Sector research reports that around 39% of law firms experienced a breach in the past year, and that among breached firms more than half exposed client data. Reported attacks on the sector have risen sharply, and the average cost of a law firm breach is put near $5.08 million.
The Concentration Is Unusual Even By This Database’s Standards
A firm advising on a merger holds the deal before it is announced. A firm running litigation holds the strategy, the weaknesses and the internal assessment of the case. A firm handling a regulatory investigation holds the client’s own account of what went wrong.
These are not incidental records. They are material a client assembled specifically because it was too sensitive to handle alone, and handed to an organisation that is typically far smaller than they are.
The Size Mismatch Is The Structural Problem
A mid-sized firm advising large corporate clients has a fraction of their security capability and all of their most sensitive documents. That asymmetry is exactly what makes the sector attractive.
It is the same shape as the business-associate pattern filed at 26-0731 and the outsourced service desk at 26-0413: the data moves to whoever does the specialist work, and the security posture does not move with it.
Client Due Diligence Is Now The Pressure Point
The change worth noting is that corporate clients have begun auditing their firms’ security as a condition of instruction, in the way they audit other suppliers.
That is more likely to shift behaviour than professional guidance has, because it attaches a commercial consequence. A firm that loses a panel appointment over an authentication finding will act faster than one issued an ethics reminder.
This is a sector analysis file built on published research, listed below. Survey figures rely on self-reporting and definitions vary between studies. Corrections: corrections@forensicpost.com.