IT Services for Law Firms

Managed IT, cybersecurity, and compliance readiness for firms of 20 to 500 users, nationwide. We secure the environment your document management system runs in, and we produce the evidence your clients ask for.

Consilien provides managed IT, cybersecurity, and compliance readiness for law firms with 20 to 500 users nationwide. We secure the environment your document management system runs in, and we produce the evidence your clients ask for during security review.

Three questions from a client security questionnaire. Can you produce an access log showing who opened a specific matter, and when? Can you show that a walled-off attorney was technically prevented from reaching those files, not just told not to? Can you name the person at your firm who owns that answer?

Firms that cannot answer all three usually find out during a panel review or a client audit, which is roughly the worst available moment to discover that nobody has owned the question, and it tends to arrive with a response deadline rather than an invitation to think about it.

134
Ransomware incidents against law firms and legal services organizations in Q1 2026, per Halcyon. Fourth most targeted industry that quarter.
$5.08M
Average breach cost in the legal sector, up 10% year over year. The US average across all industries reached $11.5 million in 2026.
42 states
Have adopted the duty of technology competence under Comment 8 to Rule 1.1.

Your clients are auditing you now

Pressure on law firm IT stopped coming from the bar a while ago. It comes from clients.

The Association of Corporate Counsel publishes Model Information Protection and Security Controls for Outside Counsel, built by in-house counsel to set a floor for the firms they hire. ACC also runs a Data Steward Program that assesses firm data security formally. When a general counsel sends a questionnaire or attaches security terms to outside counsel guidelines, this is usually where the language came from.

Six control domains show up again and again.

1

Retention, return, and destruction

What happens to client data at engagement close, and whether anything ever actually gets deleted.

2

Data handling and encryption

Encryption at rest and in transit, on servers, in the cloud, and on every laptop that leaves the office.

3

Breach reporting

Usually with a named notification window measured in hours, not the days most firms assume.

4

Physical security

Server room access, visitor handling, and what happens to paper files nobody scanned.

5

Employee background screening

On everyone with access to client data, including contract attorneys and temporary staff.

6

Cyber liability insurance

With a minimum coverage figure stated, often higher than the policy a firm already holds.

Notice what is missing from that list. Nothing about which practice management platform you run. Clients do not care what you use, and a questionnaire has never once asked a firm to justify choosing iManage over NetDocuments, because the platform was never the question. What they care about is whether you can prove control over it.

Exposure behind the questionnaire is real. Halcyon tracked 134 ransomware incidents against law firms and legal services organizations in the first quarter of 2026, making legal the fourth most targeted industry that quarter. Average breach cost in the legal sector now runs $5.08 million, up 10% year over year.

The US average across all industries reached $11.5 million in 2026, and general counsel have noticed.

Downtime is the part that gets underestimated. When systems are locked, billable work stops entirely, associates pivot from matters to incident response, partners spend the week reassuring clients instead of billing them, and the recovery invoice arrives on top of revenue the firm will never book back.

The ethics rules are the floor, not the ceiling

Every firm knows Rule 1.6. Fewer have worked out what it means for infrastructure.

Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information, wherever that information lives. Server, email, cloud platform, a laptop in a hotel room. That is an access control and encryption requirement written in ethics language.

Comment 8 to Rule 1.1 created a duty of technology competence, now adopted in 42 jurisdictions. It does not require a partner to become a security engineer. It does require the firm to understand its own risk well enough to make informed decisions, or to retain someone who can advise on it.

ABA Formal Opinion 483 sets the duties after a breach. Stop the access, restore system integrity, investigate what was actually reached, and notify current clients whose information was or may have been compromised. That third one is where firms get stuck, because determining scope requires logs that were being collected and retained before anything happened.

California adds a layer that surprises people. The State Bar Formal Opinions 2010-179 and 2012-184 hold that an attorney must exercise reasonable due diligence both in selecting a cloud or technology vendor and in continuing to use one. Vendor credentials, data security, where the data physically moves, whether the vendor subcontracts, and the terms of the contract all count.

