Law Firm Compliance Is a Five-Layer Responsibility, Not a Single Certification
Law firms do not typically follow one universal cybersecurity regulation. Instead, a firm’s obligations may come from five overlapping sources: professional-conduct rules, state privacy and breach-notification laws, client contracts, cyber insurance requirements, and industry-specific regulations connected to the matters or data the firm handles.
For a 25–50 employee law firm, the practical goal is to maintain a documented security program that protects confidential information, limits access, detects threats, supports recovery, and produces evidence that controls are working.
A managed service provider can help implement and document the technology behind that program. However, an MSP should not decide the firm’s legal obligations. Firm leadership and qualified legal counsel should determine which rules apply, while the MSP translates those requirements into technical safeguards, testing, reports, and remediation plans.
This guide uses a five-part framework to explain the standards a law firm should evaluate and the evidence its IT provider should produce.
1. Begin With Professional Duties to Protect Client Information
Lawyers have professional responsibilities involving competence, confidentiality, supervision, communication, and the protection of client property and information. Those responsibilities extend to the technology used to create, access, store, transmit, and recover client data.
The ABA Model Rules are models rather than a substitute for the rules adopted in Utah or another applicable jurisdiction. Nevertheless, they provide a useful starting point for a law firm technology review.
Technology competence
Comment 8 to ABA Model Rule 1.1 addresses keeping abreast of the benefits and risks associated with relevant technology. In operational terms, a firm should understand the material risks created by its email, cloud platforms, remote-access methods, legal applications, mobile devices, artificial intelligence tools, and third-party vendors.
Technology competence does not mean every attorney must become a cybersecurity specialist. It means the firm should make informed decisions and obtain qualified assistance when necessary.
Confidentiality
Client confidentiality should influence how the firm:
- Authenticates users
- Shares documents internally and externally
- Configures Microsoft 365
- Permits remote access
- Uses email and collaboration tools
- Manages mobile and personal devices
- Selects cloud and software vendors
- Uses generative artificial intelligence
- Disposes of computers and storage media
- Responds to suspected unauthorized access
A confidentiality policy is not enough on its own. The firm should be able to show how the policy is enforced through technical settings, access reviews, employee procedures, monitoring, and incident response.
Supervision
Partners and managers should know who is responsible for protecting the firm’s systems and information. That includes supervision of employees, contractors, vendors, and outside IT providers.
At least quarterly, firm leadership should receive understandable answers to questions such as:
- Which security risks require immediate attention?
- Are all employees protected by multi-factor authentication?
- Do former employees or vendors retain access?
- When was the last successful backup restoration test?
- Which critical vulnerabilities remain unresolved?
- Has the incident response plan been tested?
Use the six questions smart law firms should ask their IT provider every quarter as a starting agenda for these reviews.
2. Identify the Privacy and Breach Laws That Apply to the Firm’s Data
A law firm may hold personal information belonging to clients, employees, witnesses, opposing parties, experts, vendors, and other individuals. A breach can therefore create duties under one or more state laws, depending on the people affected and the information involved.
For a Utah firm, the Utah Protection of Personal Information Act should be reviewed with legal counsel as part of incident-response planning. A multi-state firm may also need to evaluate the laws of other jurisdictions when affected individuals reside outside Utah.
The firm’s written incident response plan should answer at least these questions:
- Who determines whether an event is a security incident?
- Who investigates what information was accessed or acquired?
- Who identifies the states in which affected individuals reside?
- Who determines whether notification is legally required?
- Who contacts insurance, privacy counsel, forensic specialists, and law enforcement?
- Who approves communication to clients and affected individuals?
- How will evidence, logs, devices, and email records be preserved?
- How will the firm continue operating during the investigation?
Build the plan before an incident occurs
A law firm should not wait for ransomware or account compromise to locate its insurance policy, determine who has authority, or identify outside forensic support.
Maintain an offline or otherwise protected incident-response packet containing:
- Leadership and emergency contact information
- Cyber insurance policy and claims instructions
- Outside privacy and breach counsel contacts
- IT and cybersecurity escalation contacts
- Critical vendor contacts
- System and application inventory
- Backup and recovery priorities
- Communication approval procedures
- Evidence-preservation instructions
- Copies of the incident response and business continuity plans
The firm should review this information at least annually and after major staffing, technology, insurance, or vendor changes.
3. Map Client and Matter-Specific Requirements
Many law firms receive security requirements through engagement letters, outside counsel guidelines, requests for proposals, security questionnaires, data-processing agreements, protective orders, and client vendor-management programs.
