---
title: Four Steps to Improve Digital Data Security at Law Firms
description: Four Steps to Improve Digital Data Security at Law Firms
image: https://blog.stratixsystems.com/hubfs/Imported_Blog_Media/Stratix-22-1500x430.jpg
---

- [](https://www.linkedin.com/company/stratix_systems)
- [](https://www.facebook.com/stratixsystemsinc)
- [](https://twitter.com/stratix_systems)
- [](http://www.stratixsystems.com/google.com/+StratixSystemsReading)
- [](mailto:inquiry@stratixsystems.com;marketing@stratixsystems.com)

- [Blog](http://www.stratixsystems.com/about-us/blog/)
- [Resources](http://www.stratixsystems.com/resources/)
- [Contact Stratix Systems](http://www.stratixsystems.com/about-us/contact-stratix/)

[![Stratix Systems](https://blog.stratixsystems.com/hubfs/StratixSystems-Nov2016/Image/logo-homepage.png)](http://www.stratixsystems.com/)

- [IT & Managed Services](http://www.stratixsystems.com/it/) 
    - Proactive: Managed Services 
          - [Managed IT / Network Services](http://www.stratixsystems.com/it/pro-mang-services/pro-mns/)
          - [Backup and Disaster Recovery](http://www.stratixsystems.com/it/pro-mang-services/pro-bdr/)
          - [Hosted E-mail and Management](http://www.stratixsystems.com/it/pro-mang-services/pro-email/)
          - [vCIO / CTO Services](http://www.stratixsystems.com/it/pro-mang-services/vcio-cto-services/)
          - [About our NOC](http://www.stratixsystems.com/it/pro-mang-services/about-our-noc/)
    - IT Support Services 
          - [Servers and Virtualization](http://www.stratixsystems.com/it/it-support-services/servers-virtual/)
          - [E-mail / Exchange](http://www.stratixsystems.com/it/it-support-services/email-exchange/)
          - [Networks](http://www.stratixsystems.com/it/it-support-services/networks/)
          - [Security](http://www.stratixsystems.com/it/it-support-services/security/)
          - [IT and Network Assessments](http://www.stratixsystems.com/it/it-support-services/network-assessments/)
- [Printing Systems](http://www.stratixsystems.com/print/) 
    - By Device 
          - [Copiers (MFP) & Printers](http://www.stratixsystems.com/print/by-device/copier-printers/)
          - [Production Print Systems](http://www.stratixsystems.com/print/by-device/prod-print-fiery/)
          - [Wide-format Systems](http://www.stratixsystems.com/print/by-device/wide-format/)
          - [Digital Duplicators](http://www.stratixsystems.com/print/by-device/digital-duplicators/)
          - [Toner and Supplies](http://www.stratixsystems.com/print/by-device/toner-supplies/)
    - By Solution 
          - [Managed Print Services](http://www.stratixsystems.com/print/by-solution/managed-print-services/)
          - [Fiery Solutions](http://www.stratixsystems.com/print/by-solution/fiery-solutions/)
          - [Mobile and Wireless Printing](http://www.stratixsystems.com/print/by-solution/mobile-wireless-printing/)
          - [Print Security](http://www.stratixsystems.com/print/by-solution/print-security/)
          - [Cost Recovery](http://www.stratixsystems.com/print/by-solution/cost-recovery/)
- [Document Management](http://www.stratixsystems.com/edm/) 
    - [Microsoft SharePoint Solutions](http://www.stratixsystems.com/edm/sharepoint/)
    - [Microsoft Office 365 Services](http://www.stratixsystems.com/edm/office-365/)
    - [Scan-Store-Retrieve Solutions](http://www.stratixsystems.com/edm/scan-store-retrieve/)
    - [Workflow Automation Services](http://www.stratixsystems.com/edm/workflow-automation/)
    - [Shredding and Destruction](http://www.stratixsystems.com/edm/shredding-destruction/)
- [Support](http://www.stratixsystems.com/support/) 
    - [Service Request](http://www.stratixsystems.com/support/service-request/)
    - [My Stratix: Client Portal](http://client.stratixsystems.com/einfo)
- [About Us](http://www.stratixsystems.com/about-us/) 
    - About Stratix Systems 
          - [News and Events](http://www.stratixsystems.com/about-us/news-events/)
          - [Certifications and Awards](http://www.stratixsystems.com/about-us/certs-awards/)
          - [Technology Partners](http://www.stratixsystems.com/about-us/tech-partners/)
    - Contacts and Locations 
          - [Wyomissing – Reading Area](http://www.stratixsystems.com/about-us/contact-stratix/reading/)
          - [Bethlehem – Lehigh Valley Area](http://www.stratixsystems.com/about-us/contact-stratix/lehigh-valley/)
          - [King of Prussia – Philadelphia Area](http://www.stratixsystems.com/about-us/contact-stratix/philadelphia/)
          - [Northern and Central New Jersey](http://www.stratixsystems.com/about-us/contact-stratix/nj/)
- [Careers](http://www.stratixsystems.com/about-us/careers/)



