Skip to content
// Industries

Regulated, deadline-bound, and allergic to downtime.

Confidentiality is an obligation, not a policy.

Your duty to a client does not distinguish between a leaked file and a leaked mailbox. Document management, email and time recording are the systems that carry that duty, so those are the ones we build around.

The most expensive thing that happens to a small firm is a wire that went to the wrong account.

Business email compromise targets legal practices specifically, because the profession moves large sums against emailed instructions and works to deadlines that discourage a second phone call. Almost every case follows the same route: a mailbox is accessed with a stolen password, correspondence is watched quietly, and a genuine invoice is intercepted and reissued with different banking details.

01 · What actually breaks

Five failures that cost firms money.

Ranked by what they actually cost, not by how often they are mentioned in a brochure.

Law Firms IT failures, their cause, and the fix
Failure Why it happens here What we do about it
01Invoice fraud via a watched mailbox Why it happens hereA password reused elsewhere, no MFA, and correspondence monitored for weeks before a payment is redirected What we do about itMFA everywhere, impersonation rules, DMARC enforced, and a payment-verification habit written into policy
02Document management goes down on a filing day Why it happens hereOne server, no tested restore, and a deadline that does not move What we do about itLocal image plus immutable off-site copy with a quarterly restore test
03Departed staff still have access Why it happens hereOffboarding is a manual list somebody keeps in their head What we do about itIdentity-driven offboarding — one action removes access everywhere, and it is logged
04Client files on personal devices Why it happens hereWorking from home became permanent without anyone deciding it What we do about itManaged devices with encryption and conditional access, so unmanaged hardware simply cannot reach the file store
05Retention that does not match the by-laws Why it happens hereEverything kept forever, or purged on a default nobody chose What we do about itRetention configured against your actual obligation and applied to backups as well as live data

Four of these five are identity problems wearing different clothes. That is why identity is where a legal engagement starts.

02 · Confidentiality

Four controls that carry the duty.

Professional obligation is not satisfied by a privacy policy. It is satisfied by controls that can be demonstrated after the fact.

The security stack
A lawyer and client across a desk, with orderly case files and shelves of documents behind them.
01

MFA on every account, without exception

The single control that defeats most mailbox compromise. Partners are the most-targeted accounts and the ones most often exempted — we do not exempt them.

02

Mail authentication actually enforced

SPF, DKIM and DMARC published and set to reject, so a spoofed message from your own domain does not reach a client.

03

Conditional access by device and location

A managed laptop signs in normally. An unknown device from elsewhere does not, regardless of whether the password is correct.

04

Logging that answers questions later

If a mailbox is ever questioned, the difference between a contained incident and a notification is whether you can show what was accessed and when.

03 · The matter lifecycle

Where technology touches the file.

Five points where an estate either supports the work or gets in its way.

Intake

Conflicts and onboarding

New matter, new client, new access. Permissions set at this point are the ones that persist for years.

Active

Document work

Version control, co-authoring and search. The one workload where slow storage becomes billable time lost.

Ongoing

Correspondence

Where the money risk lives. Every payment instruction that leaves here is a target.

Deadline

Filing

The estate must hold. Maintenance never runs near a known filing date.

Close

Retention

Archived under the correct retention rule, discoverable, and eventually disposed of deliberately.

// The unglamorous control that works

Verify banking details by telephone, using a number you already held, for every change of payment instruction — no exceptions for urgency, and no exceptions for a partner. Technology reduces the odds of a compromised mailbox; that one habit is what stops the loss when the odds fail.

04 · What we recommend

For a firm, in this order.

First Identity and mail security. MFA, conditional access and DMARC. This is where the money is lost, so it is where the work starts.
Second Backup & recovery. Tested restores for document management and mail, because a filing deadline does not accept an explanation.
Third Managed IT. One owner for patching, monitoring and the vendor calls, with maintenance kept away from filing dates.
Ongoing Microsoft 365. Retention, offboarding and device compliance — the administrative half of the professional duty.

Firms usually arrive here after a near miss. The ones who arrive before it pay considerably less for the same outcome. Further reading for firms: how invoice-redirection fraud actually works, and the controls insurers now ask about at renewal. The layers behind this list are the email gateway, EDR and Sophos MDR.

05 · Questions

The ones firms actually ask.

If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.

We work alongside it rather than reselling one. Most of the common practice platforms are fine; what matters is that authentication, backup and retention are configured deliberately rather than left at defaults.

Layered: MFA so mailboxes are harder to enter, impersonation rules and DMARC so spoofed mail is rejected, and a verification-by-phone habit for any change of banking details. The last one is policy, not technology, and it is the one that actually stops the loss.

Yes, on managed devices. Conditional access means a compliant laptop signs in normally and an unmanaged one cannot reach client files at all, which is a cleaner answer than a VPN and a hope.

Configured against your actual obligation rather than a default, and applied to backup copies as well as live data — the copy that people forget exists when they say a file has been destroyed.

Yes, as a matter of course. We also work to the principle of least access: engineers see what the work requires and nothing else, and that is enforced technically rather than promised.

The file stays privileged.

Twenty minutes. Tell us how your firm handles payment instructions today — that one answer tells us most of what we need to know.