How Secure Are You? Counteracting Escalating Threats in a Vulnerable Profession
7.22.2026

In June 2025, U.S. Attorney John A. Sarcone III faced a threatening individual wielding a knife and yelling at him on the streets of downtown Albany. Before law enforcement arrived, according to a Department of Justice press release, the perpetrator “charged at Sarcone again screaming and yelling while wielding the knife to make a slitting-the-throat gesture at Sarcone.” The man was apprehended without further incident.[1]
The legal profession is facing increasingly visible threats and vulnerability to personal attacks, theft and other criminal behavior. As a result, New York law firms are beginning to step up their security on a variety of levels.
Independent review of reporting indicates that doxing and online harassment of New York attorneys are not random. It most often arises in highly contentious matters, particularly those involving criminal defense, family disputes, civil rights claims, employment or sexual-misconduct allegations and politically polarizing issues. In other words, when New York lawyers are targeted online, it is usually because they are involved in cases with significant emotional or political consequences.
This pattern is not limited to online activity. In March 2025, Keystone Law’s London headquarters was vandalized by activists protesting the firm’s representation of a U.S. defense contractor. Such incidents reflect a broader trend in which law firms themselves are becoming targets, as some groups view lawyers as complicit in the actions of those they represent.[2]
In the same time period, protests occurred outside major New York law firms in connection with politically charged representations and business decisions. For example, demonstrators gathered outside firms that entered into agreements with the Trump administration to avoid punitive executive actions, and others targeted firms involved in post-election litigation. A few years earlier, tenant activists bypassed security to enter a downtown Brooklyn office building to protest a law firm representing landlords in eviction proceedings.[3] While these events were largely peaceful, they illustrate how quickly legal work can attract attention and protestors to law firms.
Duty of Care in a Foreseeable Environment
Questions of duty of care in New York often turn on foreseeability. In a law firm context, duty of care is typically understood to include providing a reasonably safe workplace for attorneys and staff, as well as taking sensible precautions to protect clients and visitors. Historically, firms have met this obligation through building security, access controls and general workplace policies. What is changing is not the legal standard itself, but the range of risks that firms must reasonably anticipate, particularly those arising from client interactions, public visibility and online exposure.
Legal scholarship has long noted that threats and violence against lawyers are underreported and often arise from interactions with clients, opposing parties, and others involved in contentious legal matters.[4] While literature specific to New York State is scant, recent empirical data out of Utah reinforces the extent of the threat. In a 2026 survey of the Utah bar, hundreds of attorneys reported threats or violence connected to their work, including dozens of physical assaults, with the highest rates occurring in high-conflict practice areas such as family and criminal law.[5]
In New York City, the density, visibility and frequency of disruptive incidents around commercial office environments make it increasingly difficult to argue that risks to employees and visitors are remote.
At the federal level, the Occupational Safety and Health Act’s general duty clause requires employers to provide a workplace “free from recognized hazards that are causing or are likely to cause death or serious physical harm.”[6] While OSHA does not mandate specific security measures, it recognizes workplace violence as a foreseeable hazard in environments where employees interact with the public or occupy visible roles.
New York law reinforces this obligation. Under New York Labor Law Section 200 and related common law principles, employers owe a duty to provide employees with a reasonably safe workplace. Premises liability doctrine also imposes a duty of reasonable care toward lawful visitors, including protection against foreseeable criminal acts by third parties.
For law firms, these principles intersect with professional culture. Attorneys routinely handle contentious matters and interact with individuals under significant emotional or financial stress. As a result, the question is less whether risks exist and more how organizations choose to address them responsibly.
Security, in this sense, is not primarily about guards or cameras. It is about creating an environment in which attorneys and staff can perform demanding work without carrying an additional burden of uncertainty about their safety.
Law Firm Security in New York City
While security is an issue for law firms statewide, it is even more so in New York City, where law firms operate in one of the most visible and complex professional environments in the world. Within a few square miles sit global financial institutions, media organizations, courts, political centers and some of the most prominent corporations on the planet. Attorneys routinely move among offices, courthouses, client sites and public venues, often working late and commuting through dense urban infrastructure. About 100 different nations have communities of at least 5,000 residents in the city, practicing hundreds of distinct religions and denominations and occupying the full spectrum of political viewpoints. And they all sit cheek to jowl. Many firms occupy multi-tenant class A office towers located near transit hubs and public plazas, spaces designed for accessibility rather than strict control.
