info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Law Firm Business Outcome

    Protecting Client Information in a Law Firm

    Confidential client information is among the most sensitive data any business holds. Protecting it requires coordinated controls across identity, access, devices, Microsoft 365, email, documents, backup and people — not a single security product.

    The two-minute answer

    How should a law firm protect client information? By building coordinated controls across the entire information environment rather than relying on a single product or perimeter.

    A practical approach covers multi-factor authentication, identity governance, least-privilege access, matter permissions, Microsoft 365 configuration, endpoint security, patching, email protection, secure sharing, verified backup and recovery, incident response, information governance, staff awareness and human accountability.

    The objective is not simply to install security tools. It is to create an environment where confidential information is appropriately protected throughout its lifecycle — from creation to disposal — and where the firm can demonstrate that protection to clients, insurers and regulators.

    Why client information requires particular care

    Law firms hold information that is attractive to cyber criminals and damaging if exposed. This includes matter information, personal information, identity records, commercially sensitive information, legal correspondence, evidence, financial information and potentially privileged material.

    The Australian Cyber Security Centre consistently identifies professional services firms as targets for cyber attacks, including business email compromise and ransomware. The Office of the Australian Information Commissioner oversees the Notifiable Data Breaches scheme, which may apply depending on the information involved and the firm's obligations under the Privacy Act.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations.

    Client Information Exposure Map

    Confidential information flows across multiple systems. Effective protection requires governance across all of them — not just the perimeter.

    Client Information
    Email
    SharePoint
    Teams
    Practice Mgmt
    Endpoints
    Mobile Devices
    Staff Accounts
    External Sharing

    Identity is the security perimeter

    Modern security starts with identity. If an attacker can access a user account, they can often access everything that user can access. For law firms, this means matter information, client correspondence and practice systems.

    Multi-factor authentication

    Enforce MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.

    Conditional access

    Use conditional access policies where appropriate to restrict access based on location, device, risk and context.

    User lifecycle

    Manage joiners, movers and leavers promptly. Dormant accounts create unnecessary access risk.

    Privileged accounts

    Restrict administrative accounts to authorised personnel. Review privileged access regularly.

    Shared accounts

    Avoid shared accounts where practical. Each user should have a uniquely identifiable account.

    Role changes

    Review and adjust access when staff change roles, leave the firm or join new matter teams.

    Matter access should reflect actual responsibility

    Law firms should implement need-to-know access so that staff can only see matters they are working on. Broad, inherited permissions accumulated over time create unnecessary risk and may conflict with professional obligations around confidentiality.

    Need-to-know access

    Matter teams should have access only to the matters they are assigned to.

    Practice groups

    Group-level access should be reviewed regularly to ensure it remains appropriate.

    Sensitive matters

    High-sensitivity matters may require additional access restrictions or dedicated permissions.

    Information barriers

    Where professionally required, firms should implement ethical walls or information barriers — this is a professional obligation, not simply a technical configuration.

    External collaboration

    Guest access and external sharing should be controlled, time-limited and reviewed.

    Regular reviews

    Review permissions at least annually and whenever matter teams are restructured.

    Microsoft 365 permissions need active governance

    Microsoft 365 provides powerful collaboration tools, but permissions require active governance. Microsoft's official documentation details how SharePoint, Teams and OneDrive permissions work — and how they can be configured to reduce oversharing risk.

    SharePoint

    Review site-level permissions, library access and sharing defaults. Avoid broad inheritance where it exceeds business need.

    Teams

    Review Team membership, channel access and guest users. Remove inactive Teams and manage private channels.

    OneDrive

    Review external sharing settings and ensure OneDrive is not used as an uncontrolled document repository.

    Guest access

    Track guest users, set expiry on guest accounts and review external collaboration regularly.

    Sharing links

    Configure appropriate sharing link defaults. Avoid anonymous links for sensitive information.

    Groups

    Review Microsoft 365 Group membership and ownership. Remove inactive groups.

