Law Firm Cybersecurity: Data Breach Costs, Cyber Insurance, and Tax Deductions for Security Investments
Law firms hold client data that is protected by attorney-client privilege, work-product doctrine, and ethical obligations under ABA Model Rule 1.6 (duty of confidentiality). A data breach at a law firm does not just expose names and Social Security numbers (like a retail breach). It exposes litigation strategy, merger negotiations, patent applications, real estate transactions, and settlement terms. The American Bar Association’s Formal Opinion 483 (2018) confirmed that lawyers have an ethical obligation to make “reasonable efforts” to prevent unauthorized access to client data, to monitor for breaches, and to notify affected clients when a breach occurs. The cost of compliance (security infrastructure, monitoring, insurance, incident response) is growing, and it is deductible.
Cybersecurity investments by a law firm are deductible as ordinary and necessary business expenses under IRC 162. Software subscriptions (endpoint protection, email security, backup, monitoring) are deductible when paid or accrued. Hardware (firewalls, secure servers, encrypted drives) is depreciable under MACRS (5-year recovery period for computer equipment) and eligible for Section 179 or bonus depreciation. Cyber insurance premiums are deductible. Data breach costs (forensic investigation, notification, credit monitoring, legal defense, regulatory fines) are deductible as business expenses, except for certain government fines and penalties that are non-deductible under IRC 162(f). The cost of a breach for a small law firm averages $120,000-$250,000 (forensics, notification, lost revenue), making prevention the more economical path.
What cybersecurity infrastructure does a law firm need?
The ABA’s Formal Opinion 477R (2017) and Formal Opinion 483 (2018) do not prescribe specific technologies but require lawyers to stay “abreast of changes in technology” and to make “reasonable efforts” to protect client information. What is “reasonable” depends on the sensitivity of the data, the size of the firm, and the sophistication of the threats.
Minimum infrastructure for a small to mid-size firm:
Endpoint protection. Antivirus and anti-malware on every device (desktops, laptops, mobile devices). Modern endpoint detection and response (EDR) platforms (CrowdStrike, SentinelOne, Microsoft Defender for Business) provide real-time monitoring and automated threat response. Annual cost: $5-$15 per device per month.
Email security. Email is the primary attack vector (phishing, business email compromise, malware attachments). A dedicated email security gateway (Proofpoint, Mimecast, Barracuda) or Microsoft 365 Defender for Office 365 filters threats before they reach the inbox. Annual cost: $3-$8 per user per month.
Multi-factor authentication (MFA). Required on all accounts: email, practice management, banking, cloud storage. MFA prevents credential theft from resulting in account access. Cost: typically included with Microsoft 365 or Google Workspace business plans; standalone MFA (Duo, Okta) costs $3-$9 per user per month.
Encrypted backup. Automated, encrypted backups to an off-site or cloud location (Datto, Veeam, Acronis). The backup protects against ransomware (the firm can restore from backup rather than paying the ransom) and hardware failure. Annual cost: $500-$3,000 depending on data volume.
Encrypted communication. Client communications that contain confidential information should use encrypted channels: encrypted email (Microsoft 365 message encryption, Virtru), secure client portals (Clio, ShareFile, NetDocuments), or encrypted messaging. The ABA’s Formal Opinion 477R addresses the duty to protect confidential information in electronic communications and concludes that encryption is not required for every communication but is required when the sensitivity of the information warrants it.
Network security. A business-grade firewall (not a consumer router), segmented network (separating guest WiFi from the firm network), and VPN for remote access. Annual cost: $1,000-$5,000 for hardware and management.
How does cyber insurance work for law firms?
Cyber insurance (also called cyber liability insurance or data breach insurance) covers the costs of a data breach and related cyber incidents. For law firms, cyber insurance is increasingly viewed as a professional obligation, and some state bars are considering requiring it.
What cyber insurance covers:
First-party coverage (the firm’s own costs): Forensic investigation (determining how the breach occurred, what data was accessed, and how to contain it), notification costs (mailing breach notifications to affected individuals as required by state law), credit monitoring services for affected individuals, data restoration (recovering encrypted or destroyed data), business interruption (lost revenue during the period the firm’s systems are down), ransomware payment (if the insurer agrees to pay the ransom, which is increasingly controversial), and crisis management (public relations, communications consulting).
Third-party coverage (claims against the firm): Legal defense costs (defending against lawsuits from clients, regulators, or third parties), regulatory fines and penalties (where insurable under applicable law), settlements and judgments, and payment card industry (PCI) fines and assessments (if the firm processes credit card payments).
What it typically does not cover: Prior known breaches (breaches discovered before the policy inception), acts of war or terrorism (standard exclusion), bodily injury or physical property damage (covered by GL, not cyber), and intentional acts by the firm’s principals.