Across the country, the legal profession itself has become more visible. High-profile litigation, regulatory enforcement and politically charged representations generate online hostility that migrates offline. Lawyers who once worked largely behind the scenes now see their names, photos and personal information easily discoverable.
The convergence of digital exposure, political and social friction, and physical proximity creates new considerations. Attorneys commute on predictable routes, work late hours and move frequently between offices and courts. Increasingly they also work from homes, cafés, airports and other environments, both public and private.
These realities are prompting many firms to reconsider whether security should remain primarily an operational function – focused on facilities, guards and access systems – or be elevated to a governance issue, with clear leadership oversight, defined accountability and integration into firmwide risk management.
The Operating Environment Is Changing
Law firms are built around service, discretion and trust. Reception areas are designed to welcome visitors. Attorneys move freely between offices and conference rooms. Staff are expected to accommodate clients and guests, not challenge them.
Those norms have served the profession well for decades. But as operating environments evolve, firms are recognizing that security expectations must evolve as well.
In many organizations, the shift is less about installing additional technology and more about aligning people, policies and expectations with modern realities. When an unauthorized individual “tailgates” through turnstiles, gets past reception desks or gains access to tenant spaces, this is rarely a failure of hardware. More often they reflect unclear expectations about when personnel should intervene and how concerns should be escalated.
Many firms are addressing these risks by establishing clearer procedures, training staff on situational awareness, and assigning specific responsibility for security decisions and incident response.
Security Is a Governance Issue
Among New York-based Am Law 100 firms, identifiable responsibility for security oversight is becoming increasingly common, though implementation varies. Where security functions exist, they are often located within operations, facilities, risk management or information technology departments. As programs mature, some firms are clarifying reporting structures and establishing formal policies and escalation procedures.
Larger firms are more likely to designate a professional responsible for areas such as access control, incident management, crisis response and executive protection coordination. In larger firms, responsibility is often assigned to a director of security, head of corporate security, or a senior operations, facilities, administration, or risk executive with security oversight. In smaller firms, responsibility may sit with facilities, information technology or administrative leadership, sometimes without a formally designated role.
A notable development in law firm security is the emergence of fractional security leadership roles. For firms reluctant to create a full-time senior position immediately, fractional directors of security help conduct risk assessments, establish governance structures, oversee and add software and hardware, and coordinate training and policy development. In several firms, these arrangements have evolved into permanent positions.
In many firms, this shift also means that senior leadership, including managing partners and executive committees, is taking a more active role in setting expectations, approving policies, and overseeing how security risks are managed.
Beyond Midtown: Security Considerations Across New York State
In May 2025, just a month earlier than the incident mentioned in the beginning of this article, an accused killer at an Orange County courthouse grabbed his defense attorney by the throat and began to strangle him. The judge subsequently declared a mistrial.[7]
While isolated incidents like this have long occurred, they are receiving greater attention as part of a broader reassessment of safety in legal environments. For law firms, the takeaway is not that courthouses must be redesigned, but that attorneys regularly operate in unpredictable environments and should be supported with training, situational awareness and clear response protocols.
While the density and character of New York City means that law firms in Manhattan need to be on alert, law firms across the state also need to become aware of their security weaknesses. Hundreds of law firms operate across New York State in cities such as Buffalo, Rochester, Albany and Syracuse, as well as in smaller markets, including Ithaca, Binghamton, Schenectady and Utica.
The risk profile in these environments is different from midtown Manhattan, but not necessarily simpler or more secure. Smaller firms often handle contentious matters involving local politics, land use, business disputes or criminal defense. Attorneys may be highly visible in their communities and more easily identifiable and approachable in daily life.
In smaller offices throughout the state, lawyers work without the layers of infrastructure common in large firms. Offices may occupy stand-alone buildings or smaller commercial properties with minimal security staffing or technology. Attorneys in smaller firms often know clients personally and maintain open-door practices that emphasize accessibility.
These characteristics are part of the strength of smaller firms, but they can also create unique vulnerabilities. Uncontrolled entry points, limited incident response planning and a lack of formal threat evaluation processes can complicate responses when problems arise.
For many smaller firms, the opportunity lies not in replicating the infrastructure of large Am Law 100 organizations, but in adopting right-sized security practices. These include clear visitor procedures, digital hygiene education, emergency response protocols, personal safety training, business continuity planning, active assailant exercises and drills and defined points of responsibility when concerns arise.
From Reactive to Preventive Thinking
Historically, many firms revisit security practices only after incidents, whether they be an unauthorized individual entering an office suite, an unusually personal online threat or confusion during an emergency.
