Skip to content
StrikeCyberStrikeCyber
Legal & Professional

Ongoing Vulnerability Assessment Programme for a Law Firm

A law firm holding highly confidential client matters needed continuous assurance, not a once-a-year point-in-time test.

Legal & Professional sector
Industry
Legal & Professional
Services
Vulnerability Assessment, Penetration Testing
Engagement
Ongoing vulnerability assessment programme
Region
National

The Challenge

The client is an established law firm handling highly confidential client matters, from commercial transactions to litigation and personal affairs. Client confidentiality is not just a professional obligation; it is the foundation of the firm's reputation. A breach that exposed privileged material would be far more damaging than the downtime alone.

Like many professional services firms, it had relied on an annual security test. That gave a single snapshot that was out of date within weeks as systems changed, staff came and went, and new services were exposed. The partners recognised that their real exposure shifted constantly, and that attackers targeting law firms favour business email compromise and invoice fraud, tricking staff or clients into redirecting settlement funds. They wanted continuous assurance that reduced risk over time, delivered with the discretion their client obligations demand.

Our Approach

StrikeCyber established an ongoing vulnerability assessment programme rather than a one-off test, run in regular cycles so that the firm's changing attack surface was assessed continuously rather than once a year.

  • Recurring external attack surface discovery and vulnerability assessment mapped everything the firm exposed to the internet, including forgotten and shadow services, so new exposure was caught soon after it appeared.
  • Focused penetration testing validated the highest-risk findings by hand, so partners received confirmed, exploitable issues rather than an unfiltered scanner report full of noise.
  • A dedicated review of email security assessed SPF, DKIM and DMARC configuration and the firm's overall exposure to spoofing and business email compromise, the attack pattern most likely to cause direct financial loss.

Every cycle produced a prioritised, plain-language view for the partners alongside technical detail for the IT provider, with progress tracked over time so the firm could see risk trending down. The whole programme was run with strict confidentiality appropriate to a legal environment.

What We Found

  • External exposure was broader than the firm realised. Discovery surfaced internet-facing services and remote access endpoints that were not being actively monitored or patched, including a legacy system left over from an old project.
  • Patching lagged on the perimeter. Several external services were running software with known, publicly documented vulnerabilities, giving an attacker straightforward avenues that a scanner and an opportunistic adversary would find quickly.
  • Email authentication was incomplete. SPF was present but permissive, DKIM was inconsistent, and DMARC was either absent or set only to monitor, which meant the firm's domain could be spoofed convincingly in a business email compromise or invoice-redirection attempt.
  • Client-facing fraud risk was real. The combination of weak email authentication and staff unfamiliarity with payment-change verification created a credible path for an attacker to impersonate the firm and redirect client settlement funds.

The Outcome

Because the programme was continuous, findings were remediated and verified cycle by cycle rather than left to accumulate. The unmonitored external services were decommissioned or brought under management, and the perimeter patching backlog was cleared and kept current between cycles. Email authentication was corrected in stages, tightening SPF, applying DKIM consistently and moving DMARC through monitoring to an enforcement policy, so spoofed mail from the firm's domain is now rejected rather than delivered. Payment-change verification steps were introduced to blunt invoice-redirection attempts.

Over successive cycles the firm's external exposure trended down and stayed down, and the partners gained ongoing, documented assurance they could speak to when clients asked how their confidential matters were protected.

Why It Matters

For a law firm, security is inseparable from client confidentiality and trust, and the threat that hurts most is often not sophisticated intrusion but a convincing spoofed email that redirects a settlement payment. A point-in-time test cannot keep pace with a shifting attack surface. An ongoing vulnerability assessment programme reduces exposure steadily and hardens email against business email compromise, turning security into something the firm can demonstrate to its clients rather than merely assert. To discuss a programme suited to your firm, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation