Legal Cybersecurity
Law Firm Penetration Testing (2026): The Attorney's Guide to Scoping, Surviving & Using a Pen Test
A complete 2026 guide to penetration testing for law firms — why clients and cyber insurers now demand it, the four test types that matter for legal practices, realistic Miami and South Florida pricing, how to scope a test without disrupting billable work, how to protect the report under privilege, and how to turn findings into a defensible remediation record.

Ten years ago, a law firm could answer a client's security question with a sentence about antivirus and a locked file room. In 2026, the question arrives as a 140-item outside-counsel guideline spreadsheet from a bank, a hospital system, or a private equity client, and one line on it reads: "Describe the frequency and scope of your most recent third-party penetration test, and attach the executive summary."
That single line is why most firms end up here. This guide explains what a penetration test actually is, which tests a legal practice genuinely needs, what it costs in Miami and South Florida, how to run one without wrecking a trial calendar, and how to handle the report so it protects the firm instead of becoming discoverable evidence of unaddressed risk.
If you have not yet built the underlying controls, start with our cybersecurity for lawyers in Miami guide — a pen test is a measurement, not a substitute for MFA, encryption and backups.
What a penetration test actually is (and what it is not)
A penetration test is an authorized, time-boxed, simulated attack performed by human testers against systems you own or control, with a written rules-of-engagement agreement and a report describing what was accessed, how, and what to change. The purpose is not to produce a list of theoretical flaws — it is to answer one question: if a motivated attacker targeted this firm this quarter, what would they reach?
Firms routinely confuse four very different products. Buying the wrong one is the most common and most expensive mistake in legal-sector security purchasing.
- **Vulnerability scan** — an automated tool checks systems against a database of known flaws and outputs a list. Cheap ($500–$2,500), fast, and full of false positives. Useful monthly. Not a pen test, no matter what the invoice says.
- **Penetration test** — a human attempts real exploitation, chains findings together, and demonstrates impact ('we reached the client trust-accounting folder'). Costs thousands, takes 1–3 weeks, produces evidence.
- **Red team engagement** — a longer, stealthy, goal-oriented simulation testing whether anyone notices. Appropriate for AmLaw-scale firms with a security team to detect it; wasted on a 12-attorney practice.
- **Security audit / gap assessment** — a documentation and configuration review against a framework such as ISO 27001 or the CIS Controls. Complements a pen test; does not replace it.
"If a vendor quotes you $900 for a 'law firm penetration test' delivered in 48 hours, you are buying an automated scan with a cover page. Clients and insurers can tell the difference, and so can a plaintiff's expert after a breach."— Cybrvault offensive security team
For the difference between offensive testing and defensive monitoring, see our breakdown of red team vs blue team.
Why law firms are being forced into testing in 2026
1. Outside counsel guidelines
Corporate legal departments in banking, healthcare, insurance and defense now push their own vendor-risk obligations down to their law firms. Their outside counsel guidelines commonly require annual third-party penetration testing, MFA on all remote access, encryption at rest and in transit, breach notification to the client within 24–72 hours, and the right to audit. A firm that cannot produce an executive summary loses the panel seat — not with a dramatic rejection, but by quietly not being renewed.
2. Cyber insurance
Cyber liability applications in 2026 ask whether the applicant performs annual penetration testing and remediates critical findings. Carriers price on it. Firms that answer yes and can evidence remediation see meaningfully better terms; firms that answer yes and cannot evidence it risk a coverage dispute at the worst possible moment — after a claim.
3. Ethical duties
ABA Model Rule 1.1 Comment 8 (technology competence) and Rule 1.6(c) ('reasonable efforts' to prevent unauthorized disclosure), together with Florida Bar Rule 4-1.6(e), do not name penetration testing anywhere. But 'reasonable efforts' is measured against professional norms, and testing has become a professional norm for firms holding sensitive client data. ABA Formal Opinion 483 pushes the same direction: firms are expected to monitor for breaches proactively, not discover them from a client.
4. Florida breach exposure
Under the Florida Information Protection Act (Fla. Stat. § 501.171), a breach of unencrypted personal information affecting 500 or more Floridians triggers notification to affected individuals within 30 days and to the Florida Attorney General. A pen test that finds and closes the exposure first is dramatically cheaper than the notification, credit monitoring, bar inquiry and client attrition that follow. Details in our Florida data breach law explainer.
