The solicitors' profession has embraced digital transformation at pace. Cloud-based case management systems, outsourced IT providers, eDiscovery platforms, transcription services and managed security providers have become integral to the way modern law firms operate. While these partnerships deliver efficiency and expertise, they also introduce a significant and often underestimated cyber risk.
Increasingly, criminals are bypassing well-defended organisations and targeting the suppliers they rely upon instead. A vulnerability in a third-party vendor can provide attackers with a route into multiple organisations simultaneously, exposing sensitive information, disrupting business operations and creating significant legal and regulatory consequences.
For law firms entrusted with confidential client information, understanding and managing third-party cyber risk is no longer optional – it is a core element of sound governance.
The rise of supply-chain attacks
Supply-chain cyber-attacks have become one of the fastest-growing threats facing organisations worldwide. Rather than attacking a firm's systems directly, threat actors compromise a trusted supplier, software provider or service partner. Once that trusted relationship is exploited, malicious code, stolen credentials or unauthorised access can be passed downstream to customers who may have little reason to suspect anything is wrong.
This approach has proven highly effective because it exploits trust rather than technology. Even organisations with mature cyber security programmes can become victims if a key supplier suffers a breach.
For legal practices, the risk is amplified by the nature of the information they hold. Client files often contain commercially sensitive information, intellectual property, merger and acquisition details, litigation strategies and personal data. A compromise involving any third-party service with access to this information can have serious financial, legal and reputational consequences.
Shared responsibility does not mean shared accountability
One of the most common misconceptions surrounding outsourced services is that responsibility for cyber security transfers to the service provider. While vendors are responsible for securing their own environments, accountability for protecting client information ultimately remains with the organisation that collects and processes that data.
Under the General Data Protection Regulation (GDPR), organisations acting as data controllers must ensure that any third-party processors provide appropriate technical and organisational measures to protect personal data. Simply relying on contractual assurances or assuming a supplier is "taking care of security" is unlikely to satisfy regulatory expectations.
Should a breach occur, clients are unlikely to distinguish between a cyber incident originating within a law firm and one caused by an external supplier. Their expectation is simple: the firm entrusted with their confidential information should have exercised appropriate oversight over every organisation handling that data.
This principle extends beyond data protection. Professional obligations relating to confidentiality, client care and risk management all require firms to understand where sensitive information resides and who has access to it throughout its lifecycle.
Where accountability gaps appear
Third-party cyber risk often develops gradually rather than through a single point of failure. Many organisations perform some level of due diligence before engaging a supplier but then assume that the risk remains static.
In reality, supplier environments change constantly. New software is introduced, infrastructure evolves, personnel change and new subcontractors may become involved in delivering services. Without ongoing oversight, today's trusted supplier can become tomorrow's weakest link.
Common accountability gaps include:
- vendors being onboarded without formal cyber security assessments;
- contracts lacking clear security obligations or incident notification requirements;
- excessive or outdated user access remaining active long after it is needed;
- limited visibility over subcontractors handling sensitive information; and
- failure to review supplier security performance on a regular basis.
Each of these gaps creates opportunities for attackers to exploit weaknesses outside the firm's direct control.
Building strong third-party risk management
Managing supplier cyber risk is not about eliminating every risk – it is about understanding where risks exist and ensuring they remain within acceptable levels.
Before engaging a supplier, firms should conduct due diligence proportionate to the sensitivity of the services being provided. This may include reviewing recognised security certifications, independent audit reports, penetration testing summaries and documented security policies.
Contracts should clearly define security expectations, including encryption standards, access controls, incident reporting obligations and audit rights. Notification timelines following a security incident should be explicit, enabling firms to respond quickly where regulatory reporting obligations may arise.
Risk management should not stop once a contract is signed. Periodic supplier reviews, updated security questionnaires and discussions around significant operational changes help ensure that security standards continue to be maintained throughout the relationship.
Access management also deserves particular attention. Suppliers should only have access to the systems and information necessary to perform their role, with permissions reviewed regularly and removed promptly when contracts end.
Cyber security Is a collective responsibility
Third-party risk management is not solely an IT issue. Procurement teams, compliance officers, risk managers, partners and operational staff all play a role in ensuring suppliers meet appropriate security standards.
Employees should also be aware that cybercriminals frequently impersonate trusted suppliers through phishing emails or fraudulent invoices. Security awareness training should therefore include scenarios involving vendor impersonation and supply-chain fraud, helping staff recognise suspicious communications before damage occurs.
By embedding supplier risk into broader governance and risk management processes, firms can reduce their exposure while demonstrating due diligence to clients, insurers and regulators alike.
Looking beyond your own perimeter
The traditional concept of securing a clearly defined organisational network no longer reflects today's interconnected business environment. Every external provider with access to your systems, data or infrastructure effectively becomes part of your security perimeter.
For Irish law firms, where trust and confidentiality are fundamental to client relationships, third-party cyber risk deserves the same level of attention as internal cyber security controls. Robust technical defences remain essential, but they are only as strong as the weakest organisation connected to your business.
In an era where cybercriminals increasingly exploit trusted relationships rather than technical vulnerabilities, organisations must look beyond their own walls. Effective cyber security now depends not only on securing your own environment but also on understanding, monitoring and managing the security posture of every supplier entrusted with your clients' information. Because, when it comes to cyber resilience, your weakest vendor can quickly become your biggest exposure.
Paul Delahunty is Chief Information Security Officer at Stryve, a leading Irish multi-cloud and cybersecurity company and ICTTF Cyber Security Company of the Year 2022. Paul is CIO and IT Leaders Security Leader of the Year 2023 and 2024, and is the Tech Excellence Awards CIO of the Year 2024.