Client Data Protection Checklist for Professional Services Firms

Client Data Protection Checklist for Professional Services Firms

In 2025, the ICO fined a UK law firm £60,000 after attackers walked in through a dormant administrator account that had no multi-factor authentication, made off with 32 gigabytes of highly sensitive case files, and published them on the dark web. The firm didn’t spot the theft itself, the National Crime Agency told them. And because the breach wasn’t reported to the ICO for 43 days, the late notification became an aggravating factor in the penalty.

Almost every part of that story is preventable, and none of it required exotic technology to prevent. That’s the awkward reality for professional services firms: the incidents that end up in enforcement notices and client termination letters rarely involve genius-level hacking. 

They involve an unused account nobody reviewed, a password without a second factor, a file share with the wrong permissions, or an email that looked convincing.

If you’re a managing partner, director or operations leader in a law firm, accountancy practice, consultancy or any business built on client confidence, this checklist is for you. It covers the controls that actually protect client data, practically, in the order that a sensible firm would tackle them.

Why client data protection matters in professional services

Confidentiality is central to the client relationship

As a professional services firm, you sell trust with expertise attached. Clients hand over the most sensitive information they possess, such as financial records, deal terms, disputes, health information, privileged correspondence, on the understanding that it will be guarded properly. That makes confidentiality a commercial asset.

It also makes firms disproportionately attractive targets. A single practice can hold the concentrated secrets of hundreds of clients, which is precisely why attackers go after the adviser rather than the client. The numbers bear this out: successful cyber attacks on UK law firms rose 77% in a single year, and the legal sector alone reported over 2,200 data breach incidents in the year to September 2024. Accountancy and advisory firms face the same logic. One breach = many victims = maximum leverage for extortion.

And unlike a lost laptop’s replacement cost, the damage compounds significantly. A breach threatens professional indemnity cover, invites regulatory scrutiny (the SRA, ICAEW, FCA and ICO all expect demonstrable safeguards), and hands competitors the easiest pitch they’ll ever make.

Sensitive information is often spread across multiple systems

Try to name every place a single client’s information lives in your firm. The practice management system, obviously. But also email threads and their attachments, SharePoint or shared drives, the document management system, personal OneDrive folders, a partner’s laptop, a few WhatsApp messages nobody will admit to, and an old file-sharing link that may or may not still work.

Confidential data has a habit of sprawling, because busy professionals optimise for getting the work done. All of it is exposure. You cannot protect information you can’t locate, and most firms genuinely can’t locate all of it, which is why this checklist starts with visibility rather than technology.

Hybrid working increases the importance of consistent controls

Client work now happens in offices, kitchens, trains and hotel lobbies, across managed laptops, personal devices and whatever Wi-Fi is nearest. That flexibility is good for the business and for recruitment, and nobody is putting the genie back in the bottle. But it means the old security model of a firewall around the office and a polite smile to the receptionist, is finished.

Protection now has to travel with the data and the identity, not the building. The controls in this checklist (MFA, device management, conditional access, approved sharing channels) exist precisely so that a fee-earner working from a spare bedroom is exactly as secure as one sitting in head office.

Data protection is a business risk, not only an IT issue

When a professional services firm suffers a serious breach, the consequences land on the letterhead, not the server room: regulatory investigation, a 72-hour ICO notification clock, difficult client calls, insurance wrangles, and partners personally fronting the apology. The government’s latest Cyber Security Breaches Survey found 43% of UK businesses identified a breach or attack in the past year –  rising to around two-thirds of medium and large organisations.

Boards manage client money risk, litigation risk and reputational risk with structure and ownership. Client data deserves the same treatment. The good news: the structure isn’t complicated. It looks like the checklist below.

Client data protection checklist: the essential controls

1. Understand what client data you hold and where it lives

Build visibility over sensitive information

Start with a data map: what client and personal data does the firm hold, in which systems, owned by whom, and accessible to whom? Include the unglamorous places, such as email archives, legacy systems from a merger, backup sets, departed employees’ mailboxes. Modern tools can scan and discover sensitive data across Microsoft 365 and file stores, which beats asking everyone nicely and hoping.

