Answers
Law firm cybersecurity, answered directly
The questions managing partners, general counsel, and IT directors actually ask — answered plainly, with the rules, benchmarks, and next steps that matter.
Do law firms need penetration testing?
Yes. Law firms hold exactly the data attackers monetize — deal terms, settlement figures, PHI, and wire instructions — and ABA Model Rule 1.6(c) requires reasonable efforts to protect it. Cyber insurers and corporate clients now routinely request recent penetration-test evidence, and the FTC Safeguards schedule of an annual pentest plus biannual vulnerability assessments is the benchmark most firms are measured against.
Read the answerHow much does penetration testing cost for a law firm?
In 2026, a one-time manual penetration test for a small or midsize law firm typically costs $4,000–$25,000 depending on scope. Continuous testing platforms cost far less: Attorney Armor starts at $199/month for automated assessment and monitoring, $499/month for weekly automated pentests across up to 10 domains, with manual red-team engagements available on Enterprise plans from $999/month.
Read the answerDoes the FTC Safeguards Rule apply to law firms?
Sometimes. The FTC Safeguards Rule implements the Gramm-Leach-Bliley Act for non-bank 'financial institutions,' and a law firm is covered only when its work qualifies as a financial activity — certain real-estate settlement, tax, or debt-collection practices, for example. But many firms comply voluntarily regardless, because clients, banks, and cyber insurers treat the Safeguards framework as the de facto baseline for protecting client financial data.
Read the answerWhat cybersecurity does the ABA require of lawyers?
The ABA doesn't certify specific tools, but three authorities define the duty: Model Rule 1.1 Comment 8 requires technology competence; Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information; and Formal Opinions 477R and 483 set expectations for secure communication and breach response. 'Reasonable' scales with data sensitivity and threat likelihood — and documented testing is the standard way to prove your efforts were reasonable.
Read the answerHow often should a law firm run a vulnerability assessment?
At minimum, run a full vulnerability assessment every six months and a penetration test once a year — the schedule the FTC Safeguards Rule sets and most cyber insurers mirror. In practice, point-in-time scans miss assets that appear between tests, so continuous automated assessment with alerting on new exposures is now considered the defensible baseline for firms of any size.
Read the answerWhat should a law firm do in the first 72 hours of a data breach?
Contain first: isolate affected systems, disable compromised accounts, and preserve logs before anything is wiped. Engage breach counsel immediately so the investigation runs under privilege, retain forensics through counsel, and notify your cyber-insurance carrier within its reporting window. Start the notification analysis early — many state clocks run from discovery — and timestamp every action, because insurers and regulators will ask for the timeline.
Read the answerCan attorneys use ChatGPT or Microsoft Copilot without waiving privilege?
Yes — with controls. The privilege risk comes from feeding client information into tools whose terms allow training on your inputs or human review of conversations. Use enterprise or business tiers with contractual no-training guarantees, disable chat-history features where possible, strip client identifiers before prompting, and adopt a written firm AI policy. Consumer free tiers should never see privileged material.
Read the answerWhat is a WISP, and does my law firm need one?
A WISP — Written Information Security Program — is the document that defines how your firm protects client data: risk assessment, access controls, encryption, vendor management, incident response, and testing cadence. Cyber insurers, corporate clients' outside-counsel guidelines, and the FTC Safeguards Rule all expect one, and it is usually the first document requested in a security review. If your firm lacks one, that gap surfaces at the worst possible time.
Read the answer