# Stratix Systems Blog

- You are here:
- [Home](http://www.stratixsystems.com)/
- [Stratix Systems Blog](https://blog.stratixsystems.com)/
- Four Steps to Improve Digital Data Security at Law Firms

[![](https://blog.stratixsystems.com/hubfs/Imported_Blog_Media/Stratix-22-1500x430.jpg)](https://blog.stratixsystems.com/hubfs/Imported_Blog_Media/Stratix-22-1500x430.jpg)

# [Four Steps to Improve Digital Data Security at Law Firms](https://blog.stratixsystems.com/four-steps-to-improve-digital-data-security-at-law-firms)

04/29/2016 /  in [Blog](https://blog.stratixsystems.com/topic/blog) /

- [Tweet](https://twitter.com/share)

![Stratix 22](https://blog.stratixsystems.com/hs-fs/hubfs/Imported_Blog_Media/Stratix-22-1500x430.jpg?width=1500&height=430&name=Stratix-22-1500x430.jpg)

Small law firms tend to think that they’re safe from becoming the target of hackers.

Unfortunately, that assumption is wrong.

In fact, hackers are attacking small- and mid-sized businesses precisely because such entities usually don’t defend themselves as well as large enterprises. Whether it’s the lack of IT resources or budget constraints, SMBs, including law firms, need to confront today’s threats head on.

Breaches at law firms are not uncommon. An [American Bar Association survey](http://www.law360.com/articles/705657/1-in-4-law-firms-are-victims-of-a-data-breach) last year found that one in four law firms with at least 100 attorneys had experienced a data breach due to a hacker, website attack, break-in, or lost or stolen computer or smartphone. Meanwhile, the consequences of weak security could impact a firm’s business, as more corporate clients insist that their outside firms do more to safeguard sensitive information.

Law firms are taking note.

[In the 2015 ILTA/InsideLegal Technology Purchasing Survey,](http://insidelegal.typepad.com/files/2015/08/2015_ILTA_InsideLegal_Technology_Purchasing_Survey.pdf) 59 percent of respondents said security management was their top IT challenge. The issue topped the list, knocking email management out of the number one spot for the first time in eight years.

To build a better defense, firms should review their data retention and security policies, ensure that both firm-owned and personally-owned hardware and software is well protected, and educate their attorneys on IT security best practices.

## Step one

#### Make sure your firm has and adheres to an appropriate data retention policy.

In its code of conduct, the ABA has published general guidelines on how long attorneys should hold documents ([see Model Rule 1.15, 1.16 (d) and DR 2-110 (A)(2)).](http://www.americanbar.org/groups/professional_responsibility/services/ethicsearch/materials_on_client_file_retention.html) Unlike most businesses, which typically retain documents for seven to 10 years, law firm have complex retention policies B because of their fiduciary duty to store, manage and maintain certain types of documents, such as wills and living trusts, for specific periods of time.

The duties can also vary according to the type of law practiced and the jurisdiction where the firm operates. Above and beyond the ABA rules, for example, each state has model rules on records to retain and for how long.

