Security Testing

Law Firm Security Testing 2026: Vendor Assessments and Client Requirements

A practical 2026 guide to law firm security testing, vendor risk assessments, client security questionnaires, outside counsel requirements, evidence review, contracts, and ongoing monitoring.

Attorney Armor Security Team September 23, 2026 16 min read
Law Firm Security Testing 2026: Vendor Assessments and Client Requirements

Law firm security testing in 2026 has two directions. A firm must test its own systems, but it must also evaluate the vendors that store client files, support attorneys, process payments, host discovery data, or connect to the firm's environment. At the same time, corporate clients increasingly ask the firm to prove its own controls through outside counsel guidelines and security questionnaires.

Direct answer: A defensible law firm security testing program should classify vendors by risk, collect evidence rather than rely on yes-or-no answers, review independent assurance and penetration-test results, contract for minimum safeguards and incident notice, monitor material changes, and reassess high-risk vendors at least annually or when their service changes. The firm should maintain the same kind of evidence package for clients evaluating the firm.

This guide focuses on that two-way evidence problem: how a law firm evaluates legal technology vendors and how it demonstrates its own security posture to clients. For a technical test of the firm's own network, see the law firm penetration testing checklist. For the differences among testing methods, see vulnerability assessment versus penetration testing.

Why vendor security assessment is the missing layer

Law firms routinely give third parties access to information whose loss could harm a client or compromise a matter: document-management providers, e-discovery platforms, managed IT providers, court reporters, payment processors, intake tools, transcription services, expert-witness portals, cloud storage, artificial-intelligence tools, and litigation-support vendors.

A contract does not transfer all of that risk. If a vendor account is overprivileged, a subcontractor is unknown, or a provider cannot restore data, the law firm still faces the operational and client consequences. Vendor assessment therefore belongs beside internal security testing, not underneath procurement as a paperwork exercise.

ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to or disclosure of information relating to a representation. Comment 18 describes a fact-specific analysis rather than prescribing a particular certification or test. ABA Formal Opinion 477R addresses reasonable safeguards when transmitting client information, while Model Rules 5.1 and 5.3 inform supervision of lawyers and nonlawyers. The precise duty depends on the jurisdiction, engagement, data, and circumstances; firms should involve qualified ethics and privacy counsel when needed.

The practical conclusion is narrower: selecting a reputable name is not the same as evaluating the safeguards relevant to the firm's use of that service.

The two security questionnaires a law firm must manage

Clients assessing the law firm

Banks, healthcare companies, insurers, technology companies, public companies, and other sophisticated clients may send outside counsel guidelines or security questionnaires before a matter begins. The Association of Corporate Counsel's Model Information Protection and Security Controls for Outside Counsel illustrates the breadth of controls clients may address, including governance, access, data handling, incident response, and third parties.

Typical requests ask whether the firm has completed an independent penetration test, how quickly critical findings are remediated, whether multifactor authentication covers remote and administrative access, how client data is encrypted, how vendors are approved, and when the client will be notified of a security incident.

The correct response is not to overstate maturity. Assign an owner, answer consistently, attach current evidence where permitted, explain compensating safeguards, and create a remediation item for every material gap. A precise “partially implemented, completion scheduled” response is more defensible than an unsupported “yes.”

The law firm assessing its vendors

The same logic runs downstream. A vendor questionnaire should establish what data and access the provider receives, what could happen if the service fails, what safeguards exist, whether those safeguards were independently tested, and how the vendor will communicate and recover after an incident.

The ABA Cybersecurity Legal Task Force vendor contracting checklist provides useful issues for diligence and contracting. Real-world vendor requirements, such as Cooley's published requirements, also show that assessment and contractual obligations should work together.

How law firms conduct vendor security assessments

Step 1 — Inventory every vendor relationship

Start with accounts payable, single sign-on logs, browser extensions, expense records, practice groups, and the managed service provider. Procurement records alone rarely reveal every tool used by attorneys and staff.

For each vendor, record the service owner, contract owner, renewal date, business purpose, systems connected, categories of data handled, geographic processing locations if relevant, subprocessors, authentication method, privileged access, and exit process. Include free trials and AI products where client material may be entered.

Step 2 — Tier vendors by consequence, not spend

A low-cost transcription service may present more confidentiality risk than an expensive office system. Use three practical tiers:

  • Critical: hosts substantial client or matter data, has administrative access, supports a time-sensitive legal workflow, moves money, or could materially interrupt representation.
  • High: processes confidential data or integrates with core systems but has limited privilege, limited volume, or a practical substitute.
  • Standard: receives little or no confidential data and cannot access production systems.

