Back to Case Studies
Case Study — Law FirmIllustrative example — anonymised

How a 45-person law firm closed three critical access gaps before they became incidents.

Sector

Legal Services

Size

45 users

Platform

Microsoft 365

Engagement

Operational Cyber Review

Timeline

3 weeks

The Situation

A UK law firm specialising in commercial property and private client work completed the Shield Cyber Services diagnostic after a partner raised concerns following a phishing email that had reached three fee earners simultaneously. Their diagnostic score came back Elevated across two areas: access control and incident readiness.

What We Found

1

Former employee accounts still active in Microsoft 365

Eleven user accounts belonging to staff who had left the firm in the previous 18 months remained active, with full mailbox access. Two had active mobile device connections at the time of review.

2

No documented incident response process

The firm had no written procedure for what to do in the event of a breach, a ransomware incident, or a client data leak. Partners were unsure who had authority to make decisions in the first hour of an incident.

3

Admin privileges assigned to non-admin users

Three fee earners had been granted global admin rights to the Microsoft 365 tenant at some point in the firm's history — likely during an IT migration — and those rights had never been reviewed or removed.

None of these gaps were the result of negligence. They were the result of growth: the firm had scaled from 18 to 45 people over four years, and the controls had not kept pace.

What We Recommended

ImmediateDeprovision all 11 former employee accounts and revoke mobile device access.
Within 30 daysReview and reduce Microsoft 365 admin privileges to named IT contacts only.
Within 60 daysDocument a one-page incident response protocol with named decision-makers and a clear notification chain.
OngoingImplement a quarterly access review process (we provided a template).

We also flagged two lower-severity observations — shared generic email accounts used for client correspondence, and an unreviewed third-party application with broad data permissions — which were noted for future review.

The Outcome

“We knew cyber security was something we should be on top of. What we didn't expect was how practical the output would be — it wasn't a list of things to buy, it was a list of things to fix. We closed the immediate gaps within a week.”

— Managing Partner (name withheld at client request)

The firm closed all three priority gaps within three weeks of receiving the report. No further engagement was required. A follow-up check-in call 30 days later confirmed the changes had been implemented correctly.

See where your firm stands.

The diagnostic takes five minutes and costs nothing. If it finds something, we'll tell you plainly.

Start Your Free Diagnostic