Read that carefully. Under California guidance, choosing your IT provider is itself an ethics decision, and it is one you are expected to revisit rather than make once in 2019 and forget.

Where law firm IT actually breaks

Firms rarely get breached through something exotic. They get breached through the ordinary parts nobody owns.

Line illustration of a padlock on a stack of legal document folders beside a magnifying glass

What we do for law firms

We are not a legal software administrator, and if what you need is someone to run your document management platform day to day, there are firms that specialize in exactly that. You should hire one of them.

Our work is the layer underneath and around it. The layer your client questionnaire is actually asking about.

Managed IT and co-managed IT. Full IT operations under our IC24 model, or support alongside your existing IT director rather than replacing them. Monitoring, patching, endpoint management, help desk, and infrastructure, with change control that accounts for a docket.

Managed cybersecurity. 24/7 security monitoring and response, endpoint protection, email security, and the detection layer that catches an intrusion before it becomes a notification obligation under Formal Opinion 483.

Identity and access control design. Matter-level permissions, role-based access tied to actual practice group assignment, MFA across every system that touches client data, and access reviews on a schedule rather than when someone remembers. This is the work that makes an ethical wall enforceable and an access log producible.

vCISO leadership. A named senior security leader who owns risk decisions, signs off on the client questionnaire, and sits in the room when a general counsel wants to walk through your controls line by line instead of accepting a form back. Firms under 100 attorneys almost never justify a full-time CISO. They increasingly need the function anyway.

Compliance readiness, as its own engagement. SOC 2 and ISO 27001 readiness run as a separate practice, not bundled into a managed IT plan. You can engage the compliance work without moving your help desk, and plenty of firms do exactly that. We support readiness, remediation, and governance, which means we get you to the point where an independent auditor can do their job. We do not certify you. Any provider who says they will is describing something that is not how attestation works, and a general counsel who has read a real SOC 2 report will know it within about a minute.

Backup and recovery. Immutable backups that ransomware cannot reach, restores tested on a schedule rather than assumed to work, and a documented recovery order that brings back the systems your filings depend on before it worries about the ones nobody would miss for a week.

Audit-readiness checklist

Run this against your current setup. It maps to the six ACC control domains, so the gaps you find are the ones a client is most likely to ask about.

  • Retention schedule exists, is written down, and is actually enforced on old matters
  • Client data return and destruction process defined at engagement close
  • AES-256 or equivalent encryption at rest, full-disk encryption on every laptop and mobile device
  • MFA on email, the document system, practice management, remote access, and every cloud portal touching client data
  • Incident response plan naming the response team, escalation thresholds, and a pre-engaged forensic investigator
  • Breach notification window you can actually meet, with templates already reviewed by counsel
  • Access logs collected, retained, and readable, covering matter-level access
  • Ethical walls enforced technically, with an audit trail, not by memo alone
  • Annual security awareness training for every attorney, paralegal, and administrator
  • Background screening on staff with access to client data
  • Cyber liability coverage at or above what your largest client guidelines require
  • Vendor due diligence documented and revisited, per California Formal Opinions 2010-179 and 2012-184

A firm that has never been through a client audit usually clears 6 or 7. The last four are where engagements tend to start.

Common questions from managing partners

Our biggest client sent a security questionnaire and we have 30 days. Where do we start?


Read it before you shop. Most of what it asks about is configuration: MFA coverage, encryption at rest, backup testing, training records. A capable provider closes those in weeks. The item that cannot be rushed is a third-party attestation, since SOC 2 readiness typically runs 3 to 6 months before an audit begins. Answer honestly, document a remediation timeline with dates, and start the work. General counsel accept a credible plan far more often than firms expect.

If the questionnaire is already sitting in your inbox

The firms that handle client security review well are not the ones with the biggest budgets. They are the ones who decided who owns the answer before anyone asked the question. If nobody at your firm currently owns it, that is the thing to fix first.