Industries
Law Firms
Confidentiality is not a preference in a law firm, it is an obligation — and increasingly your clients audit it before they instruct you.
What makes this different
The problems specific to your sector
Not a generic list. These are the things that come up repeatedly in this kind of business.
Clients now ask security questions first
Corporate clients send security questionnaires before engagement. Firms that cannot answer them lose the work to firms that can.
Everything of value is in one place
Case files, discovery material and client funds information sit together. A single compromised mailbox can expose all of it.
Wire fraud is aimed directly at you
Real estate and settlement work makes firms a standing target for payment-redirection fraud, which usually starts with a spoofed or compromised email account.
Deadlines do not move for outages
A filing deadline is not extended because your document management system was unavailable.
Compliance
What you are actually required to do
Named obligations rather than the word 'compliance'. If one of these does not apply to you, we will say so.
Confidentiality duties
Professional conduct rules require reasonable efforts to prevent unauthorised disclosure of client information.
Client security questionnaires
Increasingly contractual: MFA, encryption, backup and incident response are the standard asks.
Trust account controls
Payment instruction changes need out-of-band verification, which is a process control as much as a technical one.
Your software
We expect to find these
We work around your line-of-business software rather than asking you to change it, and we deal with the vendor when needed.
- Clio
- MyCase
- PracticePanther
- Worldox
- NetDocuments
- Tabs3
- Adobe Acrobat
Recommended
Where we would start
Cybersecurity Services
Layered defence built around how small businesses actually get breached: email, credentials and unpatched endpoints.
Managed IT Services
Proactive monitoring, patching and unlimited help desk for a flat monthly fee — so problems are fixed before they reach your staff.
Backup & Disaster Recovery
Backups that are tested on a schedule, with a recovery time you have actually seen demonstrated — not assumed.
Microsoft 365 Management
Licensing, migration, hardening and day-to-day administration of Microsoft 365 — including the security settings that ship switched off.
Questions
Common questions
How do we stop wire fraud?
Technically: DMARC so nobody can spoof your domain, MFA so accounts cannot be taken over, and blocking mailbox auto-forwarding rules — the trick attackers use to watch a matter quietly. Procedurally: verify every change of payment instructions by phone on a previously known number, never one supplied in the email.
Can you help with a client security questionnaire?
Yes. They map onto a predictable set of controls, and we produce the evidence as well as the answers.
Is Microsoft 365 acceptable for client data?
Yes, when configured properly — which means MFA, conditional access, restricted external sharing, audit retention and independent backup. The platform is not the risk; the default configuration is.
Ready to secure your business?
A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.