Vertical

SOC for law firms: professional secrecy, client data, M365

Law firms are attractive targets because a single client can unlock M&A details, litigation strategy or compliance investigations. A SOC for law firms monitors M365, DMS platforms (iManage, NetDocuments), identity and endpoints. It prevents data leaks that would breach both professional secrecy (SCC Art. 321) and revFADP. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

All

Scope: SOC vs legal-tech support vs compliance consulting

Legal tech support (DMS, time tracking, e-discovery) manages availability and configuration; the SOC monitors security-relevant activity on the same systems. Privacy and regulatory advisers define the rules; the SOC monitors compliance with those rules in practice. This page covers ongoing detection and response; for governance, see security consulting.

Short version

A mandate is a trust contract. The SOC is the technical safeguard for that contract in daily operations.

What needs monitoring in law firms

  • M365 and Google Workspace: mail, SharePoint, OneDrive, Teams, calendar.
  • Document management (iManage, NetDocuments, HighQ and similar) including external data rooms for transactions.
  • Identity platform (Entra ID or Okta) with Conditional Access, roles and external guest access.
  • Endpoints including BYOD models for partners and lawyers; EDR and a managed browser policy are mandatory.
  • Matter and time-tracking systems; anomalies there often provide the earliest signals of unauthorised activity.

Regulation and legal framework

  • Professional secrecy (SCC Art. 321): unauthorised disclosure of client data has criminal law implications. Firms are also liable for their service providers' errors.
  • revFADP (revised Federal Act on Data Protection): personal data in client matters often qualifies as sensitive personal data. Firms must notify the FDPIC as soon as possible when the risk is high. See revFADP and SOC.
  • The Lawyers Act (BGFA) and cantonal supervisory bodies require organisational and technical measures to safeguard professional secrecy. A SOC is an effective technical measure, not a substitute for internal governance.
  • In matters touching financial institutions, insurers or critical infrastructure operators, FINMA and ISG reporting deadlines can apply indirectly; the firm has to know the chain. See SOC and FINMA and SOC and ISG reporting.
  • Clients increasingly require ISO 27001, especially in RFPs from international groups. See ISO 27001 and SOC.

Effective detection and response for law firms

  1. Focus on BEC and token theft: attackers compromise law firms primarily via M365. See BEC in M365 and Token theft and session hijacking.
  2. ITDR at the centre: impossible travel, unusual OAuth grants, mass downloads from SharePoint and DMS turn into cases in the SIEM. See ITDR.
  3. DMS monitoring: model access patterns per role and matter; alert when an account suddenly seeks access to many unrelated matters.
  4. Deepfake-vishing and CEO-fraud playbooks: always use verified channels for payments under time pressure; see Deepfake and vishing.
  5. Shadow AI detection: lawyers often use AI tools without approval; prompts containing client data constitute a professional secrecy incident. See Shadow AI detection.
What law firms often underestimate

The big attack rarely arrives with noise. It arrives quietly: a compromised M365 account reads along for weeks, forwards attachments and waits for the relevant deal. A SOC that sees identity and mail anomalies within minutes is more effective than any email rule after the fact.

Frequently asked questions

May we process client data with cloud AI?

You may do so only with written client approval, a reviewed vendor contract, exclusion of training on outputs and technical safeguards. Without these safeguards, use poses a risk to professional secrecy.

How does a SOC deal with partner laptops and BYOD?

BYOD requires MDM enrolment, compliance signals and a managed browser policy. Without these prerequisites, firms must restrict access to isolated enclaves to give the SOC visibility.

Does a law firm SOC need to run 24/7?

A law firm SOC generally needs 24/7 operation because critical signals (token theft, unusual OAuth grants, mass downloads) occur around the clock. See [24/7 SOC operations](/en/soc/how-a-24-7-soc-works) for operating models and pricing.

How do we uphold professional secrecy when working with the SOC partner?

Use a responsibility agreement, minimal data visibility (log metadata rather than content where possible), retention periods and documented access procedures. The firm retains control of its data at all times.

What happens when an incident involves client data?

Open a case, block accounts and sessions, and establish the data scope and affected individuals. Notify the FDPIC and, where necessary, clients; involve the supervisory authority and document the chain of evidence. See the [incident response plan](/en/soc/create-incident-response-plan) for the workflow.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
Detecting and stopping Business Email Compromise in Microsoft 365
Business Email Compromise (BEC) in Microsoft 365 rarely involves malware. The attack chain involves phishing, session or token theft, inbox rules and OAuth consent abuse. A SOC detects BEC by correlating signals from Entra ID, Exchange Online and Defender for Cloud Apps. The email body alone is insufficient for detection. Responders revoke sessions, remove inbox rules, withdraw OAuth consents and enforce MFA again. They document these actions in line with ISG and insurance requirements.
Detecting and stopping token theft and session hijacking
Token theft means attackers steal the session or refresh token of an already authenticated user and use it to bypass MFA. The classic path is reverse-proxy phishing (adversary-in-the-middle), increasingly also endpoint info-stealers. A SOC detects this from token usage outside the user context, not from the login itself. Defence means phishing-resistant MFA, Continuous Access Evaluation, token binding and detection on refresh-token replay.
ITDR: Identity Threat Detection and Response for Switzerland
ITDR (Identity Threat Detection and Response) detects attacks on the identity itself, not just endpoints or networks. Targets are accounts, tokens, sessions, permissions and identity providers such as Entra ID or Okta. ITDR extends EDR and SIEM with signals only visible in the identity layer. These include impossible travel, consent phishing, refresh-token abuse, role abuse and attacks on federation and directory objects. For Swiss organisations running M365, Entra ID and regulated processes, ITDR today is as important as EDR was five years ago.
Shadow AI detection: when staff use AI outside policy
Shadow AI describes AI use outside approved processes. Examples include private ChatGPT accounts at work, browser extensions with LLM integration and unapproved AI features in SaaS products. Customer data, source code or confidential documents can flow uncontrollably to a vendor without a contract or documentation. Swiss organisations need technical detection at network, endpoint and identity levels to make shadow AI visible and bring it back under governance. For the policy framework, see [AI Governance](/en/soc/ai-governance-security).