AttorneyArmor
Back
SAMPLE REPORT · Illustrative content prepared for a fictional firm. All names, domains and findings are redacted or fabricated for demonstration.

Confidential — Attorney Work Product

Cyber Risk Assessment

Cole & Whitman LLP  ·  Q2 2026 Quarterly Briefing

Report ID: AA-2026-Q2-0418
Scan window: Apr 1 – Jun 15, 2026
Prepared by: AttorneyArmor SOC

AttorneyArmor Score

76

out of 100

+8 vs. prior quarter

Finding Distribution

2
Critical
2
High
2
Medium
1
Low

The firm's posture improved meaningfully this quarter following remediation of nine prior-period findings. Two newly discovered critical exposures require action inside 24 hours to remain in policy with cyber-insurance underwriter Beazley.

Executive Summary

Cole & Whitman's external attack surface remains in line with comparable AmLaw 200 practices, with notable strength in endpoint detection coverage and outbound email authentication for the primary domain. The firm continues to benefit from the 2025 migration to Microsoft 365 E5 and the deployment of conditional access for the litigation group.

Two findings classified as critical require partner-level attention this week. The first — an exposed Exchange admin portal without enforced MFA — would, if exploited, provide a quiet path into mailboxes belonging to the M&A practice. The second concerns an inadvertently public file share containing material from active discovery. Both are remediable within a single business day and do not require capital expenditure.

We recommend the firm prioritize three workstreams over the next 30 days: (1) emergency remediation of the two critical findings, (2) escalation of DMARC enforcement to p=reject, and (3) closure of the identity-lifecycle gap created by the manual offboarding process. Completion of these three items will move the AttorneyArmor Score from 76 to a projected 88.

Attack Surface Inventory

Assets discovered through passive reconnaissance, certificate transparency logs, and authenticated tenant introspection.

+3 this quarter
47
Domains & Subdomains
-12 from prior scan
128
Exposed Services
no change
19
Email Endpoints
+5 this quarter
34
Cloud Storage Buckets
+2 this quarter
22
Third-Party Integrations
3 expiring < 30 days
61
TLS Certificates

Prioritized Findings

Each finding is written for partner-level consumption with a defensible remediation path and contractual SLA.

Critical·#001

Exposed Microsoft Exchange admin portal (OWA) without MFA enforcement

SLA: 24 hours

Affected Asset

mail.[REDACTED].com

Reference

CVE-2024-21410

Business Impact

Privileged credential theft enabling silent mailbox access for partners handling M&A deal flow. Direct violation of ABA Formal Opinion 477R.

Recommended Remediation

Enforce conditional access requiring MFA + compliant device for all OWA/ECP endpoints. Restrict /ecp to internal IP space within 24 hours.

Critical·#002

Litigation file share indexed by public search engines

SLA: 24 hours

Affected Asset

files.[REDACTED].com/discovery/

Reference

Misconfiguration — directory listing enabled

Business Impact

1,247 documents from active matters discoverable via Google dorking. Includes deposition transcripts, expert reports, and protective-order material.

Recommended Remediation

Disable autoindex, add X-Robots-Tag: noindex, rotate any pre-signed URLs, and submit Google Search Console removal requests.

High·#003

Legacy Citrix NetScaler running unpatched firmware

SLA: 7 days

Affected Asset

remote.[REDACTED].com

Reference

CVE-2023-4966 (CitrixBleed)

Business Impact

Session-token leakage allows attackers to hijack authenticated remote-desktop sessions for attorneys working from co-counsel offices.

Recommended Remediation

Upgrade NetScaler to 14.1-21.57 build or later. Invalidate all active sessions post-upgrade and rotate ICA credentials.

High·#004

DMARC policy set to p=none — domain spoofable

SLA: 7 days

Affected Asset

[REDACTED].com (root domain)

Reference

Email authentication misconfiguration

Business Impact

Threat actors can spoof partner-level senders. Past 30 days: 14 phishing attempts impersonating the managing partner caught by external filters.

Recommended Remediation

Stage DMARC to p=quarantine for 14 days, then escalate to p=reject with rua/ruf forensic reporting enabled.

Medium·#005

Three former employee accounts retain VPN access

SLA: 14 days

Affected Asset

Azure AD tenant

Reference

Identity lifecycle gap

Business Impact

Offboarded associates (departed 47–112 days ago) still hold valid VPN certificates. Violates SOC 2 CC6.2 access deprovisioning.

Recommended Remediation

Revoke certificates, disable accounts, and enable HR-system-triggered automated offboarding via SCIM provisioning.

Medium·#006

Client portal accepts weak passwords (8 chars, no complexity)

SLA: 30 days

Affected Asset

portal.[REDACTED].com

Reference

Authentication weakness

Business Impact

Brute-force feasible against client logins. 22 portal accounts currently use passwords appearing in HaveIBeenPwned breach corpus.

Recommended Remediation

Raise minimum to 14 characters, screen against breached-password API, and offer SSO via clients' own identity providers.

Low·#007

Server banner discloses software version on marketing site

SLA: 60 days

Affected Asset

www.[REDACTED].com

Reference

Information disclosure

Business Impact

Reconnaissance accelerant. Reduces attacker effort to identify exploitable versions of nginx and WordPress.

Recommended Remediation

Set server_tokens off in nginx; remove generator meta tag from WordPress theme.

Compliance Posture

Mapped to the frameworks your underwriters and clients ask about.

FrameworkStatusScore
ABA Model Rule 1.6At Risk
78
SOC 2 Type II — CC6 (Access)At Risk
71
NIST CSF 2.0Compliant
86
GDPR Art. 32 (Security of Processing)Compliant
89
NY DFS 23 NYCRR 500At Risk
74

90-Day Trend

AttorneyArmor Score has improved by 18 points since the firm engaged in January.

Open Findings

Critical2 open
High2 open
Medium2 open
Low1 open

9 findings closed this quarter, 7 newly identified.

See your firm's report

A complimentary baseline assessment takes 12 minutes and produces a redacted preview of the report above, scoped to your domains.

Run my free assessment

© 2026 AttorneyArmor, Inc. Sample report for demonstration only. Confidential and prepared as attorney work product when delivered to a client firm.