βš–οΈ Industry Security

Professional Services Security

Your clients trust you with their most sensitive information β€” legal strategies, financial records, medical histories. A single data leak can end your practice. Here is how to protect what matters.

#1

professional services is the most targeted sector for business email compromise (BEC)

$275K

median loss from a single BEC attack targeting a professional services firm

74%

of law firms experienced a security breach in 2025 (ABA survey)

Why Professional Services Are Prime Targets

Attackers go where the money and secrets are. Law firms hold merger-and-acquisition details, intellectual property, and embarrassing personal information. Accounting firms have tax returns, Social Security numbers, and bank account details. Medical clinics hold protected health information (PHI) that sells for 10-50Γ— more than credit card numbers on the dark web. And most professional services firms have minimal security β€” because "it has not happened to us yet."

πŸ“§ Business Email Compromise (BEC)

Attackers impersonate a partner, client, or vendor and request a wire transfer, W-2 forms, or confidential case files. These emails are highly targeted β€” they reference real cases, use the partner's actual signature block, and arrive during busy periods when nobody double-checks.

πŸ“‚ Client File Exfiltration

Once inside your network β€” often via a compromised email account β€” attackers quietly download case files, tax returns, or patient records over weeks or months. You may not discover the breach until the data appears for sale online or a client reports identity theft.

πŸ”“ Ransomware Targeting Professional Practices

Attackers encrypt all your files β€” case management systems, document repositories, email archives β€” and demand payment. Professional services firms are specifically targeted because they are more likely to pay: the cost of lost billable hours and ethical obligations to clients create enormous pressure.

πŸ“± Lost or Stolen Devices

Laptops, phones, and USB drives containing client data get left in taxis, stolen from cars, or lost at airports. If those devices are not encrypted, every client file on them is exposed β€” and in many jurisdictions, you must notify every affected client individually.

πŸ₯ HIPAA & Regulatory Compliance Failures

For medical practices and their business associates, HIPAA violations carry fines of $100-$50,000 per record. For law firms, a data breach can trigger bar association ethics investigations and malpractice claims. For CPAs, the IRS requires written security plans under the FTC Safeguards Rule.

Security Assessment for Professional Services

Our 20-question assessment covers email security, client data handling, device encryption, access controls, and regulatory compliance readiness.

Start Free Assessment β†’

Professional Services Security Checklist

  1. 1
    Encrypt everything β€” devices, email, and files.

    Full-disk encryption (BitLocker on Windows, FileVault on Mac) is mandatory for every device that touches client data. Use encrypted email for sending sensitive documents (many secure portals exist β€” Citrix ShareFile, iManage, Clio). Encrypt cloud storage folders containing client files.

  2. 2
    Deploy multi-factor authentication (MFA) everywhere.

    Email, case management, cloud storage, accounting software, remote access β€” every system must require a second factor. Email is the #1 entry point for attackers targeting professional services. MFA blocks 99% of credential-based attacks.

  3. 3
    Create and enforce a written security policy.

    The FTC Safeguards Rule, HIPAA, and many state bar association ethics opinions require a written information security plan. It does not need to be 50 pages β€” a 5-page document covering access controls, encryption, breach response, and training is sufficient for most small firms.

  4. 4
    Verify wire transfers and sensitive requests by phone.

    Create a firm policy: any wire transfer, W-2 request, or confidential file sharing request received by email MUST be verified by a phone call to a known number β€” not a number in the email. This one rule stops 90%+ of BEC attacks.

  5. 5
    Control and audit third-party access.

    IT consultants, bookkeepers, e-discovery vendors, and cloud providers all access your systems. Maintain a list. Review it quarterly. Revoke access immediately when a vendor relationship ends. Require vendors to carry cyber insurance that covers your data.

  6. 6
    Get cyber insurance β€” with appropriate coverage.

    General liability insurance typically excludes cyber incidents. A standalone cyber policy covers breach notification costs, legal defense, forensics investigation, and ransomware negotiation. For professional services firms, this is as essential as malpractice/E&O coverage.

  7. 7
    Train every employee on phishing and BEC.

    Your smartest partner can fall for a well-crafted phishing email. Run quarterly training sessions. Send simulated phishing emails to test awareness. Make it safe to report mistakes β€” the faster someone tells IT they clicked a bad link, the less damage it causes.

FTC Safeguards Rule: Is Your Firm Compliant?

If you offer financing, process tax returns, or handle financial data for clients, the FTC Safeguards Rule likely applies. Learn the 9 requirements and how to meet them.

Read FTC Safeguards Guide β†’

Compliance Quick Reference for Professional Services

FTC Safeguards Rule: Applies to CPAs, tax preparers, and firms offering financial services. Requires a written security plan, designated security coordinator, and annual risk assessments.
HIPAA: Applies to medical practices, dental offices, and their business associates. Requires PHI encryption, access controls, and breach notification.
State Bar Ethics Rules: Most states now require "reasonable" cybersecurity measures. Check your state bar's formal ethics opinions.
GDPR: Applies if you have clients based in the EU. Client data must be protected and deletable on request.
Explore All Compliance Guides β†’