Offensive security for legal and insurance.
Law firms and insurers hold what clients handed over under a promise of confidentiality. A breach here is not an IT incident: it is a break of professional trust, with immediate legal consequences.
Concentration of sensitive information
Few sectors concentrate so much high-value information per square metre. Litigation strategy, corporate transactions under negotiation, medical reports supporting a claim, wealth history. This material interests both those looking to extort and those sitting across the negotiating table — and that second motive makes the attack targeted and quiet.
- The content carries immediate strategic value to the opposing party in a dispute.
- Professional privilege is a legal duty, not merely a contractual commitment.
- Claims fraud combines social engineering with document manipulation.
- Operations depend on constant file exchange with clients and external experts.
What we test in these environments
We follow the document: where it enters, where it rests, who can reach it and how it leaves.
Matter management and document repositories: object-level authorisation, isolation between clients and audit trails over who read what.
Authentication, password recovery, document upload and history access — including whether a policyholder can reach another's case.
Notification, report submission, assessment and payment: where the logic can be manipulated to approve what should be declined.
Resistance to payment redirection fraud, including identity verification on requests that arrive by email.
File exchange with experts, correspondents and clients: forgotten public links, over-broad permissions and missing expiry.
What access to one machine reaches in document volume, and which paths allow that material to leave without an alert.
Confidentiality as a requirement, not a recommendation
The report treats breach of privilege as its own severity category, above purely technical criteria.
- Professional privilege
- Legal professional privilege has its own statutory standing. Any path allowing improper access to client documents is classified as critical, regardless of the technical score.
- GDPR
- Case and claims data include special categories such as health and beliefs. We document data subject exposure and the lawful basis affected.
- Insurance regulation
- Insurers answer to their own internal control and operational risk requirements. The report fits as evidence of periodic testing.
- Corporate client requirements
- Large clients audit their legal suppliers. The attestation letter answers that questionnaire without exposing exploitable detail.
How we run under reinforced confidentiality
Agreement before first access
A reinforced NDA, with a specific clause covering third-party documents, is signed before any activity. We also define who on your side may see the report.
Proof without extracting content
We demonstrate improper access without exfiltrating the document: recording enough metadata and identifiers to prove it, leaving the content where it is.
Document fraud scenarios
We test the flow where a forged document would be accepted, because in claims and payments that is where the real loss sits.
Remediation and retest
We prioritise by exposure of privileged material, follow the remediation and retest before issuing the final version.
What you receive
- Executive report on confidentiality risk
- Reproducible technical report
- Map of access to privileged material
- Justified CVSS scoring
- Document fraud scenarios tested
- Evidence without content extraction
- Retest of remediated findings
- Attestation letter for clients
Sector FAQ
Will you read our clients' privileged documents?
+
We avoid it by design. Proving improper access does not require reading the content: it is enough to demonstrate the control failed, recording identifiers and metadata. Where content is unavoidable, it enters the evidence masked and the material is destroyed at the end of the cycle upon formal confirmation. The reinforced NDA is signed first.
Is claims fraud in scope?
+
It is, and it usually carries the highest financial value. We test the full flow: notification, report submission, assessment and payment release, looking for where the rule can be bent or where a forged document would be accepted without sufficient verification.
Can we use the report to answer a client audit?
+
Yes, and that is what the attestation letter exists for. It confirms scope, period and conclusion of the engagement without revealing exploitable detail — which is what a supplier questionnaire asks for. The full technical report stays restricted to whoever you nominate at kick-off.
How do you handle payment redirection fraud?
+
As a dedicated scenario, because it is the most recurring scam in the sector. We test the resilience of the process, not just the system: whether a request to change bank details arriving by email is verified through an independent channel, and whether a second approval exists for payments above a threshold.
Services applied to this sector
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.