IT & Microsoft cloud for legal
Confidentiality, compliant archiving, secure document management and matter security for law firms.
Legal
In short: Client confidentiality, SRA expectations, matter retention, and the fraud that actually happens to firms. Start with email and the money path: Friday afternoon fraud and business email compromise are the losses that occur, and the controls that stop them are cheap next to the exposure.
In legal, confidentiality isn't a feature you add on, it's the professional obligation everything else is built on, and a single mishandled document, misdirected email or breach can undo years of client trust and put you in front of your regulator.
The challenge
Law firms sit at the intersection of highly sensitive data and highly motivated attackers. You hold confidential client and matter information protected by legal professional privilege, you handle client money, and you're bound by the SRA's Standards and Regulations, including the duty to keep client affairs confidential and to protect client assets and information. Firms pursuing or holding the Lexcel practice management standard have a further, explicit bar to clear on information management and risk. At the same time, conveyancing and other matters that move money make firms a prime target for business email compromise and the 'Friday afternoon fraud' that redirects completion funds, and a misdirected email or a lost laptop is a reportable data breach. The practical need is watertight document and matter management, a defensible and independent record of every communication for disclosure and complaints, and security that stands up to both a determined attacker and a regulator's questions after the fact.
What we would do
Start with email and the money path. Friday afternoon fraud and business email compromise are the losses that actually happen to firms, and the controls that stop them, impersonation protection, DMARC, and a verification step on payment detail changes, are cheap next to the exposure.
- If the SRA position or a professional indemnity renewal is driving the timing, do the evidence-shaped work first: a documented control with a date on it answers the question a form is asking.
- If you are considering AI tools, resolve confidentiality and permissions before any pilot. Client matter separation is exactly what a badly scoped tool will cross.
When we are not the answer: If your firm already runs impersonation protection, tested restores and a payment verification process, you do not need us for this. The gap in most firms is one of those three, and knowing which costs you 45 minutes.
What we do for legal
What is 'Friday afternoon fraud' and how do you actually stop it?
It is the interception or redirection of completion funds, and it targets conveyancing because that is where large, time-critical, one-off payments happen to people who are expecting payment instructions.
The classic version: a client receives an email that appears to come from their solicitor, shortly before completion, with updated bank details. The money moves and does not come back. The name comes from the timing, late on a Friday, when the firm is closing and the client has no chance to check.
Why it exploits process rather than technology, and the rule that actually prevents the loss
The reason it keeps working is that it exploits process rather than technology. So the countermeasures have to be both. On the technical side: strong email authentication so the firm's domain is harder to spoof, anti-impersonation controls that catch lookalike domains and display-name spoofing, and multi-factor authentication so a compromised mailbox is much harder to obtain in the first place, since many of these attacks begin with a genuine mailbox rather than a forged one.
On the process side: bank details communicated through a channel that is not email, a rule that details are never changed on the strength of an email alone, and verification by a phone call to a number held on file rather than one supplied in the message. Firms that have avoided losses generally credit the process rule rather than the technology, and clients should be told about the rule at the start of the matter, before an attacker gets the chance to set the expectation instead.
What does the SRA expect from a firm's IT and information security?
The SRA does not publish a technical checklist, and firms sometimes read that as an absence of requirements.
It is closer to the opposite: the obligations are outcome-based, which means the firm has to be able to demonstrate that client confidentiality and client money are protected, rather than tick a prescribed list. The judgement about what is adequate sits with the firm.
What the principles translate into concretely, and where Cyber Essentials helps without discharging the duty
In practice that translates into a recognisable set of things. Confidentiality of client information, which means controlled access, encryption and a defensible position on who can see what. Integrity and availability of matter data, which means backups that have been tested rather than assumed. Competence and supervision, which extends to understanding the risks in the technology the firm relies on. And prompt reporting when something goes wrong, which is difficult if nothing is monitored closely enough to notice.
Cyber Essentials is a useful backbone here precisely because it is externally defined. It does not discharge a regulatory obligation on its own, but it gives a firm a structured, assessable baseline across the five control areas, and evidence that an independent party looked. For firms that also need to satisfy client questionnaires and insurers, one exercise tends to serve all three audiences.
How should a law firm handle document retention and matter archives?
Deliberately, because the default is to keep everything forever, and that is both a cost and a liability.
Legal work generates long retention obligations that vary by matter type, and firms tend to resolve the complexity by never deleting anything. The result is an archive nobody can search, on storage nobody has reviewed, containing personal data the firm has no remaining reason to hold.
