Still have questions?
Speak to our team
Law firms invest significant time and money protecting their own systems, data and training that people to ensure their data and their client data is safe. However, one of the biggest cyber security risks often sits outside of the firm.
Every supplier you work with has the potential to introduce risk into your business.
From outsourced IT providers and legal software suppliers to document management platforms, accountants and marketing agencies, suppliers often have access to confidential information, business systems or privileged accounts. If those suppliers don’t have robust cyber security controls and governance in place, your firm could be exposed to unnecessary risk.
Cyber resilience is no longer just about protecting your own organisation. It’s about understanding and managing the security of every organisation that supports your business.
Why supplier assurance mattersModern law firms depend on many third party suppliers, even smaller firms and many of them organisations process sensitive or confidential information or provide services that are critical to the day to day operations of the firm.
If one of those suppliers suffers a cyber attack, operational failure or a data breach, the impact can quickly extend to your firm.
Supplier assurance is the process of assessing whether those organisations have appropriate cyber security controls, governance and resilience measures in place before granting them access to your systems, confidential information or you being otherwise reliant on their services.
It’s about reducing risk before problems occur rather than reacting afterwards.
Every supplier should be assessed, but some deserve much closer scrutiny than others.
Practice management software providers, other cloud software, hosting and virtual desktop providers and IT support companies often have privileged access to your systems or process highly sensitive client information on your behalf.
The more access a supplier has, the greater the potential impact if their own security is compromised. These technology providers therefore require an additional level of scrutiny.
Questions you should be asking include:
Of all your suppliers, your IT support provider is likely to hold the highest level of trust.
They often have:
In many cases, they have more privileged access to your systems than anyone within your own organisation.
That means their cyber security standards become an extension of yours. If their security is anything less than the gold standard, your firm’s security is compromised.
Your IT partner should be able to clearly demonstrate how they protect both their own business and yours.
Additional areas worth discussing include:
Check out our Supplier Cyber Security Due Diligence Checklist for Law Firms to understand why these questions are important, how to ask them and more.
Many firms carry out due diligence when appointing a supplier but rarely review them afterwards.
Cyber threats evolve continuously, as do businesses. A supplier that met your expectations three years ago may have changed ownership, adopted new technologies or experienced security incidents that alter their risk profile. At the same time new cyber threats will have changed both their and your risks.
Supplier assurance should form part of your firm’s ongoing governance programme, with regular reviews of critical suppliers to ensure standards remain appropriate.
By carrying out regular supplier assurance reviews, particularly for technology providers and IT support partners, law firms can reduce risk, strengthen governance and demonstrate a proactive approach to protecting client information.
At Pro Drive IT, we work with law firms across London, the Home Counties and the South East to build secure, resilient IT environments, while helping them strengthen governance across their wider technology supply chain.
For our clients, cyber security is not just about technical controls. Our service includes providing templates and automation to help our clients build resilient policies and facilitate risk assessments in and audits. We provide assets to help with tender a proposal due diligence and assistance responding to questionnaires.
Of course making it easy to for our clients to demonstrate the resilience of their IT support provider. That’s why Pro Drive has committed to following the Cyber Assessment Framework and in on the journey to achieving the Assurix certification.
https://prodriveit.co.uk/wp-content/uploads/Checklist-Download-Graphic-selection.png
If you are not sure how to start you supplier cyber risk review process, Pro Drive can give you a helping hand.
Download the Pro Drive cyber security due diligence checklist for law firms to find out the questions you should be asking your supplier, why the controls are important for a law firm, the risks of not doing it and what good looks like.
Download checklist
Speak to our team