Protecting Client Information in a Law Firm
Confidential client information is among the most sensitive data any business holds. Protecting it requires coordinated controls across identity, access, devices, Microsoft 365, email, documents, backup and people — not a single security product.
The two-minute answer
How should a law firm protect client information? By building coordinated controls across the entire information environment rather than relying on a single product or perimeter.
A practical approach covers multi-factor authentication, identity governance, least-privilege access, matter permissions, Microsoft 365 configuration, endpoint security, patching, email protection, secure sharing, verified backup and recovery, incident response, information governance, staff awareness and human accountability.
The objective is not simply to install security tools. It is to create an environment where confidential information is appropriately protected throughout its lifecycle — from creation to disposal — and where the firm can demonstrate that protection to clients, insurers and regulators.
Why client information requires particular care
Law firms hold information that is attractive to cyber criminals and damaging if exposed. This includes matter information, personal information, identity records, commercially sensitive information, legal correspondence, evidence, financial information and potentially privileged material.
The Australian Cyber Security Centre consistently identifies professional services firms as targets for cyber attacks, including business email compromise and ransomware. The Office of the Australian Information Commissioner oversees the Notifiable Data Breaches scheme, which may apply depending on the information involved and the firm's obligations under the Privacy Act.
This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations.
Client Information Exposure Map
Confidential information flows across multiple systems. Effective protection requires governance across all of them — not just the perimeter.
Identity is the security perimeter
Modern security starts with identity. If an attacker can access a user account, they can often access everything that user can access. For law firms, this means matter information, client correspondence and practice systems.
Multi-factor authentication
Enforce MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.
Conditional access
Use conditional access policies where appropriate to restrict access based on location, device, risk and context.
User lifecycle
Manage joiners, movers and leavers promptly. Dormant accounts create unnecessary access risk.
Privileged accounts
Restrict administrative accounts to authorised personnel. Review privileged access regularly.
Shared accounts
Avoid shared accounts where practical. Each user should have a uniquely identifiable account.
Role changes
Review and adjust access when staff change roles, leave the firm or join new matter teams.
Matter access should reflect actual responsibility
Law firms should implement need-to-know access so that staff can only see matters they are working on. Broad, inherited permissions accumulated over time create unnecessary risk and may conflict with professional obligations around confidentiality.
Need-to-know access
Matter teams should have access only to the matters they are assigned to.
Practice groups
Group-level access should be reviewed regularly to ensure it remains appropriate.
Sensitive matters
High-sensitivity matters may require additional access restrictions or dedicated permissions.
Information barriers
Where professionally required, firms should implement ethical walls or information barriers — this is a professional obligation, not simply a technical configuration.
External collaboration
Guest access and external sharing should be controlled, time-limited and reviewed.
Regular reviews
Review permissions at least annually and whenever matter teams are restructured.
Microsoft 365 permissions need active governance
Microsoft 365 provides powerful collaboration tools, but permissions require active governance. Microsoft's official documentation details how SharePoint, Teams and OneDrive permissions work — and how they can be configured to reduce oversharing risk.
SharePoint
Review site-level permissions, library access and sharing defaults. Avoid broad inheritance where it exceeds business need.
Teams
Review Team membership, channel access and guest users. Remove inactive Teams and manage private channels.
OneDrive
Review external sharing settings and ensure OneDrive is not used as an uncontrolled document repository.
Guest access
Track guest users, set expiry on guest accounts and review external collaboration regularly.
Sharing links
Configure appropriate sharing link defaults. Avoid anonymous links for sensitive information.
Groups
Review Microsoft 365 Group membership and ownership. Remove inactive groups.
Email remains a major information channel
Email is both a primary collaboration tool and a significant attack surface. Phishing and business email compromise remain among the most common threats facing professional services firms.
Phishing protection
Deploy email filtering, anti-phishing policies and staff awareness training.
Business email compromise
Implement verification processes for changes to payment details, banking information and client instructions.
Attachments
Avoid emailing sensitive attachments where secure sharing alternatives exist.
Misdirected email
Implement delay-send rules or confirmation prompts for external recipients to reduce misdirected email risk.
Sensitive information
Use sensitivity labels and encryption where appropriate for confidential correspondence.
Secure alternatives
Use controlled SharePoint links or client portals instead of email attachments where practical.
Protecting documents throughout the matter lifecycle
Information protection should span the entire matter lifecycle — from creation to disposal.
Create
Classify and label information at creation
Receive
Route external documents to governed locations
Review
Control access during review and approval
Share
Use secure, time-limited sharing methods
Store
File in governed, permission-controlled locations
Retain
Apply retention policies appropriate to the information
Archive
Archive completed matters with appropriate access
Dispose
Dispose of information securely when retention expires
Backup and recovery
Backup exists does not mean recovery is verified. A firm should be able to demonstrate that business-critical information can be recovered within its recovery objectives.
