July is a good time to look at your firm's security with fresh eyes. The year's busiest filing deadlines are often behind you, summer schedules loosen up, and there is still enough runway to fix problems before year-end renewals, client audits and cyber-insurance applications arrive.
This checklist is written for firm administrators and managing partners, not for engineers. Each item can be verified in an afternoon or less, and each one closes a gap that attackers routinely use against small and mid-size firms.
Accounts and Access
Most law firm breaches start with a stolen or guessed password. Start here.
- Confirm multi-factor authentication is on for everyone. That includes Microsoft 365, your practice-management platform, your document management system, remote access and any e-filing or banking portals that support it. Do not forget partners and assistants who were "exempted" years ago.
- Review administrator accounts. List everyone with admin rights. Most firms find former vendors, old IT contacts or staff who changed roles.
- Disable accounts for departed staff. Compare your HR roster against active user lists in every system, not just email.
- Check shared mailboxes and generic logins. Shared passwords make it impossible to say who did what.
Devices and Software
- Check that every laptop and workstation is patched. Ask for a report showing the last update date per device. Anything that has not updated in a month deserves a conversation.
- Verify disk encryption. A lost laptop is a reportable event if the data is readable, and a non-event if it is encrypted.
- Retire unsupported systems. Old operating systems and abandoned printers or scanners with network access are common footholds.
- Confirm endpoint protection is actually reporting. Software that is installed but silent is not protecting anyone.
Email and Messaging
Email remains the front door for phishing, invoice fraud and wire-transfer scams.
- Confirm your email platform filters attachments and links, and that suspicious messages can be reported with one click.
- Make sure external email is visibly tagged so staff notice when a message did not come from inside the firm.
- Check that your domain publishes SPF, DKIM and DMARC records, and that DMARC is moving toward enforcement rather than sitting in monitor-only mode forever.
- Write down your wire-transfer verification rule: no change to payment instructions is honored without a call to a known phone number.
Backups and Recovery
- Confirm backups ran successfully this week, for every system that holds client data.
- Verify at least one copy is isolated from your main network so ransomware cannot encrypt it.
- Schedule a test restore. A backup you have never restored is a hope, not a plan.
- Write down how long the firm could operate without its case or document system. That number drives your recovery targets.
People and Habits
Technology fails when habits do not support it.
- Run a short refresher on phishing and fraud for all staff, including attorneys. Fifteen minutes with real examples beats an annual hour-long video.
- Make reporting easy and blame-free. The employee who clicks and immediately tells someone is your best outcome.
- Remind new and returning staff, such as summer clerks, of the acceptable-use rules before they get access.
Vendors and Data
Your exposure includes every outside service that touches client information.
- List your key vendors: practice management, document storage, e-discovery, court reporters, billing and payroll.
- Ask each how they protect your data and how they would notify you of an incident.
- Remove integrations and apps nobody uses any more.
Incident Readiness
If something happens on a Friday afternoon, who does what?
- Keep a one-page contact list: IT provider, cyber-insurance hotline, outside counsel, key partners.
- Decide who has authority to take systems offline.
- Keep a printed copy, since email may be unavailable during an incident.
- Remember that the ABA's Formal Opinion 483 addresses lawyers' obligations after a data breach, so it is worth knowing what your state bar expects before you need it.
Putting It to Work
Do not try to finish everything in a week. Pick the three items that feel weakest, assign an owner and a date, and revisit the list in September. Progress you can document is also useful when a client or insurer asks what you do to protect information.
Counsel Cyber works with law firms across Texas, Arkansas, Louisiana, Oklahoma and Kansas. If you would like a second set of eyes on this list, we are happy to walk through it with you and show you where your firm stands.