Law firms are finding that they need to shift from being reactive to preventive. Situational awareness training tailored to office environments is becoming more common. This training teaches reception staff, night personnel and attorneys working late clearer guidance on when to challenge unfamiliar individuals, how to escalate concerns and how to navigate evacuation or shelter-in-place scenarios. The following case studies offer insight some possible scenarios and what law firms might do in response.
Case Study 1: When Routine Activity Masks Unauthorized Presence
A New York law firm[8] initiated a security review after two unrelated observations raised concern within the same week. In one instance, a staff member noticed an unfamiliar individual using a conference room without having checked in. In another, facilities personnel reported that a person had accessed an upper floor from a stairwell and exited before being identified.
A review of access logs and camera footage suggested that at least one individual had entered the building during a peak period, bypassed primary reception controls, and moved between floors using a combination of elevators and secondary access points. There was no indication of theft or targeting, and it was unclear whether the same person was involved in both instances.
Rather than treating the events as isolated anomalies, the firm evaluated how ordinary building conditions could enable unverified access:
- Entry points were optimized for high tenant flow, with limited deterrence against tailgating.
- Secondary pathways (e.g., stairwells, interconnecting floors) allowed movement that bypassed reception areas.
- Temporary use spaces such as conference rooms created opportunities for individuals to blend in.
- Employees had inconsistent expectations and operational confusion about identifying and reporting unfamiliar persons.
Although the activity appeared low-level and possibly opportunistic, the firm concluded that the underlying conditions warranted attention. It implemented clearer visitor protocols, expanded internal monitoring and introduced staff guidance on when to escalate concerns.
Case Study 2: From Online Friction to Real-World Considerations
Another area of growing attention is digital hygiene. As attorneys become increasingly visible online, online exposure can translate directly into physical risk. Common digital hygiene practices include:
- Reviewing and limiting publicly available personal information.
- Removing data from broker and aggregation sites where feasible.
- Using privacy settings on social media and professional platforms.
- Separating personal and professional contact information.
- Monitoring for unauthorized use of personal data.
- Not posting times and locations of where one will be present, including posts by family members.
- Avoiding heated or inflammatory discussions on social media platforms.
A New York firm reassessed its approach to attorney safety after a series of events that began with routine online criticism.
Following a contentious engagement, several attorneys were mentioned in public forums and received direct messages that were critical but not overtly threatening. Separately, one attorney reported an encounter near his home in which an unknown individual appeared to recognize the attorney from professional activity.
These developments prompted a broader review of publicly available information. The firm found that personal details – including home locations, family names and frequent locations – could be assembled from a combination of social media, professional biographies and commercial data sources.
While no single indicator suggested imminent risk, the convergence of factors (online visibility, identifiable routines and unsolicited in-person recognition) shifted the firm’s assessment.
In response, the firm:
- Conducted individualized reviews of publicly exposed personal information.
- Assisted attorneys in reducing or removing sensitive data from common sources.
- Established a process for evaluating when patterns of attention or contact warranted escalation.
- Coordinated internal communication so that concerns raised in one context (online or physical) informed the overall picture.
The situation did not progress further. However, the firm treated it as an example of how dispersed signals, when viewed together, can have different implications than when considered in isolation.
Case Study 3: Connecting Disparate Incidents Into a Cohesive Security Function
Sometimes taking a step back is required to assess security from a higher-level perspective. Over a period of time, a New York law firm addressed a range of operational issues that were not initially viewed as related: an after-hours access anomaly, malfunctioning cameras, frequent tardiness by contract security officers, inconsistent handling of threatening communications, and uncertainty among staff during a time-sensitive health incident.
Each situation was resolved independently. However, a post-hoc review revealed common themes, including unclear decision-making authority, inconsistent escalation practices and gaps in coordination between administrative, HR, IT and facilities functions.
Rather than responding to each issue in isolation, the firm undertook a broader effort to organize its approach to security and safety.
Instead of immediately establishing a permanent executive role, the firm engaged external expertise to help with the following:
- Mapping existing responsibilities across departments and identifying gaps.
- Standardizing response protocols for different types of incidents.
- Clarifying who has authority to make decisions under time-sensitive conditions.
- Introducing training aligned to realistic scenarios rather than theoretical risks.
- Providing interim coordination during incidents that cut across functions.
- Conducting a security technology review.
- Integrating the new approach to security into firm culture.
This approach allowed the firm to integrate previously disconnected activities into a more coherent framework. As the program matured, leadership began evaluating longer-term ownership and structure, including hiring a full-time security director.
