Professional services firms hold concentrated, high-value confidential information belonging to other people — often about transactions, disputes or finances that are not yet public. That makes them an efficient target: compromise one firm and reach many clients. Clients have worked this out, which is why security reviews now decide panel appointments.
What is distinctive
- Data belongs to clients, not the firm. Obligations flow from engagement letters and professional duties as much as from regulation.
- Concentration. A single firm may hold pre-announcement merger material for several clients simultaneously — a target profile few of the clients themselves present.
- Conflicts and matter separation. Access control is not only a security control here; it underpins professional obligations, and information barriers between matters may be ethically required.
- Privilege. How incident investigations are structured affects whether findings are privileged, which is a decision to make with counsel before an incident.
- Partnership culture. Senior fee-earners are often the least willing to accept controls and hold the most sensitive access — a governance problem more than a technical one.
- Extensive third parties — e-discovery providers, barristers and counsel, experts, translators, printers — all receiving client material.
Client security reviews are the real driver
Corporate clients, especially in financial services, now audit their advisers. Expect outside counsel guidelines with security schedules, detailed questionnaires, evidence of certification, breach notification obligations shorter than any regulatory clock, restrictions on offshore access and subcontracting, and sometimes a right to audit.
The commercial consequence is direct: firms that cannot answer credibly lose panel positions. Security has moved from an overhead to a condition of winning work — which is usually the argument that unlocks partner buy-in when a risk-based one has failed.
Answer client security reviews from records
GRC Copilot keeps control status and evidence current and reusable, so client questionnaires are answered from a system instead of assembled each time.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Control priorities
- Matter-level access control. Need-to-know within the firm, not firm-wide access to everything — the control clients ask about most and the one hardest to retrofit.
- MFA everywhere, including for partners. Exceptions for senior staff are the most damaging exception a firm can grant.
- Email security. The sector's dominant loss vector is business email compromise around transactions and payment instructions, so out-of-band verification of any change to bank details is essential.
- Data classification aligned to client obligations, not a generic scheme.
- Third-party controls covering everyone who touches client material, with flow-down of client-imposed terms.
- Retention and disposal at the end of a matter — firms accumulate client data indefinitely by default, which is both a breach-scope and a professional-obligation problem.
- Secure client collaboration that is easier than email attachments, or people will use email attachments.
Certification expectations
ISO 27001 has become the common expectation for firms serving corporate clients, and in some markets a sector-specific scheme applies as well. In the UK, firms in the public sector supply chain may need Cyber Essentials or Cyber Essentials Plus. Where a firm serves regulated financial clients, those clients' own outsourcing obligations flow down as contractual security requirements.
Where firms struggle
- Partner exceptions that hollow out otherwise sound controls.
- Firm-wide document access retained because restricting it is disruptive.
- Shadow collaboration — client material moved to personal accounts and consumer file-sharing to get work done.
- Legacy matter archives nobody will authorise deleting.
- Security owned by IT with no professional-obligations input, producing controls that conflict with ethical duties.
Frequently asked questions
Do we need ISO 27001?
Increasingly yes if you serve corporate clients — it answers a large share of client security reviews in one document and is often a panel condition.
How do we get partners to accept controls?
Frame it commercially. Lost panel positions and client audit failures move partners in a way that abstract risk does not.
Should incident investigations be privileged?
Structure the engagement with counsel in advance if you want the best chance of privilege attaching. It cannot be arranged retrospectively.
How long should we keep client files?
As long as professional and legal obligations require, and no longer. Indefinite retention expands breach scope and conflicts with data protection duties.
Key takeaways
- You hold other people's secrets — obligations flow from engagement terms and professional duties.
- Client security reviews now decide panel appointments; that argument moves partners.
- Matter-level access control is the differentiator and the hardest retrofit.
- Partner exceptions and indefinite matter retention are the two structural weaknesses.