Vulnerability Assessment vs. Penetration Testing for Law Firms (2026): Which Cybersecurity Test Do You Actually Need?
Law firms are asked for 'a security test' by insurers, clients, and outside counsel guidelines — but a vulnerability assessment and a penetration test are not the same thing, don't cost the same, and don't satisfy the same requirements. Here's the 2026 breakdown: what each test finds, what each costs, how often to run them, and how to choose the right one for your firm's size and risk.

Every law firm eventually gets the email. It comes from a cyber-insurance underwriter, a Fortune 500 client's vendor-risk team, or the firm's own general counsel after a peer firm makes the news: *"Please provide evidence of recent security testing."*
That single sentence hides an expensive ambiguity. Vulnerability assessment and penetration testing are two different exercises, with different methods, different price tags, and — critically — different levels of assurance. Buy the wrong one and you either overspend by a factor of ten or hand your client a report that doesn't satisfy their requirement.
Five-minute takeaway: A *vulnerability assessment* is automated, broad, and cheap ($1,500–$8,000, or continuous for a monthly fee); it tells you what is *potentially* exploitable. A *penetration test* is human-led, narrow, and expensive ($10,000–$45,000 for a typical firm); it proves what an attacker can *actually* do with those weaknesses. Most law firms under 100 attorneys should run continuous vulnerability assessment year-round and one focused penetration test annually. Insurers and enterprise clients increasingly ask for both — and will accept an assessment only if the scope letter says so explicitly.
The one-sentence difference
- Vulnerability assessment answers: *"What known weaknesses exist across our systems?"* It is breadth-first, largely automated, and produces a prioritized list.
- Penetration testing answers: *"Can a skilled attacker chain those weaknesses into access to privileged client files?"* It is depth-first, human-driven, and produces a narrative of proven attack paths.
An assessment might report that your remote-access gateway is missing a patch. A penetration test reports that the missing patch allowed a tester to authenticate as a paralegal, pivot to the document management system, and download a folder of sealed settlement agreements in forty minutes.
For a law firm, that distinction is the whole game. Model Rule 1.6(c) requires "reasonable efforts" to prevent unauthorized disclosure of client information — and reasonableness is judged on what you knew and what you did about it. A list of unpatched systems is knowledge. A proven path to privileged material is urgency.
Side-by-side: what each test actually delivers
Vulnerability assessment
- Method: Authenticated and unauthenticated scanning of external IPs, web applications, cloud tenants, and internal networks, validated against CVE and configuration databases.
- Duration: Hours to a few days, or continuous when run as a managed service.
- Output: A prioritized inventory — CVSS scores, affected assets, remediation steps, and trend data over time.
- Strength: Coverage. It looks at everything you own, repeatedly.
- Weakness: False positives, and no proof of real-world exploitability. It cannot tell you that three "medium" findings combine into a critical breach path.
- Best for: Continuous hygiene, patch verification, M&A due diligence on a firm you're absorbing, and satisfying baseline insurance questions.
Penetration testing
- Method: A qualified tester (OSCP, GPEN, GWAPT, or CREST-certified) manually attempts exploitation within an agreed scope and rules of engagement, chaining findings the way a real intruder would.
- Duration: One to four weeks depending on scope, plus a week for reporting and retest.
- Output: An executive summary, a technical narrative with reproducible steps and evidence, a risk-ranked finding list, and a retest attestation letter — the document clients and insurers actually want on file.
- Strength: Proof. It converts theoretical risk into a demonstrated business impact you can put in front of a partnership committee.
- Weakness: It is a point-in-time snapshot of a defined scope. Anything out of scope, or deployed the week after, is untested.
- Best for: Annual assurance, outside counsel guideline compliance, enterprise client security questionnaires, cyber-insurance underwriting at higher limits, and validating a major infrastructure change.
What each one costs a law firm in 2026
Prices below reflect what U.S. firms are quoted this year for legal-sector engagements. Legal work carries a modest premium over generic SMB testing because testers must handle privileged data under strict confidentiality terms and often sign firm-specific NDAs and ethical walls.
- Automated external vulnerability assessment (one-time): $1,500–$4,000 for a firm with a single office and under 50 external assets.
- Full internal + external vulnerability assessment (one-time): $4,000–$8,000.
- Continuous / managed vulnerability management: $500–$2,500 per month depending on asset count, including monthly reporting and remediation tracking.
- External network penetration test: $10,000–$18,000.
- Internal network penetration test: $14,000–$25,000.
- Web application penetration test (client portal, intake form, extranet): $12,000–$30,000 per application depending on authenticated role count.
- Social engineering / phishing simulation add-on: $3,500–$9,000.
- Full red team engagement (multi-vector, objective-based): $45,000–$120,000 — appropriate for AmLaw 200 firms and firms handling national-security or M&A-sensitive matters.
- Retest after remediation: usually included for 30–90 days; budget $2,000–$5,000 if outside that window.
If a quote for a "penetration test" comes in at $2,500, you are almost certainly buying a vulnerability scan with a cover page. Ask a single question: *"How many hours of manual tester time are in this engagement?"* If the answer is under 40, it is not a penetration test.
Which one does your firm need? A decision guide
Solo and firms under 10 attorneys. Start with continuous external vulnerability assessment plus multi-factor authentication enforcement and phishing simulation. A full penetration test is usually premature until you host a client portal or handle regulated data (health, financial, or defense).
