Active Incident? 24/7 Response →

For Attorneys

Security and IT for a firm of two to ten attorneys

Security and IT for firms of two to ten attorneys: monitoring, dated evidence, wire verification, incident response, and support for your insurance renewal.

Legal services is the most reported sector in IC3’s non-critical ransomware complaints

In its 2025 Internet Crime Report the FBI’s Internet Crime Complaint Center counted more than 1,400 ransomware complaints from businesses and organizations not related to a critical sector. Legal services was the largest single share of them, at 18 percent, ahead of contracting services at 17 percent.

Read that number carefully, because it is easy to read as something it is not. The 18 percent is a share of the complaints IC3 received, not a rate at which law firms are attacked. It says legal services reported more of this than any other sector outside critical infrastructure. It does not say what share of firms were hit, and no such figure exists, because nobody knows how many firms never reported.

The FBI is unusually direct about the limits of its own figures. IC3 says its ransomware loss totals are artificially low, because they do not normally include the full range of costs a victim actually bears, and because some organizations report an incident without reporting any loss amount at all.

A group that targets law firms by calling them

The FBI has now warned about the same actor twice, fourteen months apart. It issued a Private Industry Notification on 23 May 2025 titled “Silent Ransom Group Targeting Law Firms”, and a FLASH alert on 26 May 2026. The 2026 alert states that while the group has victimized companies in many sectors including insurance, finance and healthcare, it has consistently targeted US-based law firms since Spring 2023.

The method is a phone call. Someone telephones the firm posing as its own IT support, asks to image the device or create a backup file, and is granted access by a member of staff who believes they are being helpful. Data then leaves over consumer file sharing services or onto a storage device inserted on site. In the 2026 pattern the pressure calls go to the firm’s clients as well as its employees.

There is no encryption. This matters, and it is the reason this section sits apart from the ranking above rather than under it. The FBI describes this group as conducting data theft and extortion without relying on traditional ransomware encryption. Nothing locks. No ransom note appears on a screen. A firm can be fully operational, with every file where it should be, and already be the subject of an extortion demand over copies that left days earlier. Controls tuned to notice encryption will not notice this.

One honest qualification, from the FBI’s own footnote to the 2025 notification. It notes that the group targets other sectors too, including medical and insurance companies, and that most of its victims are law firms or companies with similar naming conventions. The Bureau is telling you that part of its own law-firm attribution may be an artifact of how the victims are named. We would rather hand you that sentence than let you find it later.

This page is about protecting your firm. If you came looking for the other thing we do, the forensic examination of a device or a mailbox as evidence in a client’s matter, that is digital forensics for attorneys, where your firm is the buyer of an investigation. Here your firm is the thing being protected. The same offering for regulated financial firms sits at managed security and compliance.

What requires this of you, and what does not

What follows is a description of the rules as they are written, not an assessment of your firm. We have not seen your systems and we are not in a position to tell you where you stand against any of this. Where an obligation is soft we say so, because you can read the instrument yourself and a page that overstated it would not survive the reading.

The ethics rule says should

Model Rule 1.1 is two sentences and neither mentions technology. A lawyer shall provide competent representation to a client, and competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation. The word technology does not appear in the rule at all.

It appears once in the comments. Comment [8] says a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. One instrument, drafted by the same body at the same time, says shall about competence and should about technology. That contrast is the whole of the ethics argument and it needs no gloss from us.

Forty states, the District of Columbia and Puerto Rico have adopted a duty of technology competence, according to the tracker Robert Ambrogi maintains, as of its most recent entry in April 2025. Two things about that count are worth knowing. There is no official register, so a lawyer’s personal blog is the most complete tally anyone keeps. And adopted does not mean identical: Montana put the language in its preamble rather than in Comment [8], and North Carolina reworded it. The accurate description is a duty of technology competence, which is the tracker’s own phrase, rather than adoption of Comment [8] as written.

Opinion 483 does require you to tell your clients

Having said all that about softness, here is the part that is not soft, and it is the one most often missed. ABA Formal Opinion 483 says lawyers have a duty to notify clients when their information has been compromised. The trigger is stated in terms of the work rather than the data: notice is owed where the lawyer’s ability to perform the legal services for which the lawyer was hired is significantly impaired. And the opinion says that duty is owed irrespective of what type of security efforts were implemented beforehand. Doing everything right does not remove it.