Document the reason for the tier. That decision controls review depth, required evidence, approval authority, contract terms, monitoring, and reassessment frequency.

Step 3 — Define the data flow and attack path

Do not ask only where data is stored. Map how it enters the service, who can access it, where copies and backups exist, which integrations can retrieve it, what administrators can do, and how data is removed at termination.

Then model a few credible failures: a vendor administrator is phished; an integration token is stolen; a subprocessor is breached; a client portal exposes another matter; an AI feature retains prompts; the vendor becomes unavailable during a filing deadline. The assessment should test whether controls reduce those specific consequences.

Step 4 — Send a proportionate questionnaire

A critical legal technology provider warrants a detailed review. A caterer does not. For critical and high-risk vendors, cover:

  • Security ownership, written program, workforce training, and risk assessments.
  • Single sign-on, multifactor authentication, privileged access, joiner-mover-leaver controls, and access reviews.
  • Encryption in transit and at rest, key management, tenant separation, logging, and data-loss protections.
  • Vulnerability management, secure development, penetration testing, remediation deadlines, and disclosure practices.
  • Incident detection, forensic readiness, notification commitments, escalation contacts, and cooperation duties.
  • Backups, recovery objectives, restoration tests, continuity plans, and dependency failures.
  • Subprocessor approval, geographic locations, data retention, secure deletion, and return of firm data.
  • Cyber insurance, relevant independent assurance, exceptions, and the date of the next review.

Ask for explanations and evidence. A checked box without scope, date, owner, or artifact provides little assurance.

Step 5 — Review evidence critically

Evidence can include a SOC 2 Type II report, ISO/IEC 27001 certificate and statement of applicability, independent penetration-test executive summary or attestation, vulnerability-management policy, business continuity test results, data-flow diagram, subprocessor list, and incident response summary.

These artifacts are not interchangeable. A SOC 2 report is an independent attestation over stated controls and a defined period; ISO/IEC 27001 certifies an information security management system within a stated scope; a penetration test examines attack paths in a stated technical scope. None proves that every system is secure.

Check the name of the legal entity, report period, covered product, locations, exclusions, complementary user-entity controls, exceptions, subservice organizations, test scope, test date, severity of unresolved findings, and whether remediation was independently retested. A report for a parent company or a different product may not cover the service the firm uses.

Step 6 — Resolve gaps before approval

Classify each gap as accepted, remediated, contractually mitigated, or disqualifying. Record who can accept the residual risk. Critical findings should not disappear into email; they need an owner, due date, validation method, and escalation path.

Possible safeguards include reducing the data shared, disabling an integration, requiring firm-managed single sign-on, limiting administrator access, shortening retention, obtaining a remediation date, or selecting another provider. A compensating control should reduce the identified risk, not merely restate policy.

Step 7 — Put security obligations in the contract

The contract should match the assessment. Depending on the service and governing law, counsel may address permitted data use, minimum safeguards, access limits, subprocessor conditions, incident-notification timing, investigation cooperation, preservation of evidence, audit rights, vulnerability remediation, business continuity, deletion and return, insurance, indemnity, and termination assistance.

Avoid assuming that a generic data-processing addendum covers operational security. Also avoid promising clients a faster downstream notification than vendors have promised the firm. These commitments must align across the chain.

Step 8 — Monitor and reassess

Assessment is not complete at signature. Revisit critical vendors on a risk-based schedule, commonly at least annually, and after a material product change, acquisition, significant incident, new subprocessor, new AI feature, or expansion in data or access.

Track expiring reports and certificates, material service changes, security notices, exposed internet assets relevant to the service, unresolved findings, contract renewal dates, and completion of agreed remediation. Continuous monitoring can identify changes between full reviews, but it does not replace evidence review or business-owner judgment.

What penetration testing should law firms require from vendors?

There is no universal test that every vendor must run. Requirements should follow the service's risk, architecture, and contract. For a critical provider that hosts client data or exposes an internet-facing portal, the firm can reasonably ask for:

  • An independent test performed within the previous 12 months or after a material architectural change.
  • A scope covering the product and environment the firm actually uses, including relevant web applications, APIs, cloud configuration, and authorization boundaries.
  • Testing by qualified people using a recognized methodology, with manual validation rather than an automated scan labeled as a penetration test.
  • An executive summary or attestation stating dates, scope, independence, methodology, severity counts, and remediation status without exposing dangerous technical detail.
  • Evidence that critical and high-severity findings were corrected and retested, or a documented plan and compensating controls for remaining risk.
  • A process for notifying customers when a material vulnerability or incident affects their data or service.