Critical information
Identify which information is business-critical and ensure it is included in backup and recovery planning.
Restore testing
Test recovery regularly. An untested backup is an assumption, not a capability.
Separation
Ensure appropriate separation between production and backup environments.
Responsibilities
Clarify responsibilities between cloud platforms and the organisation. Cloud infrastructure resilience is not the same as organisational backup.
SaaS considerations
Assess whether Microsoft 365 and other SaaS platforms meet your recovery objectives, or whether additional capabilities are required.
Recovery planning
Document recovery objectives, priorities and procedures. Review after any significant change.
Incident response
An incident response plan helps a firm respond quickly and reduce the impact of a security incident. The plan should be documented, accessible and exercised regularly.
Detection
How will the firm detect an incident? What monitoring and alerting is in place?
Escalation
Who is notified, in what order, and how quickly?
Containment
What immediate steps contain the incident and prevent further damage?
Technical response
Who provides technical response — internal IT, managed service provider or specialist incident responders?
Communication
Who manages internal, client and external communications?
Legal and professional advice
Who provides legal, professional and regulatory advice? Notification obligations may apply depending on the circumstances.
Recovery
How does the firm restore systems and information to normal operations?
Lessons learned
Review every incident to identify improvements. Update the plan accordingly.
The Essential Eight and law firms
The Australian Cyber Security Centre's Essential Eight is a recommended baseline of mitigation strategies designed to reduce cyber risk. It is not universally mandatory by statute for private law firms, but LOOKUP recommends it as an effective operational baseline for firms handling confidential client information.
How this maps to the LOOKUP Business Modernisation Framework™
Protecting client information is not a one-off project. It follows the same structured approach as every LOOKUP engagement.
Discover
Map where confidential information lives, who has access and how it is shared.
Secure
Strengthen identity, MFA, access controls, endpoint security and recovery capability.
Modernise
Address legacy systems and unsupported technology that create security risk.
Standardise
Create consistent permissions, sharing policies and information governance practices.
Optimise
Improve Microsoft 365 configuration, email security and document workflows.
Prepare
Establish governance, policies and staff awareness for AI and future technology.
Implement
Deploy security controls, incident response plans and monitoring deliberately.
Improve
Review permissions, test recovery, exercise incident response and continuously improve.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
What success looks like
Strong information protection creates qualitative business outcomes — not just technical compliance.
Better access control
Staff can access what they need — and nothing more.
Improved information visibility
Leadership understands where sensitive information lives and who can access it.
Reduced unnecessary access
Broad, inherited permissions are reviewed and reduced.
Stronger recovery capability
Backup and recovery is tested, documented and aligned to business objectives.
More consistent sharing
Client collaboration uses governed, secure methods rather than ad-hoc email attachments.
Clearer responsibility
Security ownership is explicit, not assumed.
Better cyber resilience
The firm can detect, respond to and recover from incidents.
Safer AI foundations
Information governance supports responsible AI adoption rather than creating oversharing risk.
Research and professional guidance
The Law Society of New South Wales provides guidance to solicitors on professional obligations, technology and cyber security. The Law Council of Australia maintains policy resources addressing AI and the legal profession.
The Victorian Legal Services Board + Commissioner has published Minimum Cybersecurity Expectations. These are Victorian guidance and should not be generalised as universal Australia-wide legal requirements. Firms should confirm which professional obligations apply in their jurisdiction.
The Australian Cyber Security Centre provides the Essential Eight as a recommended baseline for reducing cyber risk. The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme.
See how information security connects to AI readiness for law firms →
Illustrative business outcome
This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges law firms may encounter and demonstrates how a structured technology approach could be applied.
Business challenge
A growing law firm has accumulated broad SharePoint permissions over several years. Former users still have access. External sharing is inconsistent. Recovery has not been recently tested. No clear security ownership exists.
Structured approach
Discover where information lives. Secure identity and MFA. Review and reduce permissions. Standardise sharing policies. Test recovery. Establish incident response. Assign clear ownership.
Potential business outcomes
- • Reduced unnecessary access to confidential matter information
- • Improved recovery confidence through tested backup procedures
- • More consistent, governed client collaboration
- • Clearer security ownership and accountability
- • Better foundations for responsible AI adoption
Frequently asked questions
How should law firms protect client information?
Law firms should protect client information through a combination of multi-factor authentication, least-privilege access controls, Microsoft 365 governance, endpoint security, email protection, verified backup and recovery, incident response planning and ongoing staff awareness. No single product achieves this — it requires coordinated controls across identity, devices, information, email and people.
What cyber security controls should law firms use?
Priority controls include multi-factor authentication across all user accounts, conditional access policies where appropriate, endpoint protection, regular patching, email security filtering, controlled external sharing, verified backup and recovery, and an incident response plan. The Australian Cyber Security Centre's Essential Eight provides a useful baseline for reducing cyber risk.
