Skip to content
Tidebreak Advisory

For law firms

An assessment your partners can read.

Tidebreak performs a practitioner-grade assessment of your firm's IT environment, mapped to the security framework your insurers and auditors already recognize and to the professional conduct rules your managing committee already follows.

CIS CONTROLS v8.1.2 × ABA MODEL RULES

What the rule actually asks for

The ABA Model Rules do not read like a technical standard, but Model Rule 1.6(c) asks for reasonable efforts to prevent inadvertent or unauthorized disclosure, and Model Rule 5.3 extends supervisory obligations to the firm's IT provider. Most states' conduct rules mirror these obligations. Cyber insurance carriers translate them into control questions. Your outside auditor translates them into workpaper requests. A firm can meet all three at once, or it can meet one and hope the other two are forgiving. A Tidebreak assessment is built to meet all three.

How the obligation runs through the firm

The obligation is not abstract once you trace it through the firm. Model Rule 1.1 Comment 8 made technological competence part of the duty of competence, which means the partnership cannot treat the IT environment as someone else's department. Rule 1.6(c) does not require any particular product or configuration; it asks for reasonable efforts, judged against what a similar firm in similar circumstances would do. That standard is the reason a documented, independent reading of the environment matters more than any single control. When a firm can show that it looked, that it understood what it found, and that it acted on it, the reasonableness question answers itself. When a firm cannot show that it looked, the absence is the finding.

Rule 5.3 is the part most firms underread. The supervisory obligation that applies to paralegals and contract reviewers applies with equal force to the managed service provider that holds standing access to the firm's systems. The MSP is a nonlawyer assistant whose conduct the firm is responsible for supervising, and supervision that exists only as a verbal understanding is not supervision a carrier or an auditor will credit. A named provider contact, a defined escalation path, and a periodic review of what the provider has actually done are the documentary form the rule expects. A Tidebreak assessment produces exactly that record, mapped to the safeguard and the rule at the same time, so the partnership can see both the control and the obligation in a single line.

What the finding set looks like in practice

What the assessment delivers, in practice, is a finding set your partners can read without translation and your IT provider can act on without a meeting to interpret it. Each finding cites the evidence behind it, the CIS Controls v8.1.2 safeguard it implicates, and the ABA Model Rule it touches, so the same document serves the managing committee, the outside auditor, and the provider who has to remediate. We test a risk-based sample rather than every control, we document why we sampled where we did, and we record what we observed against what the provider reported. The boundary is as clear as the scope. We describe exposure and recommend remediation; the firm and its counsel make every compliance and privilege determination that follows.

Worked example

From a 2026 assessment

Critical software vulnerability across the endpoint fleet, end-of-life software in daily use

CIS Safeguard 7.7 Remediate Detected Vulnerabilities · CIS Safeguard 2.2 Ensure Authorized Software is Currently Supported · ABA Model Rule 1.6(c), Rule 1.1 Comment 8, and Rule 5.3

The assessment found a critical-severity software vulnerability running across dozens of the firm's endpoints, alongside end-of-life software still in daily use. The IT provider administered the estate and had neither remediated the vulnerability nor retired the unsupported software, and no review had surfaced either to the partnership. Each item was mapped to the CIS safeguard it implicates and to the conduct rule it touches, with the evidence cited behind it.

This finding is drawn from a real 2026 law-firm assessment, anonymized to no firm name, no headcount, and no geography (decisions/0005). A critical vulnerability left unpatched across the fleet, and software the vendor no longer supports, are the kind of exposure Rule 1.6(c) treats as a failure of reasonable effort once the firm could have known. Because the IT provider administered the estate, Rule 5.3 places the supervisory obligation on the partnership: an unremediated critical vulnerability is not the provider's problem alone, it is the firm's to oversee. Rule 1.1 Comment 8 is why the partnership cannot treat that estate as someone else's department.

What Tidebreak does, and what it does not

A Tidebreak assessment delivers an Executive Report your managing committee can forward to your insurer and a Full Assessment Report your outside counsel and IT provider can work from. The methodology is documented procedurally and is the same assessment whether you engage us for a one-time Snapshot Scorecard, a Comprehensive Assessment, or an Ongoing Oversight retainer. See the methodology

Tidebreak is independent. Tidebreak is not your outside counsel, not a post-breach forensics firm, and not your managed service provider. We perform a practitioner-grade assessment of your IT environment. We do not substitute for your firm's own privilege-review process or for any legal advice your outside counsel provides.

Why this matters

For a law firm, the stakes of an IT gap are rarely measured in downtime. They are measured in the partnership's standing with the people who judge it. A cyber insurance carrier that asks for control evidence at renewal is deciding whether to write the policy and at what premium; a firm that can produce an independent assessment answers the underwriter's questions before they harden into exclusions. An outside auditor reviewing the firm's controls wants workpaper-grade documentation, not assurances. A client running its own vendor diligence increasingly sends a security questionnaire before sending the next matter, and the firm that can attach a framework-mapped reading is the firm that keeps the work. And at the partner level, the risk is personal: a conduct-rule exposure that surfaces after an incident is the kind of finding that follows a name, not just a firm. An independent assessment is how the partnership converts a question it cannot answer about itself into evidence it can hand to anyone who asks.

Who runs the assessment

We assess MSPs. I used to run one.

Jeff White has spent twenty-five years in the IT business. Enterprise infrastructure architecture. Eight years at Microsoft Consulting Services. Most recently, VP of Engineering Services at a mid-market MSP, where he built out the service delivery organization and a 24/7 security operations center from the ground up.

Now he works for you, not your provider. Tidebreak exists to give firms like yours a read most don't have a way to get: an independent look at whether the IT you pay for is actually the IT you're getting.

VP Engineering Services, MSP · 8 years Microsoft Consulting Services · Azure Solutions Architect Expert · Assessments mapped to CIS Controls v8.1.2 and NIST CSF 2.0

Schedule a scoping conversation