These contractual requirements may be more specific than a general legal or ethical standard. A client may require controls such as:
- Multi-factor authentication for all remote access
- Encryption of laptops and portable devices
- Annual penetration testing or vulnerability assessments
- Security awareness training
- Notification within a defined period after an incident
- Restrictions on subcontractors and data locations
- Documented business continuity procedures
- Background screening for certain personnel
- Specific retention and secure-deletion practices
- Evidence of cyber insurance
- Independent assurance reports or security certifications
A common compliance failure occurs when a requirement remains in an engagement agreement but is never assigned to an operational owner. The firm assumes IT is handling it, while IT has never seen the contract.
Create a requirements register
Maintain a centralized register for security and privacy commitments. For every material requirement, record:
- The source of the requirement
- The client, matter, contract, or rule involved
- The person responsible for interpreting it
- The technical or administrative control used to meet it
- The evidence that demonstrates compliance
- The frequency of testing or review
- The date the requirement expires or must be reassessed
This turns scattered contractual language into an accountable operating process.
Do not assume every requirement applies to every system
A firm may be able to isolate certain client data, establish matter-specific permissions, or apply enhanced controls to a defined workspace. In other situations, the safest and simplest approach may be to apply the stronger control throughout the organization.
The decision should be documented so the firm can explain why the selected scope is appropriate.
4. Determine Whether Industry-Specific Rules Apply
The nature of a client or legal matter does not automatically make every regulation governing that client applicable to the law firm. Applicability depends on facts such as the firm’s role, the services performed, the information received, contractual commitments, and the governing law.
Qualified counsel should determine scope. The MSP can then help implement the required safeguards.
HIPAA
A law firm may need to evaluate HIPAA obligations when it handles protected health information and acts in a role covered by an applicable agreement or regulation. Examples may include certain representations involving healthcare organizations, employee-benefit plans, or medical records.
When HIPAA applies, technology work may include:
- Risk analysis and remediation tracking
- Access controls and unique user accounts
- Encryption
- Audit logging
- Secure transmission of protected information
- Backup and recovery planning
- Workforce security training
- Vendor and business associate management
- Incident response documentation
Review HIPAA compliance services when the firm or a covered client requires technology safeguards for protected health information.
PCI DSS
A firm that accepts payment cards should evaluate how card information is collected, processed, transmitted, and stored. The simplest way to reduce exposure is often to use a properly configured third-party payment platform and avoid storing cardholder data in email, documents, spreadsheets, or practice-management notes.
PCI-related work may include:
- Mapping payment workflows
- Reducing the cardholder data environment
- Maintaining secure configurations
- Managing vulnerabilities
- Restricting access
- Completing applicable self-assessment documentation
- Coordinating required scans or testing
- Training employees who handle payments
Learn more about PCI compliance services before answering a payment processor’s security questionnaire.
FTC Safeguards Rule
The FTC Safeguards Rule applies to covered financial institutions under FTC jurisdiction. A law firm should not assume it is covered merely because it represents financial clients. It should evaluate its own activities and legal status with qualified counsel.
Even when the Rule does not directly apply, its program-based approach illustrates the kind of discipline many clients expect: assigned responsibility, written risk assessment, safeguards, monitoring, service-provider oversight, incident response, and regular reporting.
CJIS and criminal justice information
A firm that receives access to criminal justice information through a government agency, contract, or connected system may face specific security conditions. Those conditions can affect background screening, authentication, encryption, device management, physical security, logging, and incident reporting.
The agency controlling access should identify the applicable requirements. The firm’s IT provider should document how its devices, accounts, and network satisfy them.
Government contracts and CMMC
A firm working as a contractor or subcontractor in a government supply chain may need to evaluate contract clauses concerning federal information, controlled unclassified information, or CMMC requirements.
Applicability depends on the contract and the information involved. When those requirements apply, the firm may need a defined system boundary, access restrictions, secure configurations, evidence collection, written policies, and a formal remediation process.
Review CMMC compliance services when federal contract requirements are involved.
5. Treat Cyber Insurance as an Evidence-Based Compliance Layer
Cyber insurance is not a regulation, but its application and policy conditions can create practical security commitments. Firms are frequently asked whether they use specific controls, including:
- Multi-factor authentication
- Endpoint detection and response
- Offline or immutable backups
- Email filtering
- Security awareness training
- Privileged access controls
- Patch and vulnerability management
- Incident response planning
- Vendor risk management
- 24/7 security monitoring
The answers should be verified rather than estimated. A “yes” should be supported by evidence showing the control is implemented across the intended users, devices, and systems.
Questions to verify before renewal
- Does MFA cover every remote, cloud, administrative, and email account required by the application?
- Are all supported endpoints actively reporting to the security platform?
- Are backups separated from ordinary production credentials?
