Frost Brown Todd is a national law firm - founded in 1919 and currently operating across 18 offices with over 600 attorneys. The firm covers corporate, litigation, labor and employment, real estate, health care, and intellectual property law, serving clients from California to Washington D.C. and across the Midwest and South. A planned 2026 combination with Gibbons will expand the operation to roughly 800 attorneys across 26 offices under the banner FBT Gibbons.
The firm's cybersecurity surface area is what you'd expect from a large, multi-practice legal operation: sensitive client data spanning M&A, litigation discovery, health care compliance (HIPAA-adjacent), IP portfolios, and employment records. The threat model is internal and external - protecting privileged communications, securing document-heavy workflows, and meeting regulatory obligations across multiple state jurisdictions. A security team here isn't defending a product; it's protecting a trust-intensive service business where a breach means attorney-client privilege exposure and potential malpractice liability.
With practice areas in health care and intellectual property, the firm handles data that triggers specific compliance frameworks - HIPAA for health care clients, trade secret protections for IP work. The real estate and corporate practices push deal-related data at high velocity. Any security role would need to account for a distributed workforce across 18 (soon 26) offices, lateral attorney onboarding/offboarding, and the reality that law firms remain high-value targets for threat actors interested in confidential business intelligence.






