affected systems from the network. Do not power them off. Do not wipe them. Both destroy forensic evidence.
- Rotate high-privilege credentials on unaffected systems.
- Convene the response team on an out-of-band channel. Firm email may not be reliable if the mail server is potentially compromised.
Speed matters, but so does discipline. The urge to just fix it by rebooting or reinstalling can eliminate the evidence you need for insurance claims, malpractice defence, and client notifications.
Hour 1 to 4: Preserve Privilege and Engage the Right People
Once the immediate spread is contained, focus shifts to preserving privilege over the investigation and getting the right people involved.
Many firms make a point of contacting outside cyber counsel before engaging a forensic vendor. The reason has to do with privilege. If the forensic firm is engaged directly by the law firm, their reports are usually not privileged. If outside counsel engages the forensic firm to help provide legal advice, the reports may be protected as attorney work product. This protection is not automatic. Courts have not always upheld it in later litigation (see, for example, In re Capital One Consumer Data Security Breach Litigation, MDL No. 2915), so the engagement structure matters.
Also in this window:
- Formally notify the managing partner and firm general counsel
- Begin the malpractice carrier notification process according to your specific policy’s terms
- Freeze document management system exports and email forwarding until scope is understood
- Preserve forensic images of affected systems before any recovery changes
- If ransomware is involved, do not pay without cyber counsel approval and an OFAC compliance review. The U.S. Treasury’s 2021 Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments explains the exposure.
Hour 4 to 12: Scope the Damage and Notify Insurance
The forensic team is on the ground. Now you need to understand what was accessed, exfiltrated, or altered.
Scoping is often the most important and hardest part of the response. Client-by-client analysis drives every downstream notification. A breach that touched 50 client folders can create as many sets of ethical duties. A breach that touched 5,000 creates a much larger set.
Also complete during this window:
- Formal cyber insurance notification with initial scope estimate
- Court notifications for matters with imminent deadlines that will be affected
- Determine whether the firm is a HIPAA business associate for any affected client (see HHS Business Associates guidance for the current definition)
- Preserve a chain of custody log of every action taken so far
- Begin drafting the initial client notification letter template, but do not send it yet
By hour 12, you should have preliminary answers to three questions. What data was accessed? Whose data was it? How did the attacker get in?
Hour 12 to 24: Prepare Client Notification and Communications
The final stretch of the first day is about preparing the communications that will define how the outside world sees the incident.
Client notification under ABA Formal Opinion 483 should happen “as soon as reasonably practicable.” The opinion does not define a specific window. Most reviewers interpret it as “once you have enough facts to communicate clearly.” Notifying clients with incomplete information can create more confusion than reassurance.
Prepare during this window:
- Draft client notification letter, approved by outside counsel
- Internal FAQ for firm staff who will receive client questions
- Coordinate with cyber insurance on public relations support
- Language for any public disclosure required under state statutes
- A dedicated intake channel for client questions
Most firms find it useful to wait until they have a defensible factual account before sending communications. Speculation about attackers, motives, or scope in writing is usually a bad idea. Written communications during a breach can become discoverable in later litigation.
What Not to Do in the First 24 Hours
Six common mistakes that can turn a difficult situation into a much worse one:
- Pay a ransom before OFAC compliance review and cyber counsel approval
- Wipe or restore affected systems before forensic imaging
- Send incident communications through the suspected-compromised email system
- Notify clients with speculation instead of confirmed facts
- Delay malpractice carrier notification (depending on the policy, late notice can void coverage)
- Delete anything, even files that look suspicious
How a Secure File Sharing Platform Helps During Breach Response
During the first 24 hours and the days that follow, your firm has to keep functioning. Attorneys still need to send discovery to opposing counsel. Clients still need documents. The court calendar does not pause because your DMS is offline.
A secure file sharing platform that runs independently of your primary DMS can play three specific roles during response.
Business continuity: Attorneys can keep exchanging files with clients, courts, and co-counsel while the DMS is being restored. This can help avoid the missed deadlines that often lead to malpractice exposure.
Out-of-band coordination: When email is under investigation or suspected of being compromised, the response team needs a secure channel to share forensic reports, draft notifications, and privileged communications. A separate secure file sharing platform provides that channel.
Audit trail: Every file accessed or shared during recovery is logged. That log becomes part of the evidentiary record for insurance claims, regulatory inquiries, and downstream litigation.
TitanFile is an award-winning secure file sharing platform built for law firms and other regulated industries. AES-256 encryption in transit and at rest, MFA on every account, granular access, and tamper-evident audit logs come standard. SOC 2 Type II and ISO 27001 certifications support cyber insurance underwriting. Because it runs completely separately from your on-premise DMS, a breach affecting one is less likely to affect the other.
Start a 15-day free trial or book a demo to see how it fits into your firm’s response plan.
FAQs about Law Firm Data Breach
What is the first thing a law firm should do after a data breach?
Confirm the incident with a second source, note the exact time you first knew, and isolate affected systems from the network without powering them off or wiping them. Then convene your response team on an out-of-band channel and contact outside cyber counsel before engaging any forensic vendor.
Does my law firm have to notify clients after a data breach?
In most cases, yes. ABA Formal Opinion 483 requires lawyers to notify current clients whose confidential information may have been compromised, as soon as reasonably practicable. State breach notification statutes may impose additional requirements. HIPAA also applies if your firm is a business associate for any affected client. Check with ethics counsel about the specific duties in your jurisdiction.
How quickly do I need to notify my cyber insurance carrier?
Many cyber insurance policies require notification within 24 to 72 hours of discovery. Depending on the policy, late notice can void coverage. Check your specific policy language, but most firms treat carrier notification as a first-day action.
Should I pay the ransom if my law firm is hit by ransomware?
Do not pay without cyber counsel approval and an OFAC compliance review. Payment to certain sanctioned groups can trigger federal exposure separate from the breach itself, per the U.S. Treasury 2021 OFAC Ransomware Advisory. Some jurisdictions also require law enforcement notification before payment. The right call is fact-specific to the incident and the attacker.
Can attorneys keep working during a breach recovery?
Yes, if you have a secure file sharing platform that runs independently of your primary document management system. Attorneys can continue exchanging documents with clients, courts, and co-counsel while the DMS is being restored.
Conclusion
A law firm data breach is a bad day. It does not have to be a career-defining one. In many post-incident reviews, the firms that recover fastest and with the least reputational damage are the ones that responded methodically in the first 24 hours. Preserve evidence. Preserve privilege. Notify the right people in the right order. Keep the practice moving.
Preparation matters more than heroics. Write the playbook before you need it, and put the tools in place that let you execute it under pressure. Every firm’s plan should be adapted to its own size, practice areas, and jurisdictions.
To understand how this playbook aligns with a broader structure, read our guide on the seven phases of incident response.
This article is general information, not legal advice. Consult your firm’s ethics counsel and outside cyber counsel for guidance on your specific circumstances.
