Phishing and client-file lures
Practice spotting fake document shares, e-filing notices, sign-in prompts, and urgent messages that imitate trusted services.
Phishing awareness training for small law firms
Short, law-firm-specific scenarios help attorneys and staff recognize suspicious emails, business email compromise, MFA fatigue, wire fraud, and risky AI use.
No passwords. No client files. Built for small and midsize law firms.
Best for
Awareness training and everyday best practices
Employee effort
Short weekly scenarios, not a long annual seminar
Starting price
$99/month for up to 10 employees
Need simulated phishing emails?
This page is recurring decision training. For controlled email campaigns, click-rate reporting, and follow-up training, see our managed phishing testing service.
What phishing awareness training covers
Each challenge puts a familiar-looking request in front of the employee and explains the safer next step.
Practice spotting fake document shares, e-filing notices, sign-in prompts, and urgent messages that imitate trusted services.
Build the instinct to deny unexpected prompts, stop repeated push requests, and verify an urgent caller through a trusted channel.
Reinforce safe handling of payment changes, suspicious mailbox rules, reply-to changes, and requests that bypass normal approval.
Give staff a clear framework for handling confidential drafts, client information, public AI tools, and risky sharing behavior.
Included in every plan
Give your team a recurring way to practice the decisions that protect client trust, firm funds, and account access.
Keep learning
How to practice staff decisions, document results, and distinguish awareness training from a managed phishing campaign.
Read the guideWhy attorney impersonation and fraudulent payment requests work, and where staff verification habits matter.
Read the guideWhat carriers may ask firms to prove, including training records and other documented safeguards.
Read the guideSimple firm pricing
Every plan includes the same law-firm-specific training experience. Select monthly billing for flexibility or annual billing for a lower effective monthly cost.
A practical starting point for solo practices and small teams.
Stripe securely handles checkout and recurring billing. Seat limits are applied when your firm account is provisioned.
Most popular
For growing firms that need consistent training across offices or practice groups.
Stripe securely handles checkout and recurring billing. Seat limits are applied when your firm account is provisioned.
For larger teams that want one shared security habit across the firm.
Stripe securely handles checkout and recurring billing. Seat limits are applied when your firm account is provisioned.
Need more than 50 employees or a tailored program? Contact us to discuss scope.
How it works
01
Choose the seat band and monthly or annual billing option that fits your team.
02
Use the firm training workspace to invite employees and assign the current challenge.
03
Each short challenge asks people to make a realistic decision, not memorize a definition.
04
Participants see why the decision mattered, while firm leaders get a durable training record.
Training questions
The program provides short, scenario-based weekly challenges built around threats that affect legal practices: phishing, fake e-filing notices, mailbox-rule compromise, MFA push fatigue, opposing-counsel impersonation, shadow AI, and wire-instruction fraud.
If your insurer asks for security awareness training, this program gives you a documented training program and employee completion records to review with your broker. Insurers set their own requirements, so confirm whether your policy specifically requires simulated phishing, a particular platform, or a stated training frequency. If you need a managed phishing campaign, see our separate Phishing Testing & Staff Training service.
This is recurring decision-based security awareness training. It teaches people why a request is suspicious and what to do next. It does not send simulated phishing emails or measure click rates. For a controlled phishing campaign with dated campaign reporting, use Managed Phishing Testing & Staff Training.
Each weekly challenge is designed to be short enough for a normal workday. The exact time varies by scenario, but employees make one decision, receive reinforcement, and continue through the firm’s assigned training flow rather than sitting through a long annual seminar.
The training workspace records assigned challenges and completion results for your firm. Those records help an office manager track participation and provide evidence of an ongoing awareness program. They are not a guarantee that a particular insurer or client will accept them.
The subscription is priced by the number of employees in the firm: up to 10, 11–25, or 26–50. The selected Stripe plan determines the firm seat limit when the account is provisioned.
Yes. Annual plans are available for every seat band: $990 for 1–10 employees, $2,490 for 11–25 employees, and $3,990 for 26–50 employees.
No. The training is designed to reinforce the technical controls and policies your existing provider manages. It gives your people a shared, law-firm-specific way to make safer decisions.
Employees receive the challenge material and the feedback they earn from their own answers. Answer keys and unearned feedback remain server-side so the completion record reflects the person’s actual decision.
Need simulated phishing rather than decision training? Review our managed phishing testing service.
Start with context
2 minutes. No internal access. No passwords.
The free Zero-Access Exposure Review shows what is publicly observable about your firm. Training helps your team act on the warning signs that appear in everyday legal work.