SOC for law firms: professional secrecy, client data, M365
Law firms are attractive targets because a single client can unlock M&A details, litigation strategy or compliance investigations. A SOC for law firms monitors M365, DMS platforms (iManage, NetDocuments), identity and endpoints. It prevents data leaks that would breach both professional secrecy (SCC Art. 321) and revFADP. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.
Scope: SOC vs legal-tech support vs compliance consulting
Legal tech support (DMS, time tracking, e-discovery) manages availability and configuration; the SOC monitors security-relevant activity on the same systems. Privacy and regulatory advisers define the rules; the SOC monitors compliance with those rules in practice. This page covers ongoing detection and response; for governance, see security consulting.
A mandate is a trust contract. The SOC is the technical safeguard for that contract in daily operations.
What needs monitoring in law firms
- M365 and Google Workspace: mail, SharePoint, OneDrive, Teams, calendar.
- Document management (iManage, NetDocuments, HighQ and similar) including external data rooms for transactions.
- Identity platform (Entra ID or Okta) with Conditional Access, roles and external guest access.
- Endpoints including BYOD models for partners and lawyers; EDR and a managed browser policy are mandatory.
- Matter and time-tracking systems; anomalies there often provide the earliest signals of unauthorised activity.
Regulation and legal framework
- Professional secrecy (SCC Art. 321): unauthorised disclosure of client data has criminal law implications. Firms are also liable for their service providers' errors.
- revFADP (revised Federal Act on Data Protection): personal data in client matters often qualifies as sensitive personal data. Firms must notify the FDPIC as soon as possible when the risk is high. See revFADP and SOC.
- The Lawyers Act (BGFA) and cantonal supervisory bodies require organisational and technical measures to safeguard professional secrecy. A SOC is an effective technical measure, not a substitute for internal governance.
- In matters touching financial institutions, insurers or critical infrastructure operators, FINMA and ISG reporting deadlines can apply indirectly; the firm has to know the chain. See SOC and FINMA and SOC and ISG reporting.
- Clients increasingly require ISO 27001, especially in RFPs from international groups. See ISO 27001 and SOC.
Effective detection and response for law firms
- Focus on BEC and token theft: attackers compromise law firms primarily via M365. See BEC in M365 and Token theft and session hijacking.
- ITDR at the centre: impossible travel, unusual OAuth grants, mass downloads from SharePoint and DMS turn into cases in the SIEM. See ITDR.
- DMS monitoring: model access patterns per role and matter; alert when an account suddenly seeks access to many unrelated matters.
- Deepfake-vishing and CEO-fraud playbooks: always use verified channels for payments under time pressure; see Deepfake and vishing.
- Shadow AI detection: lawyers often use AI tools without approval; prompts containing client data constitute a professional secrecy incident. See Shadow AI detection.
The big attack rarely arrives with noise. It arrives quietly: a compromised M365 account reads along for weeks, forwards attachments and waits for the relevant deal. A SOC that sees identity and mail anomalies within minutes is more effective than any email rule after the fact.
Frequently asked questions
May we process client data with cloud AI?
You may do so only with written client approval, a reviewed vendor contract, exclusion of training on outputs and technical safeguards. Without these safeguards, use poses a risk to professional secrecy.
How does a SOC deal with partner laptops and BYOD?
BYOD requires MDM enrolment, compliance signals and a managed browser policy. Without these prerequisites, firms must restrict access to isolated enclaves to give the SOC visibility.
Does a law firm SOC need to run 24/7?
A law firm SOC generally needs 24/7 operation because critical signals (token theft, unusual OAuth grants, mass downloads) occur around the clock. See [24/7 SOC operations](/en/soc/how-a-24-7-soc-works) for operating models and pricing.
How do we uphold professional secrecy when working with the SOC partner?
Use a responsibility agreement, minimal data visibility (log metadata rather than content where possible), retention periods and documented access procedures. The firm retains control of its data at all times.
What happens when an incident involves client data?
Open a case, block accounts and sessions, and establish the data scope and affected individuals. Notify the FDPIC and, where necessary, clients; involve the supervisory authority and document the chain of evidence. See the [incident response plan](/en/soc/create-incident-response-plan) for the workflow.
Related terms
- revFADP The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
- BEC Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
- Phishing Phishing is an attack that uses fake emails and messages to trick people into taking an action.
- Data Exfiltration Data exfiltration is the unauthorised removal of data from an organisation, often for extortion purposes.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.