Firms of 10–50 attorneys. Continuous vulnerability management year-round, plus one external penetration test annually. Add a web application test if you run a client intake portal or extranet — that is where firms of this size actually get breached.
Firms of 50–250 attorneys. Continuous vulnerability management, an annual external *and* internal penetration test, an application test for each client-facing system, and an annual phishing campaign. Most enterprise outside counsel guidelines at this tier now specify "annual third-party penetration testing" by name.
Firms over 250 attorneys, or any firm with national-security, M&A, or high-profile litigation exposure. Everything above plus a biennial objective-based red team and tabletop exercise. At this tier, clients audit your evidence, not just your assertions.
Any firm mid-acquisition or absorbing a practice group. Run a vulnerability assessment on the incoming environment *before* network integration. Acquired infrastructure is the most common source of unmanaged, unpatched assets on a law firm network.
What insurers and clients actually accept in 2026
- Cyber-insurance applications now routinely ask whether the firm performs "regular vulnerability scanning" *and*, at limits above $5M, "annual penetration testing by an independent third party." Answering yes without evidence is a misrepresentation risk that carriers have begun using to reduce claims.
- Outside counsel guidelines from banks, insurers, healthcare systems, and public companies increasingly incorporate testing requirements by reference to a framework — most often NIST SP 800-115, the standard technical guide to security testing, or the controls in NIST Cybersecurity Framework 2.0.
- SEC-regulated clients apply Regulation S-P service-provider oversight expectations down the chain to their law firms, which in practice means the firm must show testing evidence and a written incident response plan.
- ISO 27001 and SOC 2 auditors treat vulnerability management as a continuous control and penetration testing as an annual one. An assessment does not substitute for the pen test line item.
The practical answer: keep a testing evidence folder with the last vulnerability report, the last penetration test executive summary, the retest attestation, and the remediation tracker. Ninety percent of client security questionnaires can be answered from those four documents in under an hour.
How often to run each test
- Vulnerability assessment: continuously, or at minimum monthly for externally facing assets and quarterly internally. Also immediately after any material change — a new VPN appliance, a document management migration, a new office.
- Penetration testing: annually at minimum, and additionally after a major architecture change, a merger, or a security incident.
- Phishing simulation: quarterly, with role-targeted scenarios for accounting and legal assistants, who are the actual targets in wire-fraud attempts.
- Tabletop exercise: annually, with the managing partner in the room — not delegated to IT.
The seven questions to ask any testing vendor
1. How many hours of manual testing are included, and who performs them? Names and certifications, not a firm brochure. 2. Will the report include reproducible evidence and business-impact narrative, or only CVSS scores? 3. Is a free retest included after remediation, and for how long? 4. Will you sign our confidentiality terms and handle privileged material under an ethical wall? This is non-negotiable for legal work. 5. How do you avoid disruption to matter-critical systems during business hours? 6. Can you produce a client-shareable attestation letter separate from the technical report? You do not want to hand a client your full finding list. 7. Do you test the human layer, the cloud tenant, and the third-party integrations — or only the network perimeter? Most law firm breaches begin in Microsoft 365, not on a firewall.
Common mistakes law firms make
- Buying a pen test to satisfy an insurer, then never remediating. An unremediated finding list is worse than no test at all in litigation — it is documented knowledge of an unaddressed risk.
- Scoping only the corporate website. The marketing site is rarely where privileged data lives. Scope the client portal, the DMS, the VPN, Microsoft 365, and the backup environment.
- Excluding the systems that matter most "to avoid disruption." An untested document management system is exactly the system an attacker targets.
- Treating the report as the deliverable. The deliverable is the closed finding, verified by retest.
- Letting the test expire. Client questionnaires ask for testing within the last 12 months. A 14-month-old report fails the question.
How Attorney Armor helps
Attorney Armor was built for this exact problem. Our free external attack-surface assessment runs the vulnerability-assessment layer against your firm's domain in under two minutes — exposed services, certificate and email-authentication weaknesses, leaked credentials, and misconfigurations an attacker would find first — and returns a graded report written for partners, not just engineers.
From there we run continuous monitoring so new exposures surface the day they appear rather than at next year's audit, and coordinate law-firm-specific penetration testing with testers who work under legal confidentiality terms and deliver both the technical report and the client-shareable attestation letter your matters require. If you need the evidence folder described above, we build and maintain it for you.
Start with the free assessment. If it comes back clean, you have documentation. If it doesn't, you found it before someone else did.
Frequently asked questions
Is a vulnerability scan enough for cyber insurance? At lower limits, often yes. Above roughly $5M in coverage, most 2026 carriers ask specifically for annual third-party penetration testing. Read the application language carefully — the two terms are used precisely.
Can our IT provider run the penetration test? They can run vulnerability assessments. For penetration testing, independence matters: clients and auditors discount a test performed by the same party that built and manages the environment.
How long does a law firm penetration test take end to end? Two to six weeks from kickoff to final report, including scoping, testing, reporting, and remediation retest. Book eight weeks ahead of any client deadline.
Will testing disrupt our practice? Properly scoped, no. Denial-of-service testing is excluded by default, exploitation of production systems is coordinated to off-hours, and the rules of engagement include an immediate stop-work contact.
What do we give a client who asks for our test results? An attestation letter and the executive summary — never the full technical finding list, which is itself a roadmap for an attacker.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