Careful monitoring of when documents and email may be deleted is an important part of data security because hackers can’t steal data that your firm no longer has. Another benefit is that it limits the information that may be subject to a discovery motion. If your firm retains information beyond what’s required, it can create additional risk for the firm.

Your retention policy should also follow best practices about the storage of data. Sensitive data should never be transferred onto thumb drives, which someone can easily drop in their pocket and walk out the door. Nor should it be kept on the hard drives of attorneys’ individual PCs. Rather, sensitive data should be stored only on secure servers at the firm or its vendor.

## Step two

#### Ensure end-point security.

In an ideal world, all sensitive data would be kept only on secure servers and never on individual devices, or end points. In practice, however, attorneys carry important documents on and access potentially sensitive email using desktops, laptops, tablets and phones. Each device should have anti-virus and intrusion-detection software. The IT department should make sure that all application software, operating systems and browsers are kept up to date and incorporate the latest patches issued by their vendors. Each device should include encryption capabilities both for storing data and transmitting it.

## Step three

#### Make sure to address the weakest link in data security – human beings.

Teach them when and how to encrypt data. According to the ILTA survey, nearly 35 percent of firms had no standard policy or requirement to encrypt data when it was transferred out of their litigation/practice support group. Educate everyone in the firm, including staff, attorneys and senior partners, on end-point security best practices. All should understand, for example, why they should never click on links or attachments unless they know who is sending them. Even senior business executives or law partners are susceptible to social engineering hacks such as phishing, as the horror story described in step four illustrates.

## Step four

#### Design, implement and enforce a BYOD policy that lays out what type of devices are allowed and how IT will secure these devices.

![vector flat design concept of BYOD bring you own device. hand holding device. flat style vector illustration](https://blog.stratixsystems.com/hs-fs/hubfs/Imported_Blog_Media/BYOD-for-Stephanie-post-300x300.jpg?width=300&height=300&name=BYOD-for-Stephanie-post-300x300.jpg)Increasing use of personal [mobile devices](http://www.ricoh-usa.com/services_and_solutions/ricoh_mobile_worker_services/) for work has opened up a new threat to security. Especially when using tablets or phones, attorneys may not realize they are exposing sensitive data. If their phone is lost or stolen, a bad actor could potentially use the attorney’s log-in credentials to access the firm’s network and install a Trojan horse undetected. Once in, the thief can steal information immediately or just lurk in the background and cherry-pick specific data.

In the ILTA study, some 28 percent of firms said they had no BYOD policy. Of those that did have a policy, 71 percent covered smartphones, 59 percent covered tablets and only 28 percent covered laptops.

Without a rigorously enforced BYOD policy, bad things happen. For example, a C-level executive recently shared this personal horror story: He and a fellow executive both received the same email saying that there was a problem with the firm’s payroll. Each logged into the system using their own personal, unsecured mobile devices. The e-mail turned out to be a cleverly constructed phishing adventure that redirected the executives to a site that captured their logins and passwords. The hackers then used those credentials to redirect the executives’ paychecks to an account in Grand Cayman. The company had no idea its payroll had been hacked until two weeks later, when the executives’ paychecks never showed up.

## What’s next?

By bringing a fresh eyes, an outside technology consultant can be helpful in reviewing your retention policy and evaluating your security stance. Through vulnerability testing and gap analysis, a consultant often identifies areas that have been overlooked or need updating to the latest technology. It can re-mediate problems, recommend improvements and help you deploy a sound security strategy, using the proper tools, to protect digital data from increasingly inventive hackers.

