ABA-aligned cybersecurity that respects the bar and the bottom line.
Managed cybersecurity for small and mid-size law firms running NetDocuments, iManage, Clio, MyCase, Microsoft 365, or Google Workspace. We operate MDR, ITDR, and Security Awareness Training, then package the written security evidence your bar, carrier, and ABA Formal Opinion 483 expect.
ABA Model Rule 1.6Formal Opinion 477RFormal Opinion 483NIST CSF 2.0SOC 2
CISSP-led practiceHuntress Partner
TL;DR
What law firms get, and what it costs
We operate managed detection and response, ITDR, and Security Awareness Training for your firm end-to-end. The 24/7 SOC watches every endpoint and your Microsoft 365 or Google Workspace tenant for the attack patterns documented across the legal vertical:
Ransomware against the document management server
Business email compromise targeting paralegals
Closing-wire-fraud aimed at real-estate settlement funds
Obsidian Ridge adds the security-operations side: an ABA-aligned written information security plan, MR 5.3-aware vendor management, the FO 483-aligned incident response runbook, cyber-insurance readiness, and the quarterly managing-partner briefing.
Pricing, per month:
Foundation, $15 per device: endpoint only.
Protected, $32 per user: adds identity threat detection and the awareness program. This is the tier to look at: it covers the controls cyber insurance applications ask about, including business email compromise.
Complete, from $55 per user: adds Managed SIEM and the full compliance evidence program.
Not ready for the full program yet? Ridge Watch ($15 per device per month, monitoring only) is an honest first step — real protection now, though a firm handling privileged files and trust funds will want the controls above before a renewal.
Managed detection and response on every endpoint and server
Attorney laptops, paralegal workstations, the document management server, the firm's M365 / Workspace box. The 24/7 SOC watching for ransomware canaries, credential theft, and the lateral-movement patterns documented in legal-vertical attacks.
Managed ITDR on Microsoft 365 / Google Workspace
On either platform it catches stolen session tokens replayed from somewhere new and the inbox rules used to hide closing-wire-fraud activity. On Microsoft 365 it also catches the adversary-in-the-middle kits that bypass MFA (EvilProxy, Tycoon) and the OAuth-consent attacks against firm tenants.
Managed Security Awareness Training
Phishing simulations and 5-minute micro-lessons tuned for legal staff: closing-wire-redirect themes for paralegals, court-notice phishing for legal assistants, sealed-records hygiene for partners.
Written information security plan + ABA evidence package
The written security plan many state bars and all cyber insurance carriers now require, plus the audit-control logs, MFA coverage report, encryption attestation, training records, and the firm-tailored incident response plan.
Security settings review
We review MFA, admin separation, user access, former staff, external sharing and audit logging in the firm's practice-management and document-management systems (NetDocuments, iManage, Clio, MyCase, ProLaw, PracticePanther and the like), and deliver a list of fixes the firm or its IT vendor applies.
Incident response coordination (FO 483 aligned)
If something happens, you are not alone with a vendor portal. We coordinate forensics, walk through ABA Formal Opinion 483 notification obligations to current clients, file the cyber-insurance claim, and produce the documented response evidence the bar and the carrier expect.
How we work
Alongside your current IT company
Keep your IT company. They handle the help desk, the hardware and the everyday fixes. We run the security layer beside them: threat detection and response, and the evidence insurers and auditors ask for.
2. Closing-wire-fraud via business email compromise
The attacker phishes the paralegal's Microsoft 365 credentials through an adversary-in-the-middle kit. Then:
Captures the session token, so MFA is already satisfied
Sets an inbox rule that hides wire and escrow emails
Reroutes a closing payment to a foreign bank account
IOLTA trust account exposure compounds the bar disciplinary risk. The pattern in detail.
3. Confidentiality failure via unhardened defaults
Shared paralegal accounts at reception
No MFA on the DMS admin
BYOD partner laptops with matter files in personal Gmail
Vendor access never reviewed
The kind of pattern that breaks attorney-client privilege when a court looks at the firm's actual confidentiality practices. What MR 1.6 and FO 477R actually require.
For the wider set of regulated-industry writeups — ABA opinions, HIPAA, cyber-insurance controls, breach-notification law — browse the compliance blog.
The insurance wedge
Carrier questionnaire before renewal? Start with the Readiness Sprint.
Maybe a cyber-insurance renewal just arrived with a 2026 questionnaire asking for:
A written security plan
MFA coverage
A social-engineering-fraud control the firm can't yet evidence
In 7 business days the Cyber Insurance Readiness Sprint maps every question on your carrier's questionnaire to the control that answers it, closes the gaps we can, and hands you a signed evidence pack.
