AccuSights
Partners
Book my 30-minute demo

Law Firms · Cybersecurity, compliance and GRC, in plain English

One firm holds every client’s secrets. Make confidentiality provable.

Managing partners answer to the bar, to clients’ outside-counsel guidelines and to the insurer. We turn the reasonable-efforts standard into running controls, answer the security questionnaires that hold up engagements, and watch the firm 24/7.

Built for firms of 5 to 250 attorneysQuestionnaire-ready evidencePublic pricing

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The trust-account wire that was one phone call from leaving

the managing partner of a 14-attorney firm

Tom runs a 14-attorney firm on the fifth floor of a building on Dearborn. Real estate, estates, a growing personal-injury practice. The trust account is the thing he checks before he checks his own.

On a Wednesday the bookkeeper brings him a disbursement: $186,000 in settlement funds to a client, wire instructions attached, approved in an email from the associate on the matter. The associate is in a deposition. The email came from her address at 7:12 a.m., which is not when she writes emails.

This is where the bar’s disciplinary summaries begin. In that version the wire goes, the client calls Friday, the money is in a third bank, the firm makes the client whole from partner capital, and the state bar opens a file under Rule 1.15 while the carrier reads the social-engineering exclusion aloud.

In Tom’s version, the firm’s rule is that trust disbursements are confirmed by voice with the attorney and the client, and the bookkeeper waits. The associate comes out of the deposition at noon and has never seen the email. Her mailbox had been forwarding to an outside address for three weeks; the engineer on watch had already flagged it that morning and was waiting for her to call back.

The email came from her address at 7:12 a.m., which is not when she writes emails.

What changes the ending

  1. Voice confirmation with the attorney and the client on every trust disbursement, written into the procedure (CIS Control 14, Security Awareness and Skills Training)
  2. MFA on every attorney and staff mailbox, with forwarding rules and foreign logins watched (CIS Controls 5 and 9)
  3. A rehearsed response plan that satisfies ABA Opinion 483: stop, restore, notify (CIS Control 17, Incident Response Management)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

If trust funds are wired to a fraudster on a forged instruction, who pays?

The firm, first, under Rule 1.15 and the duty to safeguard client property, and often without insurance if the policy carries a social-engineering exclusion. A voice-confirmation rule, mailbox MFA and monitoring are what keep the disbursement from leaving and the bar file from opening.

A corporate client sent outside-counsel guidelines with a 60-question security section. Can we lose the engagement?

Yes, and firms do. The guidelines ask for MFA, endpoint detection, encryption, vendor oversight and breach-notice terms, with evidence. The assessment produces the evidence set, and if the client requires SOC 2 the same controls carry into readiness.

What if a partner leaves and takes the client files and the contact list?

Scope matter access by team, log exports from the document and practice-management systems, and end access the hour notice is given. That protects the clients under Rule 1.6 and gives the partnership agreement something to enforce.

What you hold, and why someone wants it

Your data protection needs, by the data.

Client files and privileged communications

Everything a client told you in confidence, and an ABA Rule 1.6 breach if it leaves. Matter-scoped access, encryption and monitoring protect them.

The trust account and settlement disbursements

The loss that opens a bar file. Voice confirmation, mailbox MFA and disbursement controls protect it.

Attorney and staff mailboxes

The channel every impersonation and every fraud runs through. MFA, forwarding-rule alerts and login monitoring protect them.

Document management, practice management and e-discovery platforms

Vendors with every matter in them; the 2023 breach at a major firm cost $8 million to settle. Vendor review and access controls protect them.

Client data in AI tools

Matter details pasted into consumer AI is an Opinion 512 problem and a confidentiality one. Policy, approved tools and upload monitoring protect it.

$3.05B
lost to business email compromise in 2025; trust-account and settlement wire diversion is the law-firm version
Source: FBI IC3 2025 Internet Crime Report
62%
of breaches involve the human element, and mobile phishing lures now hook 40% more often than email
Source: Verizon 2026 Data Breach Investigations Report
48%
of breaches involve a third party, up 60% in a year; your e-discovery and practice-management vendors are in scope
Source: Verizon 2026 Data Breach Investigations Report

What applies to you

The rules, in one page, with the dates that matter.

