Back to news
Cybersecurity Alert
May 27, 2026 by EmailMeNow IT Consulting

Email Security Audit Reveals Wide Gap Among Top Texas Law Firms in 2026

Independent audits of major Texas law firms show significant variation in email security scores. Norton Rose Fulbright leads at 70%, while several prestigious firms score below 50%.

Law FirmsEmail SecurityCybersecurityTexasSB 2610
Digital audit dashboard showing email security scores of major Texas law firms

An independent review of email security across many of Texas’s top law firms reveals a wide range of results. While some firms demonstrate relatively strong controls, others — including several highly prestigious names — show significant vulnerabilities.

Using data from audit.emailmenow.com, we evaluated the email and domain security posture of leading Texas firms across categories such as SPF, DKIM, DMARC, transport security, and website security headers.

Email Security Scores of Major Texas Law Firms

RankLaw FirmOverall ScorePerformance Level
1Norton Rose Fulbright70%Strong
2Latham & Watkins64%Good
2Locke Lord64%Good
2Winstead64%Good
5Susman Godfrey61%Above Average
6Haynes and Boone60%Above Average
7Porter Hedges58%Average
8Sidley Austin54%Average
8Skadden54%Average
8Jones Walker54%Average
11Baker Botts50%Below Average
11Bracewell50%Below Average
13Jackson Walker48%Below Average
14Gibson, Dunn & Crutcher44%Weak
15Vinson & Elkins39%Weakest

Key Findings

  • Best Performer: Norton Rose Fulbright leads with a solid 70% score.
  • Lowest Performer: Vinson & Elkins scored the lowest at 39%, indicating significant gaps in email authentication and security controls.
  • Many nationally prestigious firms (including several Vault-ranked elite firms) are scoring in the low-to-mid 50s, which is concerning given the sensitive nature of their work.
  • Common weaknesses across lower-scoring firms include weak DMARC policies, missing or misconfigured MTA-STS, and insufficient website security headers.

Why This Matters

Even top-tier law firms with excellent legal reputations can be vulnerable to Business Email Compromise, domain spoofing, and phishing attacks if their email infrastructure is not properly secured. These weaknesses can expose client data and create professional liability risks under TDRPC 1.05 and SB 2610.

Recommendations

Law firms should prioritize:

  • Implementing a strict DMARC policy (p=reject)
  • Enabling MTA-STS and proper TLS reporting
  • Regularly auditing email security configurations
  • Conducting ongoing security awareness training for staff

Protect your firm.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com to see your firm’s current score and get specific recommendations.

Contact EmailMeNow IT Consulting for help improving your email security and overall compliance posture.


Prestige does not equal strong cybersecurity. Many of Texas’s most respected law firms still have meaningful work to do to protect client information.