The four tests a law firm actually needs
External network penetration test
Targets everything of yours reachable from the public internet: firewall and VPN appliances, remote desktop gateways, mail gateways, any leftover on-prem server, and forgotten infrastructure from an old IT provider. In legal engagements the recurring findings are an unpatched VPN concentrator, an exposed RDP port someone opened 'temporarily' during a hurricane closure, and a legacy Exchange server that was supposedly decommissioned. Typical duration 3–5 days.
Microsoft 365 / cloud identity assessment
This is the single highest-value test for a modern firm, because the modern firm is not a network — it is a tenant. The tester reviews conditional access policies, MFA coverage and exceptions, legacy authentication protocols, mailbox forwarding rules, OAuth application consents, SharePoint and OneDrive external sharing links, audit log retention, and global admin sprawl. Nearly every firm assessment surfaces at least one attorney whose mailbox silently forwards to a personal address and one 'break-glass' admin account with no MFA.
Web application / client portal test
If your firm operates a client portal, secure upload page, intake form, or a document exchange built by a marketing agency, it is a direct path to privileged material. Testers check authentication and session handling, access control between clients (can Client A enumerate Client B's document IDs?), file upload handling, injection flaws, and API authorization. Insecure direct object references in intake and portal apps remain the most common critical finding in the legal sector.
Social engineering and phishing simulation
The attack that actually drains South Florida firms is business email compromise on real-estate closings: a spoofed lender or title thread, revised wire instructions, funds gone within hours. A phishing simulation plus a voice-pretext test against the front desk and paralegal staff measures whether your people and your wire-verification callback procedure hold up. Coordinate it with the managing partner, and never with an unannounced test during a trial week.
See our guides to business email compromise and social engineering attacks for the underlying attack mechanics.
What a law firm penetration test costs in 2026
Pricing is driven by scope size (IP addresses, application complexity, user count), depth, and whether a retest is included. These are realistic 2026 South Florida ranges for reputable providers using named, certified engineers (OSCP, GPEN, GWAPT, CREST) rather than offshore scan resellers.
- **External network penetration test** — $4,500–$9,000 for a typical 1–50 attorney firm.
- **Microsoft 365 / cloud identity assessment** — $3,500–$7,500.
- **Web application / client portal test** — $7,500–$18,000 depending on authenticated roles and API surface.
- **Phishing and social engineering simulation** — $2,000–$5,000 per campaign; $6,000–$12,000 for a quarterly program.
- **Internal network test** (only if you still run on-prem servers) — $6,000–$12,000.
- **Bundled small-firm engagement** (external + M365 + phishing, with retest) — $9,000–$20,000.
- **Retest of remediated findings** — should be free within 60–90 days. If a provider charges full price to verify their own findings, walk.
For comparison against a broader assessment, see our Miami penetration testing guide and cybersecurity audit pricing.
Scoping the engagement without disrupting the practice
- 1**Define the business question first.** 'Satisfy Client X's outside counsel guidelines,' 'pass the insurance renewal,' or 'confirm our M365 migration is safe' each produce a different scope. Bring the actual questionnaire to the kickoff call.
- 2**Inventory the real attack surface.** Domains, public IPs, the marketing site, the client portal, the M365 tenant, practice management (Clio, MyCase, PracticePanther, NetDocuments), e-discovery platforms, and any remote access left behind by a prior IT provider.
- 3**Choose your knowledge level.** Grey-box — testers get standard user credentials — delivers the most value per dollar for law firms, because it models the realistic threat: a phished attorney account.
- 4**Set the calendar around the docket.** Block trial weeks, closing-heavy periods and filing deadlines. Most legal engagements run testing 7am–7pm on business days with an emergency stop contact, or overnight for anything intrusive.
- 5**Write rules of engagement.** In-scope and out-of-scope assets, permitted techniques, whether denial-of-service and password spraying are allowed, data-handling requirements for anything privileged the tester encounters, and an immediate-notification threshold for critical findings.
- 6**Require confidentiality and insurance from the tester.** An NDA, professional liability coverage, background-checked personnel, and a commitment to destroy collected data at engagement close. Your testers will see privileged material; treat them like any other vendor with access to client confidences.
- 7**Agree on deliverables up front.** Executive summary suitable for clients and insurers, technical findings with reproduction steps and evidence, risk ratings, prioritized remediation roadmap, attestation letter, and a retest window.
Privilege: how to keep the report from becoming Exhibit A
A penetration test report is a written catalogue of your firm's weaknesses. If you are breached and sued, opposing counsel will want it. Courts have reached different results on whether security assessments are protected, and several well-known decisions have compelled production of incident-response reports that were treated as ordinary business records. Reduce your exposure with structure, not hope.
