Skip to content

Industries

Law Firms

Confidentiality is not a preference in a law firm, it is an obligation — and increasingly your clients audit it before they instruct you.

What makes this different

The problems specific to your sector

Not a generic list. These are the things that come up repeatedly in this kind of business.

  • Clients now ask security questions first

    Corporate clients send security questionnaires before engagement. Firms that cannot answer them lose the work to firms that can.

  • Everything of value is in one place

    Case files, discovery material and client funds information sit together. A single compromised mailbox can expose all of it.

  • Wire fraud is aimed directly at you

    Real estate and settlement work makes firms a standing target for payment-redirection fraud, which usually starts with a spoofed or compromised email account.

  • Deadlines do not move for outages

    A filing deadline is not extended because your document management system was unavailable.

Compliance

What you are actually required to do

Named obligations rather than the word 'compliance'. If one of these does not apply to you, we will say so.

  • Confidentiality duties

    Professional conduct rules require reasonable efforts to prevent unauthorised disclosure of client information.

  • Client security questionnaires

    Increasingly contractual: MFA, encryption, backup and incident response are the standard asks.

  • Trust account controls

    Payment instruction changes need out-of-band verification, which is a process control as much as a technical one.

Your software

We expect to find these

We work around your line-of-business software rather than asking you to change it, and we deal with the vendor when needed.

  • Clio
  • MyCase
  • PracticePanther
  • Worldox
  • NetDocuments
  • Tabs3
  • Adobe Acrobat

Questions

Common questions

How do we stop wire fraud?

Technically: DMARC so nobody can spoof your domain, MFA so accounts cannot be taken over, and blocking mailbox auto-forwarding rules — the trick attackers use to watch a matter quietly. Procedurally: verify every change of payment instructions by phone on a previously known number, never one supplied in the email.

Can you help with a client security questionnaire?

Yes. They map onto a predictable set of controls, and we produce the evidence as well as the answers.

Is Microsoft 365 acceptable for client data?

Yes, when configured properly — which means MFA, conditional access, restricted external sharing, audit retention and independent backup. The platform is not the risk; the default configuration is.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.