An email in your firm's name can be forged. Clients wire money on it.
Retainer requests, trust-account transfers and closing-day wires all travel by email. We read what anyone can see about your law firm from outside, and tell you which opening to close first.
Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before you see it.
Three reporting deadlines law firms should know.
Notify affected New York residents after discovering a breach of their private information.
Tell current clients when a breach affects their information.
Report a breach that creates a real risk of significant harm to the Privacy Commissioner, and tell the people affected.
A summary of published rules, not legal advice. The Rules and Insurance Briefing names the rules that apply to your firm.
This week, in and around law firms: what attackers used, and what we check for it.
Seven in ten professional firms cannot stop an email sent in their name
What the public records of law and accounting firms say about forged email, read from outside.
The full outside watch on your firm, the proof for every finding, and the fix.
We hand your IT provider the exact fix; for forged email we close it in one click. Your evidence pack: an owner summary, the technical evidence for your IT provider, a rules and insurance briefing, and a signed assessment record.
See what is open before anyone else does.
We read your firm from outside and tell you first, with proof you can check. No access, nothing tested, no obligation.
- We read your firm from outside.
- We tell you first, with proof you can check.
- If it is worth it, you order.
What happens if you go ahead. More at getleaktrace.com/see-it-first/.
Read the transcript
- 72 hours. One domain. Nothing to install.
- What happens in the 72 hours of an External Cybersecurity Assessment.
- You confirm the scope: one domain, your firm's. Nothing to install, no access to give.
- We read what anyone can see from outside: mail records, look-alike domains, staff addresses in monitored breach databases, website software, sign-in pages. We log into nothing.
- A person checks every finding and approves the release. Each one comes with a check anyone can run.
- Three documents and a signed summary: the Owner Summary, the Technical Evidence for your IT provider, the Rules and Insurance Briefing, and the Signed Assessment Record.
- Your IT provider gets the exact fix for each finding; we re-check until it is closed. A 10-minute walkthrough, and the first month of monitoring, are included.
- Inside 72 hours of confirmation.