
A 10–50 employee law firm should use a layered cybersecurity strategy rather than relying on antivirus software alone. A practical starting framework includes at least 7 cybersecurity layers: multifactor authentication (MFA), endpoint protection, firewall protection, email security, backup, continuous security monitoring, and employee cybersecurity training.
Together, these layers help protect the firm's identities, computers, network, communications, data, and employees.
For law firms, cybersecurity should be treated as part of ongoing IT management—not as a product that is installed once and forgotten.
1. Protect Identities With MFA and Email Security
The first part of a law firm's cybersecurity strategy should focus on protecting the people accessing its systems.
Attorneys and employees may use email, Microsoft 365, legal applications, cloud services, and other systems throughout the workday. If an unauthorized person gains access to an employee's account, many of the firm's other security measures may be bypassed.
Two important layers are:
Multifactor authentication + Email security
Why MFA Matters
A password represents one authentication factor. Multifactor authentication (MFA) requires an additional form of verification before access is granted.
Law firms should determine where MFA is required across their entire technology environment rather than assuming that enabling it on one application is sufficient.
When reviewing MFA with an IT provider, ask:
- Which systems currently require MFA?
- Which accounts do not?
- How are new users enrolled?
- What happens when an employee loses an MFA device?
- How is access removed when someone leaves the firm?
The goal is to manage identity and access systematically rather than configuring individual accounts without an overall plan.
Why Email Needs Its Own Security Layer
Email is one of a law firm's primary communication tools.
It is also an environment where employees may encounter suspicious links, attachments, credential requests, impersonation attempts, and other malicious messages.
Email security should therefore be treated as a distinct cybersecurity layer rather than assuming endpoint protection alone will address every email-based threat.
A useful principle is:
Protect the account → Protect the inbox → Train the user
Those controls complement one another.
2. Protect Every Computer and the Office Network
The next two cybersecurity layers are:
Endpoint protection + Firewall protection
Although they work together, they protect different parts of the firm's technology environment.
Endpoint Protection
An endpoint can include a desktop, laptop, server, or other managed device.
A law firm with 25 employees may have considerably more than 25 endpoints when laptops, office computers, servers, and other systems are included.
Law firms should ask their IT provider:
- Which devices are being protected?
- Are all firm-owned computers covered?
- Who monitors the protection?
- How are new computers added?
- How are old devices removed?
- What happens when suspicious activity is detected?
The important issue isn't simply whether security software has been installed.
The firm needs to know who is actively managing it.
Firewall Protection
The firewall provides another layer of protection at the network level.
It should be managed as part of the firm's overall cybersecurity environment rather than treated as another piece of office equipment that is installed and then ignored.
When evaluating firewall protection, ask:
- Who manages it?
- Who updates it?
- Who monitors it?
- What happens when it generates an alert?
This shifts the cybersecurity conversation from simply owning security equipment to actively managing security.
3. Protect Law-Firm Data With Backup and Continuous Monitoring
Preventing every possible technology or cybersecurity incident is not a realistic strategy.
Law firms also need to prepare for situations in which data becomes unavailable, a system fails, or suspicious activity needs investigation.
That makes the next two layers:
Backup + Continuous security monitoring
Backup Is More Than Having Another Copy
A law firm should be able to answer at least five questions about its backups:
- What is being backed up?
- How frequently is it backed up?
- Where are the backups stored?
- Who verifies that backups are working?
- How would the firm recover the data if it were needed?
A backup that has never been monitored or tested should not automatically be assumed to be recoverable.
Backup therefore belongs inside the firm's broader IT management and business-continuity strategy.
Security Monitoring Should Be Continuous
NICG's service philosophy is proactive rather than reactive and includes 24/7 network monitoring and management.
The objective is to identify and address potential issues before they become larger problems.
For a law firm comparing cybersecurity providers, an important distinction is:
Security tools generate information. Security management requires someone to act on that information.
Ask prospective IT providers:
- What systems are monitored?
- When are they monitored?
- Who reviews alerts?
- What triggers action?
- How are important issues escalated?
These questions help determine whether "monitoring" represents active management or simply another feature on a product list.
4. Train Employees to Recognize Cybersecurity Threats
Technology alone isn't a complete cybersecurity strategy.
Employees make decisions throughout the day involving email, links, attachments, passwords, files, applications, and requests for information.
Employee cybersecurity training should therefore be treated as its own security layer.
A simple four-step framework is:
Train → Test → Reinforce → Repeat
Train
Employees should understand common cybersecurity risks and know the firm's expectations for handling suspicious activity.
Test
Training should help determine whether employees can recognize potentially dangerous situations rather than simply confirming that they completed a course.
Reinforce
Cybersecurity should remain visible throughout the year. One annual presentation can easily be forgotten.
Repeat
Threats, employees, and technology change. Security awareness should therefore be an ongoing process.
Training topics may include:
- Suspicious emails
- Links and attachments
- Credential requests
- Password practices
- MFA requests
- Unusual payment or account-change requests
- Reporting suspicious activity
- Handling confidential information
Most importantly, employees need to know what to do and whom to contact when something doesn't look right.