Classify information according to sensitivity

Not all data needs the same armour, and pretending it does guarantees the armour gets ignored. A simple classification scheme of public, internal, confidential and highly confidential lets you apply stronger controls where they matter: privileged material, deal information, personal and special category data. Keep it to three or four tiers. If your classification policy needs its own training course, it will be politely ignored by everyone billing by the hour.

Reduce unnecessary data exposure

Every file you hold is a file you can lose. Set and enforce retention schedules, archive or delete closed-matter data you no longer need, and shut down the informal habit of keeping everything forever “just in case”. Under UK GDPR you shouldn’t be keeping personal data beyond its purpose anyway, so deletion is that rare thing: a security control, a compliance win and a storage saving all at once.

2. Establish an information governance framework

Define how information should be handled throughout its lifecycle

Governance sounds dry, but it’s simply agreed answers to practical questions: how client data is collected, where it’s stored, how it’s shared, how long it’s kept and how it’s destroyed. Write those answers down for each stage. When handling rules exist only in partners’ heads, every new joiner invents their own, and one of them will invent something alarming.

Assign responsibility for information governance

Someone must own this by name, like a COO, a compliance lead, a data protection officer where required. “Everyone is responsible for data protection” is a lovely poster in the staffroom but it’s an accountability vacuum. The owner doesn’t do all the work; they make sure it happens, report to the board, and act as the person the ICO expects to find when they come asking.

Create practical policies employees can actually follow

The best policy is the one that fits how people genuinely work. If your approved file-sharing route takes eleven clicks and the deadline is in an hour, staff will email the attachment. Pair every “don’t” with an easy “do this instead”, keep documents short, and sense-check policies with the fee-earners who’ll live with them.

Review the framework as technology and working practices change

Your governance framework should evolve when reality does: new practice management platforms, AI tools (which arrive with their own data-handling questions), mergers, new regulatory guidance. An annual review is the minimum; a change-triggered review is better. 

3. Use role-based access control to limit unnecessary exposure

Give employees access based on their role and responsibilities

Access should follow the job, not the org chart’s path of least resistance. A tax associate needs their clients’ matters, not the entire firm’s. Role-based access control (RBAC) defines access by role — associate, manager, partner, support — so permissions are consistent, explainable and quick to set up correctly for every new joiner.

Avoid giving broad access by default

The classic failure mode in professional services is the “open by default” document store, where anyone can read anything because that was easiest when the system was set up in a hurry. It feels collegiate right up until one compromised account exposes every client the firm has ever acted for. Default to closed; open deliberately. 

Review access when roles change

People join, move teams, get promoted, go on secondment and leave – and their access should change the same day. Leavers are the priority: accounts disabled before the goodbye cake is cut. Run quarterly access reviews where managers actually confirm what their teams can see; you’ll be surprised what’s accumulated.

Apply the principle of least privilege

The thread running through all of this: everyone gets the minimum access needed to do their job well, and nothing more. It isn’t about distrust. It’s about blast radius, when (not if) an account is compromised, least privilege determines whether the attacker gets one matter or the whole firm.

4. Strengthen privileged access management

Identify privileged and administrative accounts

Privileged accounts such as IT admins, system administrators for the practice management system, global admins in Microsoft 365, and service accounts can change permissions, read anything and switch off your defences. Start by listing every one of them, including the forgotten ones. Remember: the £60,000 fine mentioned at the top of this article began with a little-used admin account nobody was watching.

Separate everyday accounts from administrative access

Nobody should read email or browse the web from an account with admin rights. IT staff should have two identities: a standard account for daily work and a separate privileged account used only when needed. It’s a five-minute configuration that removes an entire category of catastrophe, because phishing a standard user no longer hands over the keys to the building.

Use privileged access management to reduce unnecessary admin exposure

Privileged access management (PAM) tools go further: admin rights granted just-in-time for a specific task and automatically revoked afterwards, vaulted credentials, and approval workflows for sensitive actions. The goal is standing privilege approaching zero, admin power that exists only while it’s genuinely being used.

Monitor activity involving high-risk accounts

Privileged accounts deserve special scrutiny: alerts for logins at odd hours or from unusual locations, new account creation, permission changes and mass downloads. If an admin account starts behaving strangely out of hours, you want an automated alarm, not a discovery weeks later via the National Crime Agency.

