Over $3 billion in business email compromise losses were reported in 2025. Here's what professional service firms should know about managing cyber risk.
The FBI's 2025 IC3 Annual Report recorded more than $3.0 billion in reported losses from business email compromise. The figure spans industries, but the setup may be familiar to professional service firms: a trusted name, an ordinary request, and pressure to act quickly.
Professional services firms routinely handle sensitive client information across a variety of systems and workflows. They also create a surprising number of copies. A tax document moves from a client portal to a laptop. Consulting notes become a spreadsheet. An architect downloads drawings from a project platform, makes a revision, then emails the new version to a subcontractor. Access may be provided to new employees, temporary specialists, or outside providers.
As client information moves across systems, devices, and third parties, understanding where that information resides and who has access to it can be an important part of managing cybersecurity risk.
Key Takeaways
- Consider how client information moves through the firm. This exercise can often reveal more than a generic technology list.
- Establish verification procedures for unusual requests involving files, money, or access, even when a message appears to come from a familiar source.
- Consider how the use of AI tools and outside service providers may affect access to or handling of confidential information as part of the firm's broader cyber risk review.
- Consider business continuity planning for situations where email or shared files became temporarily unavailable.
Understanding How Client Data Moves
Routine workflows may result in copies of client information being stored across email, local devices, and project systems.
For example, a spreadsheet may be downloaded from a portal to a laptop, an attachment may be saved locally for later use, a contractor may be given access to a shared folder for a particular assignment and still has access months later. Final records may be protected inside a document system while working drafts sit in email, download folders, chat threads, or an old project workspace.
This useful exercise isn't a full inventory of every file the firm has ever touched. One approach may be to select recent matter and consider how information moved through the engagement, from the client's first upload through the final document. Where was it saved? Who received a copy? Which applications handled it? Did anything land on a personal device? What happened when the work ended?
Consider doing the same for a matter that involved an outside specialist or a client-owned platform. The path may be different.
NIST's Cybersecurity Framework 2.0 resources for small businesses may help firms begin managing and reducing cybersecurity risk, including by considering the systems, services, and data relevant to their operations.
Suspicious Requests May Look Ordinary
A request does not need bad grammar or a strange logo to be fraudulent. It may arrive inside a real email thread after an account has been compromised. It may use a familiar display name, refer to an actual transaction, or appear just before a deadline when no one wants to slow the work down.
If a request changes where confidential files should be sent, where money should go, or who should receive access, firms may want to verify the request through a known number or communication channel rather than relying on contact information provided in the new message. For higher-risk payments or access changes, firms may also consider additional verification steps, such as confirmation by a second person, when appropriate.
Verification procedures may be more effective when employees understand when and how to use them, particularly when a request involves unusual circumstances or pressure to act quickly.
The accounts behind those conversations need attention as well. Email, document storage, client portals, accounting systems, remote access, and administrator accounts can expose far more than one file. CISA's guidance for small and mid-sized businesses recommends protections that include multi-factor authentication, software updates, logging, encryption, and backups. It is important to confirm that the security settings are appropriately configured. For example, a policy that requires MFA does not guarantee that it is enabled across every relevant account.
Managing Access as Client Teams Change
Professional services work is rarely static. A new project begins. A specialist joins for three weeks. Staff move between clients. A contractor may need access to a particular folder for a limited period, but may be accidentally granted access to the entire workspace.
As projects end or team members change, access permissions may remain in place unless they are periodically reviewed or updated. The contractor is not opening files. The shared account still works, but people may have forgotten who knows the password. Dormant access can sit there for months.
Consider reviewing the systems that hold the most sensitive client information first. Look for dormant accounts, broad groups, shared credentials, and individuals who can see many clients even though they only require access to a few. Do not forget vendors with remote access or employees who changed roles.
Data retention deserves the same practical review. Firms have valid reasons to preserve records, and those reasons vary by profession and client. Still, retaining unnecessary exports, drafts, and uploads may increase the volume of information that needs to be protected. Firms may want to manage records in accordance with applicable legal, professional, contractual, and business requirements, including applicable retention and disposal requirements.
Some practices have specific obligations. The IRS notes that Federal Trade Commission regulations require professional tax preparers to create and carry out security plans that protect client data. ABA Model Rule 1.6(c) calls for lawyers to make reasonable efforts to prevent unauthorized access to or disclosure of client information. Professional-conduct rules vary by jurisdiction, so firms should confirm what governs their particular practice.
As client information moves across systems, devices, and third parties, understanding where that information resides and who has access to it can be an important part of managing cybersecurity risk.
As client information moves across systems, devices, and third parties, understanding where that information resides and who has access to it can be an important part of managing cybersecurity risk.
