Security for law and accounting firms

Small firms hold exactly what fraudsters want: client funds moving through trust accounts, confidential files, and a name clients trust enough to send money to on request.

The most common attack isn't a break-in. It's an email that looks like it came from your firm, telling a client the payment details have changed. Whether that email lands depends on settings most firms have never checked.

What usually turns up

These are the gaps most often found when businesses like yours are checked from the outside.

  • No DMARC policy, so the firm's domain can be spoofed
  • Look-alike domains registered one letter away from the firm's name
  • Client portal or document-sharing logins with no protection against password guessing
  • Outdated plugins on the firm's website

Recommended services

In the order most law and accounting firms should take them.

Find out where you stand

One free finding from your own site, by email, with no access needed. It's the quickest way to see whether the gaps above apply to you.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.