Skip to content
StrikeCyberStrikeCyber
Legal

Vulnerability Assessment Program for a Law Firm

A law firm holding privileged client material needed continuous assurance rather than an annual snapshot.

Legal sector
Legal
Industry
Legal
Services
Vulnerability Assessments
Engagement
Continuous vulnerability assessment program

The Challenge

The client is a law firm whose matters involve commercially sensitive transactions and privileged client material. Its own clients, particularly the larger corporate ones, had begun conducting security reviews of their outside counsel and asking for evidence that was more current than a once-yearly test report.

The firm faced a specific version of a common problem. It was not short of security tooling, but it had no continuous picture of its exposure, and its annual assessment was several months stale by the time the questions arrived. Losing a matter over a security questionnaire was a commercial risk the partnership took seriously.

Our Approach

StrikeCyber replaced the annual assessment with a continuous program, structured so the firm always held current evidence rather than a document with a date on it.

  • Continuous external attack surface discovery, monitoring everything the firm exposed to the internet including assets created for individual matters and client portals.
  • Quarterly authenticated internal assessment across servers, workstations and the document management system that holds the firm's most sensitive material.
  • Credential exposure monitoring, checking whether firm credentials appeared in breach corpora and whether they remained valid.

Findings were triaged by an operator and prioritized by reachability rather than raw severity, which mattered for a firm with a small IT team and no capacity to work through a scanner backlog.

What We Found

  • Forgotten matter-specific infrastructure. Several client-facing portals and file transfer sites, created for matters that had long since closed, remained live and reachable, two of them running unsupported software.
  • Document management over-permissioning. Access to matter folders had accumulated as staff moved between teams, so a number of users could reach material unrelated to their current work.
  • Exposed credentials still valid. Two sets of firm credentials appeared in breach corpora and were confirmed still working against the firm's remote access.
  • Inconsistent endpoint patching. Laptops belonging to partners who traveled frequently were consistently the furthest behind on updates.

The Outcome

The forgotten portals were decommissioned, and the firm adopted a matter-closure process that includes retiring any infrastructure created for it. Document management permissions were rebuilt around current team membership and are now reviewed quarterly. The exposed credentials were rotated immediately and phishing-resistant multi-factor authentication was extended across remote access.

The commercial outcome mattered most to the partnership. The firm now responds to client security reviews with current evidence and a documented continuous program, and has passed its subsequent reviews without remediation conditions attached.

Why It Matters

Law firms hold concentrated, high-value material and are targeted precisely because of it. An attacker who compromises a firm reaches the confidential business of every client it acts for, which is why corporate clients increasingly assess their counsel as rigorously as any other vendor. An annual test cannot answer a question asked in March about an environment that changed in February. To move from periodic testing to continuous assurance, get in touch.

FAQ

About this case study

Is this a real StrikeCyber engagement?

Yes. This legal case study is drawn from a genuine engagement, anonymised where needed to protect the client, showing the challenge, our approach and the outcome.

Can StrikeCyber deliver similar results for our organization?

Yes. The expert-led, prioritized approach behind this outcome applies across legal and other sectors and organization sizes. Scope a free consultation to discuss your environment.

How is client confidentiality protected?

Findings and client data are isolated to your organization and handled in access-limited environments we control in the United States. Nothing is published without the client's consent.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation