Securing Your Law Firm logoSecuring Your Law Firm

FAQ

Law firm cybersecurity questions, answered simply

From ABA ethics duties to DMARC to wire fraud prevention – plain answers, no jargon.

If you want one practical next step instead of reading every answer, start with the Free Zero-Access Exposure Review™.

General

Microsoft 365 or Google Workspace. Email authentication, mailbox rule audits, and domain cleanup work the same either way. Our deeper tenant-hardening engagements are Microsoft 365 today – if you’re on Workspace, tell us and we’ll scope the equivalent.

Your IT provider keeps systems running. We focus on legal-risk cybersecurity: bar duties, client questionnaires, and cyber insurance controls. We work alongside your IT team, or directly with firm leadership, not instead of them.

No. We can work with firms that already have an MSP or internal IT support, and with firms that do not. The goal is to give leadership independent evidence about the controls they depend on.

No. We are an independent cybersecurity review practice. We verify controls, document the observed state, and help firm leadership understand the gaps and next steps. We do not replace your technology provider.

No. This practice is built for small and mid-sized law firms. Smaller firms face the same wire-fraud and email-impersonation threats as larger firms, often with fewer controls in place.

The free Zero-Access Exposure Review™ is passive and takes minutes. It does not touch your systems. Most paid fixed-scope work is completed over a few weeks and scheduled around your firm. If a change affects daily workflow, we plan rollout with you first.

Yes. This practice is focused on law firms. Our recommendations are built around law-firm threats, ethics obligations, and cyber insurance requirements, not generic small-business templates.

The records are public, yes, and that is why the review is passive. The value is in turning those signals into a clear risk report. We do not access private systems. After verification, the report is displayed in the browser through the verification link and is not emailed. The submitted domain is kept only for the short verification window and the verified work email is retained for follow-up.

The free review uses only public DNS and web records. Nothing private is accessed. During paid work, evidence is reviewed under your control, handled confidentially, and never sold or shared.

We identify the externally visible technology, compare it to current vulnerability intelligence, and assess whether the finding appears applicable to the observed environment. That includes version exposure, authentication requirements, exploit conditions, and uncertainty. The result is a prioritized answer, not a long list of every CVE that happened to appear on the Internet.

Yes. Most firms already have some controls in place. We verify what is working, close the real gaps, and document the results.

Yes. If the review identifies something worth investigating, we can explain the next steps and scope any security work you want us to perform. We can implement agreed security improvements directly with firm leadership or coordinate with your existing IT provider. An IT provider is not required.

No. Monitoring and implementation are separate. Monitoring identifies what needs attention. Fixes are quoted separately so you're never surprised by costs. If you already have an IT provider, we coordinate with them. If you don't, we can implement the work directly.

No. We can work with firms that already have an MSP, coordinate with existing providers, or work directly with firms that do not have IT support. We complement your IT provider; we do not replace them.

Yes. AI Security & Governance covers workflow assessment, vendor and agent readiness, secure deployment verification, and ongoing governance review. Mention your AI or Copilot needs when you contact us and we will confirm the appropriate scope and price in writing.

Not in the way most headlines suggest. The real issue is a human attacker using AI to move faster and write better. Start with email security or Microsoft 365 and workstation security; those controls address the identity and impersonation risks that matter most.

Cyber insurance helps pay for losses after an incident. Cybersecurity helps prevent the incident or limit damage. Insurers now require specific controls, such as MFA, email authentication, and audit logging. We help firms implement and document those controls.

Compliance, ABA ethics & cyber insurance

ABA Model Rule 1.1 requires lawyers to understand the risks of relevant technology. In practice, that means reasonable safeguards for client information, including core email security, access controls, and awareness of what your systems expose.

Opinion 477R focuses on protecting client communications. Opinion 483 focuses on duties after a data breach. Together, they mean law firms need reasonable security controls and a clear incident-response process.

Requirements vary by carrier, but common controls include MFA, endpoint protection, tested backups, privileged-access controls, anti-spoofing email settings (DMARC/SPF/DKIM), and an incident-response plan. Missing controls can raise premiums, reduce coverage, or create claim issues.

Usually yes. ABA guidance, state ethics rules, and state breach laws can all create notice obligations. If client data may be compromised, assume notification duties may apply and consult ethics counsel quickly.

Most clients want proof of core controls: MFA, controlled data access, and a documented security program. Some also ask for independent assessment evidence. We help you build the controls and provide clear documentation to answer these questionnaires with confidence.

Pricing & engagement

The Zero-Access Exposure Review™ is always free. Current entry pricing: the Law Firm Security Baseline is $1,995 for firms up to 10 users; AI Governance is offered as a focused review for firms adopting Copilot or other AI tools; additional one-time services are priced by scope and confirmed in writing before work begins.

The three primary services are fixed-scope projects with a clear deliverable list. No open-ended retainer, no scope creep. If you need ongoing verification or another specialized service later, view the public service catalog and we will confirm the scope and terms in writing.

Yes. The Zero-Access Exposure Review™ is free and has no obligation. Many firms use it as a standalone check to decide whether further work is needed.

What the technical terms mean

BEC is fraud by email impersonation. An attacker pretends to be a trusted person and tries to redirect a wire or steal sensitive information. Law firms are common targets because they handle high-value transfers.

It means someone can send an email that looks like it came from your domain without access to your account. That is a common starting point for wire fraud. DMARC, SPF, and DKIM in enforcement mode help block it.

DMARC tells receiving mail servers how to handle messages that claim to be from your domain but fail checks. Without DMARC enforcement, spoofed email is much easier. With proper enforcement, many fake messages are blocked before they reach clients.

A lookalike domain is a fake domain made to resemble yours. Attackers use these domains in phishing and impersonation campaigns. We check for registered lookalike domains in the free Zero-Access Exposure Review™.

Microsoft 365 includes strong security tools, but many key controls are not fully enforced by default. Settings such as MFA coverage, legacy-auth blocking, sharing restrictions, logging, and DMARC enforcement still need deliberate configuration.

For most firms, the highest-impact controls are full MFA, strong email authentication (DMARC/SPF/DKIM), tighter access permissions, audit logging, and tested backups. We assess these controls and help close gaps with fixed-scope work.

No. Being visible online is normal. Many public-facing services are intentional. A public observation does not establish vulnerability or compromise. That is why we analyze the evidence, applicability, and attack conditions. We help you distinguish between what is visible and what actually needs attention.

We identify publicly observable assets associated with your firm, but discovery is not guaranteed to be exhaustive. Coverage depends on the review or monitoring engagement scope. Assets that are not publicly visible, use private or obscure domain registration, or are held by third parties may not appear in external discovery.

Still have questions?

The Zero-Access Exposure Review™ is the fastest way to see where you stand

2 minutes. No internal access. No passwords.

Free, passive, and takes minutes. Start there – the findings usually answer the question of whether a full engagement makes sense.