Go Back Up
29% of law firms have experienced a security breach, according to the American Bar Association's Legal Technology Survey.
ABA TechReport

of law firms have experienced a security breach, according to the American Bar Association's Legal Technology Survey.
ABA TechReport

4.44MM is the global average cost of a data breach, before factoring in lost clients, malpractice exposure, and unbillable recovery time.
IBM

is the global average cost of a data breach, before factoring in lost clients, malpractice exposure, and unbillable recovery time.
IBM

1,147 confirmed data disclosures hit professional services organizations in 2024, making the sector a proven target, not a theoretical one.
Verizon

confirmed data disclosures hit professional services organizations in 2024, making the sector a proven target, not a theoretical one.
Verizon


Why This Partner-Level Checklist Exists

Law firms run on deadlines, client trust, and uninterrupted access to matter information. A single breach threatens all three at once. Corporate clients now send security questionnaires before they send matters, cyber insurance underwriters ask harder questions every renewal, and the ABA Model Rules make reasonable security efforts an ethical obligation, not a preference.

This checklist gives firm leadership a strategic view of the security posture clients, regulators, and insurers now expect. Think of it as a record of where your firm stands on the questions that decide whether you keep the clients you have and win the ones you want, rather than just an IT Audit.

You Sign The Engagement Letters

You are the partner accountable for client confidentiality, ethical compliance, and the firm's reputation. When a client asks whether their data is safe, the answer lands on your desk.

Clients Are Asking Hard Questions

Outside counsel guidelines and security questionnaires now arrive before the work does. Corporate clients expect documented proof, not verbal assurance.

Privilege Is Your Product

Privileged communications, deal documents, discovery data, and client IP are the firm's. A breach puts client trust and decades of relationship equity at risk in a single afternoon.

Insurance And Malpractice Exposure Worry You

Your cyber insurance renewal asks about MFA, endpoint detection, and incident response. Answering wrong risks a denied claim exactly when you need coverage most.

You Want To Control Costs

You need to meet client and ethical obligations without over-engineering the firm's technology or ballooning overhead that partners feel in their draws.


The Checklist

Five Phases To A Defensible Security Posture

Work through each phase in order. Your progress feeds the saved report you can email yourself at the end. Every item you cannot check is a conversation your firm should have before a client, auditor, or underwriter forces it.
01

Phase 01: Map Privileged Data & Firm Obligations

Before spending a dollar on tools, define what you are protecting and what you are obligated to protect. Firms that skip this phase either overspend on systems that never touch client data or leave privileged information sitting outside every safeguard.

Checklist 0 out of 5

02

Phase 02: Measure The Gaps

You cannot fix what you have not measured. This phase determines the distance between your current environment and what clients, insurers, and bar regulators expect a firm your size to have in place.

Checklist 0 out of 5

03

Phase 03: Documentation & Governance

In a client audit or regulatory inquiry, if it is not documented, it did not happen. This phase builds the evidence your firm needs to answer questionnaires with confidence instead of caveats.

Checklist 0 out of 5

04

Phase 04: Technical Safeguards

Deploy the controls that protect privileged data in practice. These are the safeguards clients ask about by name, and underwriters treat as table stakes for coverage.

Checklist 0 out of 5

05

Phase 05: Culture & Readiness

Security is not an IT project. It is a professional responsibility discipline that has to survive busy season, trial prep, and the partner who never reads firm-wide emails.

Checklist 0 out of 5

Need A Next Step?

Turn Checklist Answers Into a Starting Point

Not ready to talk yet, but need more direction? If the checklist raises questions about ABA obligations, client questionnaires, or where to prioritize first, explore how Compass approaches cybersecurity and advisory for firms that handle privileged data.

Save Your Results

Want a Clear Record Of Where Your Firm Stands?

You have captured where your firm stands on the questions clients, insurers, and bar regulators are already asking. We will email you a private link to this page with your answers saved so that you can return to it before client audits, insurance renewals, and partner meetings.

Think of it as your firm's standing security position of record. No sales call required to get it.

Email My Checklist Results
industry-legal

After The Checklist

From Readiness To Resilience

A readiness checklist only matters if it leads to a defensible security program. CompassMSP brings managed IT, cybersecurity, compliance support, and strategic advisory together for law firms that need clarity and forward motion without disrupting billable work or inflating overhead.

We map your obligations, measure gaps against the frameworks clients and insurers reference, and execute remediation with audit readiness in mind. The work stays focused on what affects client trust, privilege protection, and revenue, not unnecessary tooling. While we handle the technical and governance workload, your attorneys stay focused on clients and deadlines.

FAQs

Answers To Your Questions About Law Firm Cybersecurity Readiness

For law firms, cybersecurity has moved from an IT line item to a matter of professional responsibility, client retention, and insurability. These answers address the questions managing partners and firm administrators raise most often when working through a security readiness checklist.

Why Are Law Firms A Prime Target For Cyberattacks?

