PROTECT CLIENT
TRUST.
A firm holds several clients' secrets at once, separated by matter-level permissions that were configured years ago. We test those boundaries, the mailboxes that authorise payments, and the systems holding the work product.
THE PROFESSIONAL SERVICES THREAT MODEL
You hold your clients' worst secrets, aggregated
A firm advising on a transaction holds material non-public information about several parties at once. That concentration makes an advisory firm a more efficient target than any single client. The adversary wants the deal.
The boundary is per-matter, not per-organisation
Access control here is unusually fine-grained: ethical walls, matter-level permissions, conflicts screening, and information barriers between teams in the same office. These are enforced in document management configuration, which drifts, and are rarely tested as security controls.
Payment instructions are the product being forged
Completion funds, settlement payments and invoices move on the strength of an email from a partner. Business email compromise targets the mailbox and the reply chain, and succeeds against firms with otherwise sound infrastructure.
WHAT DRIVES THE REQUIREMENT
For a professional-services firm, testing is rarely optional. Confidentiality duties, client outside-counsel guidelines and the sensitivity of the content all assume the systems have been adversarially tested.
Professional conduct obligations
Duties of confidentiality and competence (ABA Model Rule 1.6(c) and Formal Opinions 477R and 483 in the US, plus equivalent regulator guidance elsewhere) require reasonable efforts to protect client information and to respond to breaches.
Client outside counsel guidelines
Corporate clients increasingly impose security schedules on their advisers, including independent testing and the right to audit. The obligation arrives through the engagement letter.
SOC 2 and ISO 27001
Common demands from institutional clients running vendor risk programmes against their advisory panel.
Breach notification regimes
Client PII in matter files brings the firm within general data protection and notification law, alongside any duty to inform affected clients.
WHAT WE TEST
Document management & matter boundaries
- DMS access control testing (iManage, NetDocuments, SharePoint)
- Cross-matter and cross-client document retrieval attempts
- Ethical wall and information barrier enforcement in practice, not policy
- Client and deal portal authentication and tenant isolation
- Metadata, version history, and audit log exposure
Email compromise & payment fraud
- Domain spoofing, look-alike registration, and DMARC / SPF / DKIM enforcement
- Reply-chain hijacking and mailbox rule persistence
- Targeted phishing against partner and finance mailboxes, with prior authorisation
- Payment instruction verification procedure testing
- Conditional access and legacy authentication bypass in Microsoft 365
Privileged data & third-party access
- Identity attack paths to systems holding privileged material
- Remote access, VPN, and virtual desktop assessment
- Data loss prevention effectiveness against realistic exfiltration
- Encryption at rest and in transit across DMS, mail, and backups
- Vendor, e-discovery provider, and outsourced IT access review
HOW WE WORK
Machine-speed testing in an environment where the content itself is privileged. A human is accountable for what is attempted, what is reached and what is reported.
Privilege-aware scoping
Map practice areas, matter types, and data classification before touching anything, and agree with general counsel exactly which systems and which content are in bounds.
Threat modelling
Adversaries specific to advisory work: deal-motivated intrusion, extortion groups that publish stolen matter files, and payment fraud operators working the reply chain.
Agentic exploitation
Agent swarms work document management, portals, email and identity in parallel. Access boundaries are proved by crossing them with permissions, never by reading client content.
Evidence for partners and for IT
Findings mapped to the conduct obligations and client security schedules that apply, with an executive summary for the managing partner and a technical report for IT.
WHAT YOU RECEIVE
WHEN FIRMS BREAK
Public disclosures worth reading closely. In each case the leverage came from whose information the firm held, not from the firm's own size.
Grubman Shire Meiselas & Sacks
2020REvil operators exfiltrated hundreds of gigabytes of entertainment client files, then published them in stages to force payment.
Extortion leverage came from the sensitivity of the client list, not from the firm's own balance sheet.
Campbell Conroy & O'Neil
2021Ransomware against a defence litigation firm exposed client PII across a corporate client base including major manufacturers.
Notification obligations ran to the firm's clients' customers, several parties removed from the intrusion.
Accellion FTA, multiple firms
2021Zero-day exploitation of a legacy managed file transfer appliance used by law firms and their clients to exchange large matter files.
A single end-of-life transfer product placed dozens of unrelated firms in the same breach.
Conveyancing and completion fraud
OngoingA long-running pattern in which attackers monitor a compromised mailbox and intercept the moment funds are due, substituting account details in an existing thread.
Losses fall on the firm and its insurer. No malware is required and network controls never engage.
FREQUENTLY ASKED
How do you handle privileged material during testing?+
We test permissions, not content. Proving that a matter boundary can be crossed requires retrieving a document identifier and confirming access, not reading the file. Scope, evidence handling, and any content we may open are agreed with general counsel in writing before testing begins, and we work under a confidentiality agreement throughout.
Can you test the DMS without disrupting live matters?+
Yes. Where the platform supports it we test against a dedicated tenant or a restored copy. Against production we use non-destructive techniques, never modify or delete matter content, and hold an open channel to pause testing immediately.
Do your reports address our professional conduct obligations?+
They provide evidence of what was tested and what was found, which is the substantive part of demonstrating reasonable efforts under obligations such as ABA Model Rule 1.6(c). Whether that is sufficient for your regulator and your insurer is a judgement for the firm and its counsel, and we will not claim otherwise.
Can you simulate business email compromise against partners?+
Where the firm authorises it in writing. Simulations replicate the techniques actually used against advisory firms (look-alike domains, reply-chain hijacking, payment instruction substitution) and report outcomes at campaign level, with the technical and procedural controls that would have stopped each one.
Find out whether your matter boundaries actually hold
Tell us how your document management and information barriers are configured. Scoping runs through your general counsel.