**Learn more about how [legal support services can help your firm.](http://solutions.ricoh-usa.com/industry-solutions/legal) If you’d like a security assessment, check out the [services at mindSHIFT](http://www.mindshift.com/Services/Managed-IT-Services/Law-Firms.aspx%5d.).**

- [Tweet](https://twitter.com/share)

**Tags:** [Blog](https://blog.stratixsystems.com/topic/blog)

[Healthcare Professionals: 3 Data Management Strategies for Stronger Financial Results ![](https://blog.stratixsystems.com/hs-fs/hubfs/Imported_Blog_Media/Stratix-healthcare-technology-1500x430.jpg?width=80&height=80&name=Stratix-healthcare-technology-1500x430.jpg)](https://blog.stratixsystems.com/healthcare-professionals-3-data-management-strategies-for-stronger-financial-results) [![](https://blog.stratixsystems.com/hs-fs/hubfs/Imported_Blog_Media/stratix-19-1200x430.jpg?width=80&height=80&name=stratix-19-1200x430.jpg) Data Security Best Practices Every Small Business Should Follow](https://blog.stratixsystems.com/data-security-best-practices-every-small-business-should-follow)

- [Blog](https://blog.stratixsystems.com/blog)
- [News and Events](http://www.stratixsystems.com/about-us/news-events/)
- [Certifications and Awards](http://www.stratixsystems.com/about-us/certs-awards/)
- [Technology Partners](http://www.stratixsystems.com/about-us/tech-partners/)
- [Apply Now](http://www.stratixsystems.com/about-us/applynow/)
- [Careers](http://www.stratixsystems.com/about-us/careers/)
- [Our People](http://www.stratixsystems.com/about-us/our-people/)
- [The Benefits](http://www.stratixsystems.com/about-us/the_benefits/)
- [Why Stratix?](http://www.stratixsystems.com/about-us/why-stratix/)
- [Contact Stratix Systems](http://www.stratixsystems.com/about-us/contact-stratix/)

### Recent Posts

<https://blog.stratixsystems.com/benefits-of-digitized-workflow-beyond-cost-savings> 

**[Benefits of Digitized Workflow Beyond Cost Savings](https://blog.stratixsystems.com/benefits-of-digitized-workflow-beyond-cost-savings)**

 11/28/2016 - 11: 25 AM

<https://blog.stratixsystems.com/document-management-and-interoperability> 

**[Document Management and Interoperability](https://blog.stratixsystems.com/document-management-and-interoperability)**

 11/27/2016 - 11: 24 AM

<https://blog.stratixsystems.com/how-to-increase-revenue-by-7210-per-employee> 

**[How to Increase Revenue by $7,210 per Employee](https://blog.stratixsystems.com/how-to-increase-revenue-by-7210-per-employee)**

 11/23/2016 - 11: 21 AM

<https://blog.stratixsystems.com/how-less-paper-benefits-the-continuum-of-care> 

**[How Less Paper Benefits the Continuum of Care](https://blog.stratixsystems.com/how-less-paper-benefits-the-continuum-of-care)**

 11/19/2016 - 09: 00 AM

### Other Categories

- [Awards (2)](https://blog.stratixsystems.com/topic/awards)
- [Backup (2)](https://blog.stratixsystems.com/topic/backup)
- [BDR (2)](https://blog.stratixsystems.com/topic/bdr)
- [Blog (78)](https://blog.stratixsystems.com/topic/blog)
- [Business (17)](https://blog.stratixsystems.com/topic/business)
- [Cost Reduction (1)](https://blog.stratixsystems.com/topic/cost-reduction)
- [Cyber Security (2)](https://blog.stratixsystems.com/topic/cyber-security)
- [Data Loss (3)](https://blog.stratixsystems.com/topic/data-loss)
- [Dealership (5)](https://blog.stratixsystems.com/topic/dealer)
- [Disaster Recovery (1)](https://blog.stratixsystems.com/topic/disaster-recovery)
- [Events (1)](https://blog.stratixsystems.com/topic/events)
- [Intelligent Business Continuity (1)](https://blog.stratixsystems.com/topic/ibc)
- [IT Support (6)](https://blog.stratixsystems.com/topic/it-support)
- [Managed Print Services (1)](https://blog.stratixsystems.com/topic/mps)
- [Managed Services (5)](https://blog.stratixsystems.com/topic/managed-services)
- [Mobility (1)](https://blog.stratixsystems.com/topic/mobility)
- [Multi-Function (3)](https://blog.stratixsystems.com/topic/mfp)
- [News (7)](https://blog.stratixsystems.com/topic/news)
- [Office Equipment (7)](https://blog.stratixsystems.com/topic/equipment)
- [Performance (3)](https://blog.stratixsystems.com/topic/performance)
- [Print (6)](https://blog.stratixsystems.com/topic/print)
- [Proactive (3)](https://blog.stratixsystems.com/topic/proactive)
- [Security (4)](https://blog.stratixsystems.com/topic/security)
- [SMB (6)](https://blog.stratixsystems.com/topic/smb)
- [Stratix Systems (3)](https://blog.stratixsystems.com/topic/stratix-systems)
- [Stratix Systems Social Media (1)](https://blog.stratixsystems.com/topic/stratix-systems-social-media)
- [Uncategorized (5)](https://blog.stratixsystems.com/topic/uncategorized)
- [Windows (2)](https://blog.stratixsystems.com/topic/windows)