Law firms concentrate exactly what attackers want in one place: privileged communications, deal terms, litigation strategy, intellectual property, financial records, and personal information for high-value clients. A single firm breach can expose sensitive data for hundreds of client organizations at once, which makes firms a more efficient target than attacking each client individually. Verizon's Data Breach Investigations Report confirmed 1,147 data disclosures across professional services organizations in 2024 alone. [source https://www.verizon.com/business/resources/reports/dbir/]

Attackers also know that firms run on deadlines. A ransomware event during trial prep or a closing creates pressure to pay that most businesses never face. That combination of concentrated data and time pressure is why security readiness is a business continuity issue for firms, not just a technology concern.

What Do The ABA Model Rules Require For Law Firm Cybersecurity?

ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Comment 8 to Rule 1.1 extends the duty of competence to the benefits and risks of relevant technology. Together, these provisions make security a professional responsibility obligation, and most state bars have adopted comparable requirements. [source https://www.americanbar.org/groups/professional_responsibility/publications/model_rules_of_professional_conduct/]

ABA Formal Opinion 483 goes further, outlining a lawyer's obligations to monitor for breaches, stop them, restore systems, and notify affected clients when a breach involves material client information. What counts as reasonable scales with the sensitivity of the data and the resources of the firm, which is why documenting your security decisions matters as much as making them. A firm that can show a deliberate, risk-based program is in a fundamentally different position than one that cannot.

What Happens If A Law Firm Experiences A Data Breach?

The immediate impact is operational: systems locked, matters stalled, deadlines at risk, and attorneys unable to bill. The obligations start almost as quickly. Depending on the data involved, the firm may face breach notification duties under state law, contractual notification requirements in outside counsel guidelines, and the ethical notification duties described in ABA Formal Opinion 483. Firms handling protected health information or consumer financial data may trigger HIPAA or FTC Safeguards Rule obligations on top of that.

The longer-term damage is reputational and financial. Clients that trusted the firm with privileged information reassess that trust, corporate clients may be required by their own policies to move work, and malpractice exposure enters the picture if the breach traces back to safeguards a reasonable firm would have had. Preparing the incident response plan, notification map, and recovery capability before an incident is far less expensive than improvising one during it.

How Much Does A Data Breach Cost A Law Firm?

IBM's Cost of a Data Breach research puts the global average at $4.44 million, covering detection, response, notification, and lost business. [source https://www.ibm.com/reports/data-breach] For a law firm, the headline number understates the real exposure, because it does not capture what is unique to legal practice: unbillable recovery time across the entire attorney roster, blown deadlines with court and client consequences, and matters that leave the firm and do not come back.

The more useful way for a partnership to think about cost is in billable terms. If an incident takes systems down for even a few days, multiply the firm's daily billings by the outage and add remediation, counsel, notification, and increased insurance costs. That math is usually what turns security from a deferred expense into a funded priority.

What Cybersecurity Controls Do Corporate Clients Expect From Outside Counsel?

Corporate clients increasingly hold their law firms to the same vendor security standards they apply to any supplier with access to sensitive data. Outside counsel guidelines and security questionnaires commonly require multi-factor authentication, endpoint detection and response, encryption at rest and in transit, documented incident response plans, security awareness training, vendor management, and evidence of independent assessment against a framework such as the NIST Cybersecurity Framework. [source https://www.nist.gov/cyberframework]

The practical consequence is that security posture now affects business development, not just risk. Firms that can answer questionnaires quickly with organized evidence win and keep institutional clients. Firms that answer with caveats invite follow-up audits or lose the work entirely. Maintaining a current evidence file, as this checklist recommends, turns the questionnaire from a fire drill into an administrative task.

Do Small And Midsize Firms Need The Same Security As Large Firms?

The threats do not scale down with headcount. Attackers automate their targeting, and smaller firms often hold data every bit as sensitive as large firms while running thinner defenses. The ABA's Legal Technology Survey shows breaches reported across firms of every size, and smaller organizations frequently face a higher volume of social engineering attempts precisely because attackers expect weaker controls. [source https://www.americanbar.org/groups/law_practice/resources/tech-report/]

What does scale is the implementation. A 20-attorney firm does not need a large firm's security department. It needs the same core controls, MFA, endpoint detection, hardened email, tested backups, and an incident response plan, delivered in a right-sized way, often through a managed provider and fractional security leadership rather than internal hires. The ethical obligations under the Model Rules apply regardless of firm size.

How Do Cyber Insurance Requirements Affect Law Firms?

Underwriters have shifted from asking whether a firm has security to verifying specific controls before binding coverage. Applications now routinely require MFA on email and remote access, endpoint detection and response, offline or immutable backups, and security awareness training. Firms that cannot attest to these controls face higher premiums, coverage exclusions, or declined applications.

The greater risk sits on the claims side. If an application overstates the firm's controls and a breach reveals the gap, the insurer may deny the claim or rescind the policy at the moment the firm most needs it. That is why this checklist pairs the insurance question with verification: compare what the application says with what is actually deployed, and close any gap in the controls or correct the answers before renewal.

Can A Data Breach Compromise Attorney-Client Privilege?

