What Bar Association Guidance Requires

ABA Formal Opinion 477R and related state bar guidance require attorneys to make reasonable efforts to prevent unauthorized access to client information, including when using technology. "Reasonable efforts" is context-dependent. A firm handling M&A deals for Fortune 500 companies has a higher obligation than a solo practitioner handling low-stakes matters. But for any firm holding significant client data or facilitating financial transactions, independent security testing is increasingly considered part of reasonable security measures.

Scoping a Law Firm Penetration Test

A penetration test for a law firm typically includes:

  • External network assessment: Internet-facing infrastructure, email systems, remote access, and any client portals
  • Email and Microsoft 365 security: Configuration of email filtering, MFA enforcement, legacy protocol status, and mail forwarding rules (a common post-compromise persistence mechanism)
  • Internal network: Lateral movement from a compromised position, access to matter management systems and document repositories, and access to financial/billing systems
  • Social engineering: Phishing and business email compromise scenarios targeting staff who handle wire transfers and financial transactions

Confidentiality and Privilege Considerations

Law firms have legitimate concerns about what information a penetration testing firm will observe during an engagement. Grid32 addresses this directly: we execute an NDA before any engagement begins, our engineers are trained to avoid reading client matter content, we document only what is necessary to demonstrate a finding, and we do not retain client data after the engagement is complete. Many firms find it useful to discuss scope exclusions, specific matter types or data repositories they prefer to exclude, during the engagement kickoff.

Demonstrating Security to Clients

Large corporate clients, financial institution clients, and government clients increasingly ask their law firms about their cybersecurity practices as part of outside counsel due diligence. A Grid32 attestation letter provides documentation that your firm conducts annual independent security testing, a concrete answer to client security questionnaires and due diligence requests that competitors who do not test cannot provide.

Law Firm Penetration Test Scope

AreaWhat is tested
External networkInternet-facing systems, email gateways, remote access, client portals
Email and Microsoft 365MFA enforcement, filtering, legacy protocols, forwarding rules
Internal networkPaths to matter management, document repositories, and billing systems
Social engineeringPhishing and wire-fraud impersonation against staff

Wire Transfer Fraud: The Threat Testing Targets

The single most damaging attack against law firms is business email compromise, where an attacker compromises or spoofs firm email to redirect a real estate or settlement wire. A social engineering assessment measures whether staff verify payment changes and whether out-of-band call-back procedures actually hold under pressure. Pairing that with email and Microsoft 365 hardening closes the gap attackers exploit. For the broader risk picture, see cybersecurity for law firms.

Frequently Asked Questions

What does bar association guidance require for law firm security?

Bar guidance and professional conduct rules require attorneys to take reasonable measures to protect client information and communications. Independent penetration testing helps demonstrate that a firm meets that reasonable-security standard.

How is a law firm penetration test scoped?

Scope commonly covers external and internal networks, email and remote access, and often a phishing assessment, with careful handling of privileged and confidential material. Testing focuses on the paths that would expose client data or enable wire fraud.

How does testing help law firms demonstrate security to clients?

Corporate clients increasingly send security questionnaires before sharing sensitive matters. A current penetration test and attestation let a firm answer those questions credibly and win work that requires proven security.

Demonstrate your commitment to protecting client data.

Grid32 provides penetration testing and attestation documentation for law firms. Contact us to discuss your firm's specific needs.

Talk to an Expert →