Answer · Updated August 2026

How often should a law firm run a vulnerability assessment?

Direct answer

At minimum, run a full vulnerability assessment every six months and a penetration test once a year — the schedule the FTC Safeguards Rule sets and most cyber insurers mirror. In practice, point-in-time scans miss assets that appear between tests, so continuous automated assessment with alerting on new exposures is now considered the defensible baseline for firms of any size.

The minimum schedule

The widely cited floor comes from the FTC Safeguards Rule: annual penetration testing and vulnerability assessments every six months, or continuous monitoring reasonably designed to detect equivalent changes. Cyber-insurance applications echo the same cadence, and outside-counsel guidelines from financial-services clients increasingly do too.

Events that should trigger re-testing immediately

Calendar cadence is not the whole answer. Re-assess whenever the attack surface changes:

  • Launching or migrating a client portal, intake form, or document-exchange system
  • Moving practice management or email to a new tenant or provider
  • Opening, closing, or moving an office; standing up new remote-access infrastructure
  • Mergers, lateral-group arrivals, or any acquisition of another firm's systems
  • A security incident, near-miss, or a new critical vulnerability affecting software you run

Why continuous beats periodic

An annual scan tells you what was true in March. Attackers find the subdomain that appeared in July. Continuous assessment re-maps your exposure on a schedule — weekly automated pentests on Attorney Armor's Firm plan — and alerts within minutes when a new asset, expired certificate, or open service appears. That is the difference between a report and a defense.

Related questions

Is continuous monitoring a substitute for a formal assessment?

The Safeguards Rule explicitly allows continuous monitoring as the alternative to the fixed schedule, provided it is reasonably designed to detect changes. Most firms pair continuous automated coverage with an annual manual review for depth.

How long does an assessment take?

Attorney Armor's initial automated assessment of a firm's public attack surface completes in about six minutes. Manual engagements run days to weeks depending on scope.

What should we do with the results?

Severity-ranked findings should flow to whoever remediates — usually your IT provider — with a retest to verify fixes and a dated evidence trail for insurers and clients.

In-depth guides

See what your firm is exposing today

Run a free, non-intrusive assessment of your firm's public attack surface. Results in about six minutes.

Start free assessment