Back to news
Cybersecurity Alert
June 5, 2026 by EmailMeNow IT Consulting

Cybersecurity Audit of Top Pennsylvania Law Firms in 2026

Independent audits show significant variation in email security among Pennsylvania's leading law firms. Fox Rothschild, Pietragallo, and White and Williams lead at 64%, while several large firms score below 45%.

Law FirmsEmail SecurityCybersecurityPennsylvaniaData Breach
Digital audit dashboard with a Pennsylvania state map showing cybersecurity scores of top Pennsylvania law firms

An independent cybersecurity review across Pennsylvania’s top law firms reveals a wide range of performance. While some firms demonstrate solid email security controls, several of the largest names in Philadelphia and Pittsburgh show meaningful weaknesses.

Cybersecurity Scores of Top Pennsylvania Law Firms

Overall compliance scores from audit.emailmenow.com. Re-run any domain at the link to verify.

RankLaw FirmOverall ScoreWebsite ScorePerformance
1Fox Rothschild64%45%Above Average
2Pietragallo Gordon Alfano Bosick & Raspanti64%45%Above Average
3White and Williams64%45%Above Average
4Morgan, Lewis & Bockius60%45%Above Average
5Dechert54%45%Average
6Blank Rome54%45%Average
7Ballard Spahr54%45%Average
8Eckert Seamans Cherin & Mellott54%45%Average
9Reed Smith50%45%Average
10Buchanan Ingersoll & Rooney48%45%Below Average
11Marshall Dennehey48%45%Below Average
12Stradley Ronon45%45%Below Average
13Post & Schell45%70%Below Average
14Klehr Harrison Harvey Branzburg44%45%Below Average
15Cozen O’Connor39%45%Weak
16Saul Ewing38%45%Weak

Website Security Scores

Scores ranged from 70% to 45%; 0 of 16 reached the 100% ideal and 15 scored below 60%.

RankLaw FirmDomainWebsite ScoreRating
1Post & Schellpostschell.com70%Good
2Fox Rothschildfoxrothschild.com45%Below Average
2Pietragallo Gordon Alfano Bosick & Raspantipietragallo.com45%Below Average
2White and Williamswhiteandwilliams.com45%Below Average
2Morgan, Lewis & Bockiusmorganlewis.com45%Below Average
2Dechertdechert.com45%Below Average
2Blank Romeblankrome.com45%Below Average
2Ballard Spahrballardspahr.com45%Below Average
2Eckert Seamans Cherin & Mellotteckertseamans.com45%Below Average
2Reed Smithreedsmith.com45%Below Average
2Buchanan Ingersoll & Rooneybuchananlaw.com45%Below Average
2Marshall Denneheymarshalldennehey.com45%Below Average
2Stradley Rononstradley.com45%Below Average
2Klehr Harrison Harvey Branzburgklehr.com45%Below Average
2Cozen O’Connorcozen.com45%Below Average
2Saul Ewingsaul.com45%Below Average

Key Findings

  • Best performers: Fox Rothschild, Pietragallo, and White and Williams tie at the top with 64% — but no Pennsylvania firm reached a strong (70%+) posture.
  • Lowest performers: Saul Ewing (38%) and Cozen O’Connor (39%) trail the field, indicating significant gaps in email authentication and transport security.
  • A large cluster of well-known firms sits at 54% and below, notable given the high-stakes corporate, litigation, and regulatory work Pennsylvania firms handle.
  • Common weaknesses include weak DMARC policies and missing transport security (MTA-STS).

Attack exposure in this audit

Domains scoring near 45% combine weak identity enforcement, missing inbound transport protections, and sub-60% website hardening. Without naming specific organizations, entities in that tier are disproportionately exposed to:

  • Trust-account fraud — spoofed firm mail used to redirect IOLTA wires, settlement disbursements, and retainer payments.
  • Business email compromise (BEC) — spoofed messages appearing to come from executives or accounts payable, used to redirect wires and ACH payments.
  • Brand impersonation phishing — fake billing, HR, and vendor notices that pass visual inspection because DMARC and SPF are not fully enforced.
  • Credential harvesting — login pages linked from forged @company.com mail aimed at employees, contractors, and customers.
  • Invoice and procurement fraud — altered payment instructions sent to finance teams and partners who trust the corporate domain.
  • Account-recovery abuse — password-reset and MFA prompts triggered from impersonated sender addresses.
  • Inbound mail downgrade attacks — absence of enforced MTA-STS allows opportunistic TLS stripping on messages destined for the organization.
  • Clickjacking and session risks — missing HSTS, CSP, and frame protections on the public site increase browser-side attack surface for visitors and logged-in users.
  • Supply-chain targeting — partners who whitelist the domain for deliverability become secondary victims when spoofed mail originates unchecked.

These are not theoretical edge cases. State breach portals and FBI IC3 reporting consistently tie weak email authentication and header gaps to measurable financial loss at large enterprises.

Real attacks, told as stories

The stories below are made up, but they are based on real crimes that police and cybersecurity teams see every year. No Pennsylvania law firm is named. Each story shows how weak domain settings can hurt real people — customers, partners, and staff who work with Pennsylvania law firms.


Story 1: Maria and the payment that was not real

Illustration: law firm bookkeeper reviewing a spoofed trust-account change

Maria works in a bookkeeper at Cole & Hart LLP, a mid-size firm that wires client trust funds weekly.

On a Tuesday morning, she gets an email that looks normal:

From: accounts-payable@bigbrand.com
Subject: Updated trust account for settlement disbursement

The logo looks right. The tone sounds like past trust-account notices. A PDF lists a new routing number.