Do law firms need MFA?
Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. Administrative accounts, remote access and cloud services should all be covered.
How should law firms manage matter permissions?
Matter access should reflect actual professional responsibility. Firms should implement need-to-know access, review permissions regularly, manage joiners-movers-leavers promptly, and consider information barriers or ethical walls where professionally required. Broad, inherited permissions accumulated over time create unnecessary risk.
Is Microsoft 365 secure enough for law firms?
Microsoft 365 can support strong security when properly configured. Security depends on factors including identity configuration, conditional access, multi-factor authentication, information protection, external sharing settings, administrative roles and ongoing governance. Security is not automatic — it requires deliberate configuration and continuous management.
Can law firms use SharePoint for confidential information?
SharePoint can be used for confidential information when permissions, sharing settings, retention policies and information protection are properly configured. Firms should review access controls, external sharing defaults and sensitivity labels before storing sensitive matter information. Poorly governed SharePoint can create oversharing risk.
What is least privilege?
Least privilege means giving each user only the access they need to perform their role. For law firms, this means matter teams have access to their matters, administrative accounts are restricted to administrators, and broad access is regularly reviewed and reduced where it exceeds legitimate business need.
Should lawyers email confidential documents?
Email remains a common channel but carries risks including misdirected messages, business email compromise and uncontrolled forwarding. Where practical, firms should consider secure sharing alternatives such as controlled SharePoint links or client portals. Where email is used, staff should verify recipients and use appropriate protection for sensitive attachments.
How should law firms share files with clients?
Firms should use controlled sharing methods such as SharePoint external sharing with expiring links, guest access with authentication requirements, or dedicated client portals. Anonymous public links should be avoided for sensitive information. Sharing methods should reflect the firm's risk profile, client requirements and information governance policies.
Do law firms need the Essential Eight?
The Essential Eight is not universally mandatory by statute for private law firms. However, the Australian Cyber Security Centre recommends it as a practical baseline for reducing cyber risk. LOOKUP recommends the Essential Eight as an effective operational baseline for law firms handling confidential client information.
What happens if a law firm has a data breach?
A data breach may trigger obligations depending on the information involved, applicable privacy laws, professional obligations and insurer requirements. Firms covered by the Notifiable Data Breaches scheme must assess whether the breach is eligible and notify affected individuals and the OAIC where required. Firms should have an incident response plan and seek professional advice regarding their specific obligations.
How often should permissions be reviewed?
LOOKUP recommends reviewing permissions at least annually, and whenever staff change roles, leave the firm, or when matter teams are restructured. Access reviews should cover Microsoft 365 groups, SharePoint sites, Teams, shared mailboxes and administrative accounts. Dormant accounts should be identified and removed.
Do cloud systems need backups?
Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.
How does information security affect AI?
AI tools such as Microsoft 365 Copilot work within a user's existing permissions. If permissions are broader than intended, AI may make information that a user already has permission to access easier to discover. Reviewing permissions, sharing settings and information governance before AI deployment helps reduce oversharing risk.
Where should a law firm start?
Start by understanding where confidential information lives, who has access to it, and how it is shared. Then review MFA coverage, privileged accounts, Microsoft 365 sharing settings, endpoint security and backup recovery. Prioritise the highest-risk gaps first and build a practical improvement roadmap.
What business leaders should do next
Executive guides
Business Modernisation Framework™
The eight-stage methodology guiding every LOOKUP engagement.
Business Technology Roadmap
Build a practical technology roadmap aligned with long-term business goals.
AI Governance
Practical guidance for responsible AI adoption, policies and oversight.
Cyber Insurance Readiness
Strengthen cyber maturity before insurance renewal discussions.
Reducing Administrative Overhead
Standardise workflows and reduce repetitive administrative work.
How LOOKUP can help
LOOKUP helps law firms strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI — through practical, business-first technology leadership.
Sources & Further Reading
Law Society of New South Wales
Professional obligations and technology guidance
NSW solicitor guidance on professional conduct, technology and cyber security.
View SourceVictorian Legal Services Board + Commissioner
Minimum Cybersecurity Expectations
Victorian guidance on cybersecurity expectations for legal practices — applicable to Victoria, not universal nationally.
View SourceLaw Council of Australia
AI and the legal profession
National policy resources addressing AI adoption and professional obligations.
View SourceAustralian Cyber Security Centre
Essential Eight Explained
Recommended baseline of mitigation strategies for reducing cyber risk.
View SourceOffice of the Australian Information Commissioner
Notifiable Data Breaches Scheme
Guidance on privacy obligations and eligible data breach notification.
View SourceMicrosoft
Microsoft 365 Security Documentation
Official documentation on Microsoft 365 security, compliance and information protection capabilities.
View SourceEvidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations.
Protecting Client Information Starts with Better Technology Governance
LOOKUP helps law firms strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI through practical, business-first technology leadership.