Home/Services/Legal & Professional Services Penetration Testing
security service

Legal & Professional Services Penetration Testing

Legal penetration testing for law firms and professional services. Protect client confidentiality and privilege. Manual, fixed-price, free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Legal penetration testing protects the one asset a law firm cannot afford to lose: the confidentiality of client matters. We test the systems where privileged documents, deal data and personal information actually live, and we do it manually, under NDA, with a report your partners and your professional-indemnity insurer will take seriously.

SafetyBis is a European offensive-security team working with law firms and professional-services practices across Europe. Firms hold concentrated, sensitive data (merger terms, litigation strategy, personal records of clients on both sides of a dispute) and they are targeted precisely because of it. A breach is not only a GDPR problem. It is a breach of the duty of confidentiality that sits at the centre of the profession.

What legal penetration testing actually covers

The scope for a professional-services firm follows the data. That means the document management system where matters are stored, the email platform that attackers use for fraud, the client and matter portals, and the network and identity layer that ties it together. We test the paths an intruder would take to reach a privileged file.

Document management systems including iManage and NetDocuments
Microsoft 365 or Google Workspace and their email-fraud exposure
Client and matter portals used to share documents externally
Practice management and time-and-billing applications
Authentication, MFA coverage and privileged-account handling
External network and remote-access surface
Business-logic abuse in document-sharing and access controls

Document management is the crown jewel. In firms that run iManage or NetDocuments, the interesting question is rarely whether the platform itself is patched. It is whether the ethical walls and matter-level permissions actually hold when a determined user, or an attacker with one user’s credentials, tries to walk around them.

How we test

Legal penetration testing at SafetyBis is manual and evidence-based. We use Burp Suite, nmap and ffuf to map and probe, but the findings that matter to a firm come from an engineer reasoning about who should be able to see which matter, and then trying to prove they cannot be stopped.

Reconnaissance and mapping

We enumerate the firm’s external footprint: portals, remote-access gateways, forgotten microsites from a past rebrand, and email infrastructure. For firms that have grown by merger, this stage routinely surfaces systems nobody remembers owning.

Authenticated and access-control testing

Using accounts for different roles (fee-earner, paralegal, support, admin) we test whether matter-level and ethical-wall permissions are enforced on the server, or only hidden in the interface. Broken object-level authorization here means one lawyer reading another team’s confidential file, which is a professional-conduct incident, not just a technical bug.

Exploitation and email-fraud simulation

We demonstrate real impact safely. Where business email compromise is a concern, we assess how easily an attacker could impersonate a partner and redirect a completion payment, one of the most common and expensive frauds against law firms handling client money.

Reporting

Findings come with a CVSS score, a clear reproduction, and remediation written so your IT provider or in-house team can act. Anything critical is escalated to you the day we confirm it.

48h
typical time to first findings
NDA
every engagement, confidentiality first
Free
retest after you fix

Common vulnerabilities we find in professional-services firms

Broken matter-level authorization

The document platform enforces ethical walls in the UI, but a direct API call or a manipulated document identifier reaches a file the user should never see. This is the legal-sector version of IDOR, and it is the one we treat most seriously.

Business email compromise exposure

Weak or missing SPF, DKIM and DMARC records let an attacker spoof a partner’s address convincingly. Combined with a mailbox rule an intruder can plant after a phishing success, this is the mechanism behind redirected client payments.

Weak authentication on remote access

VPNs and remote-desktop gateways without enforced MFA, reused credentials, and stale accounts of departed staff. Legacy remote access is a favourite entry point, and it maps directly to MITRE ATT&CK initial-access techniques.

Over-privileged accounts and flat networks

Support staff with domain-admin rights, service accounts with passwords that never change, and a network where one compromised laptop can reach every server. This is how a single phished credential becomes a firm-wide ransomware event.

Insecure external document sharing

Client portals and file-transfer links that leak beyond their intended recipient. We test whether a share link can be guessed or enumerated, whether it expires, and whether removing a person from a matter actually revokes their access to documents they were previously sent. A link that outlives the relationship it was created for is a slow, quiet disclosure of privileged material.

Legal aspects and requirements for penetration testing

Firms ask, reasonably, about the legal aspects of penetration testing before they authorize one. The short answer: it is a controlled, contracted, authorized activity, and we treat the paperwork as seriously as the testing.

Authorization and scope

Testing begins only after a signed authorization (a rules-of-engagement document) that names the in-scope systems, the testing window, and the limits. That written authorization is what separates a penetration test from an offence under computer-misuse law across Europe. We never test anything not explicitly listed.

Confidentiality and data handling

We work under NDA, and any client data we encounter during testing is handled under strict controls and destroyed when the engagement closes. For a firm, the legal requirements for penetration testing are really a subset of your own confidentiality duty, and we contract to meet it.

Third-party and cloud systems

Where your data sits in a cloud service such as iManage Cloud or Microsoft 365, we confirm the provider’s testing terms and stay within them, so the engagement is authorized end to end.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Tools and techniques

Burp Suite Professional drives our web and portal testing. We use nmap for external service discovery, ffuf for content discovery on portals, and manual review for access-control and business-logic flaws that no scanner understands. Email security is assessed against the actual SPF, DKIM and DMARC configuration. Findings are mapped to OWASP ASVS and, for the attack narrative, to MITRE ATT&CK.