- Engage the tester through counsel — inside general counsel or outside counsel — rather than through the IT budget, and say in the engagement letter that the work is performed to provide legal advice regarding regulatory and ethical obligations.
- Label deliverables as attorney work product and privileged and confidential, and mean it — distribute on a need-to-know basis, not to the whole firm listserv.
- Keep the report out of routine business channels. Do not attach it to a general IT ticket, a vendor portal, or a marketing questionnaire response.
- Share a sanitized executive summary or attestation letter — not the full technical report — with clients and insurers. Reputable providers produce this artifact specifically for that purpose.
- Document remediation with the same care. A closed finding with dated evidence is a defense; an open finding sitting untouched for two years is the opposite.
This is a risk-reduction structure, not a guarantee, and privilege analysis is jurisdiction-specific — treat it as a topic for your firm's own risk counsel.
What testers usually find in a law firm
Across small and mid-size legal engagements the findings are remarkably consistent. If you want to know what your report will say before you buy it, this list is a good prediction.
- MFA enabled 'for everyone' with three or four legacy exceptions — typically a founding partner, a shared reception mailbox, and a service account.
- Legacy authentication protocols still permitted in the tenant, bypassing conditional access entirely.
- Mailbox auto-forwarding rules to personal Gmail addresses created by attorneys for convenience.
- SharePoint or OneDrive 'anyone with the link' shares on matter folders, created years earlier and never expired.
- A client portal with insecure direct object references — changing a document ID in the URL returns another client's file.
- Unpatched VPN or firewall firmware with a public exploit available.
- Domain-wide credential reuse and weak passwords discovered through password spraying, plus prior-breach credentials for firm addresses available on the dark web.
- No SPF/DKIM/DMARC enforcement, allowing convincing spoofing of partner addresses to clients — the mechanic behind closing wire fraud.
- Backups that exist but have never been restore-tested, and are reachable with the same admin credentials as production.
- Audit logging retained for 90 days or less, making a real investigation impossible.
Run a free external check on your own domain first with our website security scan tool to see part of what a tester sees on day one.
After the report: turning findings into defensibility
- 1**Triage within a week.** Sort critical and high findings by exploitability and by proximity to client data, not by how easy they are to fix.
- 2**Fix critical findings in 30 days, high in 60, medium in 90.** Write those targets down; the timeline is as important as the fix when a regulator or client asks.
- 3**Assign a named owner per finding.** 'IT will handle it' is how findings survive to the next annual test.
- 4**Retest and get written verification.** An unverified fix is an assumption.
- 5**Update the incident response plan** with anything the test revealed about detection gaps — several firms learn from a pen test that nobody noticed the attack at all.
- 6**Train on what actually worked against your people.** If a pretext call obtained a password reset, change the help-desk verification procedure that day.
- 7**Schedule the next test** and treat it as an annual fixed cost, plus an out-of-cycle test after any major change: a new portal, an office move, an M365 migration, or a firm merger.
How often should a law firm test?
- **Annually** — the baseline expected by outside counsel guidelines and cyber insurers for external network and cloud identity.
- **Quarterly** — phishing simulation, because staff turnover and attacker technique both move faster than a year.
- **Continuously or monthly** — automated vulnerability scanning between tests, which is cheap and catches new exposures.
- **Event-driven** — after launching a client portal, migrating to M365, opening an office, merging with another firm, or onboarding a client whose contract requires it.
Choosing a provider (the questions that separate real firms from resellers)
- 1Who specifically will test us — name, certifications, and years of experience? Ask for the résumé of the engineer, not the company brochure.
- 2Can I see a redacted sample report from a similar-size legal client?
- 3What percentage of the work is manual exploitation versus automated scanning?
- 4Is a retest included, and for how long after delivery?
- 5How is data we do not want touched — privileged matter files — handled, stored, and destroyed?
- 6Will a named engineer sign the attestation letter our clients and carrier will receive?
- 7Do you carry professional liability insurance, and will you sign our NDA and outside counsel guidelines?
- 8Can you provide three references from Florida clients in regulated industries?
More on vetting local providers in our guide to choosing a local cybersecurity company.
The bottom line for Miami firms
Penetration testing has moved from a big-firm luxury to a condition of doing business with sophisticated clients. For a South Florida practice, the practical program is straightforward: an annual external and Microsoft 365 test, a web application test if you run a portal, quarterly phishing simulations, documented remediation, and a sanitized attestation you can hand to clients and your carrier. Budget $9,000–$20,000 a year for a small-to-mid firm — roughly the cost of a single week of breach response, and a fraction of one FIPA notification event.
