Legal & Professional Services Penetration Testing
Legal penetration testing for law firms and professional services. Protect client confidentiality and privilege. Manual, fixed-price, free retest.
Legal penetration testing protects the one asset a law firm cannot afford to lose: the confidentiality of client matters. We test the systems where privileged documents, deal data and personal information actually live, and we do it manually, under NDA, with a report your partners and your professional-indemnity insurer will take seriously.
SafetyBis is a European offensive-security team working with law firms and professional-services practices across Europe. Firms hold concentrated, sensitive data (merger terms, litigation strategy, personal records of clients on both sides of a dispute) and they are targeted precisely because of it. A breach is not only a GDPR problem. It is a breach of the duty of confidentiality that sits at the centre of the profession.
What legal penetration testing actually covers
The scope for a professional-services firm follows the data. That means the document management system where matters are stored, the email platform that attackers use for fraud, the client and matter portals, and the network and identity layer that ties it together. We test the paths an intruder would take to reach a privileged file.
Document management is the crown jewel. In firms that run iManage or NetDocuments, the interesting question is rarely whether the platform itself is patched. It is whether the ethical walls and matter-level permissions actually hold when a determined user, or an attacker with one user’s credentials, tries to walk around them.
How we test
Legal penetration testing at SafetyBis is manual and evidence-based. We use Burp Suite, nmap and ffuf to map and probe, but the findings that matter to a firm come from an engineer reasoning about who should be able to see which matter, and then trying to prove they cannot be stopped.
Reconnaissance and mapping
We enumerate the firm’s external footprint: portals, remote-access gateways, forgotten microsites from a past rebrand, and email infrastructure. For firms that have grown by merger, this stage routinely surfaces systems nobody remembers owning.
Authenticated and access-control testing
Using accounts for different roles (fee-earner, paralegal, support, admin) we test whether matter-level and ethical-wall permissions are enforced on the server, or only hidden in the interface. Broken object-level authorization here means one lawyer reading another team’s confidential file, which is a professional-conduct incident, not just a technical bug.
Exploitation and email-fraud simulation
We demonstrate real impact safely. Where business email compromise is a concern, we assess how easily an attacker could impersonate a partner and redirect a completion payment, one of the most common and expensive frauds against law firms handling client money.
Reporting
Findings come with a CVSS score, a clear reproduction, and remediation written so your IT provider or in-house team can act. Anything critical is escalated to you the day we confirm it.
Common vulnerabilities we find in professional-services firms
Broken matter-level authorization
The document platform enforces ethical walls in the UI, but a direct API call or a manipulated document identifier reaches a file the user should never see. This is the legal-sector version of IDOR, and it is the one we treat most seriously.
Business email compromise exposure
Weak or missing SPF, DKIM and DMARC records let an attacker spoof a partner’s address convincingly. Combined with a mailbox rule an intruder can plant after a phishing success, this is the mechanism behind redirected client payments.
Weak authentication on remote access
VPNs and remote-desktop gateways without enforced MFA, reused credentials, and stale accounts of departed staff. Legacy remote access is a favourite entry point, and it maps directly to MITRE ATT&CK initial-access techniques.
Over-privileged accounts and flat networks
Support staff with domain-admin rights, service accounts with passwords that never change, and a network where one compromised laptop can reach every server. This is how a single phished credential becomes a firm-wide ransomware event.
Insecure external document sharing
Client portals and file-transfer links that leak beyond their intended recipient. We test whether a share link can be guessed or enumerated, whether it expires, and whether removing a person from a matter actually revokes their access to documents they were previously sent. A link that outlives the relationship it was created for is a slow, quiet disclosure of privileged material.
Legal aspects and requirements for penetration testing
Firms ask, reasonably, about the legal aspects of penetration testing before they authorize one. The short answer: it is a controlled, contracted, authorized activity, and we treat the paperwork as seriously as the testing.
Authorization and scope
Testing begins only after a signed authorization (a rules-of-engagement document) that names the in-scope systems, the testing window, and the limits. That written authorization is what separates a penetration test from an offence under computer-misuse law across Europe. We never test anything not explicitly listed.
