Cybersecurity for Small Law Firms: Microsoft 365 and Business Email Compromise
- Shay

- 7 days ago
- 11 min read

I have worked with law firms long enough to know that one of the things that concerns me most is not necessarily ransomware. It is email.
A law firm's email tells a story. If someone gets into an attorney's mailbox and stays there long enough, they can see who the firm is talking to, which matters are moving, which insurance companies or other firms are involved, and when money may be getting ready to change hands. They also learn how people communicate with each other. An attacker with that kind of access does not necessarily need to rush. Sometimes waiting and watching is exactly what makes the eventual fraud believable.
That becomes particularly concerning when a settlement or another financial transaction is approaching. If someone has been following the conversation for weeks and changes the wire instructions at exactly the right point in the process, the email may not look suspicious at all. It may look like the next completely normal message in a conversation everyone involved already recognizes.
This is where business email compromise, or BEC, gets very real for a small law firm.
For many small law firms, Microsoft 365 sits right in the middle of all of this because email, identities, files and access to company information are increasingly connected. That is why I think Microsoft 365 security for a law firm needs to involve much more than turning on MFA and assuming everything else is taken care of.
What Business Email Compromise Can Look Like in a Law Firm
Most people have gotten pretty good at recognizing the obvious phishing emails. The grammar is terrible, the logo looks wrong, or there is a big red warning telling you that your password is going to expire unless you click a link immediately.BEC can be much harder to recognize because the attacker may know what is actually happening.
Imagine someone gets into an attorney's mailbox and spends a couple of weeks reading. They see an active matter, recognize the names of the attorneys and other parties involved, and eventually realize that a settlement is getting close. They know which firm is sending the money, which firm is receiving it and how the attorneys normally communicate.
Now the attacker does not have to invent a transaction. The transaction is real. All they have to do is wait for the right point in the conversation and try to change where the money goes.
There is another version of this where nobody actually gets into the attorney's Microsoft 365 account. An attacker can register a domain that looks almost identical to the real firm's domain and impersonate an attorney, another law firm or another party involved in the matter. Someone moving quickly through email may not notice that a letter has changed or that the domain is slightly different.
This is one reason I configure SPF, DKIM and DMARC, but I don't stop there. A criminal who owns a lookalike domain can configure legitimate email authentication for that domain too. Microsoft provides additional user and domain impersonation protections through Defender for Office 365 that can help address these kinds of attacks.
Microsoft Resource:Anti-phishing and impersonation protection in Microsoft Defender for Office 365. For a law firm, I want those protections available, and I want to know how they are actually configured.
Having Microsoft 365 Does Not Mean All of the Security Is Configured
I run into this misunderstanding with small businesses all the time. They see Microsoft 365 on an invoice every month, they have MFA turned on, and they understandably assume most of the Microsoft security side is being taken care of automatically.
It does not quite work that way.
I have seen this firsthand with a law firm I worked with. They were already using Microsoft 365 and believed their email was secure, but other people began receiving suspicious messages that appeared to come from the firm's domain. When I got into the environment and started looking, several protections I would have expected to find had never been configured.
That experience is one of the reasons I generally recommend Microsoft 365 Business Premium for the small-business environments I manage. I am not recommending Business Premium because buying the license suddenly makes a business secure. I recommend it because it gives me a much better toolbox to work with.
For a law firm, I am particularly interested in phishing and impersonation protection because of the amount of sensitive and financial communication taking place through email. I want MFA properly configured, I want to know who has administrative privileges, I want SPF, DKIM and DMARC configured correctly, and I want to look at Microsoft's anti-phishing and impersonation protections instead of assuming the default configuration is good enough.
also want the endpoint, identity and device-management capabilities that come with Business Premium because email is only part of the environment I am protecting.
The firm may already be paying for some of these capabilities. My question is whether anyone has actually configured them.
MFA Is Important, but I Wouldn't Stop There
MFA makes it considerably harder for someone with a stolen password to simply log into an account, and I absolutely want it configured. I just don't want a law firm assuming that because everyone uses MFA, business email compromise is no longer a concern.
An attacker may impersonate someone without ever signing into that person's Microsoft account. A lookalike domain, a compromised account belonging to another party in the transaction, or a convincing social-engineering attempt can still put a fraudulent message in front of an employee.
That is why I want layers.
Email authentication, anti-phishing and impersonation protection, MFA, endpoint security, administrator security, employee awareness and the business procedures around financial transactions all address different pieces of the problem.