A breach does not automatically waive privilege, since waiver generally turns on voluntary disclosure rather than theft. But the surrounding questions are uncomfortable ones. Opposing parties may probe whether the firm took reasonable precautions, clients may demand accounting of exactly what was exposed, and courts weigh the reasonableness of protective measures in disputes over inadvertently disclosed material. The safer position, ethically and practically, is a documented program of reasonable safeguards.

Protecting privilege in practice means securing everywhere privileged communications live: email, the document management system, client portals, mobile devices, and backups. Matter-level access controls and ethical wall enforcement matter here too, because privilege protection includes limiting access inside the firm to the matter team, not just keeping outsiders out.

What Is A vCISO, and Does A Law Firm Need One?

A vCISO, or virtual chief information security officer, provides senior security leadership on a fractional basis. For a law firm, that means someone who owns the security roadmap, interprets obligations under the Model Rules and client contracts, answers security questionnaires with authority, prioritizes remediation by risk, and reports to the partnership in business terms rather than technical ones.

Most internal legal IT teams are excellent at keeping attorneys working, but security program leadership is a different skill set, and a full-time hire is rarely economical below a certain firm size. A vCISO closes that gap: the firm gets executive-level security judgment and audit-ready documentation at a fraction of the cost of a dedicated executive. Explore vCISO & Security Advisory to see how Compass structures the role for firms.

What Are The Most Common Security Gaps In Law Firms?

The same gaps appear across firms of every size: MFA deployed on email but missing from the document management system or remote access; endpoint protection installed but nobody monitoring alerts after hours; backups running but never test-restored; and incident response plans that exist as documents no one has rehearsed. Each looks minor in isolation. Together they are the difference between an incident and a crisis.

The other recurring gap is evidentiary. Firms often have more security in place than they can prove, because policies, training records, and assessment results were never organized into a usable evidence file. That gap costs real money when a client audit or insurance renewal arrives, which is why documentation gets its own phase in this checklist rather than a footnote.

How Long Does It Take A Law Firm To Become Audit Ready?

For most small and midsize firms, moving from an honest gap assessment to a defensible, documented security posture takes three to six months. The technical controls, MFA, endpoint detection, email hardening, and backup validation, typically deploy within the first several weeks. The longer arc is governance: writing policies leadership will actually sign, mapping notification obligations, training staff, and accumulating the running evidence that controls are operating.

Firms with pending client audits or imminent insurance renewals can compress the timeline by prioritizing the controls those specific reviews test. The mistake to avoid is rushing to answer a questionnaire affirmatively before controls are truly in place. Start from where the checklist says you actually stand, and sequence the work from there.

What Is The First Step If Our Firm Wants To Move Forward?

Start with a formal security risk assessment. It converts this checklist's directional answers into a measured baseline: which controls exist, which are partial, where privileged data is exposed, and how the firm scores against the framework its clients and insurers reference. The output is a prioritized remediation plan the partnership can budget against, ordered by impact on client confidentiality, matter continuity, and insurability.

From there, most firms address the highest-risk technical gaps first, then build the documentation and governance layer, then move to an ongoing management rhythm of monitoring, training, and annual review. Compass supports each stage, from the initial assessment through managed cybersecurity and advisory, so the firm's attorneys stay focused on clients while readiness becomes a maintained state instead of a recurring project.

Featured Resources

Keep Your Firm Sharp. Keep Your Clients Confident.

Explore expert insights, practical tips, and real-world advice from our blog curated to help you make smarter tech decisions.
Small Firm, Same Standard: The National Cybersecurity Reckoning No Legal Practice Can Outrun

Legal Articles 4 min read

Small Firm, Same Standard: The National Cybersecurity Reckoning No Legal Practice Can Outrun

As state bars, federal regulators, and corporate clients eliminate the size-based sliding scale for security, smaller and mid-sized law firms face a disproportionate burden to meet identical, national cybersecurity compliance standards in 2026.
The Verdict: Chimpoulis & Hunter Stays Protected and Productive with Outsourced IT

Cybersecurity IT Modernization Legal Case Studies

The Verdict: Chimpoulis & Hunter Stays Protected and Productive with Outsourced IT

Discover how Chimpoulis & Hunter improved productivity and cybersecurity by partnering with CompassMSP for managed IT services, ensuring uninterrupted legal operations and data protection.
Attorney Client Privilege and Legal IT 2026 Guide

Cybersecurity Legal Articles 11 min read

Attorney Client Privilege and Legal IT 2026 Guide

Learn how law firms can evaluate managed IT services to protect attorney-client privilege, ensure ABA compliance, and maintain 24/7 uptime in 2026.
Request a Conversation

Talk It Through

Let's Talk Through Your Firm's Security Path

Submit the form to review your checklist results with a security advisor who works with law firms, and understand what a defensible posture will actually require for a firm your size. Here is what happens next:

Ready to secure your future? Here is what happens next:

  • Discovery
    We schedule a brief call to understand your pain points.

  • Assessment
    We review your current infrastructure and security posture.

  • Roadmap
    We present a right-sized plan to modernize and secure your business.

 

Not ready for a conversation? Email yourself the checklist and come back when the timing is right.

Next Section