External Penetration Testing for Law Firms (2026): Scope, Cost, and What Insurers Now Demand
Your firm's perimeter is the only part of your network an attacker can reach without help from a human. This is the 2026 guide to external penetration testing for law firms: what it covers, how it differs from scans and internal tests, real price ranges by firm size, how to read the report, testing cadence, and the insurance and outside-counsel requirements now driving it.

Every law firm has a front door it never looks at.
Not the lobby. The one on the internet: the mail gateway, the client portal, the VPN concentrator, the remote-desktop host somebody stood up during a trial and never took down, the marketing subdomain running a five-year-old CMS, the document-exchange server a merged practice group brought with them. Together, those systems are the firm's external attack surface — and they are the only part of your environment an attacker can reach without help from a human being.
Five-minute takeaway: External penetration testing is an authorized attack simulation against everything your firm exposes to the public internet — domains, IPs, mail and web servers, VPNs, portals, and cloud tenants — performed from an attacker's position with no credentials and no insider access. For a typical 10–150 attorney firm it runs $8,000–$25,000 for a point-in-time engagement, takes 1–3 weeks, and is increasingly demanded outright by cyber-insurance underwriters and corporate client outside counsel guidelines. It is not a vulnerability scan, it is not a red team, and it is not optional if your firm holds M&A, healthcare, financial, or government client data.
What external penetration testing actually is
An external penetration test answers one question: *if a competent attacker on the public internet targeted this firm today, with no phishing and no inside help, could they get in — and how far?*
The tester starts where an adversary starts. They know your firm's name. From that they enumerate your domains and subdomains, your IP ranges, your cloud tenants, your mail infrastructure, your exposed applications, and the identities of your people. Then they probe every one of those systems for a way through: an unpatched edge appliance, a login page without multi-factor authentication, a forgotten staging portal, a misconfigured file-transfer service, a credential set already sitting in a breach dump that still works on your webmail.
Where they find a path, they exploit it — safely and within a defined scope — to prove the exposure is real and to demonstrate what it leads to. A finding that says "port 3389 is open" is a scan result. A finding that says "we reached a domain-joined server via exposed RDP using a password recovered from a 2023 credential breach, and from there enumerated your entire Active Directory" is a penetration test.
The distinction matters commercially. Insurers, corporate clients, and regulators have all learned to tell the difference, and a scan output submitted where a test was requested gets rejected.
External vs. internal vs. web application testing
Firms routinely buy the wrong test because the vocabulary is close and the price differences are large.
External penetration testing starts on the public internet with no access and targets the perimeter. It is the standard baseline and the one insurers ask about most often.
Internal penetration testing assumes an attacker is already inside — a compromised laptop, a malicious insider, a plugged-in device — and measures how far they can move. It is where most firms discover their flat network and over-permissioned service accounts.
Web application penetration testing goes deep on a single application, typically your client portal or intake system, testing authentication, authorization, and business logic. If clients log into something you built or configured, this is where the crown-jewel findings live.
Red teaming is a goal-oriented, multi-vector, stealth simulation involving phishing, physical access, and evasion of your detection stack. It is valuable, expensive, and premature for a firm that has not yet run a clean external test.
A firm testing for the first time should almost always buy external first. It is the cheapest, it maps directly to insurance and client questionnaires, and its findings are the ones an opportunistic attacker would have found this week anyway. Our full comparison of assessment types covers where each one earns its cost.
Why law firms specifically need this
Law firms hold concentrated, time-sensitive, high-leverage information without the security budget of the institutions that generate it. A single mid-size firm may hold the unannounced merger, the litigation strategy, the patent filing, the executive's estate, and the escrow account for a nine-figure closing — all in one place, protected by whatever the firm chose to spend last year.
That asymmetry is precisely why perimeter exposure is dangerous here. Attackers profile law firms the way they profile banks, but they find far softer edges: legacy on-premise document servers left reachable after a cloud migration, extranets built for one matter and never decommissioned, VPN appliances two firmware versions behind, and webmail without enforced MFA for partners who found it inconvenient.
