Your Law Firm’s VPN Is Supposed to Keep Attackers Out. What If It Is the Door They Use?
A law firm VPN can expose the systems it is meant to protect. Learn why ransomware groups target VPNs and what your firm should ask its MSP.
Blog post - By Securing Your Law Firm
Get your free Zero-Access Exposure Review™ | See security baseline services
The device your firm trusts to keep attackers out may be the first device an attacker sees.
That matters to managing partners and office managers because a compromised remote-access gateway can interrupt work, expose client information, and create urgent questions about notification, insurance, and responsibility.
You do not need to configure the VPN. You do need to know who maintains it, whether it is supported, and what evidence shows it is being monitored.
The security device can become the entry point
In August 2026, the FBI, CISA, and other government agencies issued a joint advisory about Gunra ransomware. Investigators observed Gunra actors obtaining initial access primarily by exploiting known vulnerabilities in internet-facing devices, including VPN and firewall appliances.
After gaining access, attackers moved through internal environments, obtained credentials, and targeted business documents, databases, email, Microsoft OneDrive, and SharePoint data.
A separate June 2026 Check Point advisory disclosed active exploitation of a critical authentication-bypass vulnerability affecting certain VPN deployments. Under the affected configuration, an attacker could establish a VPN session without a valid user password. Check Point associated post-compromise activity in one case with a Qilin ransomware affiliate.
These are not warnings about obscure technology. Google Threat Intelligence Group reported that exploitation or suspected exploitation of vulnerabilities accounted for approximately one-third of the ransomware incidents Mandiant investigated in 2025. Common VPNs and firewalls were frequent targets, and suspected data theft occurred in 77% of those intrusions.
Why should a law firm manager care?
Your VPN may not contain a single client document. It does not need to.
It may provide a route to the systems your staff use every day:
- Microsoft 365 and internal file shares
- Document-management and case-management systems
- Billing and accounting platforms
- Remote desktops and virtual servers
- Confidential client and matter information
If that route is exploited, staff may lose access to email, files, billing, or case systems when deadlines still exist. The firm may also face client notifications, forensic costs, extortion demands, and difficult questions about what information was accessed.
The problem is not that the VPN is visible. Remote-access systems generally must be reachable from the internet to work.
The problem begins when nobody can quickly answer:
- Which VPN or remote-access systems are publicly reachable?
- Who is responsible for each one – the firm, its MSP, or another provider?
- What product and version are running, and are they still supported?
- When was the latest security advisory reviewed and the last emergency patch applied?
- If exploitation began before a patch was released, were historical logs examined for evidence of access?
“Our MSP handles it” is not evidence that these questions have been answered. A Law Firm Security Baseline can help the firm independently verify exposure, patch status, and logging while complementing its existing MSP.
Visible does not mean compromised
An externally visible VPN should not automatically be labeled a vulnerability or a breach.
The distinctions matter:
- Exposure means the system is publicly discoverable and reachable.
- Vulnerability requires validation of the product, version, and configuration.
- Compromise requires evidence that unauthorized access occurred.
The first step is not to assume the worst. It is to identify what is visible, determine who owns it, and validate whether it is being maintained. This is the same outside-in question addressed by External Attack Surface Management for law firms.
Ask for evidence, not reassurance
A managing partner does not need to configure a VPN. The firm should be able to obtain a clear, evidence-backed answer about every remote-access system facing the public internet.
Ask your MSP or IT provider for answers you can keep with your security and insurance records:
- The current external-asset inventory.
- The supported version of each remote-access appliance.
- The most recent patch-review date.
- The process used to investigate actively exploited vulnerabilities.
- The log-retention and review process for remote-access systems.
If those answers take days to assemble, that is useful information. A firm cannot respond quickly to an exploited VPN if it does not know what it has or who owns it.
See the front door before an attacker uses it
A Zero-Access Exposure Review™ can identify whether remote-access infrastructure appears publicly visible and give your firm specific questions to take to its MSP. It uses public evidence without credentials, agents, or intrusive testing.
Request your free Zero-Access Exposure Review™ and see what an attacker can observe before deciding where deeper validation is needed.
A Zero-Access Exposure Review identifies observable exposure. It does not, by itself, establish that a system is vulnerable or compromised.
Related reading
- What Is External Attack Surface Management (EASM) for a Law Firm?
- Ransomware Protection for Law Firms: What’s Actually Working
- Attorney Incident Response: Your First 72-Hour Playbook
- Microsoft 365 Data Protection for Law Firms
- Cybersecurity for Small Law Firms
