Back to news
Cybersecurity Alert
May 27, 2026 by EmailMeNow IT Consulting

Email Security Audit of Top California Law Firms in 2026

Independent audits reveal significant variation in email security among California’s leading law firms. O’Melveny leads with 73%, while several prestigious firms score below 50%.

Law FirmsEmail SecurityCybersecurityCaliforniaData Breach
Digital audit dashboard showing email security scores of top California law firms

An independent review of email security across California’s top law firms shows wide variation in performance. While some firms demonstrate relatively strong controls, others — including several nationally prestigious firms — have significant gaps that increase risk of phishing, spoofing, and Business Email Compromise.

Email Security Scores of Top California Law Firms

Here are the results from recent audits:

RankLaw FirmOverall ScorePerformanceNotes
1O’Melveny73%StrongHighest score among tested California firms
2Latham & Watkins64%GoodStrong email infrastructure
3Kirkland & Ellis60%Above AverageSolid but room for improvement
4Wilson Sonsini58%AverageCommon gaps in transport security
5Morrison & Foerster55%AverageModerate performance
6Cooley54%AverageNotable weaknesses in identity & spoofing
6Paul Hastings54%AverageSimilar profile to Cooley
8Baker Botts50%Below AverageSignificant gaps identified
9Gibson, Dunn & Crutcher44%WeakLow score across multiple categories
10Arnold & Porter38%WeakOne of the lowest scores in California

Key Findings

  • Best Performer: O’Melveny leads California firms with a strong 73% score.
  • Lowest Performers: Arnold & Porter (38%) and Gibson Dunn (44%) show critical weaknesses, particularly in DMARC enforcement and transport security.
  • Many elite California firms are still scoring in the low-to-mid 50s, which is concerning given the high volume of sensitive client work and regulatory matters they handle.
  • Common issues across lower-scoring firms include weak or missing DMARC policies, lack of MTA-STS, and insufficient website security headers (HSTS, CSP, X-Frame-Options).

Why This Matters in California

California law firms frequently handle high-stakes litigation, technology transactions, venture capital, and regulatory matters. Weak email security increases the risk of:

  • Business Email Compromise and wire fraud
  • Exposure of privileged client communications
  • Reputational damage and potential professional liability

These risks are especially relevant under California’s strict privacy laws and growing expectations around cybersecurity diligence.

Recommendations

California law firms should prioritize:

  • Implementing a strict DMARC policy (p=reject)
  • Enabling MTA-STS and monitoring TLS reports
  • Regularly auditing email and domain security configurations
  • Conducting ongoing phishing and social engineering awareness training

Protect your firm.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com to see your firm’s current score and get specific, actionable recommendations.

Contact EmailMeNow IT Consulting for help improving your email security and overall compliance posture.


Even many of California’s most respected law firms still have meaningful opportunities to strengthen their email security foundations.