The professional-responsibility layer compounds it. ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information, and Formal Opinion 483 sets the duties that attach once you learn of an intrusion. "We never checked what was exposed" is a difficult position to defend to a bar committee, a malpractice carrier, or a general counsel whose deal leaked.
What an external test actually covers
A credible engagement against a law firm includes, at minimum:
- Attack-surface discovery — subdomain enumeration, IP and ASN mapping, cloud-tenant identification, shadow-IT discovery, and identification of assets the firm does not know it owns (a frequent and uncomfortable finding after mergers).
- Edge device and service testing — VPN concentrators, firewalls, remote-access gateways, and file-transfer appliances, the category responsible for the largest legal-sector intrusions of the last three years.
- Authentication attack simulation — password spraying, credential-stuffing against known breach data, MFA-coverage verification across every exposed login, and testing for MFA bypass paths such as legacy protocols.
- Web and portal testing — client portals, intake forms, extranets, payment pages, and marketing sites, including injection, access-control, and file-upload testing.
- Email infrastructure review — SPF, DKIM, DMARC enforcement, spoofability testing, and open-relay checks. Wire fraud against law firms usually begins here.
- Cloud exposure — publicly readable storage buckets, exposed management interfaces, and over-permissive tenant configuration.
- OSINT and exposure mapping — leaked credentials, exposed documents, metadata in published PDFs, and personnel information usable for pretexting.
- Safe exploitation and impact demonstration — proving what an identified weakness actually enables, without disrupting client service.
What external penetration testing costs in 2026
Pricing tracks the size of the attack surface — the number of live external hosts, applications, and login surfaces — not the number of attorneys, though the two correlate.
| Firm profile | Typical external surface | 2026 price range | Duration |
|---|---|---|---|
| Solo / small (1–10 attorneys) | 1 domain, 1–5 hosts, webmail | $4,000 – $9,000 | 3–5 days |
| Boutique (10–50 attorneys) | 1–3 domains, portal, VPN | $8,000 – $15,000 | 1–2 weeks |
| Mid-size (50–150 attorneys) | Multiple domains, several apps, multi-office | $15,000 – $25,000 | 2–3 weeks |
| Large / multi-office (150–500) | Broad surface, cloud tenants, acquisitions | $25,000 – $45,000 | 3–4 weeks |
| AmLaw / global | Extensive, multi-region, continuous | $45,000 – $120,000+ | 4–8 weeks, often recurring |
Retesting after remediation should be included or offered at a modest fee; a provider who charges full price to verify their own findings is selling reports, not security. Continuous or quarterly perimeter testing typically runs 30–50% of an annual point-in-time engagement per cycle and is increasingly what insurers reward. Our detailed breakdown of penetration testing cost for law firms covers scoping variables in depth.
Reading the report — and what "critical" really means
A useful report has three audiences, and a good provider writes for all of them: an executive summary a managing partner can read in five minutes, a risk-ranked findings table the IT lead can turn into a work plan, and technical detail with reproduction steps an engineer can act on.
Judge findings by exploitability and blast radius, not by the scanner's color coding. An unauthenticated remote-code-execution path on an edge appliance is an emergency regardless of what a CVSS score says. A missing security header on a marketing subdomain is housekeeping. Push back on any report where more than a handful of findings are informational filler — padding is a sign the tester ran tools rather than an engagement.
The single most valuable page is often the attack-narrative section: the chained story of how the tester moved from public internet to sensitive access. That narrative is what convinces a partnership to fund remediation when a findings table does not.
How often law firms should test
The working standard for 2026:
- Annually at minimum, for any firm holding client confidential data — which is every firm.
- After material change — a new client portal, an office merger, a cloud migration, a VPN or firewall replacement, or an acquisition that brings unknown infrastructure with it.
- Quarterly or continuously for firms with substantial corporate, healthcare, financial-services, or government practices, or where outside counsel guidelines require it.
- Immediately if you have never done one, or if your last test predates your current remote-access setup.
Between tests, continuous external monitoring closes the gap. Point-in-time testing tells you the perimeter was sound in March; it says nothing about the appliance vulnerability disclosed in July.
Insurance and client requirements
Two forces now drive most law-firm testing budgets, and neither is regulatory.
