Sector reporting identifies a consistent pattern in law firm attacks: client-facing document portals with weak or optional multi-factor authentication.
The portal is not an oversight. It exists because clients wanted to stop emailing documents, which was a genuine security improvement over the alternative.
The Access Population Is The Difficulty
A firm can enforce strong authentication on its own staff. A portal serves the client’s people — general counsel, finance, executives at organisations the firm does not administer.
Enforcing hardware-backed authentication on those users means a project inside every client organisation. Firms compete on responsiveness, so the friction usually loses, and the control ends up optional.
What The Portal Contains
A matter portal holds the working documents for a live engagement: draft agreements, discovery material, valuation models, board papers. It is organised by matter, which is convenient for the client and equally convenient for anyone else who reaches it.
This desk filed the same shape at Salesforce Experience Cloud in 26-0314. A portal built to share selected material with external parties, whose permission model nobody has audited since launch, is a recurring architecture with a recurring outcome.
The Economics Point One Way
The average breach cost cited for the sector — around $5.08 million — sits against the cost of enforcing phishing-resistant authentication across a client base, which is measured in inconvenience rather than millions.
The obstacle is not budget. It is that the person who would have to insist is also the person selling to the client.
This is an analysis file built on published sector reporting, listed below. It describes a general pattern rather than any named firm. Corrections: corrections@forensicpost.com.