Separating active matters from closed ones, and what it does for disclosure and subject access
A workable model separates active matters from closed ones. Active matters live where people work, with permissions scoped to the team on the matter. Closed matters move to an archive with retention applied according to matter type, so material is disposed of when the obligation ends rather than when someone remembers. Retention labels in Microsoft 365 can enforce that automatically, which matters because manual retention is retention that does not happen.
Two practical benefits follow. Subject access requests and disclosure exercises become tractable, because the search space is defined rather than the whole history of the firm. And the risk profile drops, since data you no longer hold cannot be breached.
What happens to a firm's matter data if the practice management system fails?
That depends entirely on questions most firms have not asked their supplier, and the time to ask is not during an incident.
Practice management systems hold the spine of the firm: matters, time recording, ledgers, documents. When one becomes unavailable, fee earning stops, and if client account information is involved the consequences are regulatory as well as commercial.
The questions to answer before you need them, and the gap in assuming a vendor's resilience covers you
The questions worth answering in advance are specific. Where does the data physically live, and is it backed up independently of the vendor's own infrastructure? What is the contractual recovery time, and has anyone tested whether it is achievable? Can the firm extract its own data in a usable format without the vendor's cooperation? If the system is cloud-hosted, does the vendor's backup protect against the firm's own mistakes, such as bulk deletion, or only against their infrastructure failing?
The recurring gap is assuming a cloud vendor's resilience covers scenarios it does not. Vendor infrastructure redundancy is not the same as a restorable backup of your data, and Microsoft 365 works the same way, which is why an independent backup of email and documents is worth having alongside whatever the practice management vendor provides.
Can a law firm use AI tools without putting client confidentiality at risk?
Yes, but the controls have to be decided before the tools arrive, because in most firms they have already arrived informally.
The realistic starting assumption is that some people are already pasting material into consumer AI services on personal devices, which is the version of this problem with no controls at all and no record of what left.
Where the data goes, why permissions catch firms out, and what an acceptable-use position has to say
The first distinction that matters is where the data goes. A consumer AI service processes what is submitted on terms the firm has not negotiated and cannot evidence to a client. An enterprise service operating within your own Microsoft 365 tenant keeps material inside the tenant boundary and inherits the permissions already in place, which is a fundamentally different confidentiality position and a far easier one to explain to a client or the SRA.
The second is permissions, and it is where firms get caught out. An assistant that answers from what a user can already access will surface anything over-shared, so a firm with a legacy file share migrated with broad permissions should expect it to find material a fee earner should not see. That is a pre-existing problem being revealed rather than created, but it will be revealed on the day the tool is switched on.
The practical route is an acceptable-use position stated clearly enough that people know what is and is not allowed, an approved tool that operates inside the tenant, permissions and sensitivity labelling reviewed before rollout, and a rule that AI output is checked by the responsible fee earner. That last point is professional obligation rather than technology: the duty to the client does not move because a draft was machine-generated.
Questions we hear a lot
Can you provide compliant email archiving for a law firm?
Yes. We keep a complete, searchable, tamper-proof archive of every message independent of the mailbox, supporting retention, legal hold and disclosure obligations without relying on individual users to keep records.
How do you protect confidential matter data?
Through layered security and data governance: Conditional Access and MFA on identity, sensitivity labelling and data loss prevention on documents, advanced email security against phishing, and tested backups behind it all.
Do you help law firms with SRA and Lexcel requirements?
We put the technical controls in place, secure document and matter management, independent archiving, retention, access control and Cyber Essentials, that underpin the SRA's confidentiality and information-security expectations and map onto the information-management sections of Lexcel. We can't write your policies or run your practice, but we give you the systems and the evidence behind them so your COLP and COFA can demonstrate the controls are real.
How do you protect us against completion-funds and 'Friday afternoon' fraud?
This is one of the biggest risks in legal, and it's usually an email problem rather than a hacking one. We layer impersonation and anti-phishing protection in front of mailboxes, lock down email authentication (SPF, DKIM and DMARC), enforce MFA and Conditional Access on identity, and put process controls around any change to bank details, so a convincing request to redirect completion money is far less likely to land or be acted on.
Does client information stay in the UK?
We build on Microsoft 365 and Azure, where data residency can be configured, and we'll set up your tenant so client and matter data is held in line with your confidentiality obligations and what your clients expect. We'll be clear with you about where data sits and how it's protected in transit and at rest.
IT support for legal is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Leeds, York, Sheffield, Hull, Barnsley and Halifax and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Ready to talk about your legal IT?
Every engagement starts with a free assessment. No pressure, no cost, just a clear view of what's possible.
