The Challenge
The client is a law firm whose matters involve commercially sensitive transactions and privileged client material. Its own clients, particularly the larger corporate ones, had begun conducting security reviews of their outside counsel and asking for evidence that was more current than a once-yearly test report.
The firm faced a specific version of a common problem. It was not short of security tooling, but it had no continuous picture of its exposure, and its annual assessment was several months stale by the time the questions arrived. Losing a matter over a security questionnaire was a commercial risk the partnership took seriously.
Our Approach
StrikeCyber replaced the annual assessment with a continuous program, structured so the firm always held current evidence rather than a document with a date on it.
- Continuous external attack surface discovery, monitoring everything the firm exposed to the internet including assets created for individual matters and client portals.
- Quarterly authenticated internal assessment across servers, workstations and the document management system that holds the firm's most sensitive material.
- Credential exposure monitoring, checking whether firm credentials appeared in breach corpora and whether they remained valid.
Findings were triaged by an operator and prioritized by reachability rather than raw severity, which mattered for a firm with a small IT team and no capacity to work through a scanner backlog.
What We Found
- Forgotten matter-specific infrastructure. Several client-facing portals and file transfer sites, created for matters that had long since closed, remained live and reachable, two of them running unsupported software.
- Document management over-permissioning. Access to matter folders had accumulated as staff moved between teams, so a number of users could reach material unrelated to their current work.
- Exposed credentials still valid. Two sets of firm credentials appeared in breach corpora and were confirmed still working against the firm's remote access.
- Inconsistent endpoint patching. Laptops belonging to partners who traveled frequently were consistently the furthest behind on updates.
The Outcome
The forgotten portals were decommissioned, and the firm adopted a matter-closure process that includes retiring any infrastructure created for it. Document management permissions were rebuilt around current team membership and are now reviewed quarterly. The exposed credentials were rotated immediately and phishing-resistant multi-factor authentication was extended across remote access.
The commercial outcome mattered most to the partnership. The firm now responds to client security reviews with current evidence and a documented continuous program, and has passed its subsequent reviews without remediation conditions attached.
Why It Matters
Law firms hold concentrated, high-value material and are targeted precisely because of it. An attacker who compromises a firm reaches the confidential business of every client it acts for, which is why corporate clients increasingly assess their counsel as rigorously as any other vendor. An annual test cannot answer a question asked in March about an environment that changed in February. To move from periodic testing to continuous assurance, get in touch.