ABA Model Rules 1.1, 1.6(c), 5.1 and 5.3
ABA, adopted by state bars
Technology competence, reasonable efforts to prevent disclosure of client information, and supervision of staff and vendors.
ABA Formal Opinion 483 (2018)
ABA Standing Committee on Ethics
Monitor for breaches, stop them, restore, and notify affected clients.
ABA Formal Opinion 512 (July 2024)
ABA Standing Committee on Ethics
Generative AI: competence, confidentiality, informed consent before client data enters self-learning tools, supervision and fees.
ABA Formal Opinions 477R and 498
ABA
Secure client communications and virtual practice: encryption where warranted, secure remote tools, vendor terms review.
Client outside-counsel guidelines and cyber insurance
Your clients and carriers
MFA, endpoint detection, SOC 2 or ISO 27001 evidence and incident-notice clauses as conditions of engagement.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Settlement and trust-account wire fraud through a spoofed partner or paralegal inbox.
  • Client security questionnaires that stall or lose engagements when the firm has no evidence to show.
  • Staff pasting matter details into consumer AI tools, now an Opinion 512 problem as well as a confidentiality one.

It happened to businesses like yours

Orrick, Herrington & Sutcliffe’s March 2023 breach exposed client and individual data held for corporate clients; a federal court finalized an $8 million class settlement in 2024.

March 2023, settlement 2024 · BankInfoSecurity

Jeff Anderson & Associates, a St. Paul firm representing clergy-abuse survivors, paid a ransom after a September 18, 2025 breach tied to a firewall vulnerability and notified 1,184 clients.

September 2025 · Hoodline, February 2026

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a legal business

We protect your people, every device, the servers and the website. Day and night.

  • We protect every attorney, paralegal and accounting inbox, where the forged disbursement approval arrives.
  • Every laptop and workstation, in the office, at home and in the courthouse.
  • The server, the document management system and the file share holding matter files.
  • The website and the client portal, including intake forms and secure uploads.
  • The cloud apps: practice management, document management, e-discovery, email and e-signature.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Law Firms

Built on the CIS Controls v8.1 IG1 and the ABA duties in Rules 1.1, 1.6 and Opinions 483 and 512, scoped from what a firm stands to lose: the trust account, the privilege and the engagement. The output is a questionnaire-ready evidence set and a plan a managing partner can act on between matters.

  • Inventory of every device, cloud platform and vendor holding matter files, including attorneys’ home and mobile devices (CIS Controls 1, 2 and 15)
  • Trust-disbursement workflow test and the voice-confirmation rule written into it (CIS Controls 14 and 17)
  • Mailbox security review: MFA, forwarding rules, legacy protocols, sign-in logs (CIS Controls 5, 6 and 9)
  • Matter-access review: who can reach which files, and how access ends when someone leaves (CIS Control 6)
  • AI-use policy to Opinion 512, with approved tools and upload monitoring (CIS Control 3)
  • Outside-counsel questionnaire answers, a breach response plan to Opinion 483 and a ranked remediation plan
Start with the 3-minute test

Packages

Built for legal businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

SOC 2 Readiness: Type 1 and Type 2

Enterprise and government buyers ask for SOC 2 before they sign.

Fixed feescoped in 30 minutes
Type 1 readiness: 4 to 8 weeks
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

We run your audit before your auditor does: the same evidence requests, the same interviews, the same sampling, the same findings language.

Fixed feescoped in 30 minutes
1 to 3 weeks depending on framework and scope
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Do we need SOC 2 as a law firm?
Increasingly, when corporate clients’ outside-counsel guidelines require evidence of controls. Many firms start with the risk assessment and a questionnaire-ready evidence set, then pursue SOC 2 Type I when a client asks.
What does the free check look at?
Ten plain-English questions scored against CIS IG1 and the ABA duties: MFA, backups, email protection, device encryption, vendor access and incident readiness. You get a 0 to 100 score and your top gaps immediately.

People also search: cybersecurity for law firms near me · law firm IT security in Chicago · for a 14-attorney firm · for a solo practitioner with a trust account · outside-counsel guidelines security help · cybersecurity for a personal-injury firm · for an estate-planning practice in the suburbs · law firm cybersecurity in the Midwest

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test