We Audited a 50-Person Law Firm's IT — Here's What We Found
Geek Heros War Stories
"We're Fine — Nothing Has Gone Wrong"
Those are the six most dangerous words in law firm IT. The managing partner of a 50-person firm — 20 attorneys, 30 support staff — said them to me during our initial consultation. His reasoning was simple: no breaches, no major outages, no complaints from attorneys. The IT was "fine."
He agreed to let us conduct a comprehensive assessment anyway — partly because his cyber insurance carrier had started asking uncomfortable questions during the renewal process, and partly because a colleague at another firm had recently been hit with ransomware. "Just to be safe," he said.
What we found was not fine. It was a ticking time bomb.
Finding #1: No MFA on Email Accounts
Not one email account at the firm had multi-factor authentication enabled. Not the managing partner's. Not the bookkeeper's. Not the account with access to the firm's IOLTA trust accounts. Every single account was protected by nothing more than a password.
We checked the passwords against known breach databases. Eleven accounts — including three attorney accounts and the main firm administrator account — were using passwords that had been exposed in previous data breaches. This means that anyone with access to commonly available breach databases (which are freely circulating on the dark web) could potentially log into those accounts right now.
The fix: Enable MFA on every account within 48 hours. No exceptions. We deployed Microsoft Authenticator across the firm and transitioned from SMS-based verification (which is vulnerable to SIM swapping) to app-based authentication.
Finding #2: Firewall Firmware 3 Years Out of Date
The firm's firewall — the device that controls all traffic between their internal network and the internet — was running firmware from 2023. In cybersecurity terms, this is ancient. Three years of security patches, vulnerability fixes, and feature updates had never been applied.
We checked the CVE (Common Vulnerabilities and Exposures) database for known vulnerabilities in that firmware version. There were fourteen documented vulnerabilities, including three rated "Critical" — meaning an attacker could potentially exploit them remotely to gain access to the firm's network without any credentials at all.
The firm's previous IT provider — a solo practitioner who also serviced dental offices and real estate agencies — had set up the firewall when it was new and never touched it again. No firmware updates, no configuration reviews, no security audits. Set it and forget it.
The fix: Immediate firmware update to the latest stable version, followed by a complete configuration review. We also implemented automated firmware monitoring to alert us when new updates are available.
Finding #3: Personal Gmail for Client Communication
Four attorneys at the firm were routinely using personal Gmail accounts to communicate with clients about case matters. Their reasoning varied: "It's easier on my phone," "I've always done it this way," "The firm email is too slow."
The implications are staggering. Personal Gmail accounts are outside the firm's security controls, backup systems, and retention policies. They're not covered by the firm's cyber insurance. If a personal Gmail account is compromised, the firm has no way to detect it, contain it, or assess the damage. And from an ethics perspective, communicating about client matters through unsecured personal email accounts is a textbook violation of the duty to protect client confidentiality.
We also discovered that one of these attorneys had forwarded over 2,000 client emails from the firm account to his personal Gmail "as a backup." Those emails — containing privileged communications, financial records, and personal information — were now sitting in an account with no MFA, no encryption, and no firm oversight.
The fix: Immediate policy implementation prohibiting personal email for firm business. We configured mobile device management to give attorneys secure, fast access to firm email on their phones. The attorney who had forwarded 2,000 emails worked with us to delete them from his personal account and verified the deletion.
Finding #4: No Written Incident Response Plan
When we asked the office manager what the firm would do if they discovered a data breach at 3 PM on a Friday, she said, "Call you guys, I guess?" That was the extent of the incident response plan.
There was no documented procedure for who to contact, in what order, within what timeframe. No designated incident commander. No pre-identified forensics firm. No client notification template. No regulatory reporting checklist. No communication plan for the press, clients, or bar associations.
Without an incident response plan, the firm's response to a breach would be chaotic, slow, and almost certainly more damaging than it needed to be. Every hour of delay in containing a breach increases the scope of the damage and the cost of recovery.
The fix: We developed a 12-page incident response plan specific to this firm, including contact trees, containment procedures, evidence preservation steps, client notification templates, and regulatory reporting requirements. We then conducted a tabletop exercise — a simulated breach scenario — to test the plan and identify gaps.
Finding #5: Admin Credentials on a Sticky Note
This one physically hurt. When we audited the server room (a proper, cooled server room — they had that going for them), we found a sticky note on the server cabinet with the domain administrator username and password. The same credentials were shared among four people: the previous IT provider, the office manager, a senior paralegal who "knew computers," and the firm's bookkeeper.
The domain administrator account has unrestricted access to every system, every file, every email account, and every security setting in the firm's network. Sharing these credentials means that any action taken with this account — including malicious actions — cannot be attributed to a specific person. It also means that if any one of those four people is compromised (through phishing, social engineering, or a personal device breach), the attacker has the keys to the entire kingdom.
The fix: Immediate password rotation on all administrative accounts. We created individual admin accounts for each person who genuinely needed elevated privileges, implemented privileged access management with time-limited elevation, enabled logging on all admin actions, and removed the sticky note. Permanently.
The Wake-Up Call
After presenting our findings, the managing partner sat quietly for about thirty seconds. Then he said, "How much to fix all of this?"
The total cost to remediate these five findings — plus several smaller issues we identified — was approximately $15,000 in one-time setup costs plus ongoing managed IT services. The cost of not fixing them? Potentially the firm's reputation, its client relationships, its insurance coverage, and its ability to practice law.
Every one of these findings is common. We see some version of this at nearly every firm we assess. The firms that come to us proactively — before the breach, before the insurance denial, before the bar complaint — are the ones that survive. The ones that wait for something to go wrong often don't get a second chance.
Think your firm is "fine"? [Get a free site audit](#assessment) and let us look under the hood. What we find might surprise you.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.