ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ten Quick Security Checks a Law Firm Can Run This Week

A short checklist of ten low-cost security checks that firm administrators can complete in a few days to find the most common weaknesses in a law office.

3 min readBy Counsel Cyber Team

Not every security improvement needs a project plan and a budget line. Some of the most valuable work a law firm can do is a quick review of the basics, the kind of review that takes an administrator and an IT contact a few days and often turns up problems nobody knew existed.

This checklist is deliberately practical. Each item can be checked in an hour or less, and each one addresses a weakness that attackers routinely exploit against small and mid-size professional services firms.

The Ten Checks

1. Confirm MFA on email for every account

Multi-factor authentication on Microsoft 365 or Google Workspace is the single most effective control against stolen passwords. Do not rely on a policy statement. Ask your IT provider for a report listing every user and whether MFA is enforced. Look for exceptions: shared mailboxes, old accounts, service accounts, and the managing partner who asked to be excluded because it was inconvenient.

2. List who has admin rights

Find every person with administrator privileges on email, the network, and your practice management and document systems. Most small firms discover more admins than expected. Remove admin rights from anyone who does not need them day to day, and give administrators a separate account for admin tasks.

3. Disable accounts for departed staff

Compare your current staff list to your active user accounts. Departed employees, summer clerks, and former contractors often keep working logins for months. Disable them, then add account removal to your offboarding checklist.

4. Check forwarding rules in mailboxes

Attackers who compromise an account frequently create a hidden rule that forwards or deletes certain messages. Ask your IT provider to review mailbox rules and external forwarding across the firm. Any rule forwarding mail to an outside address deserves an explanation.

5. Verify backups actually restore

A backup job that reports success is not proof that you can restore. Pick a handful of files, including something from your document management system, and have them restored to a test location. Note how long it took. If no one can say when the last test was done, schedule one.

6. Review patch status

Ask for a report showing which computers and servers are missing security updates, and how old the oldest missing update is. Also look for devices running operating systems the vendor no longer supports. Those need a replacement plan.

7. Find your remote access points

List every way someone can reach your network or data from outside the office: VPN, remote desktop, remote support tools, vendor access. Any remote desktop service exposed directly to the internet is a serious concern and should be reviewed immediately.

8. Test one phishing scenario

Send a harmless simulated phishing message to staff, or at least review whether your email filtering catches common impersonation attempts. The goal is not to catch people out; it is to learn where training should focus.

9. Check the wire-transfer process

Read the firm's actual procedure for wiring funds from trust or operating accounts. Does it require a call-back to a known phone number before any new or changed wire instructions are acted on? Is it followed under deadline pressure? The FBI's Internet Crime Complaint Center has consistently identified business email compromise as a major source of financial loss, and law firms handling closings and settlements are natural targets.

10. Read your incident contact list

Open the document that says who to call if something goes wrong. Check that the phone numbers work, that your cyber insurance carrier's reporting line is on the list, and that someone besides the IT person knows where it is.

What to Do With the Results

Do not try to fix everything at once. Sort what you find into three groups:

  • Fix now: exposed remote access, missing MFA, active accounts for departed users
  • Fix this quarter: patch gaps, unsupported systems, admin cleanup
  • Plan and budget: replacement hardware, new monitoring tools, formal training programs

Write down what you found and the date. That record is useful later, whether for a client questionnaire, a cyber insurance renewal, or simply to show progress over time.

Why This Matters for Competence

ABA Model Rule 1.1, Comment 8, says lawyers should keep abreast of the benefits and risks associated with relevant technology. Checking the basics regularly is a reasonable, concrete way to show that attention. Confirm with your state bar how your jurisdiction applies the rule.

Where Counsel Cyber Fits

If you would rather not run these checks alone, Counsel Cyber can perform them as a short security review and return a prioritized list of fixes written for a firm administrator, not an engineer.