Securing Your Law Firm logoSecuring Your Law Firm

Independent law firm security assessment

Know what is protecting your firm–and what still needs attention.

The Law Firm Security Baseline independently verifies the essential controls protecting client information and gives leadership a concise, evidence-backed plan for addressing the gaps.

$1,495 fixed price for firms with up to 10 users

What the Baseline answers

Are the essential safeguards protecting our firm actually working?

The review uses evidence across identity, access, email, and recovery. See the Microsoft 365 Security Checklist or the guide to verifying MFA enforcement before defining the assessment scope.

Email and impersonation protection

  • SPF, DKIM, and DMARC
  • Observable impersonation risk
  • Suspicious mailbox forwarding and inbox rules
  • Lookalike-domain exposure

Microsoft 365 identity and access

  • MFA enforcement
  • Legacy authentication
  • Administrator access
  • Sign-in protections
  • External sharing
  • Audit logging

Devices, backups, and security monitoring

  • Endpoint-protection evidence
  • Patch-management evidence
  • Backup configuration and testing evidence
  • Available logging and monitoring evidence

Leadership readiness

  • Incident-response planning
  • Evidence commonly needed for cyber-insurance applications
  • Evidence commonly requested by clients
  • Ability to explain the observed security state to leadership

What the firm receives

Three clear deliverables built for leadership and follow-through.

Executive Security Decision Brief
Technical Evidence Appendix for your MSP or IT provider
Leadership Readout with a 45-minute briefing
Working / Needs Attention / Not Verified evidence classifications
First three actions recommended by priority
See a sample security evidence report

Bundle option

Security Baseline + Email Domain Protection — $1,995 total.

Includes the full Security Baseline for up to 10 users plus scoped SPF, DKIM, and DMARC implementation for one eligible firm domain and agreed sending services. The $500 difference is the conditional upgrade when purchased with the Baseline; it is not a standalone email-domain implementation price.

  • Identifies the legitimate sending services within the agreed scope.
  • Corrects SPF, configures DKIM for supported sending services, and sets up DMARC reporting.
  • Creates a monitored rollout and a concise handoff with remaining dependencies documented.

Who it is for

A focused assessment for firms that need evidence, not generic advice.

Good fit

  • You want a clear view of what is working and what needs attention.
  • You already have an MSP, internal IT, or a mix of vendors and tools.
  • You need evidence for leadership, insurers, or client questionnaires.

Not included

  • You want a penetration test or exploit chain exercise.
  • You want a broad managed IT retainer or open-ended advisory relationship.
  • You want AI workflow implementation or a generic technology transformation project.

What happens next

A simple, explicit process before any work begins.

Initial inquiry and scope confirmation

We begin with a brief review of the firm’s current setup, the controls in scope, and whether the firm is looking for a standalone assessment or a decision-making review to support an existing MSP or internal IT team.

Required access and authorization

The Baseline is designed to review evidence and settings the firm already controls. We confirm what access, permissions, and evidence are needed before the work begins, and we keep the review focused on what is necessary for a defensible answer.

Firm and MSP involvement

The assessment works with either an internal team or an external provider. We can complement an existing MSP, coordinate directly with leadership, or give the firm a clear independent readout without replacing its current technology partner.

Delivery timing

Timing depends on the firm’s size, the evidence available, and the number of active systems under review. We clarify the expected timeline during the inquiry and keep it explicit before the engagement begins.

Deliverables and leadership readout

The engagement includes a concise executive brief, evidence-backed classifications, and a practical view of what needs attention first. The readout is designed to support leadership decisions rather than act as a generic remediation plan.

Larger-firm inquiries

For more complex firms, we confirm the right scope before starting work so the engagement matches the size, systems, and decision-making structure of the organization.

FAQs

Questions firms ask before they commit.

The Baseline is a fixed-price assessment for firms with up to 10 users. It includes documented findings, prioritized recommendations, and a leadership readout focused on the controls protecting client information, email, identities, devices, and Microsoft 365. It does not include configuration changes or remediation.

The Baseline + Email Domain Protection bundle includes the full Security Baseline plus scoped SPF, DKIM, and DMARC implementation for one eligible firm domain. The $500 difference is the bundle upgrade when purchased with the Baseline, not a standalone implementation price.

No. The $500 amount is the upgrade price when paired with the Baseline. The implementation is scoped to one eligible firm domain and requires confirmation of the email environment and sending services before work begins.

No. The Baseline remains an assessment, and the bundle only covers the agreed SPF, DKIM, and DMARC implementation for one domain. Full Microsoft 365 hardening, mailbox remediation, endpoint changes, and other gaps are separate work.

No. The Baseline reviews Microsoft 365 settings and evidence, but it does not include full tenant hardening or remediation. Those improvements are scoped separately when they are needed.

We confirm the in-scope sending services in writing before work begins. Complex or unsupported third-party senders, additional domains, and additional environments require separate scope and pricing.

Yes. We can work alongside your MSP or internal IT team, coordinate with them when needed, or implement agreed changes directly if that is the right fit.

No. DMARC helps reduce unauthorized use of your firm’s email domain, but it does not prevent every phishing email, lookalike domain, compromised-account message, or wire-fraud tactic. The goal is to strengthen protection, not promise absolute prevention.

Price and next step

The Baseline is a clear, fixed-scope starting point for deeper verification.