IT and cybersecurity for Legal

You are held to ABA Rule 1.6(c); WA breach law – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.

Where we usually start: Bar confidentiality + state breach law.

If this sounds familiar

“If we get breached, we don’t just lose money – we lose our clients’ trust, and trust is the whole business. That’s everything this firm stands for.”

The fear that a single security incident could destroy a reputation built over years and betray the confidentiality clients depend on.

“Our corporate and institutional clients keep sending us security questionnaires and audit requirements, and I honestly can’t answer half of them. I’m worried we’ll lose work – or never win it – because we can’t check the boxes.”

Client-imposed security demands have become a business-development gatekeeper, and the firm has no one who can credibly respond.

“We almost wired client funds to someone impersonating a client’s email. It scared the hell out of me – one wrong click and we’re out six figures and explaining it to the bar.”

Email fraud and wire/trust-account scams are a constant, terrifying exposure for a firm handling client money.

Who this is for

Typical size: 10–75 total staff, revenue $2M–$20M. If that is roughly you, the rest of this page will land.

What working with us looks like

A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Managing Partner + Firm Admin, not to a ticket queue.

Talk to us

Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.