Test search as an attack surface
Downloads were properly authorised. The autocomplete endpoint was not — it suggested filenames across all clients, and the firm named files after matters.
Penspy is an independent security firm, testing web applications and auditing against the frameworks you answer to.
A law firm’s client portal protected every document properly. The search box told you what was in them anyway.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
A mid-sized law firm.
The firm shared engagement letters, drafts and disclosures with clients through a portal built by a small agency. A corporate client’s security questionnaire asked for a recent penetration test and alignment with ISO/IEC 27001.
The firm had neither, and a renewal at stake.
Downloads were properly authorised. The autocomplete endpoint was not — it suggested filenames across all clients, and the firm named files after matters.
Email, identity and laptops were assessed against ISO/IEC 27001:2022 Annex A, since an attacker in a partner’s mailbox would not need the portal at all.
We mapped every questionnaire item to evidence or a dated remediation commitment, rather than answering “yes” and hoping.
| Severity | Finding | Maps to | Status at retest |
|---|---|---|---|
| Critical | Autocomplete returned document titles from every client’s matters to any logged-in user. | ASVS V8 · CWE-200 | Closed |
| High | Partners’ mailboxes protected by SMS one-time codes only. | ISO 27001 A.8.5 · A.5.17 | Closed |
| High | Portal sessions did not expire on logout and lasted 30 days. | ASVS V7 · A07:2025 | Closed |
| Medium | No disk encryption policy for personal laptops used for client work. | ISO 27001 A.8.1 · A.6.7 | In progress |
| Medium | IT provider held permanent global admin rights. | ISO 27001 A.5.15 / A.8.2 | Closed |
What changed.
The search leak was fixed by the agency within a week and verified at retest. Partners moved to phishing-resistant MFA.
The firm renewed its corporate client with a summary letter, a completed questionnaire and a twelve-month ISO 27001 roadmap it is now working through toward certification.
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.