Cybersecurity in law firms: the human remains the gateway
The reported breaches at Quinn Emanuel and McDermott once again bring law firm cybersecurity to the fore: the information they hold is valuable, and access is typically gained by deceiving a person, not by breaking encryption.

News summary
Reuters reported security incidents at two major law firms, Quinn Emanuel and McDermott. Beyond the names of the firms, the interest lies in the type of organisation affected: entities that centralise confidential information from numerous clients within a single system.
A law firm safeguards procedural strategies, unannounced corporate transactions, sensitive personal data, and privileged communications. For an attacker, this dataset is worth more than the infrastructure itself. And the shortest path to reaching it is almost never technical: it is a credible email, a well-prepared call, or a password reset request that sounds reasonable.
At Seintec, we see the same pattern in Spanish law firms, accountancies, and consultancies. Investment is made in firewalls and antivirus software, yet email access is protected by password alone, mailboxes retain years of unclassified history, and users share documents via links that no one subsequently reviews.
There are three controls that change the outcome disproportionately relative to their cost. First, phishing-resistant MFA for email and remote access. Second, a strict procedure —verified via a secondary channel— for any change in credentials or bank details. Third, limiting access to case files based on genuine necessity, rather than convenience.
Added to this is a sector-specific obligation: the duty of professional confidentiality does not vanish because the failure was IT-related. A firm that cannot demonstrate which files were accessed during an incident faces a deontology problem in addition to a technical one.
Training helps, but it is not sufficient on its own. Social engineering works precisely with competent people acting under pressure. Therefore, controls must be designed to withstand human error, rather than assuming it will not occur.
Source: Reuters — 3 September 2026
Why this matters to a company operating in Spain
The threat landscape affecting Spanish companies no longer distinguishes by size. Attacks are automated, sold as a service, and seek the shortest path: a reused credential, an unpatched server, or a provider with poorly controlled remote access. For an SME, the difference between a minor scare and a multi-day shutdown almost always depends on decisions made before the incident.
That is why every industry update should be read in operational terms: which specific controls would have prevented the problem, what evidence must be preserved, and who makes the decision when the clock is ticking. This is the approach we apply to managed cybersecurity projects at Seintec.
Real business impact
Before deciding on an investment, it is advisable to identify what is at stake. In cybersecurity projects, we typically review these four areas with management and the IT manager:
- Operational disruption: orders, invoicing, or production halted while systems are restored.
- Loss or exposure of personal data, with a mandatory 72-hour notification requirement to the AEPD.
- Hidden cost of recovery: overtime, external hiring, and loss of client trust.
- Contractual and compliance requirements (ENS, NIS2, ISO 27001) that demand evidence, not intentions.
Five-step action plan
A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:
- Activate phishing-resistant MFA for email, VPN and access to the document platform.
- Establish second-channel verification for password changes, bank account updates or payment recipient modifications.
- Review permissions per file and remove inherited access from closed projects.
- Enable and retain documentation access logs for at least twelve months.
- Drill a practical impersonation case with the team twice a year, with measured results.
Key indicators you should be measuring
What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:
- Percentage of accounts with phishing-resistant MFA.
- Number of accounts with access to files they no longer manage.
- Click and reporting rates in phishing simulations.
- Retention days for documentation access logs.
How we approach it at Seintec: Cybersecurity
We shield your business so it never stops. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.
These are the capabilities we bring to the table in a cybersecurity project:
- EDR / XDR: Advanced detection and response across endpoints and network.
- UTM perimeter security: Managed firewall and segmentation.
- Email filtering: Blocking of phishing, spam, and impersonation.
- WAF: Protection of published applications and services.
- Immutable backup: Backups that ransomware cannot alter.
- MFA and identity: Conditional access by user and device.
What you gain by working with a technology partner
Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:
- Total prevent–detect–respond coverage: Immutable backup, email filtering, WAF, EDR/XDR and UTM perimeter security in a single managed contract.
- Assured continuity: Regain control of your infrastructure following a cyber incident with a recovery objective agreed with you in the continuity plan.
- Zero Trust by design: Identity-based access control and MFA for every user and device.
- AI-powered defence: Machine learning engines that monitor endpoints and networks in real time, reducing the mean time to detection.
Frequently Asked Questions
- Why are law firms a frequent target?
- Because they centralise confidential information from numerous organisations within a single environment and typically possess fewer security resources than their corporate clients. The attacker achieves the same value with less effort.
- Is SMS-based multi-factor authentication sufficient?
- It is better than nothing, but it is the easiest method to bypass via SIM swapping or interception. For confidential information, we recommend an authenticator app or physical security keys.
- How do I know if my company is truly protected?
- With evidence: EDR coverage, two-factor authentication on all remote access, immutable copies, and a recently tested restoration. If any of these four points are not confirmed, there is a real risk of prolonged downtime.
- Where should a company wanting to address cybersecurity begin?
- With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
- Is it necessary to halt business operations during the project?
- No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
- What type of companies do you serve?
- SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
- What coverage and response times (SLA) do you offer?
- Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.
Concepts mentioned in this article: Cybersecurity · Antivirus · Phishing · Firewall
If your organisation safeguards third-party confidential information, email and document access security is not a technical detail. At Seintec, we reinforce identity, access, and traceability without complicating the team's daily operations. Consult us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.