For firms whose clients trust them with everything.
Law firms, accountants and advisors hold their clients’ most confidential documents, and increasingly their clients send security questionnaires of their own. We audit the firm against a framework a partner can read, and test the portal clients actually log in to.
Where firms are exposed.
01
Client portals
Document-sharing portals with predictable links, weak session handling or files indexed by filename.
02
Email and identity
Mailboxes without phishing-resistant MFA, the starting point for most wire-fraud and invoice-redirect losses.
03
Unmanaged laptops
Partners working from personal devices with no disk encryption, patching or ability to wipe remotely.
04
Supplier access
IT providers and software vendors with standing administrator access nobody reviews.
The CIS Controls v8.1 (Implementation Group 1 as the starting line), NIST CSF 2.0 and ISO/IEC 27001:2022.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
Have a client questionnaire you cannot answer yet?
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.
Let’s Connect
or email hello@penspycyber.com