What you get

Executive summary partners and management can read in five minutes
Technical report with CVSS and reproduction per finding
A privileged-data-exposure assessment across the document system
Prioritized remediation for your IT team or provider
An attestation letter for insurers, clients and ISO 27001
A free retest once fixes are in place

Many firms need the attestation letter for a client’s own vendor-security review, or to answer a professional-indemnity insurer’s question about whether the firm tests its defences. The report is written to serve both.

Compliance and standards

GDPR

Law firms process special-category and highly sensitive personal data, so GDPR’s requirement for appropriate technical measures, and for testing them, applies with force. A penetration test is direct evidence that you assess your defences rather than assume them.

ISO 27001

Many firms pursue ISO 27001 to win institutional clients. Our report supports Annex A controls, including A.12.6 on technical vulnerability management, and the remediation evidence feeds straight into your management system.

Client and sector obligations

Corporate and financial clients increasingly impose their own security clauses on outside counsel. A recent independent test is often the cleanest way to satisfy them.

Why manual testing beats a scanner for a law firm

A scanner cannot understand an ethical wall. It does not know that partner A must never see matter B, so it cannot test whether that rule holds. The confidentiality failures that would end a client relationship are logic and authorization failures, and finding them requires a human who understands how the firm works. A scanner also floods a small IT team with noise. We hand you a ranked list of things that are genuinely exploitable, so remediation is focused rather than overwhelming.

Consider a realistic chain from one of our engagements: a marketing subdomain nobody remembered still ran an old login, its credentials were reused by a support account, that account had more rights in the document system than anyone intended, and from there a determined tester could reach matters across several practice groups. No single step was exotic. A scanner would have flagged the outdated login and stopped, missing the point entirely, which is that the four ordinary weaknesses together amounted to a firm-wide confidentiality breach. Writing that chain down, with the business impact spelled out, is the part a partner actually reads and acts on.

Who books this and when

Managing partners and firm IT leads come to us after a client demands proof of security, ahead of an ISO 27001 certification, when renewing professional-indemnity cover, or after a near-miss such as an attempted payment fraud. If your firm holds anything a client would be horrified to see leaked, testing is not optional maintenance, it is due diligence on your own duty of confidentiality.

Pricing

Legal penetration testing cost depends on scope: the number of applications and portals, whether the document system and email are in scope, and the size of your external and remote-access footprint. Pricing is fixed per engagement.

Engagement What’s included Timeline Price
Essential Client portal or single web application plus external network surface, authentication and access-control testing, full report and free retest 3–5 working days from €2,500
Firm standard Portal, practice-management app and document-system access review, email-fraud (SPF/DKIM/DMARC) assessment, exec plus technical report 5–8 working days €3,500–€8,000
Advanced Document management (iManage/NetDocuments) deep access-control testing, internal network and privilege escalation, BEC scenario, attack-chaining 8–12 working days €8,000–€20,000
Compliance add-on Mapping and attestation letter for GDPR, ISO 27001 or a client’s security review with any tier from €800
Custom / multi-office Several offices, merged IT estates or a full internal assessment, scoped to the firm on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote

FAQ

How much does legal penetration testing cost?
It starts from €2,500 for a focused test and is priced by scope: how many portals and applications, whether the document system and email are included, and the size of your network. You get a fixed quote after a free scoping call.
Is penetration testing legal, and how do you authorize it?
Yes, when it is authorized. We start only after a signed rules-of-engagement document that names the in-scope systems and the testing window. That written authorization is what makes the work lawful rather than an offence, and we never touch anything outside it.
Will you see our clients’ confidential files?
We test whether access controls hold, which sometimes proves a file is reachable, but we do not read or extract matter content beyond what is needed to evidence a finding. Everything is under NDA and any data is destroyed when the engagement closes.
Can you test our iManage or NetDocuments setup?
Yes. We focus on whether matter-level permissions and ethical walls are actually enforced on the server, not just shown in the interface, which is where confidentiality failures hide. For cloud-hosted platforms we confirm the provider’s testing terms first.
Does this help with GDPR and ISO 27001?
Yes. The report and attestation letter are written to evidence GDPR’s technical-measures requirement and to support ISO 27001 Annex A, including A.12.6 on vulnerability management.
Can you assess our exposure to email fraud?
Yes. We check SPF, DKIM and DMARC and assess how easily a partner could be impersonated to redirect a client payment, which is the most common and costly fraud against firms handling client money.
Will testing disrupt fee-earners during the working day?
No. We agree any intrusive checks in advance and can run them out of hours. Availability of your systems is never the price of finding a hole.
Is the retest included?
Yes, and free. After your team fixes the findings we retest them and update the report and attestation to confirm they hold, which is what insurers and clients want to see.

Related services

Who needs this

Law firms and professional-services practices across Europe that hold privileged and sensitive client data, face client or insurer security demands, or are pursuing ISO 27001, and need an authorized, confidential test of the systems where that data lives.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Legal & Professional Services Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.