Industry
Law firms
A firm's obligation to protect client information is an ethical duty rather than a policy preference, and it does not distinguish between a breach caused by an attacker and one caused by a misconfigured folder. That framing changes how access, retention and client exchange should be set up.
The weakest link in most firms
Email attachments
for client document exchange
A portal removes the problem. Most document management systems already include one, unused.
Six priorities specific to a firm
| Priority | Nature |
|---|---|
| ConfidentialityAccess controls must reflect matter level need to know, not firm wide access | Ethical duty, not just policy |
| Document managementVersioning, retention and search matter as much as availability | The firm's entire product |
| Retention and legal holdDeleting the wrong thing is a worse outcome than storing too much | Contractual and ethical |
| Client data exchangeEmail attachments remain the default and remain the weakest link | Daily |
| Client security questionnairesCorporate clients audit their firms. Answers must be accurate | Increasingly common |
| Mobile and remote workCourt, client site and home. Data leaves the office continuously | Constant |
What a client questionnaire asks
These six appear on almost every corporate client security addendum. Each needs a truthful answer and evidence behind it.
- Multi factor authentication on email and remote access
- Encryption of devices and of data at rest
- Documented incident response and breach notification process
- Background checks and confidentiality agreements for staff with data access
- Vendor management, including what your IT provider can access
- Evidence of security awareness training with recorded completion
Access should follow the matter
Most small firms run flat access: everyone can open everything, because it is convenient and because the firm trusts its people.
Trust is not the issue. Ethical walls are, conflicts are, and so is the practical reality that a single compromised account with access to everything exposes every client rather than one.
Matter level access takes some setting up and then largely runs itself. It also makes the answer to a client questionnaire considerably more comfortable, and it is the difference between an incident affecting one matter and one requiring notification across the whole client base.
Common questions
Answered before you ask.
Is email good enough for sending client documents?
It is the default and it is the weakest part of most firms' setup. Email is fine for correspondence and poor for anything sensitive: it lands in inboxes nobody controls, forwards silently, and persists indefinitely. A secure client portal removes the problem for document exchange and most document management systems include one. Where email must be used, encryption and expiry controls in Microsoft 365 are usually already licensed and rarely switched on.
Do we need to worry about client security questionnaires?
If you act for corporate clients, institutional lenders or insurers, expect them. They arrive as a condition of panel membership or of a specific engagement, and they ask concrete questions about controls rather than general assurances. The practical issue is not usually whether a firm can meet the requirements but whether it can evidence them. Answering optimistically is the genuine risk, because an inaccurate answer that surfaces after an incident is a contractual problem on top of a security one.
How should retention work?
Deliberately, and this is worth an afternoon with someone who understands both the technology and the firm's obligations. The common failure is a retention policy written in a document and never implemented in the systems, so nothing is ever deleted and legal hold is applied by asking people not to delete things. Retention configured in the document management system, with hold applied at matter level, removes the reliance on individual memory.
Our practice management vendor hosts everything. Is that enough?
It covers their platform. Your workstations, network, identities, email and mobile devices remain yours, and each is a route to client information. Hosted practice management narrows the scope of what needs managing and does not remove the confidentiality obligation, which attaches to the firm regardless of where the data physically sits.
Related
What this sector usually needs first.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Security awareness training
Phishing simulation and short, frequent training that changes behaviour.
Accounting and CPA firms
FTC Safeguards, WISP, tax season uptime
Get an access and exchange review.
Who can reach which matters, how client documents leave the firm, and what a client questionnaire would find. Written findings either way.