Opinion 483 sets no deadline. It contains no clock of any length. If you have been told there is a 30-day or 72-hour ethics deadline for telling a client, that number came from somewhere else, usually a state breach statute that applies to different data on a different trigger. Real clocks exist and they bind, but they are not in 483.

One consequence worth stating, because it cuts against the intuition the section above builds. An incident that encrypts nothing and takes nothing can still impair your ability to do the work, and an incident that takes copies while leaving your systems running perfectly can too. Neither of those looks like a breach in the way people picture one.

The requirement that is hard is the CLE

Florida requires every member of the Bar to complete 30 credit hours every three years, and at least 3 of those 30 must be in approved technology programs. That has been the rule since 8 January 2024. Note the phrasing the rule itself uses: three of the thirty, carved out of the total rather than added on top of it.

The history is the part worth having, because it says more about how hard this obligation bites than any assertion could. When Florida adopted the technology requirement in 2017, the hours were additive: the court raised the cycle from 30 hours to 33 precisely to make room for them. In 2024 it cut the total back to 30 and kept the three. So a Florida lawyer today completes the same 30 hours per cycle that were required before technology CLE existed. The bar added a requirement and then removed the hours that paid for it.

What your state requires, and it is not the same everywhere

This is where a national page has to be careful, and where we have seen other pages get it wrong in a way that could cost a reader something. The general shape is that most states require reasonable security measures and do not require the program to be written down. One state requires it in writing, and it reaches firms well outside its own borders.

Massachusetts. 201 CMR 17.03(1) requires every person that owns or licenses personal information about a resident of the Commonwealth to develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts. There is no law-firm carve-out and no size exemption anywhere in the regulation. It applies based on where your client lives rather than where your office is, so an out-of-state firm with one Massachusetts client is inside it. It also covers paper as well as electronic records, which makes it broader than the statutes below. What it is not is a fixed standard: the regulation scales the safeguards to the size and resources of the business, and requires the technical elements only to the extent technically feasible. For a two-attorney firm the honest reading is that there is no exemption, only calibration.

New York. GBL 899-bb(2)(a) requires reasonable safeguards of anyone holding the private information of a New York resident, and that duty carries no size threshold at all. Two qualifications matter for a small firm. The word written does not appear anywhere in the section, so this is not a written-program mandate. And the list of specific safeguards is a deemed-compliance route rather than a mandate: meet them and you are deemed compliant, with the items introduced as examples. Small businesses have their own scaled way into that same safe harbour, which is a route in rather than an exemption out.

Florida. Section 501.171(2) requires reasonable measures to protect and secure data in electronic form containing personal information. The security duty carries no size threshold, though other parts of the statute do, and it never mentions law firms. It reaches your firm by definition rather than by name: a partnership, professional association or other commercial entity that acquires, maintains, stores or uses personal information is a covered entity. It requires no program and nothing in writing. The statute does not establish a private cause of action, and its civil penalty reaches the notice duties rather than the security duty, so a failure of the security duty is not the thing that penalty is for.

The practical answer for a firm with clients in several states is that the strictest rule you touch is the one that governs your paperwork, and for most firms that is Massachusetts. We are not going to tell you which of these reaches you. That is a question for the firm, and you are better placed to answer it than we are.

Why firms buy this anyway

Everything above is a reason the law will probably leave you alone. Firms still buy this, and the reasons are worth stating plainly, because none of them is a regulator.

The licence is not the control. You can buy every product in these plans yourself, and the prices are public. What the claims data says is that owning the tool is not what decides the outcome. At-Bay, reporting across more than 100,000 policy years, found that 60% of one ransomware group’s victims had a leading endpoint detection product in place and were compromised anyway. Beazley Security reported that in approximately 53% of the business email compromise cases it handled in the first quarter of 2026, the organization had multi-factor authentication enabled. Both of those firms sell insurance against the loss, so neither has a reason to flatter the tooling.