When money is actually going to move, I want one of those layers to have nothing to do with email at all.
When Money Is Moving, I Don't Think Email Should Be Enough
Even with Microsoft 365 properly protected, I don't want Microsoft to be the only thing standing between a law firm and a fraudulent transfer. There are some surprisingly simple procedures a firm can put in place that give everyone another chance to stop something before the money moves.
One that I particularly like is establishing a verification word or phrase early in a matter when everyone knows money will eventually change hands. Depending on the matter, that may be with the firm's client, another law firm, an insurance company or another party responsible for sending or receiving the funds. I would establish that word during an in-person conversation or over the phone using contact information that is already known to be legitimate. After that, it does not go into email. It does not get added to the case email thread, and nobody sends a reminder message later containing the word.
The whole point is that someone who compromises either side's mailbox cannot search the email history and find it.
The procedure also needs to be understood before anyone is waiting for money. If payment instructions change, a bank account changes or an email suddenly says settlement proceeds should be sent somewhere different, nobody changes anything based solely on that email. The request gets independently verified using the procedure established ahead of time.
Suppose one law firm is sending settlement funds to another firm and receives an email from an attorney it has been communicating with for months. Everything looks normal, except the attorney says the bank account has changed. That should trigger the verification process.
Call the other firm using the number you already have, not a phone number included in the email requesting the change. Follow the verification procedure and use the word or phrase established outside email as an additional check.
I would want the same rule working in the other direction. If your client receives what appears to be an email from your firm telling them to send money somewhere different, they should already know that your firm does not change financial instructions that way without verification.
There is one part of this that is really important: do not reply to the questionable email and ask for the verification word. If the mailbox has been compromised, you may be talking directly to the attacker.
If the change cannot be independently verified, stop the transaction and get the appropriate IT person involved. At that point I would want to know whether one of the mailboxes may actually be compromised, and I would start looking at sign-in activity, active sessions, forwarding and inbox rules, sent and deleted messages, authentication activity and anything else that looks out of place.
The verification procedure follows the money, not just the attorney-client relationship. Whoever is responsible for sending, receiving or changing instructions for those funds should know how a legitimate change will be verified before the transaction happens.
I Also Care About the Computer Accessing Your Firm's Data
Protecting the mailbox is only part of the job. I also care about the computer someone is using to access it.
One of the things I like about Microsoft 365 Business Premium is that I don't have to treat a correct password and an MFA approval as automatic permission to get into everything.
If I am managing the firm's computers through Microsoft Intune, I can establish compliance requirements for those devices and then use Microsoft Entra Conditional Access to require a compliant device before allowing access to Microsoft 365 resources protected by that policy.
Microsoft Resource:Require device compliance with Microsoft Entra Conditional Access
Consider an attorney working from home. Their company laptop is downstairs, but there is an old personal computer sitting nearby. They know their Microsoft 365 password and have their phone available to complete MFA. That does not necessarily mean I have to let that computer into the firm's protected Microsoft 365 environment.
Intune can evaluate managed devices against the compliance policies that apply to them and report their compliance state. A computer can meet those requirements today and fall out of compliance later. I can use security groups to organize users and computers and help determine where policies apply, but putting a computer into a group does not make it compliant. The computer still has to meet the requirements I established.
For attorneys working from home, court, client offices, hotels and other locations, this gives me another way to protect company information without pretending everyone is always sitting safely behind the office firewall.
What If You Don't Know Which Microsoft 365 Policies Are Actually in Place?
I don't expect the managing partner of a small law firm to know which Defender policies are configured, how Conditional Access is set up, who has administrative privileges or whether every security setting that was put in place several years ago still works the same way today. That's my side of the conversation.
This is one of the reasons I offer a Microsoft 365 Audit. Sometimes I am brought into an environment where the firm genuinely doesn't know what has been configured. Microsoft 365 may have been set up years ago, different IT providers may have worked on it, employees have come and gone, licensing has changed and nobody has recently stepped back and reviewed the tenant as a whole.
There is another reason I think an environment should be reviewed periodically even when it was configured correctly in the first place: Microsoft 365 doesn't stand still.
Microsoft is continually changing the platform. Features are added, older functionality is retired, administrative experiences change, security capabilities evolve, and Microsoft may introduce a newer way of accomplishing something that was originally configured years ago. At the same time, changes are happening inside the business. Employees come and go, licenses change, applications are added, exceptions get created and administrators make adjustments.
Over time, the environment you have today may no longer look exactly like the environment you thought you had.
