Confidentiality is an obligation, not a policy.
Your duty to a client does not distinguish between a leaked file and a leaked mailbox. Document management, email and time recording are the systems that carry that duty, so those are the ones we build around.
The most expensive thing that happens to a small firm is a wire that went to the wrong account.
Business email compromise targets legal practices specifically, because the profession moves large sums against emailed instructions and works to deadlines that discourage a second phone call. Almost every case follows the same route: a mailbox is accessed with a stolen password, correspondence is watched quietly, and a genuine invoice is intercepted and reissued with different banking details.
Five failures that cost firms money.
Ranked by what they actually cost, not by how often they are mentioned in a brochure.
| Failure | Why it happens here | What we do about it |
|---|---|---|
| 01Invoice fraud via a watched mailbox | Why it happens hereA password reused elsewhere, no MFA, and correspondence monitored for weeks before a payment is redirected | What we do about itMFA everywhere, impersonation rules, DMARC enforced, and a payment-verification habit written into policy |
| 02Document management goes down on a filing day | Why it happens hereOne server, no tested restore, and a deadline that does not move | What we do about itLocal image plus immutable off-site copy with a quarterly restore test |
| 03Departed staff still have access | Why it happens hereOffboarding is a manual list somebody keeps in their head | What we do about itIdentity-driven offboarding — one action removes access everywhere, and it is logged |
| 04Client files on personal devices | Why it happens hereWorking from home became permanent without anyone deciding it | What we do about itManaged devices with encryption and conditional access, so unmanaged hardware simply cannot reach the file store |
| 05Retention that does not match the by-laws | Why it happens hereEverything kept forever, or purged on a default nobody chose | What we do about itRetention configured against your actual obligation and applied to backups as well as live data |
Four of these five are identity problems wearing different clothes. That is why identity is where a legal engagement starts.
Four controls that carry the duty.
Professional obligation is not satisfied by a privacy policy. It is satisfied by controls that can be demonstrated after the fact.
The security stack
MFA on every account, without exception
The single control that defeats most mailbox compromise. Partners are the most-targeted accounts and the ones most often exempted — we do not exempt them.
Mail authentication actually enforced
SPF, DKIM and DMARC published and set to reject, so a spoofed message from your own domain does not reach a client.
Conditional access by device and location
A managed laptop signs in normally. An unknown device from elsewhere does not, regardless of whether the password is correct.
Logging that answers questions later
If a mailbox is ever questioned, the difference between a contained incident and a notification is whether you can show what was accessed and when.
Where technology touches the file.
Five points where an estate either supports the work or gets in its way.
Conflicts and onboarding
New matter, new client, new access. Permissions set at this point are the ones that persist for years.
Document work
Version control, co-authoring and search. The one workload where slow storage becomes billable time lost.
Correspondence
Where the money risk lives. Every payment instruction that leaves here is a target.
Filing
The estate must hold. Maintenance never runs near a known filing date.
Retention
Archived under the correct retention rule, discoverable, and eventually disposed of deliberately.
Verify banking details by telephone, using a number you already held, for every change of payment instruction — no exceptions for urgency, and no exceptions for a partner. Technology reduces the odds of a compromised mailbox; that one habit is what stops the loss when the odds fail.
For a firm, in this order.
Firms usually arrive here after a near miss. The ones who arrive before it pay considerably less for the same outcome. Further reading for firms: how invoice-redirection fraud actually works, and the controls insurers now ask about at renewal. The layers behind this list are the email gateway, EDR and Sophos MDR.
The ones firms actually ask.
If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.
We work alongside it rather than reselling one. Most of the common practice platforms are fine; what matters is that authentication, backup and retention are configured deliberately rather than left at defaults.
Layered: MFA so mailboxes are harder to enter, impersonation rules and DMARC so spoofed mail is rejected, and a verification-by-phone habit for any change of banking details. The last one is policy, not technology, and it is the one that actually stops the loss.
Yes, on managed devices. Conditional access means a compliant laptop signs in normally and an unmanaged one cannot reach client files at all, which is a cleaner answer than a VPN and a hope.
Configured against your actual obligation rather than a default, and applied to backup copies as well as live data — the copy that people forget exists when they say a file has been destroyed.
Yes, as a matter of course. We also work to the principle of least access: engineers see what the work requires and nothing else, and that is enforced technically rather than promised.
Next
The file stays privileged.
Twenty minutes. Tell us how your firm handles payment instructions today — that one answer tells us most of what we need to know.