RSI Security

4 Things Law Firms Should Look for in Cybersecurity Partner

Techincal

Cybersecurity is essential for every kind of business, across every industry. Many companies  have no choice but to shore up their cyberdefenses, with legal mandates and penalties applied for noncompliance. And, while cybersecurity requirements for law firms are relatively lax in comparison to other industries, lawyers still have an obligation to keep their clients safe. For many firms, partnering with a cybersecurity provider is the best way to do so.

But what makes a good cybersecurity partner for a law firm? Let’s discuss.

 

4 Law Firm Cybersecurity Best Practices

Law firms aren’t bound to legal-specific regulatory codes for cybersecurity, at least for now. But the American Bar Association (ABA) does require attorneys to protect their clients’ information, via rule 1.6 of the Model Rules of Professional Conduct. Plus, formal opinions in 2017 and 2018 specified tighter restrictions on digital information and data breach protocol, respectively.

Given these strictures, it’s imperative to find a quality cybersecurity partner to help implement all law firm cybersecurity best practices. Specifically, there are four key criteria your cybersecurity should help you with:

  1. Cyberdefense architecture and implementation
  2. Threat and vulnerability management
  3. Third party risk management
  4. Regulatory compliance 

These qualities are an absolute necessity for any cybersecurity partner you consider. Below, we’ll first describe what each quality is. Then, we’ll illustrate why it’s critically important.

 

Quality #1: Cyberdefense Architecture and Implementation

The first and most important quality in a cybersecurity partner is the outright strength and capability of the provider’s cyberdefense services. Nothing is more important to the overall cyberdefense of a company than the basic framework or architecture upon which it’s built.

You should seek out a partner who’s able to build a strong foundation — one that’s custom- tailored to the specific needs of your organization and adaptable to the ever-growing threats of cybercrime.

Since law firms aren’t beholden to industry-specific cybersecurity frameworks, your cybersecurity may be based off a more generalized model, such as:

These models, along with others (like the ISO/IEC 27001), provide flexible and scalable solutions that apply to a wide variety of businesses, including law firms. But there are scenarios in which targeted regulatory frameworks may apply to your practice (see quality #4 below).

 

Schedule a Free Consultation

 

Quality #2: Threat and Vulnerability Management

The second quality your cybersecurity partner should have is a strong focus on potential weaknesses in your architecture and general network — vulnerabilities that could be exploited by cybercriminals. This internally focused form of cyberdefense is often referred to as threat and vulnerability management.

Just as threats vary widely across companies, so too do the specifications for how to manage them. The Department of Homeland Security (DHS) has developed a four-step, cyclical approach to vulnerability management that’s applicable for any company:

A stringent focus on the risks that exist within your architecture is one key to staying safe. But it’s far from the only consideration, as many risks also lurk outside your perimeter.

Quality #3: Robust Third-Party Risk Management

The third quality you should look for in a cybersecurity partner is an unrelenting commitment to minimizing risks that come from outside the firm — namely, risks from other strategic partners. Third-party risk management (TPRM) involves vetting and ongoing oversight of all other businesses you work with to ensure that they don’t bring any cybersecurity risks into your orbit.

The HITRUST Alliance has defined a flexible TPRM process applicable to any institution, including law firms and legal practices. It includes the following procedures:

While you can exercise complete control over your own cybersecurity architecture and practices, you have scant control over other businesses’ practices. When entering into contract with a vendor, supplier, or other third-party, you need to account for any potential flaws in their armor.

Your cybersecurity partner should help develop and implement a plan based on this (or any other) TPRM framework. That way, one partner can become the key to security across all others.

 

Quality #4: Comprehensive Compliance Guidance

The last quality you should look for has to do, ironically, with the legality of your own legal practice. You want a cybersecurity partner that helps you meet all legally required security measures as defined by any regulatory guidelines you need to be compliant with.

Aside from the ABA guidelines detailed above, legal practices aren’t categorically beholden to many specific cybersecurity rules. However, one regulatory body that governs the majority of law firms is the Security Standards Council (SSC) of the Payment Cards Industry (PCI). This is because all businesses that process credit card payments need to be PCI-compliant.

Specifically, if you accept credit payments from clients, you’ll need to follow the rules set out in the PCI’s Data Security Standard (DSS), including:

While these rules don’t apply categorically to law firms, there are very few businesses that don’t accept credit cards. As such, PCI DSS compliance is a de-facto requirement for all businesses.

A slightly more niche set of requirements you may need to follow come from the Health Insurance Portability and Accountability Act, more commonly known as HIPAA. While HIPAA applies unilaterally across covered entities in the healthcare sector, it also applies to select business associates, like attorneys, who come into contact with protected health information.

If you’re in contract with a covered entity, chances are you’ll need to be HIPAA-compliant.

Find Your Perfect Cybersecurity Partner

Ultimately, your firm needs a cybersecurity partner that takes you and your clients’ safety seriously — one such as RSI Security.

We’re experts with over a decade of experience providing cybersecurity solutions to law firms and all other kinds of businesses. We’re highly flexible and happy to tailor a cybersecurity plan to the exact needs and means of your company.

As we addressed above, the specific cybersecurity requirements for law firms are relatively lenient, compared to other industries. But that’s no reason for legal practices to take a similarly lax approach to cyberdefense. For a partner that provides a robust framework, addresses internal and external risks, and oversees compliance, contact RSI Security today!

 

 

Exit mobile version