Protecting confidential client documents in a small firm
Client confidentiality is a professional obligation long before it is an IT problem. The controls that satisfy it are unglamorous and mostly about where files live and how they leave the building.
The problem
A small professional firm holds material that is genuinely sensitive — matter files, tax positions, personal data, sometimes information that would harm a client if it were disclosed. The realistic risks are not sophisticated. They are an attachment sent to the wrong recipient, a shared link that outlives the engagement, a laptop left on a train, and an ex-employee who still has access because nobody handled the offboarding properly.
Decide where documents are allowed to live
Most firms cannot answer the question "where are our client files?" with a single sentence, and that is the root problem. Documents accumulate in a practice system, in personal cloud folders, in email attachments, on a legacy file server, and on individual laptops.
Pick one authoritative location per document type and make everything else a working copy that is expected to disappear. In Workspace, that means organisation-owned shared drives structured by client or matter, not personal My Drive folders — see securing Google Workspace for how that changes ownership and access review.
Stop sending confidential documents as email attachments
An attachment leaves your control the moment it is sent, sits in an unknown number of mailboxes indefinitely, and cannot be recalled meaningfully. Misdirected email remains one of the most common reported breach causes for professional firms, and autocomplete is usually the culprit.
The alternative is a link to a permissioned location, with access granted to a named person and an expiry on the share. For firms exchanging documents with clients regularly, a client portal is a better answer again: the client logs in, the firm sees who accessed what, and there is no attachment to misdirect. That is a small custom software build for many firms, or a feature of the practice system you already pay for.
The controls a client questionnaire will actually ask about
Larger clients increasingly send security questionnaires to their advisers. The questions are consistent enough that you can prepare once and reuse the answers.
Being able to answer these in a day rather than a fortnight is itself a commercial advantage, and increasingly a condition of winning the work.
- Is multi-factor authentication enforced for all staff, including partners?
- How is access removed when someone leaves, and how quickly?
- Are backups taken, and when was a restore last tested?
- Is data held in the UK or EU, and who are your sub-processors?
- Do you hold Cyber Essentials or an equivalent certification?
- How would you notify us of a breach, and within what timeframe?
Devices are where the policy meets reality
Confidentiality controls on documents mean less if the device holding them is unencrypted, unpatched, shared with a family member, or personally owned with no way to remove firm data from it.
The baseline is modest: full-disk encryption on every device, a supported operating system, automatic patching, screen lock, and the ability to revoke access remotely. For personal devices, the honest choice is either to manage them or to stop firm data reaching them — running an unmanaged BYOD estate and calling it a policy satisfies nobody, least of all an insurer.
Retention: keeping everything is also a risk
Firms tend to keep documents indefinitely because deletion feels dangerous and storage is cheap. But data you no longer need is pure liability: it expands what a breach exposes and what a subject access request has to cover.
Agree a retention period per document category with reference to your professional body's requirements, then actually apply it. This is a governance decision rather than a technical one, but the tooling to enforce it — retention rules, Vault policies, archive locations — should follow the decision rather than substitute for it.