Heights Consulting Group

Legal and Professional Services

Law firms, accounting practices and other professional services firms hold the most sensitive information their clients have, under professional duties that predate the technology now carrying it. They need security leadership that can satisfy ethics obligations, answer client security audits, and protect the confidentiality the practice is built on.

Obligations

What applies in this sector

Descriptions are of the published requirements, not claims about outcomes.

How we establish which obligations apply
Regimes that commonly apply to Legal and Professional Services organizations, NIST Cybersecurity Framework, ISO/IEC 27001, SOC 2, all resolving into one governed security program.

Regimes in play

  • NIST CSF Voluntary framework
  • ISO 27001 Certifiable standard
  • SOC 2 Attestation examination

One control base

Mapped once, evidenced once, and maintained between assessments.

The environment

What shapes security decisions here

A professional services firm is a concentration of other organizations' secrets: deal terms, disputes, tax positions, financials, privileged communications. That makes the firm a more attractive target than its own size suggests, because compromising one firm exposes many clients at once.

The obligations are professional as well as legal. Bar rules require lawyers to make reasonable efforts to prevent unauthorized disclosure of client information and treat technological competence as part of professional competence; accountants handling tax data carry statutory safeguard duties. These are duties owed to clients, enforced by regulators of the profession itself.

Meanwhile the buying side has changed. Corporate clients now send outside counsel guidelines and security questionnaires that read like vendor risk assessments, because that is what they are. The firm's answers become commitments, and a firm that cannot answer well loses work it never sees.

Exposure

Risks that behave differently in this sector

Not a general threat list. These are the exposures that need a different response here than they would elsewhere.

  • One breach, many clients

    A single compromise can expose matters belonging to dozens or hundreds of clients simultaneously, multiplying notification duties, engagement-letter obligations and reputational consequence far beyond the firm's own size.

  • Email as the primary attack surface

    The practice runs on correspondence, and business email compromise aimed at wire instructions, settlement funds and trust accounts is a routine, well-funded attack against firms of every size.

  • Privilege and confidentiality fallout

    A security incident at a firm is not only an IT event. It raises questions about protective orders, privileged material and ethical duties that ordinary incident-response playbooks were not written to answer.

  • Partners as unmanaged administrators

    Flat partnership structures resist central control: personal devices, matter files in personal cloud storage, and long-tenured staff with access nobody has reviewed in years.

Requirements

Regulatory and contractual pressure

General descriptions of published requirements. Which of them apply to a particular organization is the first question an engagement answers.

ABA Model Rule 1.6(c)
Requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Adopted in substance by most state bars.
ABA Model Rule 1.1, Comment 8
Extends the duty of competence to the benefits and risks of relevant technology, making security literacy part of professional competence rather than an IT concern.
ABA Formal Opinions 477R and 483
Address securing client communications and a lawyer's obligations after a data breach, including the duty to notify affected clients of a material breach.
FTC Safeguards Rule
Applies to professionals engaged in tax preparation and certain financial activities, requiring a written information security program with designated accountability, risk assessment and prescribed controls.
Outside counsel guidelines
Client-imposed security requirements that function as contractual obligations: encryption standards, access restrictions, breach notification windows and audit rights over the firm.

How we establish which obligations apply

What we hear

What leadership raises with us

  • A client audit or outside counsel guidelines arrived, and the honest answers are not the ones the firm wants to give.
  • Confidential matter files live wherever each partner or practice group put them, and nobody can say where everything is.
  • The firm has grown by lateral hires and mergers, and access rights have accumulated rather than been managed.
  • Wire fraud attempts are reaching the firm, and the controls protecting client funds are informal.
  • Managing partners are personally accountable to clients and the bar for a program nobody actually runs.

What prompts an engagement

  • A major client sent a security questionnaire or new outside counsel guidelines with a deadline.
  • The firm's malpractice or cyber insurer has tightened its application questions.
  • A phishing or wire-fraud attempt got further than anyone is comfortable admitting.
  • A lateral group or merger is bringing systems and matter files the firm has never assessed.
  • A client matter now involves data subject to regulatory requirements the firm has not handled before.

Alignment

Frameworks that apply here

NIST Cybersecurity Framework
Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
ISO/IEC 27001
Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
SOC 2
Technology and service companies whose enterprise customers require evidence of a controlled environment.

FAQ

Questions from legal and Professional Services leaders

General questions about the vCISO role are answered on the vCISO page.

Do bar association rules actually require law firms to have a security program?

Not in those words, but in effect. Model Rule 1.6(c) requires reasonable efforts to protect client information, Comment 8 to Rule 1.1 makes technological competence part of the duty of competence, and Formal Opinion 483 describes obligations after a breach. Together they describe a managed program: someone accountable, risks assessed, safeguards chosen deliberately, and a tested plan for when something goes wrong.

What counts as reasonable scales with the sensitivity of the matters the firm handles. A firm holding deal or litigation data for large clients is measured against a higher bar than the rules' minimum.

Our clients keep sending security questionnaires to the firm. How should we respond?

Treat the answers as representations to a client, because that is what they are. The work happens before the response: establishing what is actually true about the firm's controls, fixing what is cheap to fix, and recording honest, defensible answers for what remains.

Firms that answer these well maintain one accurate, current description of their security program rather than improvising per client. That consistency is itself evidence of governance, and it shortens every subsequent audit.

Does the FTC Safeguards Rule apply to accounting and tax practices?

If the practice prepares tax returns or engages in the financial activities the rule covers, yes. It requires a written information security program with a designated qualified individual responsible for it, a risk assessment, specific controls including encryption and multi-factor authentication, and oversight of service providers.

The designated-individual requirement is the one smaller practices most often cannot answer, and it is a role a fractional security leader can legitimately hold.