Some vendors cannot share a full report because it contains exploit details or information about other customers. A controlled review, independent attestation, sanitized executive summary, or discussion with the assessor can provide useful assurance. Refusal to share the full report is not automatically disqualifying; refusal to provide any credible evidence deserves escalation.

For lower-risk providers, a current vulnerability-management summary, secure-development evidence, and contract commitments may be proportionate. Do not demand expensive testing that has no connection to the product or data in scope.

Build an evidence package clients can review

The law firm should be able to answer its own client questionnaires from a controlled evidence library. Keep current versions of:

  • Written information security and incident response plans.
  • Independent penetration-test attestation and remediation or retest status.
  • Vulnerability assessment cadence and aging metrics.
  • Multifactor authentication and access-review evidence.
  • Phishing simulation and security awareness completion summaries.
  • Tabletop exercise record and recovery-test evidence.
  • Vendor inventory, tiering method, assessment records, and approved exceptions.
  • Relevant assurance reports, policies, insurance certificates, and data-flow diagrams.

Restrict sensitive technical reports, use nondisclosure terms when appropriate, watermark shared copies, and log disclosures. A client generally needs enough evidence to evaluate the control, not a roadmap an attacker could use.

A 90-day implementation plan

Days 1–30: discover and prioritize

Name an accountable owner, assemble the vendor inventory, identify every provider with client data or privileged access, select the top ten by consequence, and gather current contracts and evidence. Create one intake path for new technology.

Days 31–60: assess and contract

Complete evidence-based reviews for the highest-risk providers. Record gaps, assign owners, and align security addenda with client commitments. At the same time, assemble the firm's own client-facing evidence library and normalize questionnaire answers.

Days 61–90: validate and monitor

Validate closed findings, establish reassessment triggers, track evidence expiration, and present unresolved critical risks to firm leadership. Test one scenario in which a key vendor is breached or unavailable. Record decisions and lessons rather than aiming for a perfect score.

Frequently asked questions

How do law firms conduct vendor security assessments?

Law firms inventory and risk-tier vendors, map the data and access involved, issue a proportionate questionnaire, review independent evidence, resolve gaps, negotiate security obligations, approve residual risk, and monitor material changes. High-risk providers receive deeper and more frequent review than vendors without client data or system access.

What penetration testing do law firms require for vendors?

For a high-risk internet-facing service, firms commonly request recent independent penetration-testing evidence covering the product they use, plus remediation and retest status for serious findings. The exact scope and cadence should be risk- and contract-based; a certification or automated vulnerability scan is not the same as a penetration test.

How often should a law firm reassess a vendor?

Use a risk-based schedule. Critical providers are commonly reviewed at least annually and whenever a material service, ownership, subprocessor, data-use, or security change occurs. Lower-risk vendors may be reviewed less often. Contract renewal should never be the only trigger.

Does a SOC 2 report replace a vendor penetration test?

No. A SOC 2 report evaluates specified controls over a defined period and may reference vulnerability management or penetration testing. A penetration test evaluates attack paths within a technical scope at a point in time. Review both in context rather than treating either as a universal guarantee.

Who should approve vendor security risk at a law firm?

Security or IT should evaluate technical risk, privacy and legal teams should evaluate obligations, the business owner should confirm necessity, and an authorized leader should accept material residual risk. The managed service provider should not be the only approver of its own controls or those of closely related services.

How Attorney Armor supports law firm security testing

Attorney Armor helps law firms turn security testing into current, reviewable evidence. Our penetration testing identifies and validates exploitable paths across external systems, cloud environments, and client-facing applications. Our vulnerability assessments prioritize known weaknesses and support documented remediation.

Between formal tests, continuous security monitoring watches the firm's external attack surface for meaningful changes. Security awareness training and phishing simulations test human workflows, while compliance reporting organizes evidence for client reviews, insurers, and applicable requirements.

Start with a free external assessment or contact Attorney Armor to scope a law-firm-specific testing program. Attorney Armor provides cybersecurity services, not legal advice; requirements should be confirmed with qualified counsel for the firm's jurisdictions, clients, and data.

Attorney Armor services

Turn security testing into evidence your firm can use

Choose the testing, monitoring, training, and reporting support that fits your firm. Start with a plan or ask us to scope a tailored program.

Plans start at $199/month

Practice is $199/month, Firm is $499/month, and Enterprise pricing is tailored for larger or multi-office firms.

Free Assessment

See what an attacker sees.

Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.

Start the assessment

Continue reading