Information Security Policy Template for Law Firms (2026): A WISP That Survives Audit, Insurance, and Client Review
A complete, copy-ready information security policy template built for law firms — the 14 sections a Written Information Security Program (WISP) needs to satisfy ABA Model Rule 1.6(c), the FTC Safeguards Rule, SEC Regulation S-P, and outside-counsel guidelines, plus how to fill it in, who signs it, how often to review it, and the evidence that proves you actually follow it.

Most law firms already have an information security policy. It is four pages long, it was written by a managed IT provider in 2019, it says "the Firm shall employ industry-standard safeguards," and nobody has read it since the day it was saved to the shared drive.
That document will not survive contact with a cyber-insurance underwriter, a Fortune 500 client's outside-counsel guidelines, an FTC Safeguards examination, or — worst case — a plaintiff's expert reconstructing what your firm knew and when after a breach.
This is a working information security policy template for law firms. It is structured as a Written Information Security Program (WISP), which is the term regulators, insurers, and state bars use. Copy the section headings, fill in the bracketed fields, delete what genuinely does not apply, and keep the evidence each section implies. That last part is what separates a policy from a piece of paper.
What an information security policy actually is
A policy is a set of binding statements about how your firm protects information: what it protects, who is responsible, what controls are required, and what happens when someone deviates. It is not a technical runbook, not a vendor's product list, and not an aspirational statement of values.
Three documents are commonly confused:
- Policy — what the firm requires, and who owns it. Short, stable, signed by leadership. Changes annually at most.
- Standard — the specific settings that satisfy the policy (e.g. "passphrases of 14+ characters, MFA on all remote access"). Changes as technology changes.
- Procedure — the step-by-step of how someone performs the task. Owned by IT or the practice group. Changes constantly.
Auditors read the policy. Insurers read the policy. Clients ask for the policy. Attackers, in effect, test your procedures. All three have to line up, because the fastest way to create liability is to publish a policy your firm demonstrably does not follow.
Why law firms specifically need a WISP in 2026
Four separate pressures now converge on the same document:
ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. Formal Opinions 477R and 483 make clear that "reasonable efforts" is a fact-specific analysis — and a documented program is the most direct way to show your firm performed that analysis rather than guessing.
The FTC Safeguards Rule applies to law firms that qualify as financial institutions under the rule (real-estate settlement work, certain tax and debt-related practices, firms operating title agencies). It explicitly mandates a written program, a designated qualified individual, a written risk assessment, annual penetration testing plus biannual vulnerability assessments (or continuous monitoring in lieu of both), and written incident response.
SEC Regulation S-P, as amended in 2024, pushes incident-response and customer-notification obligations down through covered entities to the service providers they use — which includes the law firms advising broker-dealers, RIAs, and funds. Compliance now arrives as a contract term.
Outside-counsel guidelines. Corporate clients no longer ask whether you have a policy; they attach a security exhibit to the engagement letter and ask for the document by name, along with proof of testing. Firms without one negotiate from behind.
If your firm handles healthcare matters you inherit HIPAA business-associate obligations, and firms operating in New York inherit NY DFS 23 NYCRR 500 through covered clients. The good news: one well-built WISP satisfies the overlapping core of all of them.
The 14 sections a law firm WISP needs
Use these headings verbatim. Reviewers scan for them, and a familiar structure gets approved faster than an original one.
1. Purpose and scope
State what the program protects and where it applies.
> This Written Information Security Program ("Program") establishes [FIRM NAME]'s administrative, technical, and physical safeguards for Protected Information. It applies to all partners, associates, of-counsel attorneys, staff, contract attorneys, temporary personnel, and third-party service providers with access to Firm systems or Protected Information, regardless of location or device ownership.
Define Protected Information explicitly: client confidential information and work product, personally identifiable information, protected health information, financial account data, trust and IOLTA account information, firm employment records, and authentication credentials.
2. Roles and responsibilities
Name a human being. The single most common gap in law-firm policies is a program with no owner.
- Qualified Individual / Information Security Officer — [NAME, TITLE]. Owns the Program, reports to [MANAGING PARTNER / EXECUTIVE COMMITTEE] at least annually in writing.
- Managing Partner or Executive Committee — approves the Program and the annual risk-assessment findings.
- IT provider or internal IT — implements standards; does *not* own the Program. A vendor cannot be your qualified individual under the Safeguards Rule's intent, though it may support the role under supervision.
- All personnel — comply with the Program; report suspected incidents immediately.
3. Risk assessment
Commit to a written, periodic assessment — at least annually and after material changes (a merger, new practice area, new matter-management system, office relocation, or a significant incident).
The assessment should identify: information assets and where they live, reasonably foreseeable internal and external threats, the likelihood and impact of each, the sufficiency of existing safeguards, and a remediation plan with owners and dates. Keep the prior three years on file — the trend line is what demonstrates a program rather than a one-time exercise.
4. Access control and identity
This section carries more weight with underwriters than any other.
- Access is granted on least privilege and by role, not by seniority. Partners do not need administrative rights.