see all

### Post Archives

- [April 2016 (22)](https://blog.stratixsystems.com/archive/2016/04)
- [May 2016 (9)](https://blog.stratixsystems.com/archive/2016/05)
- [September 2016 (9)](https://blog.stratixsystems.com/archive/2016/09)
- [November 2016 (9)](https://blog.stratixsystems.com/archive/2016/11)
- [October 2016 (7)](https://blog.stratixsystems.com/archive/2016/10)
- [June 2016 (6)](https://blog.stratixsystems.com/archive/2016/06)
- [July 2016 (4)](https://blog.stratixsystems.com/archive/2016/07)
- [October 2014 (3)](https://blog.stratixsystems.com/archive/2014/10)
- [March 2015 (3)](https://blog.stratixsystems.com/archive/2015/03)
- [December 2015 (3)](https://blog.stratixsystems.com/archive/2015/12)
- [March 2016 (3)](https://blog.stratixsystems.com/archive/2016/03)
- [July 2014 (2)](https://blog.stratixsystems.com/archive/2014/07)
- [February 2015 (2)](https://blog.stratixsystems.com/archive/2015/02)
- [April 2015 (2)](https://blog.stratixsystems.com/archive/2015/04)
- [June 2015 (2)](https://blog.stratixsystems.com/archive/2015/06)
- [July 2015 (2)](https://blog.stratixsystems.com/archive/2015/07)
- [November 2014 (1)](https://blog.stratixsystems.com/archive/2014/11)
- [August 2016 (1)](https://blog.stratixsystems.com/archive/2016/08)

see all

- Quick Nav 
    - [IT & Managed Services](http://www.stratixsystems.com/it/)
    - [Printing Systems](http://www.stratixsystems.com/print/)
    - [Document Management](http://www.stratixsystems.com/edm/)
    - [Support](http://www.stratixsystems.com/support/)
    - [Contact Stratix Systems](http://www.stratixsystems.com/about-us/contact-stratix/)

- Learn More 
    - [Resources](http://www.stratixsystems.com/resources/)
    - [Blog](https://blog.stratixsystems.com/blog)
    - [News and Events](http://www.stratixsystems.com/about-us/tech-partners/)
    - [Technology Partners](http://www.stratixsystems.com/about-us/tech-partners/)
    - [Certifications and Awards](http://www.stratixsystems.com/about-us/certs-awards/)

### Recent Posts

### Contact Stratix

Corporate Headquarters  
 1011 North Park Road  
 Wyomissing, PA 19610  
 P: 610-374-1936  
 F: 610-375-1957  
 E: [Send an E-mail](mailto:inquiry@stratixsystems.com,marketing@stratixsystems.com)

[Stratix Systems Employee Sign-in](https://mail.stratixsystems.com/owa) | Locations in: [Reading,](http://www.stratixsystems.com/about-us/contact-stratix/reading/) [Bethlehem,](http://www.stratixsystems.com/about-us/contact-stratix/lehigh-valley/) [King of Prussia,](http://www.stratixsystems.com/about-us/contact-stratix/philadelphia/) [and Edison.](http://www.stratixsystems.com/about-us/contact-stratix/nj/)

© Stratix Systems | [Privacy Policy](http://www.stratixsystems.com/about-us/privacy-policy/) | No one knows technology solutions like Stratix.