Services
Security that protects the firm without grinding it to a halt.
Cybersecurity and risk work, in our practice, is a small number of controls that materially reduce the odds of account takeover, ransomware, wire fraud, and data loss, implemented in a way that respects how the firm works. The outcome is a defensible security posture you can describe to a client, insurer, or regulator without hedging.
How we run it
Four phases, applied to this practice
Phase 1
Discovery & Audit
We baseline against the small number of controls that matter: identity, endpoint, email, backup, vendor, and human. We map who has access to what, whether MFA is enforced rather than merely switched on, and where privileged access lives.
Phase 2
Architecture & Design
We produce a ranked remediation plan. Every gap is tied to the specific risk it opens and the effort to close it. Nothing is added for theater; every recommendation names the incident it is meant to prevent.
Phase 3
Build, Integrate & Automate
We roll out controls in a sequence that avoids a mid-rollout self-lockout: phased MFA, staged conditional access, tested endpoint policy, verified backup restores. We rehearse the incident response plan on paper before we need it live.
Phase 4
Train, Measure & Refine
We train the humans (partners included), test annually with a tabletop, monitor identity and endpoint signals, and revisit vendor risk on renewal. Security posture is an ongoing state, so it lives on the roadmap.
What this looks like in practice
Recent work and field notes
Security engagements and incident work: what was in place, what changed, and how the posture held up afterwards.
Article
Incident response and cyber hardening: build the team before you need it
Proactive training plus disciplined response — why a cross-functional cyber response team that can swarm and neutralize risk is a best practice for growing firms.
ReadArticle
Identity is the new perimeter
SSO, MFA, and password management are the foundation everything else rests on. Why identity is now the front line of security for growing firms.
Read
Engagement models
How this work is scoped
Model
Project Delivery
The default fit. A defined program of identity hardening, endpoint rollout, and incident readiness, scoped and shipped.
Model
Audit & Roadmap
The right start when you need a written baseline for an insurer, client, or new managing partner.
Model
Fractional Leadership
For firms that need a security lead in the room continuously for vendor risk, client questionnaires, and incident response ownership.
FAQ
Questions we answer often
Are you a managed security service (MSSP)?
No. We design and stand up the program, tune the controls, and either transition day-to-day monitoring to your MSP or select and manage an MSSP on your behalf. We provide the security leadership; the SOC work sits with your monitoring provider.
How do you handle a live incident?
We follow a documented incident-response plan we build with you in advance. It covers containment, communications with internal and external counsel, forensics vendor engagement, and regulator or client disclosure timing. If we haven't done that plan yet, the first job in a live incident is to write it in the first hour.
What about SOC 2, HIPAA, or client security questionnaires?
We prepare the evidence and answer the questions honestly. We do not sell certification as a security outcome. A clean SOC 2 report and a secure firm are related, and we will tell you where they diverge.
Do you require us to buy a specific EDR, SIEM, or password manager?
No. We work with the tools you have if they are competent, and we recommend replacements only when a gap is material. For most firms our recommended baseline stack is one identity provider, one endpoint agent, one password manager, and one backup verified quarterly.
How much does a reasonable security program cost a mid-size law firm?
Programs land in a wide range depending on headcount, existing tools, and regulatory posture. We publish a specific number in the roadmap and we defend it.
Considering this work for your firm?
Drew replies personally within three business days.