Flat fee, $1,500–$3,500 depending on office count and scope. Delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
Pre-merger cyber diligence, the lateral-hire onboarding problem, the 4-quarter program, and the identity-consolidation question every growing firm hits.
The role-distinction reframe for law firms. What your IT provider owns, what a security operation owns, the specific questions to ask to tell whether the layer is covered, and why co-managed is the healthy model.
Solo and small firms (1–10 attorneys) building a defensible program for the first time
Mid-size firms (10–75 attorneys) renewing cyber insurance against the 2026 questionnaire
Firms preparing for or going through merger / lateral-hire activity
Firms with real estate, closings, settlements, or IOLTA exposure
Firms with sealed records, IP, M&A, or other high-sensitivity matter types
Managing partners who want senior security expertise without staffing it internally
And who it is not for
Firms with no email, no document management, and no cloud anything (rare in 2026)
Firms that already operate an in-house 24/7 SOC with senior identity-security expertise
Firms looking for a one-time security audit document with no ongoing service
How we start
From first call to operating program
01
Discovery call (30 minutes)
Tell us how the firm runs. Practice areas, DMS, office count, attorney + staff headcount, current IT firm, cyber-insurance renewal date, any recent incidents, and what is driving the conversation. We tell you which tier fits and where the real risks are.
02
Scoped proposal (within 3 business days)
Endpoint and user counts, tier recommendation, the implementation schedule, and the ABA-aligned deliverables (written security plan, IR plan, vendor management review). Fixed monthly pricing. Month-to-month or annual. No vendor markup games.
03
Deployment (5–10 business days)
Managed detection and response agent on every endpoint and server. Managed ITDR connected to your Microsoft 365 or Google Workspace tenant. Awareness program launched with a phishing simulation calibrated to the firm's practice areas. Written engagement agreement covering MR 5.3 supervisory expectations signed before any access.
04
24/7 operation + 90-day check-in
The 24/7 SOC is watching from day one. Obsidian Ridge handles escalations, quarterly managing-partner briefings, the written security plan, the FO 483 incident response runbook, the cyber-insurance renewal support, and the tabletop exercise every firm should be running annually.
ABA duties in plain English
What the rules actually require.
Three ABA sources set the practical cybersecurity floor for law firms in 2026:
Model Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of client information. Comment [18] sets a sliding scale based on data sensitivity, likelihood of disclosure, cost of safeguards, difficulty of implementation, and effect on representation — not a fixed checklist.
Formal Opinion 477R applies MR 1.6 to electronic communication. Standard email is generally adequate for routine matters; particularly sensitive matters call for stronger protective measures on the communication channel and the accounts that hold the file.
Formal Opinion 483 imposes an affirmative duty under MR 1.4 to notify current clients of a breach affecting their material confidential information, with enough detail for the client to make informed decisions about ongoing representation. State breach notification statutes apply in parallel and can run ahead of the FO 483 timeline.
This is a general summary for educational purposes, not legal advice. Application to a specific matter depends on jurisdiction and facts, and the rules and formal opinions change over time. Consult qualified bar counsel and the official ABA guidance. Source: ABA Model Rules of Professional Conduct (americanbar.org).
Wire fraud in North Carolina closings
The Lawyers Mutual safe harbor, and the controls behind it.
Lawyers Mutual says every policy it issues carries a Financial Fraud Exclusionary Endorsement, and that the endorsement contains a safe harbor for attorneys in real estate transactions, made of two procedures:
Incoming wires. Every new client, for every new matter, gets an engagement letter carrying Lawyers Mutual's wire warning: call the office to verify before sending any wire, the firm will not change wiring instructions, and instructions for a different bank or account should be presumed fraudulent. The client signs it, and the signed copy stays in the file.
Outgoing wires. Before any money leaves the trust account by wire, the firm obtains “a written, original, notarized disbursement instruction” and keeps the original in the file.
Those are the firm's procedures, in Lawyers Mutual's terms. We don't read your policy or say what it covers; your endorsement and Lawyers Mutual answer that.
The controls and staff habits that support it
A callback to a number you already have. Lawyers Mutual advises calling a known number before wiring any funds. In one fraud it described, a forged notarized directive, apparently built from a real notary's recorded signature and seal, was stopped only because the closing attorney still called the seller's previously verified number.
Notarized is not proof. Lawyers Mutual also advises verifying notary credentials with state notary offices, and treating a notary in a different state from the owner's confirmed residence as a sign of fraud.
