Engagements  /  PSY-WEB-0365

A document portal that leaked through its filenames

A law firm’s client portal protected every document properly. The search box told you what was in them anyway.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
Professional services
Engagement
Web app pentest & ISO 27001 gap
Frameworks
OWASP ASVS 5.0, ISO/IEC 27001:2022 Annex A
Duration
3 weeks

A mid-sized law firm.

The firm shared engagement letters, drafts and disclosures with clients through a portal built by a small agency. A corporate client’s security questionnaire asked for a recent penetration test and alignment with ISO/IEC 27001.

The firm had neither, and a renewal at stake.

What we did

Test the portal, then the firm around it.

Test search as an attack surface

Downloads were properly authorised. The autocomplete endpoint was not — it suggested filenames across all clients, and the firm named files after matters.

Check the parts a portal depends on

Email, identity and laptops were assessed against ISO/IEC 27001:2022 Annex A, since an attacker in a partner’s mailbox would not need the portal at all.

Answer the questionnaire properly

We mapped every questionnaire item to evidence or a dated remediation commitment, rather than answering “yes” and hoping.

What we found

What a search box gave away.

SeverityFindingMaps toStatus at retest
CriticalAutocomplete returned document titles from every client’s matters to any logged-in user.ASVS V8 · CWE-200Closed
HighPartners’ mailboxes protected by SMS one-time codes only.ISO 27001 A.8.5 · A.5.17Closed
HighPortal sessions did not expire on logout and lasted 30 days.ASVS V7 · A07:2025Closed
MediumNo disk encryption policy for personal laptops used for client work.ISO 27001 A.8.1 · A.6.7In progress
MediumIT provider held permanent global admin rights.ISO 27001 A.5.15 / A.8.2Closed

What changed.

The search leak was fixed by the agency within a week and verified at retest. Partners moved to phishing-resistant MFA.

The firm renewed its corporate client with a summary letter, a completed questionnaire and a twelve-month ISO 27001 roadmap it is now working through toward certification.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.