ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Year-End Security Review: A Twelve-Point Checklist for Law Firms

The quiet days at year-end are a good time to review security. Work through this twelve-point checklist and start the new year with fewer open risks.

3 min readBy Counsel Cyber Team

The week between Christmas and New Year's is quieter for most firms. Court calendars thin out, phones ring less and partners find time to think. It is a good moment for a deliberate security review, before the new year's matters, hires and deadlines crowd it out.

This twelve-point checklist is designed for a managing partner or administrator working with an IT provider. Each item can be answered with a quick yes or no, and each no becomes a task.

Accounts and Access

1. Is multi-factor authentication enforced for every user and every key system?

Check email, remote access, document management, practice management, billing and administrative consoles. Look for exceptions and end them.

2. Have you reviewed who has access to what?

Pull a list of active accounts and compare it to your current staff. Remove former employees, inactive accounts and unneeded administrator rights. Confirm that ethical walls are enforced in system permissions.

3. Do any shared logins still exist?

Shared accounts make it impossible to know who did what. Replace them with individual accounts, or with managed shared mailboxes where appropriate.

Devices and Systems

4. Are all devices encrypted, patched and protected?

Confirm laptops have disk encryption, operating systems and applications are updated and endpoint protection is reporting. Identify any hardware or software that has reached end of support.

5. Is someone actually monitoring for threats?

Installed tools are not the same as monitored tools. Confirm who receives alerts, how quickly they respond and what happens after hours.

Data Protection

6. Have you tested a restore recently?

Ask for the date and result of the last test. If there has been none, schedule one. Confirm at least one backup copy is offline or immutable.

7. Do you know where your client data lives?

Update the technology inventory, including cloud tools that lawyers adopted on their own. Unknown systems are unprotected systems.

Email and Fraud

8. Are your wire and payment-change procedures written and followed?

Confirm callback verification, dual approval for outgoing wires and clear warnings to clients. Review any exceptions that were made during the year.

9. Is email security configured properly?

Review filtering, external sender banners, forwarding rules and domain authentication settings.

People and Planning

10. Did everyone complete security awareness training this year?

Record completion, and plan next year's schedule. Include partners. Consider a simulated phishing exercise to measure progress.

11. Is the incident response plan current?

Check the contact list for changes in staff, providers and insurers. Confirm the cyber-insurance carrier's hotline number is in the plan. Hold a short tabletop discussion if you have not done one this year.

12. Have vendors been reviewed?

List vendors with access to client data or firm systems. Confirm that contracts, confidentiality terms and security practices have been reviewed. Remove vendors you no longer use.

Turning the Checklist Into Action

  1. Score yourself. Mark each item yes, partly or no.
  2. Rank the gaps by potential impact and effort. MFA exceptions and untested backups generally rank near the top.
  3. Assign an owner and a date for each fix.
  4. Report to partners with a one-page summary. Partners benefit from seeing risks in plain language.
  5. Schedule the next review for mid-year.

Document the Results

Keep a record of the review and the actions taken. It supports answers on cyber-insurance renewals and client security questionnaires. It also demonstrates the sort of reasonable, ongoing attention discussed in ABA Model Rule 1.1 Comment 8 and Rule 1.6(c). Confirm any state-specific expectations with your bar.

Include a Look at Next Year's Budget

Use the findings to inform budget requests. Aging hardware, license upgrades for stronger security features and training are easier to justify when tied to specific gaps.

Common Trouble Spots

  • MFA exceptions granted "temporarily" and forgotten.
  • Backups that report success but have never been restored.
  • Former employees' accounts left active.
  • Unsupported systems running because "they still work."
  • Training that covers staff but skips partners.

How Counsel Cyber Helps

Counsel Cyber offers law firm security reviews built around checklists like this one, with a plain-English report and prioritized fixes. If you would like help scoring your firm, we can walk through it together.