Securing Your Law Firm logoSecuring Your Law Firm

Services

Continuous cybersecurity for law firms — outside-in, inside-out, or both.

Three service tiers designed around how much visibility and control your firm needs. Every tier starts with a free Proprietary Exposure Review and is scoped for attorneys, not generic IT checklists.

Continuous tiers

Choose the level of protection that fits your firm.

Tier 1 — External Continuous

Ongoing outside-in visibility

$249 / month

Continuous monitoring + monthly or quarterly report

Always-on monitoring of everything the public internet — and attackers — can already see about your firm. No system access required.

Best for

Firms seeking low-friction, always-on external hygiene and questionnaire-ready evidence without granting system access.

What's included

  • Continuous Proprietary Exposure Review (email spoofing posture, SPF/DKIM/DMARC, lookalike domains, exposed infrastructure)
  • Recurring external vulnerability and attack-surface scans
  • Light external web application testing of public sites and intake forms
  • Monitoring for new exposures, certificate changes, and subdomain drift
  • Credential exposure monitoring for firm domains and key personnel
  • Alerting on material changes
  • Optional light email hardening guidance

Key deliverables

  • Updated exposure grade
  • Prioritized findings with month-over-month deltas
  • One-page summary for clients and insurers
  • Partner-ready executive brief
Start with a free review

Tier 2 — Internal Continuous

Microsoft 365 identity, email, and endpoint hardening

$1,495 / month

Quarterly re-assessment + ongoing monitoring and simulations

Recurring assessment and continuous optimization of your internal environment, centered on the Microsoft 365 controls insurers and clients ask about.

Best for

Firms that already have solid external posture (or have completed Tier 1) and need sustained internal maturity for insurance renewals and outside-counsel guidelines.

What's included

  • Structured internal security assessment (Microsoft 365 review + key staff interview)
  • Core hardening of MFA, email impersonation protections, mailbox forwarding rules, external sharing, admin privileges, and audit logging
  • Defender XDR policy tuning and optimization
  • Conditional Access policy design and ongoing refinement
  • Safe Links and Safe Attachments configuration and tuning
  • Authenticated internal vulnerability scanning
  • Quarterly phishing / BEC simulation campaigns
  • Continuous control monitoring and drift detection
  • Cyber-insurance attestation and client questionnaire support

Key deliverables

  • Plain-English partner report
  • Before/after configuration evidence (Defender XDR, Conditional Access, Safe Links)
  • Prioritized internal roadmap
  • One-page security summary
  • Questionnaire-ready evidence package
Start with a free review

Tier 3 — Full Baseline Continuous

Recommended

Combined external + internal perpetual program

$4,495 / month

Continuous + quarterly + annual penetration test and tabletop

The complete, always-on Law Firm Security Baseline. Everything in Tier 1 and Tier 2 plus deeper testing, exercises, and advisory support.

Best for

Mid-sized and growing firms with active client obligations, insurance requirements, or demanding outside-counsel guidelines.

What's included

  • Everything in Tier 1 and Tier 2
  • Unified external + internal vulnerability scanning and monitoring
  • Annual (or semi-annual) scoped external + internal penetration test
  • Annual tabletop incident exercise (BEC/wire fraud, ransomware, or client-data exposure)
  • Continuous optimization of Defender XDR, Conditional Access, and Safe Links
  • Optional named security advisor
  • Multi-office scope capability
  • Board and partnership-level reporting
  • Optional Elastic SIEM or network segmentation modules

Key deliverables

  • Single unified partner readout covering external and internal posture
  • Complete before/after evidence packages
  • Prioritized roadmap
  • One-page client/insurer summary
  • Tabletop after-action report
  • Ready-to-use questionnaire responses
Start with a free review

Final scope and pricing are confirmed after your free Proprietary Exposure Review — no blind quotes.

Compare

What each tier includes

CapabilityTier 1Tier 2Tier 3
Free Proprietary Exposure Review
Continuous external monitoring
Lookalike domain alerts
External vulnerability scans
Microsoft 365 hardening
Defender XDR / Conditional Access tuning
Authenticated internal scanning
Quarterly phishing simulations
Annual penetration test
Annual tabletop exercise
Named security advisorOptional
Insurance / client questionnaire support

Optional add-ons

Extend any tier with deeper capabilities.

Elastic SIEM

Deployment guidance, tuning, and ongoing oversight for centralized logging and detection.

Network segmentation design

Assessment and segmentation recommendations, including VLAN architecture where relevant.

Named security advisor

A dedicated point of contact for board updates, partnership questions, and ongoing guidance.

Multi-office scope

Extend any tier across multiple offices with consolidated reporting.

Not ready for a continuous program?

We also offer focused, one-time engagements — for example, configuring SPF, DMARC, and DKIM, or a single Microsoft 365 hardening sprint. Final scope and price are confirmed before work begins.

Ask about a single service

Common questions

Services FAQ

No. Tier 1 is entirely outside-in. We use public DNS, web, and breach-database records. We never log into your systems.

External signals are checked frequently — typically daily or weekly depending on the signal. Internal control drift detection runs on the settings we harden. You also receive formal reports monthly, quarterly, or annually depending on your tier.

Yes. Most firms start with the free Proprietary Exposure Review, add Tier 1 to establish external visibility, then upgrade to Tier 2 or Tier 3 once they are ready for internal hardening or a full baseline program.

The Security Baseline is a one-time, three-phase engagement. The Full Baseline Continuous tier (Tier 3) is the ongoing, always-on version of that same program.

Yes. Tiers 2 and 3 include attestation support and questionnaire-ready evidence for the controls insurers most commonly ask law firms about.

Tier 1 is month-to-month. Tiers 2 and 3 are scoped engagements with a clear statement of work and deliverable schedule.

No obligation

Start with the free Proprietary Exposure Review

The review is always free. It shows you where you stand and which tier, if any, makes sense for your firm.

Must match your domain so another firm cannot request your review.

We use only public records. No login, no access to anything private.