    Learn how LOOKUP helps law firms optimise Microsoft 365 →

    Email remains a major information channel

    Email is both a primary collaboration tool and a significant attack surface. Phishing and business email compromise remain among the most common threats facing professional services firms.

    Phishing protection

    Deploy email filtering, anti-phishing policies and staff awareness training.

    Business email compromise

    Implement verification processes for changes to payment details, banking information and client instructions.

    Attachments

    Avoid emailing sensitive attachments where secure sharing alternatives exist.

    Misdirected email

    Implement delay-send rules or confirmation prompts for external recipients to reduce misdirected email risk.

    Sensitive information

    Use sensitivity labels and encryption where appropriate for confidential correspondence.

    Secure alternatives

    Use controlled SharePoint links or client portals instead of email attachments where practical.

    Protecting documents throughout the matter lifecycle

    Information protection should span the entire matter lifecycle — from creation to disposal.

    Create

    Classify and label information at creation

    Receive

    Route external documents to governed locations

    Review

    Control access during review and approval

    Share

    Use secure, time-limited sharing methods

    Store

    File in governed, permission-controlled locations

    Retain

    Apply retention policies appropriate to the information

    Archive

    Archive completed matters with appropriate access

    Dispose

    Dispose of information securely when retention expires

    Backup and recovery

    Backup exists does not mean recovery is verified. A firm should be able to demonstrate that business-critical information can be recovered within its recovery objectives.

    Critical information

    Identify which information is business-critical and ensure it is included in backup and recovery planning.

    Restore testing

    Test recovery regularly. An untested backup is an assumption, not a capability.

    Separation

    Ensure appropriate separation between production and backup environments.

    Responsibilities

    Clarify responsibilities between cloud platforms and the organisation. Cloud infrastructure resilience is not the same as organisational backup.

    SaaS considerations

    Assess whether Microsoft 365 and other SaaS platforms meet your recovery objectives, or whether additional capabilities are required.

    Recovery planning

    Document recovery objectives, priorities and procedures. Review after any significant change.

    Incident response

    An incident response plan helps a firm respond quickly and reduce the impact of a security incident. The plan should be documented, accessible and exercised regularly.

    Detection

    How will the firm detect an incident? What monitoring and alerting is in place?

    Escalation

    Who is notified, in what order, and how quickly?

    Containment

    What immediate steps contain the incident and prevent further damage?

    Technical response

    Who provides technical response — internal IT, managed service provider or specialist incident responders?

    Communication

    Who manages internal, client and external communications?

    Legal and professional advice

    Who provides legal, professional and regulatory advice? Notification obligations may apply depending on the circumstances.

    Recovery

    How does the firm restore systems and information to normal operations?

    Lessons learned

    Review every incident to identify improvements. Update the plan accordingly.

    The Essential Eight and law firms

    The Australian Cyber Security Centre's Essential Eight is a recommended baseline of mitigation strategies designed to reduce cyber risk. It is not universally mandatory by statute for private law firms, but LOOKUP recommends it as an effective operational baseline for firms handling confidential client information.

    Application control
    Patch applications
    Configure Microsoft Office macro settings
    User application hardening
    Restrict administrative privileges
    Patch operating systems
    Multi-factor authentication
    Regular backups

    Learn how LOOKUP implements the Essential Eight →

    How this maps to the LOOKUP Business Modernisation Framework™

    Protecting client information is not a one-off project. It follows the same structured approach as every LOOKUP engagement.

    Discover

    Map where confidential information lives, who has access and how it is shared.

    Secure

    Strengthen identity, MFA, access controls, endpoint security and recovery capability.

    Modernise

    Address legacy systems and unsupported technology that create security risk.

    Standardise

    Create consistent permissions, sharing policies and information governance practices.

    Optimise

    Improve Microsoft 365 configuration, email security and document workflows.

    Prepare

    Establish governance, policies and staff awareness for AI and future technology.

    Implement

    Deploy security controls, incident response plans and monitoring deliberately.