5. Enforce MFA across critical systems

Why passwords alone do not provide sufficient protection

Passwords leak. They’re phished, reused across services, and traded in bulk by criminals. Multi-factor authentication adds a second proof of identity such as an app prompt or hardware key, so a stolen password is a dead end rather than an open door. It remains the single best return on investment in security, and its absence is now routinely cited by the ICO as a factor in enforcement. 

Prioritise MFA for high-value systems

Everything internet-facing should have it, but start where the crown jewels live: email (the master key to password resets everywhere else), Microsoft 365, the practice or case management system, the document management system, finance and banking, remote access, and every admin console. Cover partners and senior staff first, as they hold the most access and receive the most convincing phishing.

Combine MFA with wider identity controls

MFA works best as part of a layered identity approach: conditional access policies that consider device health and location, blocking legacy authentication protocols that bypass MFA entirely, phishing-resistant methods (hardware keys or passkeys) for admins, and single sign-on so people authenticate strongly once rather than weakly ten times a day. Attackers have learned to nag users with endless MFA prompts hoping one gets approved – number-matching prompts and user awareness close that gap.

Use secure client portals and approved file-sharing methods

Email attachments are the traditional way to share client documents, and traditions can be terrible. Attachments get forwarded, misaddressed and stored in unknown inboxes forever. Secure client portals and controlled sharing links give you encryption, authentication, expiry dates and – crucially – the ability to see who accessed what and to revoke access when needed. Clients increasingly expect this; a decent portal quietly signals that you take their confidentiality seriously.

Standardise approved file-sharing methods

Pick your approved channels, make them genuinely easy to use, and communicate them clearly, then close the side doors. Personal Dropbox accounts, WeTransfer links and “I’ll just WhatsApp it” exist in every firm that hasn’t provided a better alternative. This is a solvable problem: when the secure route is also the convenient route, shadow IT mostly evaporates on its own.

Remove access when engagements end

Sharing has a lifecycle. When a matter closes or an engagement ends, external access should end with it – we’re talking expired links, deactivated portal accounts, archived collaboration spaces. Set expiry dates by default so cleanup happens automatically rather than depending on someone remembering, and include a sharing review in your matter-closure process.

6. Use data loss prevention to reduce accidental and intentional data leakage

What data loss prevention controls are designed to do

Data loss prevention (DLP) tools watch for sensitive information heading somewhere it shouldn’t (client identifiers, financial data, documents marked highly confidential) whether by honest mistake, misjudged shortcut or, occasionally, deliberate exfiltration. Think of DLP as a seatbelt for the firm’s most common accident: the right document sent to the wrong place. Misdirected email remains one of the most frequently reported breach types to the ICO, year after year.

Monitor high-risk sharing and transmission

Focus on the risky movements: emails to personal addresses, bulk downloads from the document management system, uploads to unapproved cloud services, USB transfers, and large attachments leaving the firm. A spike in downloads from someone who’s just resigned is a pattern worth noticing, leavers taking “their” client files with them is one of the oldest problems in professional services.

Apply controls carefully to avoid blocking legitimate work

Heavy-handed DLP is self-defeating: block too aggressively and people find workarounds, which is worse than the problem you started with. Begin in monitoring mode to learn normal patterns, then introduce gentle friction such as “this email is going to an external personal address, are you sure?” prompt catches a remarkable number of mistakes without blocking anything. Reserve hard blocks for the clearly indefensible.

Combine technology with clear handling policies

When staff understand why client data can’t go to personal accounts, the technology becomes a helpful backstop rather than an adversary. Tools plus understanding beats either alone.

7. Strengthen email security for client communications

Email remains one of the biggest routes to confidential information

Phishing is the most common attack type facing UK organisations by a wide margin, and professional services email is a particularly rich target: it carries privileged advice, deal detail and, in many firms, instructions about money. Business email compromise, where an attacker hijacks or convincingly imitates a genuine thread to redirect a payment, has cost firms and their clients dearly, with conveyancing and completion funds a perennial favourite. AI has made the bait better: today’s phishing reads fluently, references real matters and arrives at plausible moments.

