Photo: Iñaki del Olmo / Unsplash

Case Study · Legal

International Law Firm

  • Legal Privilege
  • BEC
  • Client Audit
  • 9 weeksFrom assessment to passed audit
  • 3Client questionnaires met with evidence
  • −85%Clicks on targeted phishing simulations

The challenge

An international law firm, with offices across several jurisdictions, held case files for corporate clients who had begun to require contractual security guarantees. Three key clients had announced a supplier security audit, with the right to verify the measures protecting case data.

The risk was not theoretical: partners were receiving targeted phishing and BEC messages built around counterparty names, aimed at diverting payment instructions and exfiltrating privileged documents. A single mistake could have compromised a mandate and the firm’s reputation.

My approach

I mapped where case data lived and who accessed it, then hardened the essentials: phishing-resistant multi-factor authentication, segmentation of files by mandate, and encryption at rest and in transit. Information classification was aligned to legal privilege obligations.

For phishing and BEC I combined technical controls — email authentication, anti-impersonation rules, out-of-band verification of payment instructions — with targeted simulations and short training for partners and assistants, the most exposed group.

Finally I prepared the firm for audit: an evidence pack mapped to the clients’ recurring questions, so the three mandators’ requests were met with verifiable documentation rather than reassurance. The audit was passed with no blocking findings.

A similar situation?

Start with a confidential briefing.

Book a consultation