Some firms are also formalizing criteria for when additional protective measures may be appropriate. These may include cases involving heightened visibility, credible threats or significant public attention. Such measures can include enhanced travel awareness, coordination with building security or, in limited cases, personal protective support, including drivers, vehicles and close protection agents.
New York Firms Set the Pace
The legal industry is famously imitative. Major shifts in governance rarely begin with a single firm; they begin when a small group of influential firms take visible steps that prompt others to reassess their own practices.
New York firms have historically led similar transitions in areas such as cybersecurity governance, talent recruitment and retention, crisis communications and enterprise risk management. Physical security may be following a similar path.
Firms are recognizing that security programs do not need to be large to be effective. What matters most is clarity of responsibility, leadership engagement and alignment between policy and practice.
For firms of all sizes, that evolution is already underway. As the external environment evolves, expectations around duty of care are evolving alongside it.
The next step for many firms is not dramatic transformation but thoughtful alignment: clarifying ownership, establishing governance and ensuring that training, procedures and leadership expectations reflect modern realities.
For firms beginning to formalize their approach, initial steps often include:
- Identifying who is responsible for security oversight.
- Conducting a basic risk assessment.
- Establishing clear incident reporting and escalation procedures.
- Providing staff with situational awareness training.
- Reviewing digital exposure and personal information risks.
Given an employer’s obligation to provide a reasonably secure workplace, many law firms, particularly smaller ones without internal security resources, seek outside guidance. Numerous advisory options exist, but no single model fits every firm. Effective approaches are those that align with a firm’s size, culture and risk profile.
No two firms face identical risks. But across the profession, the trajectory is clear: Security is increasingly viewed not as a reactive expense but as part of the infrastructure that enables attorneys and staff to perform demanding work safely and confidently.
While this shift is well underway in the high rises of Manhattan, this new mindset is also taking root in firms from Albany to Buffalo and beyond.
Michael Gips is managing director of Enterprise Security Risk Management at Kroll, where he advises law firms, professional services organizations in critical infrastructure and essential sectors, and Fortune 1000 corporations on security, risk, governance and organizational resilience. He is the author of “It’s Not in the Manual: Real-World Leadership for Security and Risk Professionals” (Routledge, 2026). He is from New Rochelle.
Emily Baum is managing director and chief of staff of Enterprise Security Risk Management at Kroll, with extensive experience advising and designing programs for Am Law 100. She focuses on comprehensive security programs including master planning, risk assessments, systems design, engineering, threat management, policies and operational security. She resides in Rochester.
Endnotes:
[1]Shane Galvin and Jennie Taer, US Attorney for NY John Sarcone Chased by Knife-Wielding Illegal Salvadoran Migrant Who Threatened to Slit His Throat: Prosecutors, New York Post (June 18, 2025, updated June 20, 2025), https://nypost.com/2025/06/18/us-news/us-attorney-for-ny-john-sarcone-chased-by-knife-wielding-illegal-salvadoran-migrant-who-threatened-to-slit-his-throat-prosecutors/.
[2] Tom Parry, Why Attacks on Law Firm Offices Are Increasing and What They Should Do About It, Lawyers and Democratic Decline (Apr. 16, 2025), https://ladd.law.wisc.edu/2025/04/16/why-attacks-on-law-firm-offices-are-increasing-and-what-they-should-do-about-it/.
[3] Robert Abruzzese, Brooklyn Tenants Rally To Support Activist Facing Retaliatory Eviction, Brooklyn Eagle (Nov. 15, 2023), https://brooklyneagle.com/258488/tenants-rally-to-support-activist-facing-retaliatory-eviction.
[4] Stephen Kelson, Violence Against Lawyers: The Increasingly Attacked Profession, 10 B.U. Pub. Int. L.J. 260 (2001).
[5] Utah State Bar, Violence in the Utah Legal Community: Results of the 2026 Survey (2026).
[6] 29 U.S.C. § 654(a)(1).
[7] Blaise Gomez, Juror: Accused Orange County Killer Strangles Attorney During Courtroom Outburst, Causing Mistrial, News12 Westchester (May 19, 2025), https://westchester.news12.com/juror-accused-orange-county-killer-strangles-attorney-during-courtroom-outburst-causing-mistrial.
[8] The case studies described in the article are composites based on patterns and scenarios observed across multiple law firms and engagements. They are not intended to describe any specific firm or incident, in part to protect firm confidentiality.




