Law firms are a prime target for cybercriminals: highly sensitive data (professional privilege), a human-scale workforce — meaning attack surfaces that are often insufficiently protected — and an obligation to maintain continuity. According to the national cyber maturity barometer for micro and small businesses (Cybermalveillance.gouv.fr, CPME, MEDEF, U2P), 16% of micro and small businesses report having experienced at least one cybersecurity incident in the past 12 months, and 43% of reported attacks are linked to phishing (compared with 24% the previous year)1. Law firms are no exception.
Here are seven projects that a firm of any size should prioritise in 2026, ranked by impact.
1. Roll Out MFA Universally — No Exceptions
Multi-factor authentication (MFA) must be active on all services exposed to the internet: email, practice management platforms (LGD, RPVA), VPN, administration panels, and bank accounts.
A password alone is no longer a serious barrier: sooner or later it will be compromised (phishing, supplier data breach, brute-force attack). According to Microsoft, enabling MFA blocks more than 99.2% of account compromise attacks2.
Concrete action: audit your critical services this week. Enable MFA wherever possible. For administrator accounts, require a hardware key (YubiKey or equivalent).
2. Move to Managed EDR on Workstations
Traditional antivirus is no longer sufficient against modern ransomware. A managed EDR (Endpoint Detection & Response) detects abnormal behaviour — not just known signatures — and alerts a human operator.
For a law firm, the return on investment is immediate: a compromised workstation left undetected for 48 hours means the entire file server encrypted.
3. Back Up Using the 3-2-1-1 Method, with Immutability
The 3-2-1-1 rule remains the benchmark:
The Principle at a Glance
- 3 copies of data (1 original + 2 backups)
- 2 different media types (distinct storage types)
- 1 offsite copy
- 1 immutable / air-gapped copy (non-modifiable)
The final 1 is the modern evolution in response to ransomware — a copy that nobody can encrypt, delete, or alter, even via a compromised administrator account. Attackers target backups as a priority — without immutability, your disaster recovery plan is compromised before it can even be used.
Essential test: restore a complete file every quarter. An untested backup is an imaginary backup.
4. Train Your Teams — Properly
Email (phishing) is the primary attack vector identified by ANSSI and Cybermalveillance.gouv.fr13. The best technical protection will be bypassed by a single ill-advised click.
Effective awareness training combines:
- Short e-learning modules (15 min/month) with quizzes
- Realistic simulated phishing campaigns
- An annual in-person workshop with practical scenarios
Do not underestimate the cultural impact: staff become a line of defence when they understand what is at stake.
5. Document GDPR Compliance
GDPR requires the firm, as the data controller for highly sensitive data, to be able to demonstrate its compliance. In practical terms:
- An up-to-date records of processing activities (clients, HR, prospects, suppliers)
- Data Protection Impact Assessments (DPIAs) for high-risk processing activities
- Data processor agreements compliant with Article 28
- An explicit data retention policy
- A documented incident procedure — notification to the supervisory authority within 72 hours
Regulatory bodies show no leniency towards regulated professions. A well-maintained file is your best defence in the event of an audit.
6. Prepare an Incident Response Plan — on Paper
When ransomware strikes, the first few hours are critical. If you do not know who to call, in what order, and within what chain of command, you lose precious time while the encryption spreads.
An incident response plan fits on two pages:
- Who makes the decision to isolate the IT system?
- Who notifies the supervisory authority? The Bar Council?
- Which technical provider do you call first?
- How do you maintain a communication channel outside the IT system?
- How do you inform clients (with what message, via what channel)?
Print this plan. Store it outside the information system. Have it reviewed every year.
7. Audit Your Security Posture Annually
A cyber posture deteriorates in silence. An annual audit — internal or external — makes it possible to measure the gap between the objective and reality, and to prioritise corrective actions.
At IMACS SERVICES, we offer a free 15-question preliminary assessment to provide, within 24 hours, an objective measure of your IT and cybersecurity maturity. You leave with a score, costed recommendations, and a prioritised action plan.
In summary: these seven projects require neither an enormous budget nor a dedicated in-house team. They require a clear intent, a plan, and a serious technical partner. That is precisely the role we fulfil for the firms we support.
Request your free preliminary assessment — personalised report within 24 hours, no commitment required.
Sources
Statistics verified in May 2026. Operational figures (response times, case study feedback) reflect IMACS SERVICES' practice and are presented as such.
Footnotes
-
Cybermalveillance.gouv.fr, CPME, MEDEF, U2P — National cyber maturity barometer for micro and small businesses (2nd edition, 2025). cybermalveillance.gouv.fr ↩ ↩2
-
Microsoft — based on Microsoft Entra research, MFA blocks more than 99.2% of account compromise attacks (figure cited in the Entra ID MFA enforcement documentation). learn.microsoft.com ↩
-
ANSSI — Cyber Threat Overview. Phishing is listed among the primary threats addressed. cyber.gouv.fr ↩
Keywords
- Cabinets d'avocats
- MFA
- Sauvegarde
- RGPD
- EDR