Cybrvault runs penetration tests, cloud identity assessments and phishing programs for law firms across Miami-Dade, Broward and Palm Beach, with named engineers and privilege-aware reporting. Book a confidential consultation to scope your firm's test.
// frequently asked
Questions teams ask us
Do law firms legally have to get penetration testing?+
No U.S. statute or bar rule names penetration testing outright. The obligation is indirect but real: ABA Model Rules 1.1 and 1.6(c) and Florida Bar Rule 4-1.6(e) require reasonable efforts to protect client confidences, and 'reasonable' is judged against professional norms. In practice, the enforceable requirements arrive by contract — corporate outside counsel guidelines and cyber-insurance applications increasingly require annual third-party testing.
How much does penetration testing cost for a small law firm?+
In South Florida in 2026, an external network test for a 1–50 attorney firm runs roughly $4,500–$9,000, a Microsoft 365 identity assessment $3,500–$7,500, a client portal web application test $7,500–$18,000, and a phishing simulation $2,000–$5,000. A bundled small-firm engagement with a free retest typically lands between $9,000 and $20,000.
What is the difference between a vulnerability scan and a penetration test?+
A vulnerability scan is automated: a tool compares your systems to a database of known issues and prints a list, often with false positives. A penetration test uses human testers who verify findings, chain them together, and demonstrate real impact — for example, proving that a phished paralegal account leads to a client trust-accounting folder. Scans are a monthly hygiene tool; only a test answers what an attacker could actually reach.
Will a penetration test disrupt our firm's operations?+
A properly scoped test should not. Testing is normally scheduled around trial calendars and closing deadlines, intrusive techniques are run outside business hours or excluded by the rules of engagement, and an emergency stop contact is agreed in advance. Denial-of-service testing is almost always excluded for law firms.
Is a penetration test report discoverable if our firm is later sued?+
It can be. Courts have compelled production of security and incident-response reports treated as ordinary business records. Firms reduce exposure by engaging the tester through counsel for the purpose of legal advice, labeling deliverables as privileged attorney work product, restricting distribution, and sharing only a sanitized executive summary externally. Privilege analysis is jurisdiction-specific — consult your firm's risk counsel.
How often should a law firm run a penetration test?+
Annually for external network and Microsoft 365 identity, quarterly for phishing simulations, monthly automated vulnerability scanning in between, and an out-of-cycle test after any major change such as launching a client portal, migrating email platforms, or merging with another firm.
What do penetration testers find most often at law firms?+
MFA gaps for a handful of exception accounts, legacy authentication still enabled in Microsoft 365, mailbox forwarding rules to personal email, expired-but-still-live SharePoint sharing links on matter folders, client portals that expose other clients' documents by changing a URL ID, unpatched VPN firmware, and missing SPF/DKIM/DMARC enforcement that enables closing wire fraud.
Does Cybrvault perform penetration testing for law firms in Miami?+
Yes. Cybrvault runs external network, Microsoft 365 cloud identity, client portal and social engineering tests for legal practices across Miami-Dade, Broward and Palm Beach, with named certified engineers, privilege-aware reporting, a client- and insurer-ready attestation letter, and a free retest of remediated findings.
// miami, fl services
Cybersecurity built for South Florida
// need help applying this?
Book a free, confidential consultation.
Our engineers can map this to your environment in 30 minutes.
Get secured// keep reading
Related articles

Legal Cybersecurity
Cybersecurity for Lawyers (2026): The Miami Law Firm's Guide to ABA, Florida Bar & Client Data Protection
A practical 2026 cybersecurity playbook for solo attorneys and law firms in Miami and across Florida — covering ABA Model Rules 1.1/1.6, Florida Bar Rule 4-1.6(e), the Florida Information Protection Act (FIPA), email encryption, MFA, secure file sharing, incident response, and the exact stack a small-to-mid firm needs to stay defensible.

Cybersecurity
How to Prevent Ransomware in 2026: The Miami Business Owner's Playbook
A field-tested 2026 ransomware prevention playbook from a Miami cybersecurity firm — the six attack vectors that actually hit South Florida businesses this year, the exact controls that stop them, and the 30-day hardening plan we run for clients before the encryption starts.

Miami Cybersecurity
Miami Cybersecurity Consulting (2026): When to Hire, What to Ask & What It Actually Costs
A candid, no-fluff 2026 guide to hiring a cybersecurity consultant in Miami — what the different consulting models actually deliver (vCISO, risk assessment, pen test, compliance readiness, incident response), what South Florida firms should pay, the 12 questions to ask before signing, and the red flags that mean you're being sold shelfware.
