Before renewing your IT provider
Compare the agreement with configuration exports and operational records. Establish who handles alerts, access changes, patching, and recovery, including work outside normal hours.
For law firms
Client information, payment instructions, and the systems needed for client work deserve clear responsibilities. The Security Reality Check gives managing partners, firm leaders, and their IT teams an independent view of what the reviewed evidence supports and what needs attention.
An independent, fixed-fee review for in-house IT, outside providers, or both. We compare service commitments, configuration exports, and operational records. We do not access or test systems. See the full scope and deliverables.
These situations connect to the existing review and advisory services. During scoping, we agree the environment, participating providers, available records, fee, and schedule.
Compare the agreement with configuration exports and operational records. Establish who handles alerts, access changes, patching, and recovery, including work outside normal hours.
Review the records behind user access, external sharing, offboarding, and provider administration. Identify which systems are in scope and where ownership or evidence is missing. Client matter files are not needed for the initial inquiry.
Review the documented approvals, verification steps, and email protections around payment instructions. A focused Wire and Escrow Fraud Defense Review can be scoped separately.
Look beyond completed backup jobs to the recorded restore scope, elapsed time, data age, and usability of recovered systems. Clarify who demonstrates recovery and which dependencies remain unproven.
Review who can access email and files, share documents externally, or administer accounts, and how access changes when staff join or leave. For an AI tool, a separately scoped Secure AI Adoption Review examines what information it can access, who can use it, and which outputs or actions need human approval. You receive a written decision record.
The same review methodology and deliverables apply: an executive findings summary, security confidence scorecard, and 30/60/90-day roadmap. We walk through the report with leadership. Findings identify next steps, owners, and the evidence needed to show progress.
The report is yours to use with your own team or provider. Optional remediation oversight and ongoing security leadership are scoped separately. We do not assess work we planned or supported, operate your systems, or take commissions or referral fees. Our independence commitments.
Conclusions are limited to the agreed scope and evidence reviewed. This is not a compliance certification or a guarantee of security. Missing records and material disagreements are stated in the report. How review and corrections work.
Our work addresses operational security records and responsibilities. Legal advice about your obligations or agreements belongs with your counsel.
Use the free Security Reality Snapshot with your IT team or provider. No email is required. It helps you identify questions; it does not verify your security. For an inquiry, describe only the decision, the providers or systems involved, and the timing. Do not send client matter files, payment details, credentials, or confidential records.
Looking for another industry? Explore the general review or browse all services.
We reply within two business days to arrange a free 30-minute scoping call, or to scope by email if you prefer. You receive a written fixed-fee quote before any work starts.
Request a scoping call