5. Manage All 7 Cybersecurity Layers as One System
A law firm can purchase multiple cybersecurity products and still have serious gaps if nobody is responsible for managing the complete environment.
The 7-Layer Law Firm Cybersecurity Framework is:
- MFA — protects identities and access
- Endpoint protection — protects computers, laptops, and servers
- Firewall protection — protects the network
- Email security — protects a critical communications system
- Backup — protects data and supports recovery
- Security monitoring — provides ongoing visibility and response
- Employee training — helps people recognize and respond to threats
Another way to visualize the framework is:
Identity → Device → Network → Communication → Data → Monitoring → People
Each layer addresses a different part of the firm's risk.
For firms using cloud and legal applications, cybersecurity also needs to coexist with the technology attorneys and staff use to perform their jobs.
For example, a firm using Clio may also depend on Microsoft 365, email, computers, network infrastructure, backups, and other services.
NICG supports Clio products as a Clio Channel Partner, while also managing the broader IT environment surrounding the firm's legal applications.
The objective should be security that supports the firm's work rather than security controls implemented without considering how attorneys and employees actually operate.
Real-World Example: A 17-User Law Firm
RLT Law is a 17-user law firm supported by NICG for cybersecurity and data-management needs.
NICG's approach for the firm includes the same seven layers described in this framework:
1. MFA
Additional authentication protection for user access.
2. Endpoint Protection
Protection for computers and devices within the supported environment.
3. Firewall Protection
A security layer protecting the network.
4. Email Security
Additional protection around a critical communication system.
5. Backup
Protection of business data and support for recovery requirements.
6. Security Monitoring
Ongoing monitoring of the technology environment.
7. Employee Training
Helping users understand and recognize cybersecurity risks.
This real-world example demonstrates an important point:
Cybersecurity for a small law firm doesn't need to mean one security product. It can be approached as a coordinated, seven-layer system.
How Much Cybersecurity Is Enough for a Small Law Firm?
There isn't one universal cybersecurity package appropriate for every 10–50 employee law firm.
A firm's requirements depend on factors such as:
Number of users → Number of devices → Applications → Data → Remote access → Infrastructure → Risk
However, every firm can start by evaluating the seven core layers.
7-Layer Law Firm Cybersecurity Scorecard
| Security Layer | In Place? | Actively Managed? |
|---|---|---|
| MFA | Yes / No | Yes / No |
| Endpoint protection | Yes / No | Yes / No |
| Firewall protection | Yes / No | Yes / No |
| Email security | Yes / No | Yes / No |
| Backup | Yes / No | Yes / No |
| Security monitoring | Yes / No | Yes / No |
| Employee training | Yes / No | Yes / No |
The "Actively Managed?" column is particularly important.
A law firm may discover that it owns several security products but cannot identify who is responsible for managing them.
That is a cybersecurity gap worth addressing.
What Should a Law Firm Ask Its IT Provider About Cybersecurity?
Use these 10 questions during a cybersecurity review:
- Where is MFA required today?
- Are all of our computers and servers protected?
- Who manages our firewall?
- How is our email environment protected?
- What information is backed up?
- Who verifies that our backups are working?
- What parts of our environment are monitored 24/7?
- What happens when a security alert is generated?
- How are employees trained to recognize threats?
- Who is responsible for coordinating all of these security layers?
If the answers are unclear, the firm has identified areas that deserve further investigation.
NICG Cybersecurity and Law-Firm IT Experience
NICG has provided technology services since 1995.
For law firms evaluating cybersecurity and managed IT support, NICG offers several relevant capabilities:
- 30+ years in business
- Clio Channel Partner
- Experience supporting law-firm technology environments
- MFA implementation and management
- Endpoint protection
- Firewall protection
- Email security
- Backup
- Security monitoring
- Employee cybersecurity training
- Proactive 24/7 network monitoring and management
- Live-person business-hours support
- Remote PC and server support
- Seasoned technicians with continuing education
- Plain-English technology explanations
- Technology and vendor coordination
- 100% satisfaction guarantee
NICG primarily serves businesses throughout Somerset County, Hunterdon County, and Central/North-Central New Jersey.
The 7-Layer Cybersecurity Checklist for Law Firms
A 10–50 employee law firm doesn't need to begin its cybersecurity discussion with a long list of product names.
Start with seven straightforward questions:
-
Do we have MFA?
-
Are our endpoints protected?
-
Is our firewall managed?
-
Is our email protected?
-
Is our data backed up?
-
Is our environment continuously monitored?
-
Are our employees trained?
If the answer to one or more of these questions is "No" or "We don't know," that is where the firm's cybersecurity review should begin.
The goal isn't to accumulate more security products.
The goal is to create a managed, layered cybersecurity environment that protects the people, technology, and data the law firm depends on every day.
Talk With NICG About Your Law Firm's Cybersecurity
If you're unsure whether all seven cybersecurity layers are in place—or whether the security products you already have are being actively managed—NICG can review your current technology environment and help identify potential gaps.
NICG has been providing technology services to New Jersey businesses since 1995 and understands the technology, cybersecurity, and support requirements of small and medium-sized law firms.
Book a Free 15-Minute Consultation with NIC Group Inc.
Visit www.nicg.com to get started.