Cost for law firms: Annual premiums range from $1,500-$5,000 for a solo or small firm (under 10 attorneys) with $1 million in coverage, to $5,000-$25,000 for a mid-size firm (10-50 attorneys) with $2-5 million in coverage. The premium depends on: the firm’s revenue, the number of records held (client files, personal information), the firm’s security posture (firms with strong controls get lower premiums), and the firm’s claims history.
Tax treatment: Cyber insurance premiums are deductible as an ordinary and necessary business expense under IRC 162, the same as malpractice insurance or general liability insurance.
What happens when a breach occurs?
Immediate response (first 72 hours). The firm must: contain the breach (isolate affected systems, change all passwords, disable compromised accounts), engage a forensic investigator (the cyber insurance carrier typically provides a pre-approved panel of forensic firms), and preserve evidence (do not wipe or rebuild affected systems until the forensic investigation is complete).
Notification obligations. All 50 states have data breach notification laws that require notification to affected individuals when personal information (name plus SSN, driver’s license number, financial account number, or other specified data elements) is compromised. The notification timeline varies by state: some require notification within 30 days, others within 60 days, and some require notification “without unreasonable delay.” If the breach involves residents of multiple states, the firm must comply with each state’s notification law.
For law firms, the ABA’s Formal Opinion 483 adds an ethical notification obligation: the lawyer must inform current clients whose data was accessed, even if the data does not trigger the state notification law. The notification should describe the breach, the data involved, the steps the firm is taking, and the steps the client should take.
Regulatory reporting. Some industries require regulatory reporting: HIPAA (if the firm handles protected health information for healthcare clients), SEC (if the firm handles material nonpublic information for public company clients), and state attorney general offices (most state breach notification laws require a copy of the notification to the AG).
How are cybersecurity costs deducted?
Software subscriptions. Endpoint protection, email security, backup, and monitoring subscriptions are deductible as ordinary business expenses under IRC 162 when paid (cash method) or when the subscription period elapses (accrual method). If a subscription covers more than 12 months, the 12-month rule under Reg. 1.263(a)-4(f) applies (deductible in the year paid if the benefit period does not extend more than 12 months beyond the end of the tax year in which payment is made).
Hardware. Firewalls, servers, encrypted drives, and other security hardware are tangible personal property with a 5-year MACRS recovery period. They are eligible for Section 179 expensing (up to $1,250,000 for 2025) and 100% bonus depreciation under IRC 168(k) (made permanent by OBBBA). Most small law firms expense all security hardware in the year of purchase.
Consulting and assessment. The cost of a cybersecurity assessment, penetration test, or security audit is deductible as a professional service expense under IRC 162.
Training. Employee cybersecurity training (phishing simulation, security awareness programs) is deductible as a training expense under IRC 162.
Breach costs. Forensic investigation, notification, credit monitoring, legal defense, and settlement costs are deductible under IRC 162 as ordinary business expenses related to the operation of the business. Government fines and penalties may be non-deductible under IRC 162(f) if they are “punitive” rather than “compensatory” in nature. The 2017 TCJA modified IRC 162(f) to deny deductions for amounts paid to a government in relation to a violation of law, with exceptions for restitution and amounts paid to come into compliance. Regulatory fines for data breaches (state AG penalties, HIPAA fines) should be analyzed individually to determine deductibility.
What should I do next?
If your firm does not have MFA on all accounts, implement it this week (it is the single highest-impact, lowest-cost security measure). If you do not have cyber insurance, obtain quotes from at least two carriers. If you have never had a cybersecurity assessment, engage a qualified firm to evaluate your current posture and identify gaps. If a breach has occurred, engage your cyber insurance carrier and forensic panel immediately, before attempting remediation.
- Law firm tax deductions, the full inventory of deductible expenses for law firms, including malpractice insurance, bar dues, and technology
- Law firm bookkeeping, the chart of accounts where cybersecurity costs are categorized
- IOLTA trust accounting, the trust account security obligations that intersect with cybersecurity (trust account compromise is the highest-risk breach for law firms)
- Law firm billing and collections, the business interruption impact when systems are down after a breach
- Construction insurance and bonding, the parallel insurance analysis for another industry with significant liability exposure
The assessment is a fixed $250. You get a written, CPA-reviewed analysis of your cybersecurity spending, deduction optimization, cyber insurance adequacy, and the tax treatment of any breach-related costs.
One or two plain-English guides a week on US-Canada tax. No spam, unsubscribe anytime.
Done. The next guide will land in your inbox.
Yarik Yarosh, CPA. "Law Firm Cybersecurity: Data Breach Costs, Cyber Insurance, and Tax Deductions for Security Investments." Blue Cloud CPA, August 27, 2026. https://bluecloudcpa.com/guides/law-firm-cybersecurity-data-breach-tax-deductions
This guide is general information, not tax advice for your specific situation. Which points apply, and how, depends on your facts.