Security, for practices of two to ten

You should be able to see what’s switched on.

Most firms this size don’t know whether multi-factor authentication is enforced on every account, whether a backup has ever been restored, or who still has access after leaving. Not because nobody set it up — because nobody ever showed them.

This page sets out exactly what we configure, and exactly what you can read for yourself afterwards.

A person answers. If we can’t take it there and then, you’re given a time — not a promise to get back to you.

A — What we switch on

Six things, configured and kept configured

A1

Multi-factor authentication, everywhere

Enforced by policy on mail, practice management and remote access — including the accounts that get forgotten: the principal’s phone, the shared reception mailbox, the person who left in March.

A2

Endpoint protection on every device

Detection running on each machine, with alerts going somewhere a person reads them. An unwatched console is a licence, not a control.

A3

Email filtering and rule alerting

Impersonation and lookalike-domain filtering, external senders marked as external, and an alert when a new forwarding or hidden-folder rule appears on a mailbox.

A4

Patching, on a schedule

Operating systems and the software that actually gets attacked — browsers, PDF readers, Office — updated on a cycle rather than when someone notices.

A5

Backups tested by restoring them

Mail and files in Microsoft 365, restored on a schedule so we know it works. Cloud practice management systems are backed up by their own vendors. An untested backup is a story.

A6

Access that closes when people leave

Offboarding runs the same day: accounts disabled, sessions revoked, devices removed, mail handled the way you ask. Not a task that waits for someone to remember it.

Security that makes the working day harder gets switched off by the people it was meant to protect. This is run by the same desk that answers when a document won’t open.

B — What you can see

Five things you can ask for, any day, and read yourself

A control you can’t verify is a control you’re taking on faith. Each of these is a document, not a conversation, and it is yours whether you stay with us or not.

  • The restore log. What was restored, when, and whether it came back intact.
  • The account list. Every account in your tenancy, who holds it, and whether multi-factor authentication is enforced on it.
  • The device list. Every machine, who uses it, and when it last checked in.
  • The administrator inventory. Who has elevated access to what — including us.
  • The offboarding record. Who left, what was closed, and on what date.

If you ever appoint someone else, you hand them these and they can begin. That is the point of keeping them.

C — What we don’t do

Where our work stops

We configure and maintain the controls above, and we give you the evidence of what is running. We do not advise you on whether that satisfies your insurer, your professional obligations, or a client’s security review, and we don’t complete those questionnaires on your behalf. Those are judgement calls with consequences that land on you, and they belong with your broker and your own advisers.

We’d rather say that plainly than have you find the boundary later. What we can do is tell you exactly what is switched on in your firm, in writing, so that whoever does answer those questions is working from facts rather than assumptions.

D — Where to start

Find out where you actually stand

None of this is worth acting on until you know which of it is already true in your firm. Fifteen minutes on a call, and we’ll talk through what’s likely running, what probably isn’t, and what it would take to find out properly.

  • Australian law firms only, two to ten people.

Start with a conversation. Decide about us afterwards.

Call and a person answers. If we can’t take it there and then, you’re given a time — not a promise to get back to you. Fifteen minutes is usually enough to know whether we’re the right fit.