Industry

Legal

You already have the strictest confidentiality obligation of any industry. It is rarely written down as a security program.

Legal organizations hold an unusual concentration of other people’s most sensitive material, under a professional duty that predates every framework anyone would map it to. What they frequently lack is the translation: the same duty expressed as controls, evidence and a named owner, in the form a client’s security team is asking for.

The pressure almost always arrives through clients. Large corporate clients audit their outside counsel now, and the questionnaire is the same one they send technology vendors.

The pressure

What this sector is actually under

Client security audits

Corporate clients increasingly audit outside counsel and legal service providers on the same terms as software vendors. The questionnaire assumes a named security owner, a documented program and access controls you can evidence.

Systems that grew around the work

Document management, matter systems, email archives and file shares that accumulated over a long period, each with its own access model and its own history. Nobody designed the estate; it arrived.

Matter-level access control

Ethical walls and need-to-know are professional obligations before they are technical ones, and the technical implementation is usually the weaker of the two. Showing that a wall held is a different problem from declaring one.

Email is the attack surface

The profession runs on email, which is where the credential and payment-diversion attacks land. The identity layer is the part worth hardening first and the part most often left at its defaults.

Outside vendors holding client material

E-discovery providers, transcription, translation, cloud storage and now AI tooling, each holding privileged material under terms somebody agreed to once.

AI, arriving whether or not it was approved

Staff adopt assistants on their own and they work. The failure here is rarely a stalled pilot; it is successful adoption with no acceptable use policy, no inventory and no answer to a client asking what happens to their material.

Where to start

Which side of the practice you need

If the pressure is a client audit or an undocumented program, that is the fractional CISO side.

If the estate itself is the problem, or a platform decision is coming, that is the CTO side. Firms with both usually have one person who has been absorbing both jobs alongside another role.

The two pillars

Where this usually starts

Common questions

Questions I get asked first

Our IT is outsourced. Is that not covered?

A managed provider delivers services against a contract that is usually uptime and support. Deciding what those services must achieve, and verifying that they do, is a different job, and it cannot be the same supplier because it includes judging whether the first one is performing.

What do clients actually ask for?

A named security owner, a current risk assessment, access control and offboarding evidence, incident history and response arrangements, subprocessor lists, and increasingly a statement on AI tooling. Most of it is answerable; the difficulty is that it has never been assembled.

We had an incident and it is contained. What now?

The architecture and identity layer that allowed it are still in place, and closing that is a separate engagement from the response. Clients and insurers will ask what changed, and the answer needs to be a record rather than a list of intentions.

Related reading

Written on this

Start with a conversation

Tell me what’s going on. I will tell you which of these it actually is, and whether you need me for it.

Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.

Not ready for a call? Send a message instead.

For companies looking to engage BATO. Vendors, please email.