- Multi-factor authentication is required for email, remote access, the document management system, the client portal, the practice-management platform, the financial system, and all administrative accounts. Phishing-resistant methods (passkeys, FIDO2 security keys) required for administrators and for anyone with wire-transfer authority.
- Matter-level access restrictions ("ethical walls") are configured in the DMS for conflicts, laterals, and sensitive matters, and are reviewed quarterly.
- Access is reviewed at least [QUARTERLY / SEMIANNUALLY] and revoked within [4 HOURS / SAME BUSINESS DAY] of separation.
- Shared accounts are prohibited except where documented and compensating controls exist.
5. Data classification and handling
Three tiers is enough for most firms. More tiers means nobody complies.
| Tier | Examples | Handling requirements |
|---|---|---|
| Highly Confidential | M&A deal data, PHI, trade secrets, sealed filings, trust account data | Encryption at rest and in transit, matter-level access, no removable media, DLP on outbound email, retention per matter |
| Confidential | General client matter files, work product, contracts | Encryption in transit, DMS storage only, secure portal for external sharing |
| Internal | Firm operations, marketing drafts, internal memos | Standard controls, no public posting |
Prohibit storing Protected Information in personal cloud accounts, consumer messaging apps, or local device folders outside the DMS sync path.
6. Encryption
State the requirement, not the algorithm-of-the-week: full-disk encryption on all laptops and mobile devices, TLS 1.2 or higher for data in transit, encryption at rest for all systems holding Protected Information, encrypted backups with keys managed separately from the backup store, and secure-portal or encrypted-email delivery for Highly Confidential material sent outside the firm.
7. Endpoint, network, and email security
- Managed endpoint detection and response (EDR) on every firm-issued device, centrally monitored.
- Patching windows: critical vulnerabilities within [7 DAYS], high within [30 DAYS], with documented exceptions.
- Email authentication: SPF, DKIM, and DMARC at enforcement (`p=reject` or `p=quarantine`) on every firm domain and every lookalike domain the firm owns.
- External-sender banners enabled; auto-forwarding to external addresses disabled by default.
- Segmented guest wireless; no client data traverses guest networks.
8. Wire transfer and funds-handling controls
Law firms lose more money to business email compromise than to ransomware. This section belongs in the policy even though it looks operational.
- All payment instructions and any change to existing instructions must be verified by outbound voice call to a number obtained independently of the request — never a number in the email.
- Dual authorization for transfers above [$AMOUNT].
- No wire instructions transmitted by unencrypted email; use the client portal.
- Written client acknowledgment at engagement that the firm will never change wire instructions by email.
9. Vendor and third-party management
Inventory every provider that touches Protected Information: DMS, cloud hosting, e-discovery, court reporters, translation, litigation support, outside copy services, MSP, and AI tools. For each, record the data accessed, the contractual security terms, the security evidence on file (SOC 2 report, questionnaire, or attestation), and the review date. Require breach notification to the firm within [24–72 HOURS] and flow down confidentiality obligations at least as strict as the firm's own.
10. Personnel security and training
Background screening where permitted by law, confidentiality agreements at hire, security awareness training at onboarding and at least annually, and phishing simulations at least quarterly with documented completion. Track the metrics — the phish-prone rate and, more importantly, the report rate — because insurers increasingly ask for them.
11. Testing and continuous monitoring
Say precisely what you test and how often, because this is the clause insurers verify.
- Annual penetration testing of internet-facing systems and the client portal, performed by an independent party.
- Vulnerability assessments at least semiannually, or continuous monitoring in lieu of the annual pentest plus biannual scan schedule where permitted.
- Retesting of critical and high findings within [30 DAYS] of remediation.
- Written results retained for [3 YEARS] and reported to firm leadership.
12. Incident response
Reference a standalone incident-response plan, then state the non-negotiables in the policy itself: who declares an incident, the 24/7 contact path, that outside breach counsel is engaged before forensic work begins to preserve privilege, cyber-insurance carrier notification timing per the policy, evidence-preservation requirements, and the fact that legal notification clocks vary by jurisdiction and are determined by counsel, not by IT.
13. Business continuity and backup
Backups following a 3-2-1 pattern with at least one immutable or offline copy, restoration tested at least [SEMIANNUALLY] with documented results, and defined recovery objectives per system (a docketing system and a marketing site do not deserve the same RTO).
14. Governance, exceptions, and enforcement
Annual review and approval by [MANAGING PARTNER / COMMITTEE], a written exception process with a named approver and an expiration date, disciplinary consequences for violations, and a version-history table on the final page. The version history is small and disproportionately persuasive: it proves the program is alive.
How to fill it in without turning it into fiction
Three rules keep a WISP defensible:
Write only what you do. A policy that requires quarterly access reviews you have never performed is worse than one that requires annual reviews you actually complete. Aspirational language becomes an admission after an incident.
Use ranges and named owners, not vendor names. "EDR deployed on all firm endpoints, monitored 24/7" survives a vendor change. "CrowdStrike Falcon" requires a policy amendment every time procurement moves.
