Skip to main content

Law firm cybersecurity: the way in is still the person

The breaches reported at Quinn Emanuel and McDermott put law firm cybersecurity back in the spotlight: the information they hold is valuable, and access is usually gained by deceiving a person rather than breaking encryption.

CybersecuritySeintec Team2-3 min read
Law firm cybersecurity: the way in is still the person

News summary

Reuters reported security incidents at two large legal firms, Quinn Emanuel and McDermott. Beyond the names, the interest lies in the type of organisation affected: entities that concentrate confidential information from many clients in a single system.

A firm holds litigation strategies, unannounced corporate transactions, sensitive personal data and privileged communications. To an attacker, that combination is worth more than the infrastructure itself. And the shortest path to it is almost never technical: it is a credible email, a well-prepared phone call or a password reset request that sounds reasonable.

At Seintec we see the same pattern in Spanish law firms, advisory practices and consultancies. Money goes into firewalls and antivirus, but email access is protected by a password alone, mailboxes hold years of unclassified history, and staff share documents through links nobody reviews afterwards.

Three controls change the outcome out of all proportion to their cost. First, phishing-resistant multi-factor authentication on email and remote access. Second, a strict procedure — verified through a second channel — for any change of credentials or bank details. Third, limiting access to case files by genuine need rather than convenience.

There is also a sector-specific obligation: professional confidentiality does not disappear because the failure was an IT one. A firm that cannot demonstrate which files were accessed during an incident has an ethical problem as well as a technical one.

Training helps, but it is not enough on its own. Social engineering works precisely on competent people acting quickly. Controls therefore have to be designed to withstand human error, not to assume it will not happen.

Source: Reuters 3 September 2026

Why this matters to a company operating in Spain

The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.

That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.

Real business impact

Before deciding on an investment, it is advisable to identify what is at stake. In cybersecurity projects, we typically review these four areas with management and the IT manager:

  • Operational disruption: orders, invoicing, or production halted while systems are restored.
  • Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
  • Hidden cost of recovery: overtime, external hiring, and loss of client trust.
  • Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.

Five-step action plan

A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:

  • Enable phishing-resistant multi-factor authentication on email, VPN and the document platform.
  • Require second-channel verification for password changes, bank account changes or changes to a payment recipient.
  • Review permissions file by file and withdraw access inherited from closed matters.
  • Enable and retain document access logs for at least twelve months.
  • Run an impersonation exercise with the team twice a year and measure the results.

Key indicators you should be measuring

What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:

  • Percentage of accounts with phishing-resistant multi-factor authentication.
  • Number of accounts with access to matters they no longer work on.
  • Click and report rates in phishing simulations.
  • Retention period, in days, of document access logs.

How we approach it at Seintec: Cybersecurity

We shield your company so it never stops. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.

These are the capabilities we bring to the table in a cybersecurity project:

  • EDR / XDR: Advanced detection and response across endpoints and network.
  • UTM perimeter security: Managed firewall and segmentation.
  • Email filtering: Phishing, spam, and spoofing blocking.
  • WAF: Protection of published applications and services.
  • Immutable backup: Backups that ransomware cannot alter.
  • MFA and identity: Conditional access based on user and device.

What you gain by working with a technology partner

Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:

  • Total prevent–detect–respond coverage: Immutable backup, email filtering, WAF, EDR/XDR, and UTM perimeter security in a single managed contract.
  • Ensured continuity: Regain full control of your infrastructure in the event of a cyber incident in less than 4 hours.
  • Zero Trust by design: Identity-based access control and MFA for any user and device.
  • AI-powered defence: Machine learning engines that monitor endpoints and networks in real time and reduce the mean time to detection.

Frequently Asked Questions

Why are law firms such a frequent target?
Because they concentrate confidential information from many organisations in a single environment and usually have fewer security resources than their corporate clients. The attacker gets the same value for less effort.
Is SMS-based multi-factor authentication enough?
It is better than nothing, but it is the easiest method to bypass through SIM swapping or interception. For confidential information we recommend an authenticator app or physical security keys.
How do I know if my company is truly protected?
With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
Where should a company wanting to address cybersecurity begin?
With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
Is it necessary to halt business operations during the project?
No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
What type of companies do you serve?
SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
What coverage and response times (SLA) do you offer?
Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.

If your organisation holds confidential information belonging to third parties, email and document access security is not a technical detail. At Seintec we strengthen identity, access and traceability without complicating your team's day. Get in touch.

Contact Seintec

Related service

Cybersecurity

We shield your company so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.