The application is answered from an archive or from memory. A cyber proposal form is not a questionnaire that gets filed away. Carriers state that the application is deemed attached to and becomes part of the policy, and that a misrepresentation in it is grounds for rescinding the policy that was issued on it. Rescission means the policy is treated as never having existed, so it pays nothing, and it lands after the loss rather than before it. Answering the control sections from a dated record of what was actually running is the cheapest protection available against that mechanism, and it is most of what the monthly evidence pack is for. One caveat we will offer unprompted: the rescission matter usually cited to make this point was resolved on the parties’ own stipulations, with no admitted misrepresentation, no court finding and no published opinion. Anyone citing it to you as precedent is citing a stipulation.

Privilege. For every other kind of client, running the incident response plan and the annual tabletop under a counsel engagement is a workaround we have to explain. For your firm it is simply the natural arrangement, because the counsel is you. This is the one place where an offering built for regulated financial firms fits a law firm better than it fits the buyer it was written for.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Written security program and incident readiness
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Client notification decision file, including the reasons not to notifyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and 72-hour notice termsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule and a document pack you can hand to an insurerNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.

Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. A firm smaller than that pays the same monthly figure, so a two-attorney firm should weigh it against what a single incident would cost it rather than against a per-seat rate.

Your cyber cover, and how you probably got it

Most pages about law firm cyber insurance describe a transaction their reader has never had. Among ABA survey respondents in 2023, 37% of firms of two to nine attorneys and 31% of solo attorneys reported carrying cyber liability cover at all, both down from the year before. And of the firms that do have it, many did not fill in a standalone cyber application to get it. They got it through their malpractice carrier, sometimes attached automatically to a quote, sometimes on a short bar-endorsed form of about nine questions. One legal malpractice insurer includes first-party cyber protection at no extra charge, with no controls application at all, and sets its limit higher for firms above ten charged-for attorneys than below.

So the first honest thing to say is that controls may not be what stands between your firm and a policy. On the revenue-banded application most small firms would actually see, the phrase about coverage not being bindable does not appear. Endpoint detection and next-generation antivirus are asked as two separate questions, so the second is a complete answer on its own. Backups are a list to tick rather than a threshold to clear. One large carrier’s short cyber form asks for active antivirus and asks nothing about endpoint detection; another puts the control questions in an optional supplement that earns a discount, which is the opposite of a gate.

What controls actually do here is move your price and your options. Multi-factor authentication on email and on remote access, endpoint protection or next-generation antivirus, and backups that are segregated or held offline are the questions that recur across every form we have read. On a preferred programme a no answer can push you out of that programme and onto a quote priced by hand. Anyone telling a two-attorney firm it is uninsurable without a named product is describing a market we could not find in any carrier document. What we did find, consistently, is that the answers change the number.

The trust account

A regulated financial adviser does not hold client money, because the custody rules put it with a qualified custodian. You do, by rule. Model Rule 1.15(a) requires client funds to be held separate from the firm’s own property, and for a firm doing closings, settlements or estates that account is the single largest thing an attacker can reach in one move.

The important sentence is about liability rather than about insurance. If a wire leaves your trust account to the wrong destination, you remain liable to the client for the shortfall regardless of who took the money, and a trust account shortfall is itself a matter your bar can act on. That obligation does not depend on whether anyone reimburses you. It is why this control is worth more attention than its position on any application would suggest.

The cover for it sits in a seam. One legal malpractice insurer states plainly that its policy, and most professional liability policies, do not cover these events. Where cyber cover is bundled with malpractice the sublimit for funds transfer fraud is often around sixty thousand dollars, which is worth setting against the size of a single closing wire. And at least one carrier conditions that coverage on a safe harbour requiring a written, original, notarized disbursement instruction for outgoing trust wires, which is a procedure a firm either follows every time or does not have.

Every plan here includes a written wire verification procedure: call-backs to a number agreed at onboarding rather than a number supplied in the request, and dual control on transfers above ten thousand dollars, approved by someone other than the person who started them, on a different device. It is the least sophisticated control in this offering and the one most likely to be the reason a firm is still solvent.

What we do, and how often

Every month

  • Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
  • Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
  • Evidence packProduces: A dated snapshot of every device and user, filed to your archive

Every quarter

  • Restore testProduces: A written result for a real file set restored from backup
  • Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
  • Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
  • Report to the partner who owns thisProduces: One page: what changed, what lapsed, what needs a decision

Every year

  • Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
  • End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
  • Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records

The written security program

Included in Monitor + Comply and Complete. No rule of professional conduct requires a law firm to hold a written information security program, and Opinion 483 recommends an incident response plan rather than requiring one. If your firm holds personal information about a Massachusetts resident then that state’s regulation does require the program in writing, and that is the one place this becomes a legal question rather than a commercial one.