Confidentiality and data handling
We work under NDA, and any client data we encounter during testing is handled under strict controls and destroyed when the engagement closes. For a firm, the legal requirements for penetration testing are really a subset of your own confidentiality duty, and we contract to meet it.
Third-party and cloud systems
Where your data sits in a cloud service such as iManage Cloud or Microsoft 365, we confirm the provider’s testing terms and stay within them, so the engagement is authorized end to end.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Tools and techniques
Burp Suite Professional drives our web and portal testing. We use nmap for external service discovery, ffuf for content discovery on portals, and manual review for access-control and business-logic flaws that no scanner understands. Email security is assessed against the actual SPF, DKIM and DMARC configuration. Findings are mapped to OWASP ASVS and, for the attack narrative, to MITRE ATT&CK.
What you get
Many firms need the attestation letter for a client’s own vendor-security review, or to answer a professional-indemnity insurer’s question about whether the firm tests its defences. The report is written to serve both.
Compliance and standards
GDPR
Law firms process special-category and highly sensitive personal data, so GDPR’s requirement for appropriate technical measures, and for testing them, applies with force. A penetration test is direct evidence that you assess your defences rather than assume them.
ISO 27001
Many firms pursue ISO 27001 to win institutional clients. Our report supports Annex A controls, including A.12.6 on technical vulnerability management, and the remediation evidence feeds straight into your management system.
Client and sector obligations
Corporate and financial clients increasingly impose their own security clauses on outside counsel. A recent independent test is often the cleanest way to satisfy them.
Why manual testing beats a scanner for a law firm
A scanner cannot understand an ethical wall. It does not know that partner A must never see matter B, so it cannot test whether that rule holds. The confidentiality failures that would end a client relationship are logic and authorization failures, and finding them requires a human who understands how the firm works. A scanner also floods a small IT team with noise. We hand you a ranked list of things that are genuinely exploitable, so remediation is focused rather than overwhelming.
Consider a realistic chain from one of our engagements: a marketing subdomain nobody remembered still ran an old login, its credentials were reused by a support account, that account had more rights in the document system than anyone intended, and from there a determined tester could reach matters across several practice groups. No single step was exotic. A scanner would have flagged the outdated login and stopped, missing the point entirely, which is that the four ordinary weaknesses together amounted to a firm-wide confidentiality breach. Writing that chain down, with the business impact spelled out, is the part a partner actually reads and acts on.
Who books this and when
Managing partners and firm IT leads come to us after a client demands proof of security, ahead of an ISO 27001 certification, when renewing professional-indemnity cover, or after a near-miss such as an attempted payment fraud. If your firm holds anything a client would be horrified to see leaked, testing is not optional maintenance, it is due diligence on your own duty of confidentiality.
Pricing
Legal penetration testing cost depends on scope: the number of applications and portals, whether the document system and email are in scope, and the size of your external and remote-access footprint. Pricing is fixed per engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Client portal or single web application plus external network surface, authentication and access-control testing, full report and free retest | 3–5 working days | from €2,500 |
| Firm standard | Portal, practice-management app and document-system access review, email-fraud (SPF/DKIM/DMARC) assessment, exec plus technical report | 5–8 working days | €3,500–€8,000 |
| Advanced | Document management (iManage/NetDocuments) deep access-control testing, internal network and privilege escalation, BEC scenario, attack-chaining | 8–12 working days | €8,000–€20,000 |
| Compliance add-on | Mapping and attestation letter for GDPR, ISO 27001 or a client’s security review | with any tier | from €800 |
| Custom / multi-office | Several offices, merged IT estates or a full internal assessment, scoped to the firm | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote
FAQ
How much does legal penetration testing cost?
Is penetration testing legal, and how do you authorize it?
Will you see our clients’ confidential files?
Can you test our iManage or NetDocuments setup?
Does this help with GDPR and ISO 27001?
Can you assess our exposure to email fraud?
Will testing disrupt fee-earners during the working day?
Is the retest included?
Related services
Law firms and professional-services practices across Europe that hold privileged and sensitive client data, face client or insurer security demands, or are pursuing ISO 27001, and need an authorized, confidential test of the systems where that data lives.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.