Obsidian Ridge

Compliance

Small law firm cybersecurity: duties, costs and choices

A three-attorney cost example, ABA duties, provider questions and the evidence a small law firm should ask for.

SMB

For a law firm with three attorneys and no other counted people or unassigned shared computers, Obsidian Ridge costs $75 per month for Ridge Core or $150 per month for Ridge Plus, with business onboarding separate. Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate.

This is an example for three counted people, not a promise that a three-attorney firm has only three users. Include paralegals, assistants and other staff. A shared computer with no named user counts as one person. Business setup is $500 for up to 25 machines, or $1,000 for 26 to 100. See current pricing and the law-firm service scope.

Which ABA duties matter to a small firm?

Model Rule 1.1 Comment 8 includes keeping up with the benefits and risks of relevant technology as part of competence. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to or disclosure of information relating to representation.

These are model provisions. Check your jurisdiction's adopted rules and the demands of particular matters or client agreements. Neither is a certification that a law firm becomes compliant by buying a named security product.

What do the formal opinions add?

ABA sourceWhat it addressesA practical provider question
477R: securing communicationsReasonable precautions for transmitting client information; some information or agreements call for additional protectionHow do we select and configure an appropriate client communication route?
483: electronic breachesMonitoring, responding to a breach, restoring systems and communicating with affected clientsWho preserves the facts and supports the firm's notification decisions?
512: generative AICompetence, confidentiality, communication and other professional duties in AI useWhich AI tools and data uses are approved, and who reviews the output?

Use these to assign work and ask better questions. They do not replace jurisdiction-specific advice or matter-specific judgment.

What should the security provider cover?

Ask for a written inventory and a responsibility table before choosing the lowest price:

  • Computers: identify supported laptops, desktops and servers, including remote work and shared devices.
  • Accounts: identify the Microsoft 365 or Google Workspace tenant and the scope of identity monitoring.
  • Response: name the party watching alerts, the person allowed to approve containment and the person responsible for follow-through.
  • Evidence: identify the reports, logs and export process available after an incident or for a client review.
  • Recovery: identify who restores files, systems and case-management access. Monitoring is not a backup service.
  • Exclusions: state whether everyday support, legal advice, breach notices and extended response work are outside the fee.

Our MDR service covers endpoint detection and response; ITDR covers the account layer. Compare supported identity platforms in the ITDR provider comparison. A case-management application is not automatically within every integration or response permission.

What records should the firm be able to find?

Keep an approved access list, evidence of MFA and device coverage, a training roster, backup and restore-test records, and a short incident contact sheet. For each record, retain the date and system scope so it answers a concrete question later. This is a practical evidence list, not an exhaustive statement of legal retention duties.

Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Use managed SIEM when separately scoped logging addresses a defined risk or evidence requirement. Agree record access and confidentiality before collection.

Ridge Reserve costs $70 per person per month on an annual term, billed monthly, with no minimum and onboarding separate. It adds an incident-response plan and annual tabletop, quarterly admin-access review, monthly patch reporting and an annual questionnaire refresh to Ridge Plus. The monthly service is still different from legal review, forensic investigation or unlimited recovery work.

How should the firm handle generative AI?

Adopt a written approval process before staff paste client information into personal accounts. Check the tool's terms, data flows, access and retention; decide whether informed consent or additional safeguards are required. A lawyer remains responsible for reviewing work used in a representation. ABA Formal Opinion 512.

The copyable AI policy supplies a starting point for firm approval. Technical controls help apply it, but do not make the professional judgment for the lawyer.

What should the firm do first?

Start with the inventory and the unanswered responsibility questions. If a client or insurer has sent a form, use free application help and the questionnaire worksheet. The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Readiness Sprint is separately scoped around the evidence work. Talk with us when the firm knows which systems and people the proposal must cover.

Sources

Fetched October 2, 2026.

Last updated

October 2, 2026. We refresh this content as the threat landscape and tools evolve.

FAQ

Questions readers usually ask next

What does security cost for a three-attorney firm?

For a law firm with three attorneys and no other counted people or unassigned shared computers, Obsidian Ridge costs $75 per month for Ridge Core or $150 per month for Ridge Plus, with business onboarding separate.

Add staff and any shared computers without named users to the count. Core is month-to-month; Plus is annual, billed monthly.

Does the ABA require one named cybersecurity product?

The cited Model Rules and opinions address competence, confidentiality, reasonable safeguards and responsibilities after an incident. They do not certify one vendor or make purchasing a particular product the test. Check the rules adopted in your jurisdiction.

What should we ask a managed security provider?

Ask which endpoints and cloud accounts are covered, who can contain a threat, who handles follow-through, how records are exported and what is excluded. Put after-hours responsibilities and restore ownership in writing.

Can lawyers put client information into generative AI?

Do not assume every tool or account is approved. Evaluate confidentiality, access and retention, the task and any required informed consent. ABA Formal Opinion 512 addresses competence, confidentiality, communication and other duties when using generative AI.

Full bio & provenanceSee related service

Related reading