Blog··8 min read

Law firm cybersecurity checklist: the attack paths that actually get exploited

A checklist organised by attack path rather than by product: identity and Microsoft 365, client portals, the document management system, remote access, suppliers and the funds workflow. With the professional secrecy basis (art. 66-5, RIN art. 2, ABA 1.6(c)) and what a penetration test must prove on each path.

Most law firm cybersecurity checklists are lists of products: antivirus, backups, a firewall, training. They are not wrong, but they are organised around what you buy rather than around how a firm actually gets breached. This checklist is organised by attack path: the five routes through which a firm's client files, correspondence and funds flows get reached, what to verify on each, and what a penetration test should prove. The legal basis is professional secrecy and data protection, not NIS2: law firms are not a sector listed in NIS2 Annex I or II.

Why a law firm is a specific target

A firm concentrates privileged correspondence, litigation strategy, transaction terms, client identity documents and, in many practices, instructions to move funds. France's Conseil national des barreaux singles out fund theft through identity usurpation and falsified bank details as a key scenario in its cybersecurity guide. ANSSI was informed of 196 data-exfiltration incidents in 2025, against 130 in 2024, across all sectors (panorama de la cybermenace 2025). No authoritative figure exists for the share of law firms among them, and we will not invent one.

Path 1: identity and Microsoft 365

Nearly every modern intrusion into a firm starts with an account. Mailboxes hold the matter history; the identity provider holds the keys to SharePoint, Teams and the practice-management SaaS.

  • MFA enforced for every user and every protocol, with legacy authentication (IMAP, POP, SMTP AUTH, ROPC) blocked. A test should attempt the legacy paths, not read the policy.
  • Conditional access on admin roles, with no standing Global Administrator account in daily use.
  • Mailbox rules and OAuth application consents reviewed: forwarding rules to external addresses and third-party apps with mail-read scopes are how business email compromise persists after the password is changed.
  • External sharing and anonymous links on SharePoint and OneDrive limited and set to expire.
  • Delegations tested for privilege: can an assistant's mailbox delegate reach a partner's matters?

What a test proves: whether an attacker holding one phished password, and no second factor, reaches a mailbox, a document library or an admin role, and what path leads from there to funds instructions.

Path 2: client portals and the firm's web presence

Client extranets, e-signature flows, intake forms, and the public site with its CMS.

  • Portal authentication (password policy, MFA option, session handling) and authorisation between clients: can client A open client B's documents by changing an identifier in the URL?
  • Upload handling: file-type checks, malware scanning, where uploads are stored and who can reach them.
  • CMS and plugins current; administration interfaces not reachable from the internet without a second factor.
  • TLS configuration and security headers on every public host, including forgotten subdomains.

What a test proves: horizontal access between clients, injection and upload flaws, exposed administration paths.

Path 3: the document management system and practice software

The DMS is where secrecy lives. On premises or SaaS, it concentrates the files that article 66-5 protects.

  • The access model follows ethical walls: matter-level permissions, not firm-wide read.
  • Service accounts and API keys for integrations (e-signature, billing, e-discovery) scoped to what they need and rotated.
  • Audit logging on access and export, retained long enough to investigate an incident.
  • Backups tested for restoration and isolated from the domain: an attacker who reaches the domain should not reach the backups.

What a test proves: whether a compromised standard account enumerates matters outside its walls, and whether an attacker with domain access can reach, alter or encrypt the backups.

Path 4: remote access and the office network

  • VPN and remote-desktop gateways patched within days of vendor advisories; edge devices remain a heavily targeted vector in ANSSI's 2025 panorama.
  • No RDP or management interface exposed directly to the internet.
  • Active Directory hygiene: no shared local administrator password, tiered admin accounts, Kerberos delegation reviewed, legacy protocols disabled.
  • Laptops and travel devices encrypted, managed, and remotely wipeable.
  • Smart cards and, in France, e-Barreau and RPVA tokens handled as credentials: not left in readers, never shared.

