Answer · Updated August 2026

Do law firms need penetration testing?

Direct answer

Yes. Law firms hold exactly the data attackers monetize — deal terms, settlement figures, PHI, and wire instructions — and ABA Model Rule 1.6(c) requires reasonable efforts to protect it. Cyber insurers and corporate clients now routinely request recent penetration-test evidence, and the FTC Safeguards schedule of an annual pentest plus biannual vulnerability assessments is the benchmark most firms are measured against.

Where the expectation comes from

No single statute says 'law firms must pentest,' but four overlapping forces make it the de facto requirement:

  • Legal ethics: ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information, and Formal Opinions 477R and 483 make clear that includes testing the defenses you claim to have.
  • Clients: corporate legal departments send outside-counsel security questionnaires that ask when you last tested, by whom, and what you fixed.
  • Cyber insurers: renewal applications ask for penetration-testing evidence, and claims can be contested when the application answers don't match reality.
  • Regulators: firms whose work touches financial-institution activity can fall under the FTC Safeguards Rule, which names annual penetration testing and biannual vulnerability assessments explicitly.

What a law-firm pentest should actually cover

Generic IT checklists miss how firms are really breached. Testing should be scoped to the surfaces that hold privileged material:

  • Email infrastructure — the SPF, DKIM, and DMARC gaps behind wire-fraud and business-email-compromise pretexts
  • Client intake portals and document-exchange systems, including file-upload paths
  • Microsoft 365 and practice-management tenants: MFA enforcement, session handling, third-party OAuth grants
  • External perimeter: public IPs, VPN and remote-desktop gateways, forgotten subdomains and legacy microsites

How often is enough

Once a year is the floor, not the ceiling. The defensible pattern is an annual manual test plus continuous automated assessment between engagements — because new assets, expired certificates, and misconfigurations appear every week, not every twelve months. Re-test after any material change: a new client portal, a practice-management migration, an office move, or a merger.

Related questions

Will penetration testing disrupt our systems or expose privileged documents?

No, when scoped properly. Attorney Armor performs non-intrusive, read-only testing by default, and deeper testing happens only with written authorization in agreed windows. We test the infrastructure surrounding your data — login flows, APIs, configurations — without reading document contents.

Is a vulnerability scan the same thing as a penetration test?

No. A vulnerability assessment tells you what is exposed and how severe it is; a penetration test proves whether those exposures can actually be exploited. Insurers and clients increasingly ask for both. See our comparison of the two for the full breakdown.

What does it cost?

One-time manual engagements for small and midsize firms typically run $4,000–$25,000 depending on scope. Continuous platforms cost far less: Attorney Armor starts at $199/month for always-on assessment and monitoring.

In-depth guides

See what your firm is exposing today

Run a free, non-intrusive assessment of your firm's public attack surface. Results in about six minutes.

Start free assessment