Answer · Updated August 2026
How often should a law firm run a vulnerability assessment?
Direct answer
At minimum, run a full vulnerability assessment every six months and a penetration test once a year — the schedule the FTC Safeguards Rule sets and most cyber insurers mirror. In practice, point-in-time scans miss assets that appear between tests, so continuous automated assessment with alerting on new exposures is now considered the defensible baseline for firms of any size.
The minimum schedule
The widely cited floor comes from the FTC Safeguards Rule: annual penetration testing and vulnerability assessments every six months, or continuous monitoring reasonably designed to detect equivalent changes. Cyber-insurance applications echo the same cadence, and outside-counsel guidelines from financial-services clients increasingly do too.
Events that should trigger re-testing immediately
Calendar cadence is not the whole answer. Re-assess whenever the attack surface changes:
- Launching or migrating a client portal, intake form, or document-exchange system
- Moving practice management or email to a new tenant or provider
- Opening, closing, or moving an office; standing up new remote-access infrastructure
- Mergers, lateral-group arrivals, or any acquisition of another firm's systems
- A security incident, near-miss, or a new critical vulnerability affecting software you run
Why continuous beats periodic
An annual scan tells you what was true in March. Attackers find the subdomain that appeared in July. Continuous assessment re-maps your exposure on a schedule — weekly automated pentests on Attorney Armor's Firm plan — and alerts within minutes when a new asset, expired certificate, or open service appears. That is the difference between a report and a defense.
Related questions
Is continuous monitoring a substitute for a formal assessment?
The Safeguards Rule explicitly allows continuous monitoring as the alternative to the fixed schedule, provided it is reasonably designed to detect changes. Most firms pair continuous automated coverage with an annual manual review for depth.
How long does an assessment take?
Attorney Armor's initial automated assessment of a firm's public attack surface completes in about six minutes. Manual engagements run days to weeks depending on scope.
What should we do with the results?
Severity-ranked findings should flow to whoever remediates — usually your IT provider — with a retest to verify fixes and a dated evidence trail for insurers and clients.