    Improve

    Review permissions, test recovery, exercise incident response and continuously improve.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    What success looks like

    Strong information protection creates qualitative business outcomes — not just technical compliance.

    Better access control

    Staff can access what they need — and nothing more.

    Improved information visibility

    Leadership understands where sensitive information lives and who can access it.

    Reduced unnecessary access

    Broad, inherited permissions are reviewed and reduced.

    Stronger recovery capability

    Backup and recovery is tested, documented and aligned to business objectives.

    More consistent sharing

    Client collaboration uses governed, secure methods rather than ad-hoc email attachments.

    Clearer responsibility

    Security ownership is explicit, not assumed.

    Better cyber resilience

    The firm can detect, respond to and recover from incidents.

    Safer AI foundations

    Information governance supports responsible AI adoption rather than creating oversharing risk.

    Research and professional guidance

    The Law Society of New South Wales provides guidance to solicitors on professional obligations, technology and cyber security. The Law Council of Australia maintains policy resources addressing AI and the legal profession.

    The Victorian Legal Services Board + Commissioner has published Minimum Cybersecurity Expectations. These are Victorian guidance and should not be generalised as universal Australia-wide legal requirements. Firms should confirm which professional obligations apply in their jurisdiction.

    The Australian Cyber Security Centre provides the Essential Eight as a recommended baseline for reducing cyber risk. The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme.

    See how information security connects to AI readiness for law firms →

    Illustrative business outcome

    Illustrative Scenario

    This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges law firms may encounter and demonstrates how a structured technology approach could be applied.

    Business challenge

    A growing law firm has accumulated broad SharePoint permissions over several years. Former users still have access. External sharing is inconsistent. Recovery has not been recently tested. No clear security ownership exists.

    Structured approach

    Discover where information lives. Secure identity and MFA. Review and reduce permissions. Standardise sharing policies. Test recovery. Establish incident response. Assign clear ownership.

    Potential business outcomes

    • • Reduced unnecessary access to confidential matter information
    • • Improved recovery confidence through tested backup procedures
    • • More consistent, governed client collaboration
    • • Clearer security ownership and accountability
    • • Better foundations for responsible AI adoption

    Frequently asked questions

    How should law firms protect client information?

    Law firms should protect client information through a combination of multi-factor authentication, least-privilege access controls, Microsoft 365 governance, endpoint security, email protection, verified backup and recovery, incident response planning and ongoing staff awareness. No single product achieves this — it requires coordinated controls across identity, devices, information, email and people.

    What cyber security controls should law firms use?

    Priority controls include multi-factor authentication across all user accounts, conditional access policies where appropriate, endpoint protection, regular patching, email security filtering, controlled external sharing, verified backup and recovery, and an incident response plan. The Australian Cyber Security Centre's Essential Eight provides a useful baseline for reducing cyber risk.

    Do law firms need MFA?

    Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. Administrative accounts, remote access and cloud services should all be covered.

    How should law firms manage matter permissions?

    Matter access should reflect actual professional responsibility. Firms should implement need-to-know access, review permissions regularly, manage joiners-movers-leavers promptly, and consider information barriers or ethical walls where professionally required. Broad, inherited permissions accumulated over time create unnecessary risk.

    Is Microsoft 365 secure enough for law firms?

    Microsoft 365 can support strong security when properly configured. Security depends on factors including identity configuration, conditional access, multi-factor authentication, information protection, external sharing settings, administrative roles and ongoing governance. Security is not automatic — it requires deliberate configuration and continuous management.

    Can law firms use SharePoint for confidential information?

    SharePoint can be used for confidential information when permissions, sharing settings, retention policies and information protection are properly configured. Firms should review access controls, external sharing defaults and sensitivity labels before storing sensitive matter information. Poorly governed SharePoint can create oversharing risk.

    What is least privilege?

    Least privilege means giving each user only the access they need to perform their role. For law firms, this means matter teams have access to their matters, administrative accounts are restricted to administrators, and broad access is regularly reviewed and reduced where it exceeds legitimate business need.