What the document is worth without a rule behind it is this. The incident response program keeps its three parts separate and visible: assessment, containment and control, and notification. The notification decision file is a template for the decision Opinion 483 leaves to your judgment, with a filing structure that records why you decided not to notify where that was the outcome, which is the record you would want if the decision were questioned later. The vendor inventory is the list of outside companies that touch client data, their due diligence files, and a 72-hour notice expectation put to each of them in writing. The records schedule and document pack exist so that an insurance renewal, a client questionnaire or a client asking what happened is answered from a folder rather than from a scramble.

An annual tabletop exercise and a written after-action report are included on those two plans. Nothing requires that either, and we say so rather than imply otherwise. It is what turns a written plan into a tested one, and it is the deliverable that most often changes what a firm does next.

An honest boundary. We prepare these documents for the firm to review, revise and adopt. We are not your lawyers and we do not give legal or regulatory advice, which is a slightly absurd sentence to write to this reader and is true anyway. Where a judgment call belongs to the firm, we set it up so the decision is easy to make and easy to evidence, and then you make it.

What this means for you

What is included, what is not, and what stays yours

We do

  • Configure, monitor and maintain every product in your plan
  • The monthly, quarterly and annual work in the service calendar above
  • Deliver a dated evidence pack to your archive every month
  • Support one insurance application or renewal each year
  • Escalate anything we find, with a written record
  • On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month

We do not

  • Helpdesk on the two Monitor plans, which stays with your existing IT provider
  • Incident response and forensics inside the monthly fee, which is billed separately
  • Buying or owning your hardware, software licenses, phones or cabling
  • Legal, regulatory or insurance advice
  • Writing or sending your breach notifications
  • Standing in for the partner who owns your technology and security decisions
  • Work on site or outside business hours, except by arrangement

You do

  • Name a primary and a backup technical contact, and tell us if that changes
  • Respond within four business hours when we escalate something urgent
  • Review and adopt the policies we prepare
  • Own the accuracy of anything you file with a court, a bar or an insurer
  • Tell us before you add people, offices, systems or vendors
  • Keep your existing IT resource in place on the Monitor plans, or tell us if that ends

Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.

If the worst happens

Most providers hand you off at the worst possible moment. We do not. The people who protect your firm are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.

Hour one to day ten

  1. Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
  2. Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether client information was actually reached. That last question is the one your notification decision turns on, and with an actor that takes copies without encrypting anything it is the only question that matters.
  3. By day ten, report. A written forensic report the firm, your insurer and if necessary a court can all read. Written to be defensible, because we write reports that go to court.
  4. Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.

Who does the work

A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.

Two things we put in writing, and you will recognise both. Where privilege matters we work under an engagement from the firm as counsel, set up at onboarding so it is ready rather than improvised at 2am. You do not need us to explain what that protects or why the timing of it matters. And you can always get a second opinion: you may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.

A great deal of what we are called for is not an outside attacker at all. A departing associate who copied the client file to a personal drive. A dispute where the record sits in a mailbox or on a phone. A preservation request that needs a defensible extraction. And a wire that went to the wrong account after a convincing email. Tracing where the money went is a different discipline from reading a firewall log, and it is what this firm was built to do.

The first ninety days

  1. Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor. You get our own due diligence pack: our controls, our insurance, our subprocessors, our incident plan. We hand it over before you ask because you are about to make us one of the outside companies that touches your client data, and you should be able to answer for us the way you would answer for any other vendor.
  2. Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. Wire verification procedure written and agreed. First backup taken and first restore proven, not assumed.
  3. Days 30 to 60, the program. On the Comply plans: incident response program drafted, notification templates prepared, vendor inventory built and the 72-hour expectation put to each provider in writing. The firm reviews and adopts.
  4. Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing or renewing insurance, we assemble the control evidence for your broker.

What we need from you to start: a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches client information, your current policies however incomplete, and the name of whoever at the firm owns this decision.

