Trust nothing, verify everything. The shift every law firm should understand.

3 min read.

News Article
22 June 2026

Not so long ago, IT security had a clear edge. There was an office, a firewall at the door and a simple rule: if you were on the network, you were trusted. Everything inside was ours, everything outside was checked.

Then that edge disappeared. Email, documents and case management moved to the cloud. People started working from home, from chambers, from client sites and from court. The wall you were defending stopped existing. In its place came a username and password box on the internet that, in theory, anyone anywhere could try.

The industry response has gone full circle. First everything was locked down on-premise and tightly controlled. Then the cloud swung the door wide open, on the logic that access from anywhere was the whole point. Now it is swinging back, but smarter. The aim is to keep the flexibility people now expect while putting real control back around it.

For law firms this matters more than for most. You hold the most sensitive material your clients will ever hand over. A breach is not just downtime. It is a regulatory problem, a reputational one, and a direct hit to client confidence. Attackers know the legal sector is data-rich and that the stakes for getting it wrong are high, which is exactly why regulators expect firms to be able to demonstrate control, not just claim it.

The shift underneath all of this is straightforward, even if the labels are not. Instead of trusting someone because of where they are, you instead verify who they are, what device they are on and what they are allowed to reach, every time. The industry calls this zero trust, or ZTNA. In practice it works a bit like a single door with one person checking ID on the way in, every time, rather than waving people through because they look like they belong.

Some of this is available and practical today. When a company laptop leaves the office, the protection should leave with it. With Fortinet’s FortiClient installed on the device, the same web filtering that blocks malicious and harmful sites in the office stays switched on when that laptop is sitting on someone's home wifi. The device does not become less safe simply because it left the building. We manage it centrally, so it rolls out across a fleet of laptops without anyone having to set anything up themselves. It works now and for any company with people regularly working off-site it closes an obvious security gap.

The bigger shift is still taking shape. The direction is to route access through a single, controlled point, so your cloud services, your email included, only accept connections that come through you and nothing else. The industry term for this is SASE (Secure Access Service Edge). We see it as where serious security for the legal sector is heading.

The right setup is not the same for everyone, it depends on how your people work, what they need to reach and where you are actually exposed. That is the conversation we have with our legal clients, so let's have the conversation with you.

Get in touch to speak to one of our friendly team.