Skip to main content
← Back to writing
Web design

What She Typed Into That Form: Security and Client Confidentiality for Law Firms

2 September 2026·5 min read·Ben Adams
law firm seo sydney

A prospective client fills in a law firm’s contact form late one evening. She names the other party. She describes the allegation. She leaves a phone number and asks the firm to call before her partner is home. That form submission travels through the site’s hosting, very possibly through a third-party analytics or advertising script sitting on the same page, and lands in an inbox that may or may not be properly secured. She has just disclosed privileged, sensitive information to a system nobody at the firm ever reviewed with confidentiality in mind.

This is the part of "security" that a firewall diagram doesn’t capture. For a law firm, security and confidentiality are not adjacent concerns. They are the same obligation, and a website that handles them carelessly is failing at something closer to the core of legal practice than most firms treat it as.

Confidentiality is the product, not a line item

Every other professional service can suffer a data incident and survive it as a reputational problem. A law firm’s entire value proposition rests on the client’s confidence that what they disclose stays confidential. A breach involving client matter details isn’t just a privacy failure to be reported and remediated. For a legal practice, it goes to the heart of what a client is actually paying for.

This is worth stating plainly because most website security conversations get pitched in generic terms, firewalls, SSL certificates, malware scanning, that apply equally to a retail website and a law firm. The generic version isn’t wrong, but it misses what makes a law firm’s exposure distinct: the information moving through the site is often exactly the kind of information the firm exists to protect.

Where law firm websites actually leak

In practice, the vulnerabilities that matter most for a legal practice aren’t exotic. They tend to cluster in a few specific places.

Contact and intake forms. These are usually the single richest source of sensitive disclosure on the entire site, and they’re often the least scrutinised part of it. Where does the submission go? Is it encrypted in transit and at rest? Who has access to the inbox or database it lands in, and is that access reviewed?

Third-party scripts on the same page as those forms. Analytics tags, advertising pixels, chat widgets and heatmap tools are common on marketing websites, and several categories of these tools capture more than firms realise, sometimes including form field content, depending on configuration. A pixel installed to measure ad performance has no legitimate reason to see what a client typed into a confidential intake form, and in most cases it shouldn’t be positioned to.

Outdated plugins and unmanaged admin access. Much of the Australian legal sector still runs on WordPress, which is a perfectly reasonable platform when maintained and a genuine liability when it isn’t. Unpatched plugins are the most common entry point for the kind of automated, opportunistic attacks that don’t care what kind of firm they’ve hit. Former staff or ex-agency contractors retaining admin credentials is the quieter version of the same problem.

Where the firm doesn’t actually know what "the website" includes. A snapshot tool, an old campaign landing page, a subdomain from a previous agency relationship, these accumulate over years and often sit outside whatever security review the firm most recently commissioned.

The regulatory backdrop, briefly

Australia’s Notifiable Data Breaches scheme requires organisations, including many law firms, to report eligible data breaches to the Office of the Australian Information Commissioner and to affected individuals. I’m not a lawyer and this isn’t legal advice on your firm’s specific obligations, but the practical point stands regardless of the exact threshold that applies to your practice: a breach involving client matter information is not a private, contained problem. It carries a reporting obligation, a reputational cost, and for a legal practice specifically, a question about privilege that a retail business never has to answer.

What a proper security review actually looks at

A genuine review for a law firm goes beyond confirming the site has an SSL certificate, which is table stakes and not evidence of much. It looks at how form data is captured, transmitted and stored, and by whom. It audits every third-party script on the site against what it actually needs to see. It checks patching cadence on the CMS and its plugins, and reviews who currently holds admin-level access against who actually still needs it. It accounts for the forgotten corners, the old subdomains and abandoned tools, that nobody has looked at since the last website project wrapped up.

None of this is dramatic work. It’s the same duller, more durable discipline that underpins search visibility and accessibility: substance, checked properly, rather than a badge or a plugin standing in for the real thing.

Where this fits

Security is the first of the six pillars a Digital Capacity Diagnosis examines, and for a law firm it’s arguably the pillar with the least room for error. The client who filled in that late-evening form was trusting the firm with something she couldn’t take back once disclosed. The website should be built to deserve that trust as carefully as the lawyer who eventually reads it.

Learn more about the Digital Capacity Diagnosis

Learn more about SEO for Law Firms

Law Firms
Begin

Need more than a document?Start with a Diagnosis.

The Digital Capacity Diagnosis gives your organisation a full digital risk assessment with a clear, prioritised action plan.