- When was the most recent successful restoration test?
- How quickly are critical vulnerabilities remediated?
- When did employees last complete security training?
- Has the incident response plan been tested?
- Who monitors alerts outside business hours?
The firm should retain a copy of the completed application, the supporting evidence, and any explanations provided to the insurer.
Use the Control-to-Evidence Framework
A law firm can simplify compliance by evaluating every requirement through four questions:
- What is required?
- Which control satisfies the requirement?
- Who owns the control?
- What evidence proves the control is working?
This framework prevents firms from confusing a purchased product with a functioning control.
| Requirement | Control | Owner | Evidence |
|---|---|---|---|
| Protect user accounts | Multi-factor authentication and access policies | IT provider and firm administrator | User coverage report and authentication policy |
| Remove former employee access | Documented offboarding process | HR, firm administrator, and IT provider | Completed checklist and account-disable records |
| Recover critical information | Protected backups and recovery procedures | IT provider and system owner | Dated restoration-test report |
| Address vulnerabilities | Patching and vulnerability management | IT provider and application owner | Current vulnerability and remediation report |
| Respond to incidents | Incident response plan | Firm leadership, counsel, and IT provider | Approved plan and tabletop exercise record |
| Train personnel | Security awareness program | Firm administrator and IT provider | Completion and phishing-simulation reports |
What an MSP Should Do for Law Firm Compliance
An MSP should help the firm convert approved requirements into repeatable technical and operational controls.
1. Inventory the environment
Document users, devices, servers, cloud platforms, legal applications, network equipment, vendors, administrative accounts, data locations, and backup systems.
2. Assess gaps
Compare current protections with the firm’s approved requirements. Findings should be prioritized by risk, business impact, implementation effort, and deadline.
3. Build a remediation roadmap
Separate urgent issues from longer-term improvements. Every action should have an owner, target date, budget, and expected outcome.
4. Implement safeguards
Examples include multi-factor authentication, endpoint protection, encryption, secure Microsoft 365 settings, access restrictions, backups, email security, monitoring, and employee training.
5. Test controls
Controls should be tested rather than assumed. Examples include restoring data, reviewing terminated-user access, checking MFA coverage, validating encryption, testing phishing reporting, and running an incident-response exercise.
6. Produce evidence
The MSP should provide reports understandable to partners, administrators, insurers, clients, auditors, and counsel. Evidence should identify the scope, date, result, exceptions, and remediation status.
7. Review the program quarterly
A quarterly review should cover open risks, security events, backup tests, account changes, vulnerabilities, training, upcoming renewals, technology projects, and contractual requirements.
911 IT’s managed IT services combine 24/7 support, proactive management, cybersecurity, cloud administration, and strategic planning.
What an MSP Should Not Claim
Be cautious when a provider promises to “make the firm compliant” without first identifying the applicable rule, contract, scope, and evidence requirements.
An MSP should not:
- Provide a legal conclusion about regulatory applicability unless qualified to do so
- Guarantee that an organization can never experience a breach
- Treat a software purchase as proof of compliance
- Complete questionnaires with unverified answers
- Ignore client contracts and outside counsel guidelines
- Use “industry best practices” as a substitute for defined requirements
- Claim that passing one assessment covers every client or matter
The strongest model is a partnership among firm leadership, legal or compliance counsel, the MSP, insurance advisors, and relevant business owners.
A Practical Example for a 35-Employee Utah Law Firm
Consider a Salt Lake City firm with 35 employees, Microsoft 365, a cloud practice-management platform, remote attorneys, electronic payment processing, and clients in healthcare and financial services.
The firm begins by identifying five requirement sources:
- Utah professional-conduct obligations and firm policies
- Privacy and breach-notification laws
- Outside counsel guidelines from major clients
- Payment-card requirements
- Cyber insurance representations
The firm’s counsel interprets the requirements. The MSP then maps each requirement to controls and evidence.
The resulting 90-day roadmap might include:
- Enforcing MFA for all 35 employees
- Creating separate administrative accounts
- Encrypting every firm laptop
- Reviewing Microsoft 365 sharing permissions
- Removing inactive accounts and outdated vendor access
- Deploying managed endpoint detection
- Validating backup isolation
- Completing a real restoration test
- Documenting the incident response plan
- Running a tabletop exercise
- Training employees on phishing and payment fraud
- Creating a quarterly evidence package for leadership
At the end of the project, the firm does not simply receive a statement that it is “secure.” It receives reports showing which controls are active, which systems are covered, when they were tested, what exceptions remain, and who is responsible for resolving them.
