COMPLIANCE · CYBERSECURITY BASELINE

Cybersecurity baseline, configured and evidenced.

Your firm holds privileged communications, client money and identity documents. We configure your devices and Microsoft 365 to the ASD Essential Eight, at the maturity level that fits your firm, register every device that touches firm data, and keep the evidence your insurer and law society expect to see.

Confidentiality now means technical controls.

Your duty to protect client information doesn't stop at a locked filing cabinet. Law societies publish cybersecurity guidance for practitioners, insurers ask about your controls at renewal, and a breach involving personal information can trigger the Notifiable Data Breaches scheme. The ASD Essential Eight is the Australian baseline most of these point back to.

Phishing was the most common way in, identified in 38% of the incidents ASD's ACSC responded to in FY2024–25.

Source: ASD Annual Cyber Threat Report 2024–25

What you'll be able to prove

  • The ASD Essential Eight put in place and documented, at an agreed maturity level: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.
  • Multi-factor authentication on every account, with conditional access so unmanaged devices can't reach firm data.
  • Every device that touches firm data, firm-owned or personal, registered and covered by policy before it gets access.
  • Email authentication (SPF, DKIM and DMARC) at enforcement, so your domain is much harder to spoof to clients.
  • Backups that are tested, not just scheduled.
  • A written incident response plan that names who does what, including the Notifiable Data Breaches steps.
  • A verification procedure for any change to payment or account details, so a change is always checked by phone on a number you already hold.

How the evidence is captured

Device compliance, multi-factor coverage and security configuration are reported from your tenant, so drift shows up before an insurer or a breach finds it. Every tenant-level change goes through change control, so there's a record of who changed what, and when.

Who does what

We hold the tenant configuration and security policy. Your local IT provider keeps the hands-on work. Ongoing security monitoring is a condition of our engagement, and it can sit with the same provider, working to a scope we agree with them. A security operations centre is optional, if you want one.

Some firms need a higher Microsoft 365 plan to switch on the security features their obligations require. We tell you before any work starts.

What can be included

  • Baseline review against the ASD Essential Eight
  • Multi-factor authentication and conditional access
  • Device registration and policy, for firm-owned and personal devices
  • Email security and domain authentication
  • Backup verification
  • Incident response plan, including Notifiable Data Breaches steps
  • Microsoft 365 plan review

Book a baseline review

Frequently asked questions

  • The ASD Essential Eight, with the cybersecurity guidance your law society publishes for practitioners.

  • Possibly. Some security features need a higher plan. We tell you what's needed, and why, before any work starts.

  • No. We hold the tenant configuration; your IT provider keeps the hands-on support.

  • They can, once the device is registered and covered by policy. Until then, access to firm data is blocked.

Find out where your baseline stands.

Fixed scope, fixed fee, and a clear list of what to fix first.