Rates, growth and the small print

Project and hourly rates

Hourly rates, standard and on a plan.
WorkStandardOn a plan
Remediation beyond the included allowance$400/hr$195/hr
Security consulting, assessment and hardening$400/hr$275/hr
Incident response, containment and rebuild$400/hr$275/hr
Forensic examination and written report$400/hr$325/hr
Deposition and trial testimony, four-hour minimum$400/hr$400/hr Same as the standard rate.
Done-for-you device forensicsfrom $2,000from $2,000 Same as the standard rate.
Refundable engagement retainer$5,000Waived

All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.

As your firm grows

Additional named user

$35/mo

Additional workstation

$25/mo

Additional server

$70/mo

New user setup

$150

User departure and offboarding

$100

New device deployment

$200

Term

Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.

Your data

Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.

Our duty to you

We will tell you within 72 hours of becoming aware of a breach affecting a system that holds your client information. That is a contractual commitment we make to you, not a regulated status we hold.

Insurance

We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.

Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.

How an engagement begins

  1. A scoping call. Forty-five minutes. We walk your environment and put a fixed number against what it would take to run it properly. There is no charge and no obligation, and we do not produce a written finding about your current state unless you ask us to.
  2. Written scope. Deliverables, timeline and price, approved by you before any work begins.
  3. Discovery, deployment and the program. The ninety days above, with a dated record at every step.

Why this work matters

A firm of four people holds the same confidences as a firm of four hundred, with none of the staff to protect them. Almost nothing in the rules requires what is on this page. What argues for it is a named group that calls law firms pretending to be their IT department, a trust account that cannot be un-emptied, and a client who will one day ask what happened to their file. Producing a dated record every month is the whole of this offering.

Plain terms

What we are, and what we are not

What we are

A private investigation agency in the making, with full digital forensics included. SleuthX is not yet a licensed private investigation agency; licensure is in progress. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. Where a matter needs field work today, whether backgrounds, locates or physical surveillance, we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked by small law firms

Can we just buy the software ourselves?
Yes, and the prices are public. The licence cost is not the control, though. Running it is. At-Bay, reporting across more than 100,000 policy years, found that 60% of one ransomware group's victims had a leading endpoint detection product in place and were compromised anyway. Beazley Security reported that in approximately 53% of the business email compromise cases it handled in the first quarter of 2026, the organization had multi-factor authentication enabled. The tool was bought in both cases. What was missing was somebody watching what it reported.
We already have someone who does our IT. Does this replace them?
Not on the Monitor plans. They keep the day to day and we sit above it, watching the controls and producing the record. That is usually the cheapest and least disruptive arrangement, and it works whether your IT is a person down the hall or a firm you call. On Managed IT and Complete we do take the day to day, which firms choose when the arrangement they have stops covering what they need.
Are we going to be disciplined for this?
That is not the usual shape of the risk, and we would rather say so than sell you fear. Florida's data security statute is enforced by the Department of Legal Affairs rather than by a private plaintiff, and the statute does not establish a private cause of action. It also lets a firm decide that a breach will not likely result in identity theft or other financial harm, provided that decision is documented in writing, kept for five years and filed with the Department. What a small firm actually tends to face is the cost and disruption of the incident itself, and a client who wants to know what happened to their file.
Our clients have never asked us about security. Is that unusual?
No. Among ABA survey respondents in 2023, 14% of firms of two to nine attorneys and 4% of solo attorneys reported having been asked to complete a client security questionnaire. Larger firms answer them constantly, which is why the practice feels universal from the outside. If it reaches you at all, it will usually arrive with a single institutional client, and answering it well the first time is much easier than answering it late.
What happens to privilege if you are in our systems?
You already know the answer better than most of our clients do, so we will be direct. Where privilege matters we work under an engagement from the firm as counsel, set up at onboarding rather than improvised during an incident, and the incident response plan and the annual tabletop run under that engagement. We are not your lawyers and we do not give legal advice. Privilege is your call to make and your call to waive, and we set the arrangement up so the choice is still yours when it matters.
How is this different from the forensics you already do for us?
Different product, same firm. The forensic work you may already know us for is evidence in your client's matter, where your firm is the buyer of an investigation. This protects your own systems, your own mailboxes and your own trust account, where your firm is the thing being protected. Firms use us for one, the other, or both.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management