The mailbox the fraud starts in. Lawyers Mutual names business email compromise as one of the most common scenarios. On Protected and Complete, identity threat detection watches Microsoft 365 or Google Workspace for suspicious sign-ins and the inbox rules that hide wire emails.
Multi-factor authentication on email. Lawyers Mutual lists it among the steps to protect the firm's data and systems. We report where it is missing.
Staff who expect the trick. Security awareness training on Protected and Complete runs closing-wire-redirect simulations for paralegals and assistants.
Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
Sources, all from Lawyers Mutual and fetched September 25, 2026:
We deliver the technical safeguards that ABA Model Rule 1.6 requires — audit controls, encryption, identity threat detection, integrity monitoring — and we sign a written engagement agreement that addresses MR 5.3 supervisory expectations before any work begins.
Vendors are not 'ABA certified' in any formal sense; the meaningful question is whether they can produce the technical evidence and meet the firm's supervisory standards. We can do both.
We are not the firm's ethics counsel and we do not claim to be.
Do you replace our IT company?
No, and we are explicit about that. We are a managed cybersecurity firm, not a legal-IT MSP. Your IT company continues to handle help-desk, Wi-Fi, hardware, e-filing system support, and DMS administration.
We handle 24/7 monitoring, identity threat detection, security awareness training, incident response coordination, and the FO 483 breach response support.
The two functions belong with different specialists; most general legal-IT MSPs are not staffed or licensed to operate a 24/7 SOC.
What does this cost for a 6-attorney firm?
Foundation starts at $15 per agent per month — that covers every workstation, every server, and partner laptops with 24/7 monitoring.
Protected at $32 per user per month adds Managed ITDR on the M365 or Google Workspace tenant and the awareness training program. That is the tier built for identity-layer attacks that bypass MFA.
Complete at $55 per user per month adds Managed SIEM and the formal compliance evidence program for firms with an upcoming insurance renewal or matter-specific compliance obligation.
We use NetDocuments / iManage. Can you protect it?
Yes. Managed detection and response covers every endpoint and server, including on-prem DMS servers (iManage Work on-prem, ProLaw, older NetDocuments hybrid deployments).
Managed ITDR covers the identity-layer attacks that target the DMS through SSO compromise.
For the DMS itself, we run a security settings review — MFA, admin separation, user access, former staff, external sharing and audit logging — and deliver a list of fixes the firm or its IT vendor applies.
We use Clio / MyCase / PracticePanther — cloud-only platforms. Do we still need this?
Yes, arguably more. Cloud DMS shifts the server burden to the vendor and the threat model toward account compromise.
That is exactly where Managed ITDR matters most: monitoring sign-in anomalies, mailbox rules, and token-replay attacks on your M365 or Workspace tenant, plus OAuth consent on Microsoft 365 — the front door to the cloud DMS.
The endpoint side is still important — laptops accessing the cloud DMS still get phished — so the Protected tier is usually the right starting point for cloud-only firms.
How long does deployment take?
Endpoint agent rollout typically completes within 5 business days of contract signing. Identity threat detection on Microsoft 365 or Google Workspace activates within 24–48 hours of tenant connection.
The awareness training program launches within the first two weeks. The written security plan and incident response plan are drafted in the first 30 days and reviewed with the managing partner before finalization.
Do you help with the cyber insurance application?
Yes. Our Cyber Insurance Readiness sprint maps the carrier questionnaire to the actual controls you have or need, packages the evidence the underwriter wants to see, and tells you honestly which gaps are worth closing before renewal.
The goal is to turn a declined, surcharged, or uncertain application into a cleaner underwriting conversation backed by evidence. We are not an insurance broker — we don't sell the policy, we help you qualify for it.
What happens if we have a breach during your service?
Huntress's 24/7 SOC acts on the alert around the clock. For an active incident, call your cyber insurance carrier's breach hotline first; there is no emergency line here. Within one business day, Kfir takes over everything past containment.
We coordinate forensics, walk through ABA Formal Opinion 483 notification obligations to current clients whose material confidential information was affected, help file the cyber-insurance claim, and produce the documented response evidence.
The managing partner remains the decision-maker for client communication and ethical disclosures — we operate every technical and process step required by the breach response.
Two ways to start
See where you stand, or book the full law-firm briefing.
The 10-minute assessment scores your firm against the controls the bar and your carrier ask about — no email required to see your result.
The 30-minute law-firm briefing goes deeper — DMS, office count, practice areas, insurance renewal, the threat model, and what your first 90 days would look like.
Both are free, both are no-obligation, and we tell you when you don't need us.