Independent cyber resilience for law firms

We keep law firms insurable.

Cyber insurance renewals, client security audits, and ABA Opinion 483 duties, answered by an independent assessor. Fixed scope, fixed fee, one week to your first answer.

For firms of 10 to 150 attorneys and legal operations teams.

Why firms call us

If any of these is on your desk, we should talk.

Your cyber insurance renewal questionnaire

The form is not paperwork. It is the document the carrier’s claims team reads after an incident, checking whether your answers were accurate. An unverified yes about MFA or tested backups is a coverage risk hiding in plain sight.

A client’s security audit

Corporate and insurance clients attach security requirements to outside counsel guidelines and audit against them, usually on a 60 to 90 day clock, usually at firms with nobody assigned to answer.

ABA Formal Opinion 483

Lawyers have a duty to monitor for breaches and to notify affected clients. A gap you have found and not addressed is a worse position than one you never knew about, unless a remediation plan is on file.

Why an outside party

Whoever runs IT cannot be the one who verifies it.

In most firms this size, the same party designs the environment, operates it, and reports on whether it works. Internal, outsourced, or one of each. The model does not matter. Self-assessment is not independent verification, and the audiences asking the question are the ones who care about that distinction: a carrier deciding what it will cover, and a client deciding whether your firm meets its outside counsel guidelines.

This is not a judgment about competence. The people running your systems are usually good at running your systems. They are simply being asked to confirm their own work to an audience that specifically needs someone with no stake in the answer.

We do assessment only. We do not sell you the fix and we do not take over your IT. Whoever runs your environment keeps running it. We verify, in writing, that it does what your carrier and your clients have been told it does.

Engagements

Four fixed-fee engagements. Start wherever the deadline is.

Prices shown are founding client rates, available to our first engagements in the legal practice.

Start here

Insurance Readiness Assessment

$4,650 · one week

We verify your environment against your carrier's actual questionnaire and hand you evidence-backed answers, a gap register, and a 90-day fix plan, before underwriting sees the form.

The full picture

Law Firm Resilience Audit

$11,100 · three weeks

Board-ready proof the firm can survive an incident. Business impact analysis, a supervised test restore, DR and governance review, mapped to Opinions 483 and 477R and to your clients' outside counsel guidelines.

Close the gaps

Remediation Sprint

from $5,600 · scoped to findings

The red findings closed, with before and after evidence, ahead of your renewal or audit deadline. The base covers coordination, evidence capture, and re-verification of up to six findings. Anything beyond that is quoted against your gap register or billed at $190 an hour. Your provider does the work where it is theirs to do. We run the plan and confirm the result.

Keep it true

Managed Resilience Program

$7,875 / quarter

Quarterly tested restores and a signed Resilience Attestation your carrier and your clients can rely on. Findings are re-verified, not assumed. Includes up to four hours of advisory each month and support on one renewal questionnaire a year. Incident response is quoted separately.

Who runs the work

Peter Schabinger

IT Audit & BCDR, GroupA LLC

  • Commvault MVP
  • Commvault Master
  • MCSE
  • MCSA
  • Pursuing CISA (ISACA)

Over a decade at Commvault Systems, including time as a Resident Support Engineer embedded with enterprise customers across healthcare, financial services, and biotech. That is the difference between an assessor who reads your documentation and one who has watched restores fail in production and knows why.

Peter leads IT audit and BCDR engagements for PE-backed portfolio companies at GroupA, delivering infrastructure and cybersecurity assessments, business impact analyses, and remediation frameworks to executive and investor stakeholders. The law firm practice applies the same method on a smaller footprint and a fixed fee.

The person you meet does the work. No hand-off to a delivery pool.

What you actually receive

A finding is specific, or it is not a finding.

Finding 04 of 19Backup & Recovery

Backups complete nightly. Recovery has never been tested.

Nightly jobs report success across all servers, and the firm’s renewal questionnaire answers yes to tested backups. No restore has been performed since the platform was installed. Job success confirms data was written. It does not confirm data can be read back, that the document management database returns to a consistent state, or how long that takes.

Maturity
1 of 4 Defined, not verified
Exposure
Questionnaire answer cannot be evidenced at claim time.
Fix
Supervised restore of the document management system to isolated infrastructure. Record actual recovery time against the stated objective.
Owner
Named in the report. Every finding has one.
Effort
One day, provider-led, GroupA supervising.

Illustrative excerpt, composed for this page. Every finding in a live report is scored on the same fixed 1 to 4 maturity scale, so your second audit is comparable to your first.

Free, no gate

The Questionnaire Decoder: what your carrier is really asking.

Ten questions from a standard cyber insurance renewal application, translated into the underwriting logic behind them, with the evidence a carrier expects if the answer is ever challenged. Written for the person at your firm who has to sign the form.

Straight answers

Questions partners ask first

We already have IT handling this.

They probably handle most of it well, and this does not replace them. Internal team, outside provider, or both — the issue is the same: when a carrier or a corporate client asks whether your controls actually work, an answer from the party that built those controls carries less weight than one from a party with no stake in the answer. We work alongside your team, not around them, and they see every finding before your partners do.

How much partner and staff time does this take?

For the Insurance Readiness Assessment, roughly two hours total: a scoping call, a short interview with whoever owns IT, and read access to your environment. The Resilience Audit adds a half day, most of it observing a test restore your provider performs.

What happens if you find something serious?

You get it in writing with a named owner, an effort estimate, and a fix sequence, and you get it before a carrier or a client finds it. A documented gap with a dated remediation plan is a defensible position. An undocumented one is not.

Is the report confidential?

Yes. Deliverables belong to the firm. Where you want the work covered by privilege, we can be engaged through your outside counsel. Ask about this before the engagement letter is signed, not after.

Do you sell the software or the fix?

No. We take no vendor commissions or referral fees, and we do not resell hardware, software, or managed IT to assessment clients. The Remediation Sprint runs the plan and verifies the result. Your provider does the work that is theirs.

Get started

Tell us what your carrier or your client is asking for.

Twenty minutes, no slideware. You will leave the call knowing whether you have a real gap, what it would cost to close, and whether you need us at all. We respond within one business day.

References to ABA Formal Opinions on this page are general descriptions and are not a substitute for reading the opinions or consulting counsel. Nothing here forms an advisory or client relationship.