How mature is your IT, really? A Legal self-assessment
24 questions, about seven minutes, no email address required. The scoring happens right here in your browser either way. By default we also record your answers so we can see how this lands – one click on the checkbox below the score button turns that off, and the score still shows exactly the same.
Running a Legal business 1. Which practice management / DMS do you run?2. Is your practice management system vendor-supported and on a current version?3. Can you restrict a matter's documents to just the team on it?Ethical walls stop being theoretical the moment you take a conflicted matter.
4. How do you handle client security questionnaires and audit requests?5. Is there an out-of-band check before funds leave a trust account?6. Do any of your corporate clients impose their own security requirements on you, and can you meet them?Outside counsel guidelines are usually far stricter than the bar rules, they are contractual rather than advisory, and they are the thing that actually costs a firm the panel seat.
7. If a partner lost their phone tonight, could you wipe the client material on it?Matter documents and privileged email reach phones whether or not anybody planned for it.
The basics 8. Are your systems and data backed up automatically, every day?File sync is not backup. OneDrive, Dropbox, Google Drive and SharePoint copy your mistakes and your ransomware to the cloud just as faithfully as your work. What counts here is a separate, versioned copy you could restore from after the original was encrypted.
9. When did somebody last actually RESTORE from a backup to prove it works?A backup nobody has restored from is a hypothesis, not a backup.
10. Is multi-factor authentication switched on for email and remote access?Partial MFA is not partial compliance. Almost every rule that applies to you treats this as a yes or no, so this answer can cap the whole result on its own.
11. Do you carry cyber-liability insurance?12. How do computers and servers get their security updates?13. What protects the laptops and desktops?14. Is there anything in front of your email beyond the built-in spam filter?Phishing is still how most of these firms actually get hit.
15. When somebody leaves, how quickly do their accounts get shut off?16. Who owns IT day to day?17. If your main systems were unavailable tomorrow morning, is there a written plan?18. Do people here get security training, and does anyone test whether it stuck?Almost every incident starts with somebody being convinced to do something reasonable-looking. Training that is watched once at induction and never tested is a record that it happened, not a defence.
19. When did somebody last check WHO can reach what, and take away the access they no longer need?Access accumulates. People change roles and keep the old permissions, and the account that gets compromised is usually the one that could reach far more than that person's job required.
20. Do you know which apps and cloud services your team signed up for without telling anyone?Not a discipline question. Client data ends up in whatever tool made somebody's week easier, and you cannot protect, back up or hand back data you do not know exists.
Where you stand on compliance 21. Where do you operate?We are Seattle based, so where a rule below is named, it is the Washington one. If you work elsewhere there is almost always a state equivalent and the question is the same. This answer is not scored.
22. Do you have a written information security program covering ABA Rule 1.6(c); WA breach law?23. When was your last written risk assessment?24. If a client, an auditor or an insurer asked you to evidence your controls this week, could you?Not whether the controls exist – whether you can PROVE they do.
25. Is there an incident-response plan naming who does what, and by when?26. Do you check the security of the vendors who touch your client data?