Attach the evidence. Each section should map to an artifact you can produce in under an hour: the access-review export, the training completion report, the last pentest letter, the restore test log, the vendor inventory. Reviewers do not read policies closely — they sample two or three claims and ask for proof.
Who signs, who reviews, and how often
| Activity | Owner | Frequency |
|---|---|---|
| Program approval | Managing partner or executive committee | Annually |
| Risk assessment | Qualified Individual | Annually and after material change |
| Access review | IT with practice-group confirmation | Quarterly |
| Security awareness training | Qualified Individual | At hire, then annually |
| Phishing simulation | Qualified Individual | Quarterly |
| Penetration test | Independent third party | Annually (or continuous monitoring) |
| Vulnerability assessment | Independent third party or internal | Semiannually or continuous |
| Vendor review | Firm administrator | Annually, higher-risk vendors semiannually |
| Backup restore test | IT | Semiannually |
| Incident-response tabletop | Qualified Individual + leadership | Annually |
The seven mistakes that get policies rejected
1. No named qualified individual. "The IT Department" is not a person. 2. Downloaded generic template with another industry's language. References to "cardholder data" and no reference to matter confidentiality signal a copy-paste job. 3. No testing clause. Underwriters now look specifically for pentest cadence, and outside-counsel guidelines increasingly require it in writing. 4. Vendor product names throughout. Guarantees the policy goes stale. 5. No version history or approval signature. Undated policies read as never-reviewed. 6. No exception process. Every firm has exceptions; a program without a documented path for them just drives them underground. 7. Controls the firm does not actually run. The fastest way to convert a security incident into a malpractice theory.
Frequently asked questions
Q: Is an information security policy the same as a WISP? A: In practice, yes for most law firms. "WISP" is the term used by the FTC Safeguards Rule and by several state data-security statutes (notably Massachusetts 201 CMR 17.00) for the overall written program. An information security policy is the core document of that program. Titling your document "Written Information Security Program (WISP)" makes it recognizable to regulators, insurers, and clients.
Q: How long should a law firm's information security policy be? A: Fifteen to thirty pages for the full WISP is typical for a firm of 10–200 attorneys, with the core policy running 10–15 pages and standards, the risk-assessment summary, and the incident-response plan attached as appendices. Anything under five pages usually lacks the testing, vendor, and governance clauses reviewers look for.
Q: Do solo attorneys and small firms need a written policy? A: Yes. ABA Model Rule 1.6(c) applies regardless of firm size, cyber-insurance applications ask the same questions of a solo as of an AmLaw 100 firm, and corporate clients send the same security exhibit. A solo practitioner's WISP is shorter, but the same 14 sections apply.
Q: Can we just use our IT provider's policy? A: No. An MSP policy describes how the MSP operates, not how your firm handles client confidences, ethical walls, wire verification, or matter retention. Use the provider's documentation as evidence supporting your technical sections, and own the program yourself.
Q: How often does the policy need to be updated? A: Review and re-approve at least annually, and immediately after a merger or lateral group arrival, a new practice area with new regulatory exposure, a change in core systems (DMS, email, portal), or any significant security incident. Record each review in the version-history table even when nothing changes.
Q: What evidence do cyber-insurance underwriters ask for alongside the policy? A: Most commonly: proof of MFA coverage on email and remote access, EDR deployment percentage, backup immutability and restore-test results, security-training and phishing-simulation completion rates, the most recent penetration-test or vulnerability-assessment letter, and the incident-response plan with a tested call tree.
Q: Does the policy have to cover AI tools? A: If attorneys use them, yes. Add a clause specifying which AI tools are approved, that Protected Information may only be entered into tools with contractual no-training terms, and that outputs must be verified before use in client work. Unapproved consumer AI tools should be explicitly prohibited for client matter content.
Q: What is the difference between a policy and a risk assessment? A: The risk assessment identifies what could go wrong and how likely it is; the policy sets the controls that respond to those risks. Regulators expect the policy to be *derived from* the assessment — which is why the assessment should be dated earlier than the policy revision it justifies.
Turning the document into a defensible program
A policy claims controls exist. Evidence proves they work. The gap between the two is where most firms are exposed, and it is exactly what Attorney Armor was built to close:
- Continuous external testing and attack-surface monitoring — satisfies the testing clause in Section 11 with dated, independent results instead of a once-a-year PDF.
- Authenticated assessments of the client portal, Microsoft 365, and DMS tenants — the systems your Section 4 access controls actually govern.
- Phishing simulation with legal-specific pretexts — produces the training and report-rate metrics Section 10 requires.
- Audit-ready reporting mapped to ABA Model Rule 1.6(c), the FTC Safeguards Rule, SEC Regulation S-P, HIPAA, and NY DFS 500 — formatted for underwriters, general counsel, and outside-counsel-guideline reviewers.
Start with the free external assessment — it takes about two minutes and gives you a dated baseline to attach to Section 11 the day your policy is signed. If you want to see what the evidence package looks like first, review the sample report.
A policy nobody tests is a document. A policy with evidence behind it is a defense.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


