This document provides guidance for law firms on basic cyber security controls and governance. It recommends that firms start by understanding the risks to client information, intellectual property and billing systems. It also advises implementing cyber security best practices from frameworks like NIST and the SANS 20 critical controls. These controls address technical areas like device/software inventory, secure configurations, vulnerability management and more. The document suggests some enhanced protections for law firms, including cyber threat intelligence to monitor digital shadows and deception/decoy technologies to detect advanced threats that evade other defenses. It emphasizes that cyber security is important for maintaining client trust and demonstrates a firm's trustworthiness in today's environment where breaches are assumed.