What Bar Association Guidance Requires
ABA Formal Opinion 477R and related state bar guidance require attorneys to make reasonable efforts to prevent unauthorized access to client information, including when using technology. "Reasonable efforts" is context-dependent. A firm handling M&A deals for Fortune 500 companies has a higher obligation than a solo practitioner handling low-stakes matters. But for any firm holding significant client data or facilitating financial transactions, independent security testing is increasingly considered part of reasonable security measures.
Scoping a Law Firm Penetration Test
A penetration test for a law firm typically includes:
- External network assessment — Internet-facing infrastructure, email systems, remote access, and any client portals
- Email and Microsoft 365 security — Configuration of email filtering, MFA enforcement, legacy protocol status, and mail forwarding rules (a common post-compromise persistence mechanism)
- Internal network — Lateral movement from a compromised position, access to matter management systems and document repositories, and access to financial/billing systems
- Social engineering — Phishing and business email compromise scenarios targeting staff who handle wire transfers and financial transactions
Confidentiality and Privilege Considerations
Law firms have legitimate concerns about what information a penetration testing firm will observe during an engagement. Grid32 addresses this directly: we execute an NDA before any engagement begins, our engineers are trained to avoid reading client matter content, we document only what is necessary to demonstrate a finding, and we do not retain client data after the engagement is complete. Many firms find it useful to discuss scope exclusions — specific matter types or data repositories they prefer to exclude — during the engagement kickoff.
Demonstrating Security to Clients
Large corporate clients, financial institution clients, and government clients increasingly ask their law firms about their cybersecurity practices as part of outside counsel due diligence. A Grid32 attestation letter provides documentation that your firm conducts annual independent security testing — a concrete answer to client security questionnaires and due diligence requests that competitors who do not test cannot provide.
Demonstrate your commitment to protecting client data.
Grid32 provides penetration testing and attestation documentation for law firms. Contact us to discuss your firm's specific needs.
Talk to an Expert →