Cyber-insurance underwriters have moved from asking whether you have a firewall to asking for evidence: date of last external penetration test, remediation status of critical findings, MFA coverage across all external access, and EDR deployment. Firms that answer well see materially better terms; firms that answer poorly see higher retentions, sublimits on social-engineering coverage, or declination.
Corporate clients apply the same pressure through outside counsel guidelines. Financial-services, healthcare, and technology clients increasingly require annual third-party testing, prompt breach notification, and the right to review results or receive an attestation. Failing a client security questionnaire does not usually produce a rejection letter — it produces work quietly routed to a firm that passed.
What to require from a provider
Before signing, insist on: named testers with verifiable credentials (OSCP, GPEN, CREST) rather than an anonymous team; a sample redacted report you can actually read; explicit scope, rules of engagement, and testing windows; a written authorization letter; manual testing clearly distinguished from automated scanning; free remediation retesting; and a confidentiality posture appropriate to privileged material, including a signed NDA and clarity about where your data is stored.
Ask directly what percentage of the engagement is manual. If the honest answer is "our platform runs continuously," you are buying scanning with a report template attached — useful, but not what an insurer or a general counsel means by a penetration test.
Frequently asked questions
Q: What is external penetration testing? A: External penetration testing is an authorized simulated attack conducted from the public internet against an organization's internet-facing systems — domains, IP addresses, web applications, mail servers, VPNs, and cloud services — to identify and safely exploit weaknesses an outside attacker could use to gain access, without any credentials or insider assistance.
Q: How much does external penetration testing cost for a law firm? A: In 2026, a point-in-time external penetration test typically costs $4,000–$9,000 for a solo or small firm, $8,000–$15,000 for a boutique, $15,000–$25,000 for a mid-size firm, and $25,000–$120,000+ for large or AmLaw firms, driven primarily by the size of the external attack surface rather than attorney headcount.
Q: How is external penetration testing different from a vulnerability scan? A: A vulnerability scan is automated and reports potential weaknesses; an external penetration test adds human testers who validate those weaknesses, chain them together, and safely exploit them to prove real-world impact. Scans produce lists; penetration tests produce demonstrated attack paths and are what insurers and corporate clients typically require.
Q: How long does an external penetration test take? A: Most law-firm external tests take one to three weeks from kickoff to final report, with testing itself running three to ten business days depending on scope, plus time for reporting and a findings review call.
Q: How often should a law firm run an external penetration test? A: At least annually, plus after any material infrastructure change such as a new client portal, cloud migration, VPN replacement, office merger, or acquisition. Firms serving corporate, healthcare, or financial-services clients increasingly test quarterly or maintain continuous external monitoring between annual tests.
Q: Does external penetration testing disrupt firm operations? A: A properly scoped engagement is designed to avoid disruption. Denial-of-service testing is excluded by default, destructive actions are prohibited by the rules of engagement, and any high-risk testing is scheduled in agreed windows with an escalation contact available throughout.
Q: Is penetration testing required by the ABA? A: The ABA does not mandate penetration testing by name. ABA Model Rule 1.6(c) requires reasonable efforts to protect client information, and Formal Opinions 477R and 483 address secure communication and breach response. Testing is one of the clearest ways a firm demonstrates that its efforts were reasonable.
How Attorney Armor helps
Attorney Armor was built for this specific problem. Our external attack-surface assessment maps everything your firm exposes to the internet — including the assets you have forgotten — and shows you exactly what an attacker sees, in language a managing partner can act on.
- Free external attack-surface scan. Enter your firm's domain and get a no-obligation view of your exposed hosts, login surfaces, email authentication posture, and known vulnerabilities in under two minutes.
- Full external penetration testing performed by credentialed testers, with manual exploitation, attack-narrative reporting, and free remediation retesting.
- Continuous perimeter monitoring that alerts you when a new host, port, certificate, or vulnerability appears between annual tests.
- Insurance and client-questionnaire support — attestation letters and evidence packages formatted for underwriters and outside counsel guidelines.
Start with the free assessment. If the results are clean, you have documentation. If they are not, you found it before someone else did.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