Protect email accounts with layered controls

Layer the defences: MFA on every mailbox; anti-phishing and impersonation protection; link and attachment scanning; SPF, DKIM and DMARC configured and enforced so criminals can’t send email as your domain (and so your genuine mail is trusted by clients’ systems); external sender banners; and alerts for the classic compromise signs – new forwarding rules, unusual login locations, sudden mass sends. Attackers who breach a mailbox typically set up a quiet forwarding rule and read for weeks before striking; that rule should trigger an alarm the moment it’s created.

Introduce verification processes for high-risk requests

Some requests should never be actioned on email alone: changes to bank details, urgent payment instructions, requests for sensitive files, anything invoking pressure and secrecy. The control is procedural and almost free, so verify via a known phone number or a separate trusted channel before acting. Tell clients about this practice at engagement stage; it protects them too, and it makes the awkward “just checking this is really you” call feel like professionalism rather than paranoia. 

8. Enable audit logging and security monitoring

Maintain visibility over access to sensitive systems

If confidential data is accessed inappropriately, could you tell who, what, when, from where? Audit logs are the firm’s memory. Without them, incident response becomes educated guessing, regulatory notifications become vague, and you may never know the true scope of a breach (which, under GDPR, can force you to assume the worst). Many firms discover at the worst possible moment that logging was off by default or retained for a fortnight.

Prioritise logging for high-risk systems

Log everything, in an ideal world; in the real one, prioritise: email and Microsoft 365 activity, the practice and document management systems, finance platforms, remote access, and anything touching privileged accounts. Capture logins, document access, downloads, permission changes and sharing events for the data that matters most.

Use monitoring to identify suspicious behaviour

Logs nobody reads are a diary of the crime, written for the benefit of the post-mortem. Monitoring – whether a SIEM platform, Microsoft’s built-in alerting, or a managed detection service – turns logs into signals: impossible-travel logins, mass downloads, disabled security settings, out-of-hours privileged activity. For most firms without a 24/7 security team, outsourcing the watching is the pragmatic answer, because attackers are inconsiderate about time zones.

Retain logs appropriately for investigations and compliance

Breaches are often discovered months after they began, so logs kept for 30 days may miss the entire story. Retain key logs for at least 12 months (check your insurer’s and regulator’s expectations), store them where an attacker with admin rights can’t delete them, and confirm retention settings rather than assuming defaults are sensible. They rarely are.

9. Protect endpoints and remote access

Secure the devices employees use to access client information

Every laptop, desktop and phone that touches client data is part of your security perimeter now. A stolen, unencrypted laptop containing client files is a reportable breach with a hardware problem attached. Baseline protections for every device: full-disk encryption, automatic screen locks, up-to-date operating systems and applications, and modern endpoint detection and response (EDR) that spots malicious behaviour rather than just known malware signatures.

Apply consistent endpoint security controls

Use central device management (MDM) to enforce the same standards everywhere, so security doesn’t depend on which office someone sits in or how diligent they feel about updates. Central management also gives you the ability to locate and remotely wipe a lost device.

Control access from unmanaged devices

Use conditional access to decide what unmanaged devices can do: perhaps web-based email with no download rights, but no full sync of the document management system to a home PC you’ve never seen. If the firm allows personal devices for work, containerise work data so it can be wiped without touching family photos, a distinction people care about deeply, and rightly.

Secure remote access

Remote access to firm systems should require MFA without exception, use modern encrypted connections (a well-configured VPN or zero-trust access), and be limited to what each role needs. Retire any legacy remote access methods such as old VPN appliances and exposed remote desktop services – they are among attackers’ favourite front doors, and they scan the internet for them constantly.

10. Review third-party and supplier access

Professional services firms depend on external technology providers

The modern firm runs on suppliers, and many hold or can reach client data. Supply chain attacks are rising precisely because one compromised provider opens dozens of firms at once; the legal sector saw this vividly when a single managed service provider’s outage in 2023 left scores of conveyancing firms unable to complete transactions, and again with the Legal Aid Agency breach in 2025. Their incident becomes your incident with remarkable speed.

Give suppliers the minimum access they need

Least privilege applies to companies too: named accounts rather than shared logins, MFA enforced, access scoped to the systems their work requires, and time-limited where possible. When a contract ends, access ends that day. Dormant supplier accounts are exactly the sort of forgotten door attackers love.

