We keep law firms insurable.
Cyber insurance renewals, client security audits, and ABA Opinion 483 duties, answered by an independent assessor. Fixed scope, fixed fee, one week to your first answer.
For firms of 10 to 150 attorneys and legal operations teams. Based in Chicago, working with firms across Illinois and nationally.
If any of these is on your desk, we should talk.
Your cyber insurance renewal questionnaire
The form is not paperwork. It is the document the carrier’s claims team reads after an incident, checking whether your answers were accurate. An unverified yes about MFA or tested backups is a coverage risk hiding in plain sight.
A client’s security audit
Corporate and insurance clients attach security requirements to outside counsel guidelines and audit against them, usually on a 60 to 90 day clock, usually at firms with nobody assigned to answer.
ABA Formal Opinion 483
Lawyers have a duty to monitor for breaches and, where material client confidential information is involved, to notify affected current clients under Model Rule 1.4. For former clients the ethics duty is narrower, though privacy statutes, common law duties, or your own retention agreements may still require notice. Most of what a firm holds is closed matters, so the notification analysis has to cover both.
Whoever runs IT cannot be the one who verifies it.
In most firms this size, the same party designs the environment, operates it, and reports on whether it works. Internal, outsourced, or one of each. The model does not matter. Self-assessment is not independent verification, and the audiences asking the question are the ones who care about that distinction: a carrier deciding what it will cover, and a client deciding whether your firm meets its outside counsel guidelines.
This is not a judgment about competence. The people running your systems are usually good at running your systems. They are simply being asked to confirm their own work to an audience that specifically needs the answer to come from someone who does not operate the environment being judged.
We take no vendor commissions or referral fees, and we resell no hardware, software, or managed IT to assessment clients. We do not take over your IT. Whoever runs your environment keeps running it, including through a Remediation Sprint, where your provider does the work and we run the plan and verify the result. What we sell you is the verification, in writing, that your environment does what your carrier and your clients have been told it does.
Where privilege matters, engage us through your counsel.
Deliverables belong to the firm. Where you want the assessment covered by attorney-client privilege, we can be engaged through your outside counsel rather than directly. That decision has to be made before the engagement letter is signed, not after the report exists.
Four fixed-fee engagements. Start wherever the deadline is.
Prices shown are launch pricing for the legal practice, available through December 31, 2026.
Insurance Readiness Assessment
We verify your environment against your carrier's actual questionnaire and hand you evidence-backed answers, a gap register, and a 90-day fix plan, before underwriting sees the form.
Book a callLaw Firm Resilience Audit
Documented evidence of what recovers, how fast, and what does not. Business impact analysis, a supervised test restore, DR and governance review, mapped to Opinions 483 and 477R and to your clients' outside counsel guidelines.
Book a callRemediation Sprint
The red findings closed, with before and after evidence, ahead of your renewal or audit deadline. The base covers coordination, evidence capture, and re-verification of up to six findings. Anything beyond that is quoted against your gap register or billed at $190 an hour. Your provider does the work where it is theirs to do. We run the plan and confirm the result.
Book a callManaged Resilience Program
Quarterly tested restores and a signed Resilience Attestation your carrier and your clients can rely on. Findings are re-verified, not assumed. Includes up to four hours of advisory each month and support on one renewal questionnaire a year. Incident response is quoted separately.
Book a callCan You Prove It?
The 10 cyber questionnaire answers carriers verify after a claim.
Send us your details and your renewal or audit date. You get the guide, and a straight answer on whether your date leaves room to close what it turns up. Have a question instead? Same form.
Peter Schabinger
IT Audit & BCDR, GroupA LLC
- Commvault Master
- MCSE
- MCSA
Over a decade at Commvault Systems, including time as a Resident Support Engineer embedded with enterprise customers across healthcare, financial services, and biotech. That is the difference between an assessor who reads your documentation and one who has watched restores fail in production and knows why.
Peter leads IT audit and BCDR engagements for PE-backed portfolio companies at GroupA, delivering infrastructure and cybersecurity assessments, business impact analyses, and remediation frameworks to executive and investor stakeholders. The law firm practice applies the same method on a smaller footprint and a fixed fee.
The person you meet does the work. No hand-off to a delivery pool.
A finding is specific, or it is not a finding.
Backups complete nightly. Recovery has never been tested.
Nightly jobs report success across all servers, and the firm’s renewal questionnaire answers yes to tested backups. No restore has been performed since the platform was installed. Job success confirms data was written. It does not confirm data can be read back, that the document management database returns to a consistent state, or how long that takes.
- Maturity
- Defined, not verified
- Exposure
- Questionnaire answer cannot be evidenced at claim time.
- Fix
- Supervised restore of the document management system to isolated infrastructure. Record actual recovery time against the stated objective.
- Owner
- Named in the report. Every finding has one.
- Effort
- One day, provider-led, GroupA supervising.
Illustrative excerpt, composed for this page. Every finding in a live report is scored on the same fixed 1 to 4 maturity scale, so your second audit is comparable to your first.
Questions partners ask first
We already have IT handling this.
They probably handle most of it well, and this does not replace them. Internal team, outside provider, or both — the issue is the same: when a carrier or a corporate client asks whether your controls actually work, an answer from the party that built those controls carries less weight than one from a party that does not operate them. We do not operate your environment, we take no vendor commissions or referral fees, and we resell nothing to assessment clients. We work alongside your team, not around them, and they see every finding before your partners do.
Our IT provider offered to do this for free.
They may well be capable of the work. The question is who the answer is for. A carrier at claim time, and a corporate client auditing against its outside counsel guidelines, are both asking for a review by a party with no stake in the result. An assessment performed by the party that built and maintains the environment does not answer that question, however good the work is. If your provider is offering, take it. It will make our engagement shorter. It will not replace it.
How much partner and staff time does this take?
For the Insurance Readiness Assessment, roughly two hours total: a scoping call, a short interview with whoever owns IT, and read access to your environment. The Resilience Audit adds a half day, most of it observing a test restore your provider performs.
What happens if you find something serious?
You get it in writing with a named owner, an effort estimate, and a fix sequence, and you get it before a carrier or a client finds it. A documented gap with a dated remediation plan is a defensible position. An undocumented one is not.
Do you sell the software or the fix?
No. We take no vendor commissions or referral fees, and we do not resell hardware, software, or managed IT to assessment clients. The Remediation Sprint runs the plan and verifies the result. Your provider does the work that is theirs.
Tell us what your carrier or your client is asking for.
Twenty minutes, no slideware. You will leave the call knowing whether you have a real gap, what it would cost to close, and whether you need us at all. We respond within one business day. We are Chicago based and work with firms across Illinois and nationally.
References to ABA Formal Opinions on this page are general descriptions and are not a substitute for reading the opinions or consulting counsel. Nothing here forms an advisory or client relationship. GroupA LLC does not place, broker, or underwrite insurance, and does not guarantee any coverage or claims outcome.
