Legal
You already have the strictest confidentiality obligation of any industry. It is rarely written down as a security program.
Legal organizations hold an unusual concentration of other people’s most sensitive material, under a professional duty that predates every framework anyone would map it to. What they frequently lack is the translation: the same duty expressed as controls, evidence and a named owner, in the form a client’s security team is asking for.
The pressure almost always arrives through clients. Large corporate clients audit their outside counsel now, and the questionnaire is the same one they send technology vendors.
What this sector is actually under
Client security audits
Corporate clients increasingly audit outside counsel and legal service providers on the same terms as software vendors. The questionnaire assumes a named security owner, a documented program and access controls you can evidence.
Systems that grew around the work
Document management, matter systems, email archives and file shares that accumulated over a long period, each with its own access model and its own history. Nobody designed the estate; it arrived.
Matter-level access control
Ethical walls and need-to-know are professional obligations before they are technical ones, and the technical implementation is usually the weaker of the two. Showing that a wall held is a different problem from declaring one.
Email is the attack surface
The profession runs on email, which is where the credential and payment-diversion attacks land. The identity layer is the part worth hardening first and the part most often left at its defaults.
Outside vendors holding client material
E-discovery providers, transcription, translation, cloud storage and now AI tooling, each holding privileged material under terms somebody agreed to once.
AI, arriving whether or not it was approved
Staff adopt assistants on their own and they work. The failure here is rarely a stalled pilot; it is successful adoption with no acceptable use policy, no inventory and no answer to a client asking what happens to their material.
Which side of the practice you need
If the pressure is a client audit or an undocumented program, that is the fractional CISO side.
If the estate itself is the problem, or a platform decision is coming, that is the CTO side. Firms with both usually have one person who has been absorbing both jobs alongside another role.
The two pillars
Where this usually starts
Questions I get asked first
Our IT is outsourced. Is that not covered?
A managed provider delivers services against a contract that is usually uptime and support. Deciding what those services must achieve, and verifying that they do, is a different job, and it cannot be the same supplier because it includes judging whether the first one is performing.
What do clients actually ask for?
A named security owner, a current risk assessment, access control and offboarding evidence, incident history and response arrangements, subprocessor lists, and increasingly a statement on AI tooling. Most of it is answerable; the difficulty is that it has never been assembled.
We had an incident and it is contained. What now?
The architecture and identity layer that allowed it are still in place, and closing that is a separate engagement from the response. Clients and insurers will ask what changed, and the answer needs to be a record rather than a list of intentions.
Written on this
Start with a conversation
Tell me what’s going on. I will tell you which of these it actually is, and whether you need me for it.
Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.
Not ready for a call? Send a message instead.
For companies looking to engage BATO. Vendors, please email.