Assess how suppliers handle client information

Before entrusting client data to a provider, ask the adult questions: where is data stored and processed, what certifications do they hold (Cyber Essentials Plus, ISO 27001), how do they control their own staff access, and how quickly would they notify you of a breach? Get data processing agreements in place as UK GDPR requires. A supplier who bristles at security questions has answered them.

Include third-party risk within the wider information governance framework

Keep a live register of suppliers, the data they touch and the access they hold; review it at least annually and at every renewal. Include critical suppliers in your incident response planning. If your practice management platform goes down or gets breached, you want to already know their emergency contacts, their obligations and your fallback for serving clients in the meantime.

11. Prepare for a client data breach or security incident

Create a clear incident reporting process

Speed of detection depends on the person who first notices something odd. Everyone should know exactly how to report a concern, immediately and without fear of blame. A no-blame culture is a genuine security control: the employee who reports their own mistake within five minutes has just saved the firm days of head start it would otherwise have gifted the attacker.

Prepare for containment and investigation

Decide in advance who leads an incident, who can authorise disruptive action (isolating systems, forcing password resets, taking services offline), and which external specialists you’d call. Preserve evidence rather than destroying it in a panic: don’t wipe machines, do capture logs. The middle of a crisis is the most expensive possible time to be exchanging introductory emails with an incident response firm.

Plan communications before an incident occurs

A serious breach involves several conversations, some on a statutory clock: the ICO within 72 hours where the breach risks individuals’ rights, affected clients without undue delay where risk is high, your professional regulator where obligations apply, your insurer, and your own staff. 

Draft the skeleton communications now, calmly. Firms that communicate quickly and honestly consistently fare better with clients and regulators than those that go quiet – the DPP Law case showed that late reporting doesn’t just look bad, it costs a lot of money.

Test the incident response process

Run a tabletop exercise once or twice a year: pick a plausible scenario, and walk the leadership team through it hour by hour. These sessions are inexpensive, occasionally uncomfortable, and reliably surface the gaps (the out-of-date phone list, the unclear decision rights, the backup nobody has restored) while they’re still cheap to fix.

12. Review client data protection controls regularly

Data protection is not a one-off project

Everything above decays without attention. Staff change, systems change, attackers change, and controls quietly drift out of alignment with reality. The firms that stay secure treat this checklist as a cycle – assess, improve, verify, repeat – with a named owner and board visibility, exactly like any other standing risk.

Schedule regular access and security reviews

Put the rhythm in the diary: quarterly access reviews (including supplier accounts), monthly patching and vulnerability checks, periodic restore tests of backups, an annual policy and framework review, and a proper lessons-learned exercise after any incident or near miss. Certifications such as Cyber Essentials Plus or ISO 27001 provide a useful external forcing function  and increasingly, clients and insurers ask for them anyway.

Use managed security services where internal capacity is limited

Very few mid-sized firms can build 24/7 monitoring, incident response capability and specialist security expertise in-house, and honestly, very few should try. Managed security services provide round-the-clock detection and response, patching, identity management and compliance support at a fraction of the cost of employing it  and they let your internal IT resource focus on making the firm more productive rather than permanently firefighting. The pertinent question isn’t whether expert support costs money. It’s what a serious breach would cost without it.

Protecting client confidentiality requires more than one security control

If there’s one theme running through the enforcement notices, the insurance claims and the client departures of the last few years, it’s this: firms rarely fall due to a single dramatic failure. They fall to a chain of small ones. Each link seemed minor. Together they were enough to prise the cracks open.

The reassuring thing is that resilience is also cumulative. No single control on this list will make your firm secure, but layered together, they make you a genuinely hard target, and they give you the evidence of “appropriate technical and organisational measures” that regulators, insurers and increasingly clients expect to see.

Work through the checklist honestly, score the firm as it is rather than as the policies say it should be, and fix the highest-risk gaps first. And if your internal capacity can’t stretch across all of it – true of most professional services firms, and no bad reflection on anyone – bring in a partner who does this every day.

The first step is a clear picture.

At Utilize, we help professional services firms protect confidential client information with managed IT, cyber security and compliance support built around how firms actually work. If you'd like an honest assessment of where you stand against this checklist and a pragmatic plan to close the gaps, take a look at our security audit. It's a much better conversation to have before an incident than after one.

Professional Services IT Support Book your IT Security Audit