Real-World Proof: Compliance Must Produce Peace of Mind
Customer feedback collected by 911 IT repeatedly connects security and compliance work with practical business outcomes: confidence, responsiveness, clear communication, and the ability to focus on core work.
One client described 911 IT as an invaluable partner in meeting IRS and PCI security requirements. The client emphasized the value of having a team that understood the company’s environment, maintained backend security measures, and could respond without requiring the organization to explain its systems from the beginning each time.
Another client reported that a security audit identified vulnerabilities and provided a path to correct them, describing the resulting peace of mind as significantly more valuable than the cost of the assessment.
A legal-services owner also described depending on immediate, patient support for court filing, legal research, email, documents, and other attorney workflows. That experience demonstrates why compliance technology must remain usable: controls that protect information should support legal work rather than create unmanaged workarounds.
The Law Firm Compliance Evidence Checklist
Use this checklist during a quarterly review or client security assessment:
- We have identified the rules, contracts, and insurance requirements that apply.
- Qualified counsel has reviewed uncertain applicability questions.
- Each requirement has an assigned control and owner.
- We maintain a current inventory of users, devices, systems, vendors, and data locations.
- MFA coverage is documented and exceptions are approved.
- Administrative accounts are separate, restricted, and reviewed.
- Firm laptops are encrypted.
- Endpoint security is active and monitored across all intended devices.
- Microsoft 365 access and sharing settings are reviewed regularly.
- Critical vulnerabilities have defined remediation deadlines.
- Former employee and vendor access is removed promptly.
- Backups are protected from ordinary production credentials.
- A successful restoration test has been documented within the last quarter.
- Employees receive recurring security training.
- The incident response plan identifies decision-makers and outside contacts.
- The firm has completed a tabletop exercise within the last year.
- Client security commitments are recorded in a central register.
- Cyber insurance answers are supported by current evidence.
- Leadership receives a quarterly risk and compliance report.
- Open exceptions have owners and deadlines.
Any item that cannot be demonstrated should be treated as an open compliance gap, even when the firm believes the control is in place.
Frequently Asked Questions
Is there one cybersecurity regulation for every law firm?
No. A firm’s requirements can come from professional-conduct rules, state and federal law, client contracts, court orders, insurance conditions, and the type of data or work involved. Applicability should be evaluated based on the firm’s specific circumstances.
Does attorney-client confidentiality require a particular cybersecurity product?
Professional duties generally focus on reasonable protection rather than prescribing one universal product. Appropriate safeguards depend on the sensitivity of the information, foreseeable threats, cost and difficulty of the safeguards, client requirements, and the firm’s environment.
Does HIPAA automatically apply when a law firm handles medical records?
Not automatically. Applicability depends on the firm’s role, the source and use of the information, applicable agreements, and governing law. The firm should obtain legal guidance and then implement the required technical safeguards.
Does representing a bank make a law firm subject to the FTC Safeguards Rule?
Not by itself. The firm should evaluate whether its own activities bring it within the definition of a covered financial institution and whether contracts create additional obligations.
Can an MSP certify that a law firm is compliant?
An MSP can assess and document technical controls, but legal applicability and final compliance conclusions may require qualified counsel, an auditor, an assessor, or another authorized party. Be cautious of broad guarantees.
How often should compliance controls be reviewed?
Leadership should review material risks, open findings, account access, backup testing, security events, and remediation progress at least quarterly. The broader program should also be reviewed after major technology, staffing, client, contractual, or legal changes.
What evidence should a law firm request from its MSP?
Useful evidence includes asset inventories, MFA coverage reports, endpoint status, vulnerability reports, patching results, access reviews, backup restoration tests, training completion, incident-response exercises, and remediation tracking.
What is the difference between compliance and security?
Compliance demonstrates that defined requirements are being met. Security reduces risk through appropriate safeguards. A firm can pass a narrow assessment and still have unmanaged risks, so it should use compliance as a minimum structure rather than the entire security strategy.
Build a Compliance Program You Can Prove
The most dangerous answer during a client review, insurance renewal, or security incident is, “We assumed our IT provider handled that.”
A defensible program connects every obligation to a control, every control to an owner, and every claim to evidence. That process helps the firm protect confidential information, answer client questionnaires, prepare for insurance renewal, and respond more effectively when an incident occurs.
911 IT helps Utah law firms implement and document cybersecurity controls, Microsoft 365 protections, business continuity, employee training, monitoring, and ongoing technology management.
Explore our cybersecurity services, read about the compliance gap between controls and evidence, or schedule a 10-minute discovery call to identify the highest-priority gaps in your firm.
This article provides general technology and risk-management information and is not legal advice. Consult qualified counsel to determine which laws, professional rules, contracts, and regulatory requirements apply to your firm.