What a test proves: whether the external edge is exploitable and, from a single workstation, how far an attacker gets toward domain administration, the DMS and the finance system.

Path 5: suppliers and the funds workflow

  • A supplier inventory: IT provider, DMS vendor, e-signature, cloud accounting, payroll, translation, e-discovery, each with its access level and contractual security clauses.
  • Payment and settlement instructions verified out of band, by calling a known number, and never changed on the strength of an email alone.
  • Your IT provider's own access: remote-management tooling behind MFA, named accounts, logs you can read.
  • Incident contacts and the GDPR Article 33 clock (notification to the supervisory authority within 72 hours of becoming aware, where required) written down before you need them.

What a test proves: how a compromised provider account or mailbox translates into a payment redirection, and whether the controls around funds instructions hold under a realistic business email compromise scenario.

Attack pathTypical entryWhat the pentest must demonstrate
Identity and Microsoft 365Phished password, legacy protocol, consented OAuth appReach from one account to mailboxes, libraries and admin roles
Client portals and webWeak authorisation, upload flaw, outdated CMSCross-client access, injection, exposed admin paths
DMS and practice softwareOver-broad permissions, unrotated integration keysEnumeration outside ethical walls; reach to backups
Remote access and networkUnpatched edge device, exposed RDP, AD misconfigurationEdge exploitation; workstation to domain admin path
Suppliers and funds workflowCompromised provider or mailbox, falsified bank detailsPath from compromise to payment redirection

The legal basis: professional secrecy and GDPR, not NIS2

Law firms are not a sector listed in NIS2 Annex I or II. A firm's security duties stem from professional secrecy and from data-protection law.

  • France. Article 66-5 of loi n° 71-1130 du 31 décembre 1971 places under professional secrecy, "en toutes matières", the consultations, the correspondence between lawyer and client, the notes d'entretien and "plus généralement, toutes les pièces du dossier". Article 2 of the Règlement intérieur national states that the lawyer's secrecy is "d'ordre public, absolu, général et illimité dans le temps" (both quoted in the CNB report of July 2025). Breach is sanctioned by article 226-13 of the Code pénal.
  • United States. ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. State rules follow the model with variations.
  • European Union. GDPR Article 32 (appropriate technical and organisational measures) and Article 33 (72-hour notification). A penetration test is one way to document the measures Article 32 requires.
  • Indirectly. Clients that are NIS2 essential or important entities must manage supply-chain security under Article 21(2)(d) and may pass requirements to their counsel. Cyber-insurance questionnaires ask about MFA, backups and testing, although no authoritative list of insurer prerequisites exists.

As of 4 October 2026, the French NIS2 transposition law is not in force. Our NIS2 guide explains which sectors are listed and how the size rule works.

Not legal advice

This article is a security engineer's reading of the texts cited, not legal advice. Your bar association, your counsel and your insurer define your actual obligations. Darkmoon does not certify compliance.

Confidentiality of the test itself

A penetration test of a law firm touches the systems that hold privileged material, so the tester's tooling is itself a confidentiality question. Darkmoon's Privacy Gateway tokenizes IPs, hostnames, URLs, emails, credentials and internal paths on the client's machine before anything reaches the model, and rehydrates them locally; a local model via Ollama or llama.cpp is supported. The mechanism and its limits are described in Inside the Privacy Gateway. In the managed service, the test authorisation, scope and liability clauses are signed before anything starts, and the report lives in a client space protected by email and a single-use OTP code.

Where to start

The cybersecurity for law firms page details the exposures, the six surfaces and the tests we run for a firm. For a firm without an in-house security team, Pentest on Demand runs the engagement end to end: legal framework signed online, scoping call, report and debrief in a secure client space, at a flat €799 per engagement, indicative and adjusted to the final scope.

Next
Run it against your own lab

Darkmoon is open source (GPL-3.0) and self hosted. Clone it, point it at a target you own, and read every line.