Ask a managing partner how many applications hold client information and the answer is usually a confident number that turns out to be too low. Practice management, document management, email and billing are obvious. Then come the e-signature tool someone signed up for, the scanner that emails PDFs, the court filing portal, the transcription service, the shared drive an associate set up and the AI assistant a paralegal tries on weekends.
You cannot protect, back up, audit or explain what you have not listed. A software inventory is the least glamorous and most useful security document a firm can own. It supports incident response, client questionnaires, cyber insurance applications, vendor oversight under Model Rule 5.3 and the general habit of technology competence reflected in Comment 8 to Rule 1.1.
What goes in the inventory
For each application, record a handful of fields. More than this and nobody will maintain it.
- Name and vendor.
- Purpose: what the firm uses it for.
- Business owner: the person who decides whether it stays.
- Technical owner: who administers it.
- Data it holds: client files, personal information, financial data, none.
- Hosting: vendor cloud, firm-managed cloud, on-premises.
- Sign-in method: single sign-on, separate login, shared account. Is MFA enforced?
- Users: who has access and how many.
- Contract and renewal date.
- Backup: who backs it up, and how recently was a restore tested?
- Last review date.
How to discover what you have
Start with the obvious
Walk through each practice group and ask what they use daily. Include mobile apps.
Check the money
Review credit card statements, expense reports and accounts payable for software subscriptions. Small recurring charges often reveal unofficial tools.
Check identity logs
If you use Microsoft 365 or another identity provider, review which applications users have signed in to or authorized. Many tools connect through "sign in with" options and appear in these lists.
Ask IT
Your provider can export installed software on managed devices, browser extensions, and network traffic summaries pointing to cloud services.
Look beyond software
Include devices that hold data: scanners and copiers with hard drives, phones, tablets, removable drives and old servers in closets.
Classify by sensitivity
Not all applications deserve equal attention. A simple three-level classification helps.
- High: privileged client documents, trust accounting, personal identifiers, credentials.
- Medium: internal business data without client content.
- Low: public or non-sensitive tools.
Spend the most oversight time on the high group: confirm MFA, review contracts, ask for security reports and test backups.
What the inventory reveals
Once built, patterns appear.
- Duplicates. Three tools doing the same job, two of which could be retired.
- Orphans. Accounts nobody owns, often belonging to former employees.
- Shared logins. Credentials used by several people, making accountability impossible.
- Unprotected systems. High-sensitivity apps without MFA.
- Unknown vendors. Services whose terms the firm never read.
- Expiring support. Software or hardware no longer receiving security updates.
Use it for vendor oversight
For each high-sensitivity vendor, keep a short file: contract, security documentation if available, breach notification terms, data location and an exit plan. When a client asks who handles their data, you will be able to answer in minutes.
Use it for incident response
When something goes wrong, the first questions are "what systems are affected" and "what data lives there." An inventory shortens that discovery from days to minutes. Store a copy offline or somewhere that does not depend on firm systems.
Keep it alive
Inventories decay quickly. Build maintenance into existing routines.
- Procurement rule: no new software that touches client data without adding it to the inventory first.
- Offboarding: check every application on the list when staff depart.
- Quarterly review: the administrator and IT provider walk through changes.
- Annual deep review: retire unused tools, renegotiate contracts and verify security settings.
A simple format
A spreadsheet is fine. Avoid elaborate asset management systems until the habit is established. The point is accuracy and ownership, not sophistication.
Link it to access reviews
Pair the inventory with a periodic review of who can access each high-sensitivity application. Remove those who no longer need it and confirm administrator accounts are limited.
How Counsel Cyber can help
Counsel Cyber builds software and asset inventories for law firms as part of onboarding, including discovery of unofficial tools and review of vendor terms. If you would like help creating a starting inventory, we are happy to assist.