Securing Your Law Firm logoSecuring Your Law Firm

FAQ

Questions we hear from managing partners

General

Your IT provider keeps systems running. We build and document a security program designed around bar ethics duties, client questionnaires, and cyber insurance requirements. We work alongside your IT provider, not instead of them, and hand them a clear roadmap where relevant.

The Proprietary Exposure Review is passive and instant. Nothing touches your systems. A full Foundation engagement is typically completed over a few weeks, scheduled around your firm. Most hardening changes are invisible to attorneys. Where a change affects daily workflow (like adding multi-factor authentication), we plan the rollout with you.

Yes. This practice is built exclusively for small and mid-sized law firms. The founder's background is in safety-critical automotive cybersecurity, where security has to be provably correct before anything ships. That same standard applies here.

The free Proprietary Exposure Review uses only public records. Nothing private is ever accessed. During a paid engagement, technical evidence is pulled from your Microsoft 365 tenant under your control, handled under confidentiality, and never sold or shared.

Absolutely. Most firms we work with have done something: multi-factor authentication turned on for some users, email protections partly configured, an IT provider who handles patches. We assess what's actually in place, close the gaps, and document the full picture.

Pricing & engagement

Pricing is directional until we've seen your environment. The Proprietary Exposure Review is always free. Engagements start at the figures shown in our tiers, with final scope confirmed after the review so you're never quoted blind.

Foundation engagements are scoped as fixed-price projects with a clear deliverable list, no open-ended retainer, no scope creep. Managed tier engagements have a monthly agreement with a defined scope of services.

Yes. The Proprietary Exposure Review is always free and carries no obligation to proceed. Many firms use it as a standalone check-in even if they're not ready for a full engagement.

What the technical terms mean

It means someone can send an email that looks exactly like it came from your domain, partner@smithlaw.com for example, without having access to your account. The recipient's inbox shows your firm's name and address. There's no indication it's fake. This is how most wire fraud attacks against law firms start. The controls that prevent it need to be deliberately configured and turned on. By default, most email setups leave this gap open.

A lookalike domain is one registered to impersonate your firm, such as smithlaw-legal.com if your domain is smithlaw.com. Attackers register these to send phishing emails to your clients that appear to come from your firm. Because they're sending from a different domain, your own email protections don't stop them. We scan for active lookalike registrations as part of the Proprietary Exposure Review.

Microsoft 365 includes the tools, but most security controls are turned off by default or set to a permissive level that doesn't actually stop attacks. Multi-factor authentication, legacy access blocking, external sharing restrictions, and full audit logging all require deliberate configuration. The defaults are designed for easy sign-up, not for security.

Still have questions?

The Proprietary Exposure Review is the fastest way to see where you stand

Free, passive, and takes minutes. Start there, the findings usually answer the question of whether a full engagement makes sense.

Must match your domain so another firm cannot request your review.

We use only public records. No login, no access to anything private.