Law firms invest significant time and money protecting their own systems, data and training that people to ensure their data and their client data is safe. However, one of the biggest cyber security risks often sits outside of the firm.

Every supplier you work with has the potential to introduce risk into your business.

From outsourced IT providers and legal software suppliers to document management platforms, accountants and marketing agencies, suppliers often have access to confidential information, business systems or privileged accounts. If those suppliers don’t have robust cyber security controls and governance in place, your firm could be exposed to unnecessary risk.

Cyber resilience is no longer just about protecting your own organisation. It’s about understanding and managing the security of every organisation that supports your business.

Why supplier assurance matters

Modern law firms depend on many third party suppliers, even smaller firms and many of them organisations process sensitive or confidential information or provide services that are critical to the day to day operations of the firm.

If one of those suppliers suffers a cyber attack, operational failure or a data breach, the impact can quickly extend to your firm.

Supplier assurance is the process of assessing whether those organisations have appropriate cyber security controls, governance and resilience measures in place before granting them access to your systems, confidential information or you being otherwise reliant on their services.

It’s about reducing risk before problems occur rather than reacting afterwards.

Not all suppliers carry the same level of risk

Every supplier should be assessed, but some deserve much closer scrutiny than others.

Practice management software providers, other cloud software, hosting and virtual desktop providers and IT support companies often have privileged access to your systems or process highly sensitive client information on your behalf.

The more access a supplier has, the greater the potential impact if their own security is compromised. These technology providers therefore require an additional level of scrutiny.

Questions you should be asking include:

  • Do they hold recognised security certifications such as Cyber Essentials Plus, IASME Cyber Assurance or ISO 27001 or equivalent?
  • Do they have documented information security policies
  • What are their business continuity and disaster recovery plans and when were they lasted tested.
  • How often to they carry out security risk assessments
  • Do their staff security awareness training and how frequently?
  • Do they have clearly defined security responsibilities? Who are the people responsible?

Why your IT support provider is your greatest areas of risk and what to expect from them

Of all your suppliers, your IT support provider is likely to hold the highest level of trust.

They often have:

  • Unrestricted access to you email, Teams chats and data in Microsoft 365
  • Administrator credentials for servers, firewalls, security and other critical systems
  • Access to backups and compliance archives
  • Remote access to every workstation

In many cases, they have more privileged access to your systems than anyone within your own organisation.

That means their cyber security standards become an extension of yours. If their security is anything less than the gold standard, your firm’s security is compromised.

Your IT partner should be able to clearly demonstrate how they protect both their own business and yours.

Additional areas worth discussing include:

  • What are their security certifications? Do they hold those expected of your other supplier or better, operate to the National Cyber Security Centre’s Cyber Assessment Framework as evidenced by certifications such as Assurix?
  • How do they secure privileged administrator accounts?
  • How do they enforce multifactor authentication and passkeys for all staff?
  • Are accounts protected with Conditional Access policies?
  • How to they secure their remote access tools and systems containing your passwords?
  • How do they regularly review administrative permissions?
  • How do they verify requests for security changes your firm makes with them are genuine?
  • What security monitoring do they operate internally?
  • What incident response procedures do they have in place?

Check out our Supplier Cyber Security Due Diligence Checklist for Law Firms to understand why these questions are important, how to ask them and more.

Supplier reviews are an ongoing process, not a one-off exercise

Many firms carry out due diligence when appointing a supplier but rarely review them afterwards.

Cyber threats evolve continuously, as do businesses. A supplier that met your expectations three years ago may have changed ownership, adopted new technologies or experienced security incidents that alter their risk profile. At the same time new cyber threats will have changed both their and your risks.

Supplier assurance should form part of your firm’s ongoing governance programme, with regular reviews of critical suppliers to ensure standards remain appropriate.

By carrying out regular supplier assurance reviews, particularly for technology providers and IT support partners, law firms can reduce risk, strengthen governance and demonstrate a proactive approach to protecting client information.

How Pro Drive IT supports law firms

At Pro Drive IT, we work with law firms across London, the Home Counties and the South East to build secure, resilient IT environments, while helping them strengthen governance across their wider technology supply chain.

For our clients, cyber security is not just about technical controls. Our service includes providing templates and automation to help our clients build resilient policies and facilitate risk assessments in and audits. We provide assets to help with tender a proposal due diligence and assistance responding to questionnaires.

Of course making it easy to for our clients to demonstrate the resilience of their IT support provider. That’s why Pro Drive has committed to following the Cyber Assessment Framework and in on the journey to achieving the Assurix certification.

The supplier cyber security due diligence checklist for law firms

If you are not sure how to start you supplier cyber risk review process, Pro Drive can give you a helping hand.

Download the Pro Drive cyber security due diligence checklist for law firms to find out the questions you should be asking your supplier, why the controls are important for a law firm, the risks of not doing it and what good looks like.