    Should lawyers email confidential documents?

    Email remains a common channel but carries risks including misdirected messages, business email compromise and uncontrolled forwarding. Where practical, firms should consider secure sharing alternatives such as controlled SharePoint links or client portals. Where email is used, staff should verify recipients and use appropriate protection for sensitive attachments.

    How should law firms share files with clients?

    Firms should use controlled sharing methods such as SharePoint external sharing with expiring links, guest access with authentication requirements, or dedicated client portals. Anonymous public links should be avoided for sensitive information. Sharing methods should reflect the firm's risk profile, client requirements and information governance policies.

    Do law firms need the Essential Eight?

    The Essential Eight is not universally mandatory by statute for private law firms. However, the Australian Cyber Security Centre recommends it as a practical baseline for reducing cyber risk. LOOKUP recommends the Essential Eight as an effective operational baseline for law firms handling confidential client information.

    What happens if a law firm has a data breach?

    A data breach may trigger obligations depending on the information involved, applicable privacy laws, professional obligations and insurer requirements. Firms covered by the Notifiable Data Breaches scheme must assess whether the breach is eligible and notify affected individuals and the OAIC where required. Firms should have an incident response plan and seek professional advice regarding their specific obligations.

    How often should permissions be reviewed?

    LOOKUP recommends reviewing permissions at least annually, and whenever staff change roles, leave the firm, or when matter teams are restructured. Access reviews should cover Microsoft 365 groups, SharePoint sites, Teams, shared mailboxes and administrative accounts. Dormant accounts should be identified and removed.

    Do cloud systems need backups?

    Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.

    How does information security affect AI?

    AI tools such as Microsoft 365 Copilot work within a user's existing permissions. If permissions are broader than intended, AI may make information that a user already has permission to access easier to discover. Reviewing permissions, sharing settings and information governance before AI deployment helps reduce oversharing risk.

    Where should a law firm start?

    Start by understanding where confidential information lives, who has access to it, and how it is shared. Then review MFA coverage, privileged accounts, Microsoft 365 sharing settings, endpoint security and backup recovery. Prioritise the highest-risk gaps first and build a practical improvement roadmap.

    What business leaders should do next

    1.Identify where confidential client information resides.
    2.Review identity and MFA coverage.
    3.Review administrative privileges and dormant accounts.
    4.Review Microsoft 365 permissions and external sharing.
    5.Review devices, patching and endpoint security.
    6.Assess backup and recovery — and test it.
    7.Review email security and phishing protection.
    8.Establish incident response responsibilities.
    9.Review AI usage and information governance.
    10.Create a technology and security improvement roadmap.

    How LOOKUP can help

    LOOKUP helps law firms strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI — through practical, business-first technology leadership.

    Sources & Further Reading

    Law Society of New South Wales

    Professional obligations and technology guidance

    NSW solicitor guidance on professional conduct, technology and cyber security.

    View Source

    Victorian Legal Services Board + Commissioner

    Minimum Cybersecurity Expectations

    Victorian guidance on cybersecurity expectations for legal practices — applicable to Victoria, not universal nationally.

    View Source

    Law Council of Australia

    AI and the legal profession

    National policy resources addressing AI adoption and professional obligations.

    View Source

    Australian Cyber Security Centre

    Essential Eight Explained

    Recommended baseline of mitigation strategies for reducing cyber risk.

    View Source

    Office of the Australian Information Commissioner

    Notifiable Data Breaches Scheme

    Guidance on privacy obligations and eligible data breach notification.

    View Source

    Microsoft

    Microsoft 365 Security Documentation

    Official documentation on Microsoft 365 security, compliance and information protection capabilities.

    View Source

    Evidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations.

    Protecting Client Information Starts with Better Technology Governance

    LOOKUP helps law firms strengthen cyber security, improve Microsoft 365 governance and build safer foundations for AI through practical, business-first technology leadership.

    Avatar
    Hi there! Have a question? Chat with us here.