Can law firms put a price on their clients’ privacy?

Law firms are a one-stop-shop for cyber criminals – but there’s plenty of sensitive, highly valuable client information to be had too…
shutterstock_1140535328

Share this article:

Law firms are a one-stop-shop for cyber criminals – not only can they get their hands on large financial transactions, but there’s plenty of sensitive, highly valuable client information to be had too. Protecting this confidential information is paramount to law firms keeping their reputation – and the reputations of their clients – intact.

Confidentiality is at the heart of the legal sector, with individuals and businesses alike placing their trust in law firms to transact securely and discreetly on their behalf. A breach of this trust can mean the end of the road for a law firm – just look at Mossack Fonseca, the firm that lost 11.5 million documents (2.6TB of data) in a 2016 breach dubbed the ‘Panama Papers’, due to weaknesses in their client portal which hadn’t been updated. The sensitive information in those documents about wealthy, famous, and public office clients was exposed to the press. Mossack Fonseca never recovered from the massive reputational damage caused by the breach and was forced to close.

Law firms’ reliance on digitised information makes them particularly vulnerable to data breaches. They are accustomed to taking instruction and conducting transactions almost exclusively via email, including the transfer of extensive amounts of confidential, personal, and financial information. The constant movement of this information increases the risk of exposure.

The impact of the media

The affairs of high net worth individuals are temptingly lucrative targets for cyber criminals. Secrets and scandals sell newspapers. The 2017 ‘Paradise Papers’ scandal saw 13.4 million files leaked to the International Consortium of Investigative Journalists. The documents were stolen from Appleby, a major offshore law firm based in Bermuda that “specialises in advising some of the world’s wealthiest individuals”. The files showed the multitude of ways companies and affluent individuals avoid tax and included names and financial information. Needless to say, the press had a field day.

Getting personal

It’s not just the rich and famous who are at risk of having their confidential information stolen. Enlisting the services of a law firm normally involves sharing a small library of personal information which, in the wrong hands, could easily lead to identity theft and fraud. Clients’ names, addresses, dates of birth, financial records, and sometimes medical information are all held by law firms, and usually transferred by email.

Law firms need to be particularly careful with this level of sensitive personal information, not least because of the further crimes it could be used for if stolen. The introduction of the GDPR in 2018 has already seen eye-watering fines making the headlines for Marriott and BA. Any breach of personal information must be reported, and fines are levied against the company that held the data for not adequately protecting it.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top