Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-10-02By Securing Your Law Firm

Law Firm Incident Response Plan Template

Know who to call and what to do when your firm faces a cyber incident. Get a free 17-page fillable plan with response checklists, worksheets, and a practice exercise.

A client calls about wire instructions your firm never sent. An attorney cannot sign in to email. A paralegal finds a ransom note on a shared drive.

Those are not moments to start looking for the insurer's phone number or deciding who is in charge.

Our free law firm incident response plan template helps you make those decisions before you need them. It brings your contacts, first-hour checklists, and response worksheets into one document.

The October 2026 edition is a 17-page fillable PDF for small and midsize firms. Enter your work email below, and we'll send you a copy. You can fill it in on your computer or print it for your team.

What's inside

  • Who to call: an emergency contact card, response-team roles, and backup contacts.
  • What to do first: a first-hour checklist and a guide to deciding how serious an incident is.
  • Five common scenarios: email account takeover, wire fraud, ransomware or data theft, a fake support caller gaining access, and a lost device or vendor breach.
  • What to confirm with your insurer: policy questions, notice requirements, vendor approvals, and spending records.
  • What to record: an incident timeline, client deadlines, notification decisions, and draft messages.
  • How to prepare and recover: a systems and vendor list, readiness checks, a short practice exercise, and recovery and review worksheets.

The template gives you a place to start. Your firm's contacts, systems, client obligations, and insurance policy make it your own.

Start with the people your staff should call

If a staff member notices something wrong, they should not have to decide who needs to hear about it.

Fill in the emergency contact card first. Name the person who will lead the response and someone who can step in. Include a way to reach them when firm email is down or cannot be trusted.

Work through the technical responsibilities with your existing IT provider or managed service provider (MSP). They already support your systems. Our role as an independent cybersecurity advisor is to help you check the plan and address gaps, not replace that relationship.

Make the plan fit your firm

Set aside time with your office manager, IT provider, broker, and counsel to answer a few practical questions:

  • Who can activate the plan, pause payments, or approve emergency spending?
  • How does your policy require you to notify the insurer, and which vendors can you use?
  • Who will preserve logs and keep a record of what happened?
  • How will you protect court deadlines and client work if email or files are unavailable?
  • Who decides whether clients or others must be notified?

If you want more help working through those decisions, read How to Build a Law Firm Data Breach Response Plan. Our First 72-Hour Playbook takes a closer look at the response itself.

Give the plan a practice run

A plan can look complete until someone asks, "What would we do right now?"

Page 11 gives you a 15-minute tabletop exercise: a discussion of how your team would handle a fictional incident. It starts with a suspicious sign-in, adds changed wire instructions, and puts a court deadline in the mix.

Walk through it with the people named in your plan. Can they find the right contacts? Who calls the bank? How do they communicate if email is compromised? Write down what was unclear and fix it before the next exercise.

Staff need practice too. Our security awareness training for law firms helps attorneys and staff recognize suspicious requests, verify them, and know when to report them.

For authorized test emails and follow-up training, see managed phishing testing. These are different activities: awareness training builds everyday judgment, phishing tests examine responses to test emails, and a tabletop exercises the team's response decisions. None guarantees that an incident will be prevented.

Review it, then keep it somewhere safe

Ask your broker to confirm the insurance answers against your actual policy. Have counsel review legal duties and notification language. The template is not legal advice, proof of compliance, or a guarantee of coverage.

Once completed, the plan may contain sensitive contacts and incident details. Keep copies where your response team can reach them safely, even if the firm network is unavailable. Do not put passwords or recovery codes in it.

We'll send you a blank template. You do not need to return the completed plan or send us client information.

Dealing with an incident now? Contact your IT provider, insurer, and response team directly. This form delivers a planning resource; it is not an emergency support channel.

A useful plan is one your team can use

You do not need to finish every page in one sitting. Start with the contact card, confirm your insurer's requirements, and schedule the short exercise. Then work through the gaps with the people who will help you respond.

For more on staff preparation, read Phishing Training for Law Firms: What to Test and Measure. For the evidence your broker may ask for, see Cyber Insurance Requirements for Law Firms.

If you want an independent check of the safeguards behind your plan, our Law Firm Security Baseline can help. We work alongside your IT provider to verify controls and explain the gaps.

Get your free incident response plan

We'll send the PDF as an attachment. Please use your firm's email, not a personal or temporary address.

The PDF is yours either way. If you'd like occasional emails, check the box and confirm using the link we send. Leaving it unchecked won't sign you up or change any preference you've already set. We never sell your email or share it for others' marketing. Privacy policy.