Maria does not know that bigbrand.com has weak email security. A stranger sent the message from their own server and pretended to be the big brand. That is called brand impersonation.

She approves a $284,000 wire. The money goes to the attacker, not the real company.

The next day, the same fake sender emails two more partners Maria knows from bar association events. One ignores it. One also changes bank details. That is supply-chain targeting — hurting partners by faking the main organization’s name.

Attack vectors in this story: brand impersonation · invoice and procurement fraud · supply-chain targeting · business email compromise (BEC)

Simple fix: Strict DMARC (p=reject), SPF (-all), and a rule that every bank change needs a phone call to a known contact — not just email.


Story 2: Jordan clicks “reset password”

Illustration: paralegal facing a fake firm intranet reset email

Jordan is a paralegal at an AmLaw 100 firm. On Wednesday at 2 p.m., his phone buzzes:

From: it-security@bigbrand.com
Subject: Reset your password in 2 hours or lose access

Jordan is busy. The email looks like IT mail he has seen before. He clicks the link.

The page looks like his company login. It is not. It is a copy on a similar-looking website (bigbrand-secure.com). He types his username and password. The attacker saves them.

This is account-recovery abuse and credential harvesting. The criminal used a fake “reset your account” message because people trust mail from @company.com.

That night, the attacker signs into Jordan’s mailbox and reads old threads about a settlement wire to a client. On Thursday, they email the CFO’s assistant:

From: cfo@bigbrand.com
Subject: Urgent — confidential wire for escrow

That is BEC — business email compromise. The assistant almost approves it. A bookkeeper asks, “Did you talk to the CFO on the phone?” The wire stops. Jordan still has to change every password he reused.

Attack vectors in this story: account-recovery abuse · credential harvesting · business email compromise (BEC)

Simple fix: DMARC p=reject, train staff that IT will never rush a reset by email alone, and require a callback before any wire.


Story 3: The contract email no one knew could be copied

Illustration: settlement term sheet exposed on an unencrypted mail path

Priya is a partner emailing privileged acquisition terms. She emails a settlement term sheet to an inbox at @bigbrand.com. The send button works. Her screen says Delivered.

What Priya cannot see: on part of the internet path, the mail server connection was downgraded from locked (TLS) to unlocked. Without MTA-STS set to mode=enforce, the recipient’s mail system still accepts the message. An attacker on that path can copy attachment text in plain form.

This is an inbound mail downgrade attack. Most people worry about fake outgoing email. MTA-STS protects incoming mail — mail sent to your organization.

Priya’s managing partner’s office sees green checkmarks in their dashboard. Nothing looks wrong. Weeks later, opposing counsel seems to know the settlement floor early. The leak might have started on the wire, not in someone’s inbox.

Attack vector in this story: inbound mail downgrade (no MTA-STS)

Simple fix: Publish MTA-STS in enforce mode and turn on TLS-RPT reports so IT gets alerted when encryption fails.


Story 4: Alex applies for a job online

Illustration: client caught on a fake law firm extranet login

Alex is a college senior. He is already logged into his school portal in one browser tab. In another tab, he opens a job post: “Client extranet — upload discovery documents.

The site asks him to “confirm your profile” on what looks like the real company careers page. He clicks.

He does not know the page is a trap. The real login screen is hidden inside an invisible frame on a scam site. That trick is called clickjacking. The company’s website scored 45% on security headers, missing strong HSTS, CSP, and frame blocking.

Alex thinks he is on the real site. He is really interacting with a layer the attacker controls. If he had been logged into the company’s vendor portal in another tab, the same trick could hijack that session.

No phishing email was needed. The attack lived on the website, not in the inbox.

Attack vectors in this story: clickjacking · session risks (missing HSTS/CSP)

Simple fix: Add HSTS, Content-Security-Policy, and frame-ancestors / X-Frame-Options so login pages cannot be embedded on random sites.


How the stories connect

All four stories can hit one organization with a weak audit score (near 45%):

StoryWho got hurtMain gap
Maria (partner)Outside partnersFake mail from your domain
Jordan (employee)Inside staffFake password-reset mail
Priya (professional)Confidential data in transitIncoming mail not forced to stay encrypted
Alex (visitor)Website visitorsLogin page can be framed by attackers

Together, that is not one bug — it is a pattern. Fixing it means better DNS (DMARC, MTA-STS), better website headers, and better office rules (call back before you wire).

Why This Matters in Pennsylvania

Pennsylvania law firms manage privileged client information across corporate, healthcare, and financial matters. Weak email security increases the risk of Business Email Compromise, domain spoofing, and exposure of confidential client data — undermining the duty of confidentiality under the Pennsylvania Rules of Professional Conduct.

See also — national audit

Recommendations

Pennsylvania law firms should prioritize:

  • Implementing a strict DMARC policy (p=reject)
  • Enabling MTA-STS and monitoring TLS reports
  • Regularly auditing email and domain security configurations
  • Conducting ongoing security awareness training

Protect your firm. Run a free Instant Cybersecurity Audit at audit.emailmenow.com/?industry=law-firms&state=pennsylvania to see your firm’s current score and specific recommendations.

Contact EmailMeNow IT Consulting for help improving your email security and overall compliance posture.


Source & methodology: Overall compliance scores from the free scan at audit.emailmenow.com — each domain checked for email authentication (SPF, DKIM, DMARC), transport security (MTA-STS/TLS), website security headers, and network security. Re-run any domain at the link to verify.