That is what I mean when I talk about configuration drift. It doesn't automatically mean someone did something wrong. Sometimes it is the cumulative result of years of normal business changes, administrative changes and changes Microsoft has made to the platform itself.
During a Microsoft 365 Audit, I want to establish what is actually in place today. I can review accounts and administrative access, authentication, licensing, Conditional Access, email-security protections and other relevant security configurations. I also want to know whether older configurations still make sense, whether something has been replaced or retired, and whether the firm's current licensing gives us security capabilities that aren't being used.
For a firm that had its Microsoft 365 environment reviewed several years ago, the question isn't necessarily: “Did our IT provider configure this incorrectly?”
A better question may be:
“Does the Microsoft 365 environment we have today still match the security posture we intended to have?”
That is a very different conversation.
For firms that want me to look beyond Microsoft 365, I also offer an IT Baseline Assessment, where I step back and look at the broader technology environment, including computers, administrative privileges, endpoint security, firewall, networking, Wi-Fi, backups and remote access.
If I end up managing the environment, I maintain a detailed IT runbook with version numbers, dates and timestamps, along with an appendix documenting what changed and when. If I change a security policy today and need to understand something six months from now, I don't want to rely on my memory. I want to be able to go back and see what was changed.
I would much rather find a security policy that has drifted, an old configuration Microsoft has replaced, or a protection the firm owns but isn't using during an audit than discover it while investigating an incident.
Where I Would Start
A small law firm does not need the IT department of a 500-attorney firm, but somebody needs to be looking at the whole picture.
Microsoft 365 can provide a strong foundation for a small law firm, but the licensing is only part of it. The environment needs to be configured, managed and revisited as the firm and Microsoft's platform change.
I also don't want technology to become the only line of defense. If money is moving, the firm should have a verification procedure that does not depend on email being trustworthy. If attorneys are accessing company information remotely, I want to think about the devices being used to access it. If Microsoft 365 was configured years ago, I want to know whether the environment that exists today still matches what everyone believes is in place.
If I were sitting down with a small law firm for the first time, I would probably start with two questions:
Do you know how your Microsoft 365 environment is actually configured today?
If payment instructions changed tomorrow, does everyone involved know exactly how that change would be verified?
If either answer is “I'm not sure,” that's useful information. Now we know where to start.
Frequently Asked Questions
Is Microsoft 365 secure enough for a small law firm?
It can provide a strong security foundation, but licensing, configuration and ongoing management matter. Owning a security capability and having somebody properly configure and maintain it are two different things.
Why do you recommend Microsoft 365 Business Premium for small law firms?
When I am responsible for a small-business environment, Business Premium gives me access to identity, device-management, endpoint and email-security capabilities I want available. Those tools still need to be configured around the business.
Does MFA prevent business email compromise?
MFA is important, but I would never rely on it by itself. BEC can involve account compromise, impersonation, lookalike domains and social engineering, so MFA should be one layer of a broader strategy.
Can a law firm block Microsoft 365 access from unmanaged computers?
Microsoft Entra Conditional Access can be configured to require a device to be marked compliant before granting access to resources protected by the policy. The exact implementation needs to be designed and tested for the firm's environment.
Should changes to payment or wire instructions be verified outside email?
I think they should. A change should be independently verified using trusted contact information and a procedure established before the questionable email arrived. A verification word or phrase established outside email can provide another layer in that process.
What should we do if a payment-change request fails verification?
Stop the transaction. Do not continue the verification through the questionable email. Contact the other party using trusted information and get the appropriate IT provider involved so the email environment can be investigated.
Our IT company already configured Microsoft 365. Why would we need an audit?
Having Microsoft 365 properly configured in the past doesn't necessarily tell you what the environment looks like today. Employees, administrators, licensing and applications change over time, and Microsoft continually updates the platform itself. Features can be added, changed or retired, and newer security capabilities may become available.
A periodic review can help identify configuration drift and confirm that the protections the firm believes are in place still match the environment it has today.
What is Microsoft 365 configuration drift?
Configuration drift is what can happen when the Microsoft 365 environment gradually changes from its original or intended configuration. It can result from normal administrative changes, new employees and applications, licensing changes, policy exceptions or changes Microsoft makes to the platform itself.
Finding drift does not automatically mean something was configured incorrectly. The point of reviewing it is to make sure today's environment still reflects the security posture the business intends to have.
Official Resources
This article provides general information about cybersecurity and Microsoft 365 technology. It is not legal advice or a determination of a law firm's professional-responsibility obligations.




Comments