Developing Practical Guidelines for AI Use
Someone at the firm may already be using AI to summarize notes, compare documents, organize research, or refine a draft. Depending on the tool and its intended use, firms may want to consider what information is appropriate to provide to the tool and whether the tool has been reviewed or approved for that use.
"Be careful with AI" is unlikely to settle the question employees face in that moment. General guidance on AI use may not address every situation that employees encounter. More specific guidelines can help identify which tools have been reviewed or approved and what types of information should not be entered into these tools.
Clear, practical guidelines may help employees understand permitted uses and applicable limitations.
For legal practices, ABA Formal Opinion 512 provides guidance regarding lawyers’ professional obligations when using generative AI, including confidentiality, competence, and supervision. Other professions and client requirements may present different considerations.
Consider establishing approved uses before employees must make that call under deadline pressure.
Your Providers May Have Access, Too
Cloud platforms, billing systems, file-sharing tools, electronic signature services, IT support firms, and client project portals help facilitate the work. Some may also have access to confidential information or critical systems.
The Verizon 2026 Data Breach Investigations Report found that 48% of breaches in its dataset involved a third party. A provider does not need access to every client file to create a significant risk. One shared platform or support connection may be enough.
Consider focusing on the providers that could potentially expose client information or disrupt the firm’s operations. Confirm what the provider can access and whether the firm could continue operations during an outage. The review should also consider incident notice and the handling of data and access when the relationship ends.
Information about these connections may be available through product settings, security documentation, or a direct conversation with the provider. Acrisure's guide to managing third-party cyber risk offers a broader framework for evaluation these connections.
Could the Firm Work Without Email for a Day?
Imagine the timing: a filing is due, a client presentation begins in two hours, and the shared document system is unavailable. Email may be down too. People still need to reach one another, decide which client matters can't wait, and recover the right files.
An incident response plan might include an offline contact list for firm leaders, IT or cybersecurity support, legal counsel, insurance contacts, and critical providers. Firms may also want to establish an alternative way for employees to report suspicious activity when email is unavailable or potentially compromised and periodically test whether backups can be restored.
CISA's Cyber Guidance for Small Businesses recommends a written incident response plan. CISA also provides tabletop exercise resources to help organizations discuss and test their ability to respond to cyber incidents. Consider keeping the exercise practical: pick a plausible interruption, such as a compromised mailbox, a missing laptop, or an unavailable document platform, and walk through the first hour to identify any gaps in communication, access, and recovery.
Prioritize Changes Based on Potential Client Impact
With limited time and budget, consider starting with the changes that would address the greatest potential client impact. Consider the information that could cause the greatest harm if exposed and the systems whose disruption could prevent the firm from meeting an important deadline.
The next step may be to enforce MFA on email and document systems, remove old accounts, or test recovery from backup. Verification should be part of the same task: confirm that MFA is enforced, open the restored file, or confirm that access was removed.
How Acrisure Cyber Services Can Help
Acrisure Cyber Services can help professional services firms identify where client information may potentially be at risk and prioritize areas for improvement. Relevant support may include cyber risk analysis, employee awareness programs, and managed protection and monitoring services.
The work begins with how the firm serves its clients: the files people exchange, the accounts they use, the providers they rely on, and the deadlines they can't miss.
Talk with Acrisure Cyber Services about cybersecurity solutions designed to help manage risks to client information and business operations.
This content is for informational purposes only and is not intended as legal, cybersecurity, or other professional advice. Cybersecurity needs and appropriate measures will vary based on a firm’s size, operations, systems, risks and other circumstances.
Frequently Asked Questions
What might count as client data in a professional service firm?
Client data might include more than names and contact details. Tax records, contracts, legal files, financial statements, employee information, strategy documents, intellectual property, payment details, and credentials to a client's systems may also require protection.
Is email safe for confidential client information?
It depends on the circumstances. The answer will vary based on the circumstances, including the type of information being shared, the firm's obligations, the client's expectations, and the protections in place. For highly sensitive files, an appropriately configured portal or controlled sharing link may offer additional security controls compared with a standard email attachment.
Should employees use generative AI with client documents?
Employees should use client documents only with generative AI tools and for use cases that the firm has reviewed and approved. They should understand which information may be submitted, how the service handles uploaded content, and what information should not be pasted or uploaded.
Where might a firm begin?
There is no one size-fits-all approach and the appropriate starting point will vary based on the firm’s operations, systems, risks and resources. You may want to consider starting with a typical client matter and identifying potential weak points. From there, common areas to evaluate may include MFA, software updates, device encryption, access management, file-sharing practices, backup testing, and employee reporting procedures.


