A1
Multi-factor authentication, everywhere
Enforced by policy on mail, practice management and remote access — including the accounts that get forgotten: the principal’s phone, the shared reception mailbox, the person who left in March.
Security, for practices of two to ten
Most firms this size don’t know whether multi-factor authentication is enforced on every account, whether a backup has ever been restored, or who still has access after leaving. Not because nobody set it up — because nobody ever showed them.
This page sets out exactly what we configure, and exactly what you can read for yourself afterwards.
A person answers. If we can’t take it there and then, you’re given a time — not a promise to get back to you.
A — What we switch on
A1
Enforced by policy on mail, practice management and remote access — including the accounts that get forgotten: the principal’s phone, the shared reception mailbox, the person who left in March.
A2
Detection running on each machine, with alerts going somewhere a person reads them. An unwatched console is a licence, not a control.
A3
Impersonation and lookalike-domain filtering, external senders marked as external, and an alert when a new forwarding or hidden-folder rule appears on a mailbox.
A4
Operating systems and the software that actually gets attacked — browsers, PDF readers, Office — updated on a cycle rather than when someone notices.
A5
Mail and files in Microsoft 365, restored on a schedule so we know it works. Cloud practice management systems are backed up by their own vendors. An untested backup is a story.
A6
Offboarding runs the same day: accounts disabled, sessions revoked, devices removed, mail handled the way you ask. Not a task that waits for someone to remember it.
Security that makes the working day harder gets switched off by the people it was meant to protect. This is run by the same desk that answers when a document won’t open.
B — What you can see
A control you can’t verify is a control you’re taking on faith. Each of these is a document, not a conversation, and it is yours whether you stay with us or not.
If you ever appoint someone else, you hand them these and they can begin. That is the point of keeping them.
C — What we don’t do
We configure and maintain the controls above, and we give you the evidence of what is running. We do not advise you on whether that satisfies your insurer, your professional obligations, or a client’s security review, and we don’t complete those questionnaires on your behalf. Those are judgement calls with consequences that land on you, and they belong with your broker and your own advisers.
We’d rather say that plainly than have you find the boundary later. What we can do is tell you exactly what is switched on in your firm, in writing, so that whoever does answer those questions is working from facts rather than assumptions.
D — Where to start
None of this is worth acting on until you know which of it is already true in your firm. Fifteen minutes on a call, and we’ll talk through what’s likely running, what probably isn’t, and what it would take to find out properly.
Call and a person answers. If we can’t take it there and then, you’re given a time — not a promise to get back to you. Fifteen minutes is usually enough to know whether we’re the right fit.