"You will not survive without endpoint security"

7 min read.

News Article
8 October 2026

Step inside one legal practice's approach to endpoint security

Our client is a mid-sized legal practice with a hybrid workforce, a busy conveyancing department and a low tolerance for risk. We spoke to them about why the practice deployed FortiClient, what changed afterwards and what they would say to any practice still weighing it up.

Tell us about your company.

We are a mid-sized legal practice with just under 50 staff. Our main areas are conveyancing, wills, probate and trusts and we have a Court of Protection department. We work privately and we also act for members of trade unions.

How does the team actually work day to day?

We are very much a hybrid practice and we have a good flexible working policy. We have over 50 staff and our office isn’t able to house everyone at once, so home working is a permanent part of how we operate. It makes for a good balance.

It does mean that our people are working on their own broadband, in their own homes on devices that leave the building every day. Everyone has a work laptop and we have moved to docking stations in the office which is a good setup. But it is only a good setup if the security around it is right.

What prompted you to look at endpoint security specifically?

It was a combination of things rather than one incident. We were conscious that once a laptop leaves the office, people become more relaxed about where they use it. We had requests to take devices abroad and there is always the possibility of somebody deciding to work from a cafe or an airport on public Wi-Fi. Everyone here receives very good security awareness training and they know the risks, but we are all human. Having something that actively prevents it, rather than relying on people to remember, felt like the right safeguarding measure.

Cyber risk is evolving quickly, particularly with AI in the mix and we wanted to be ahead of it rather than reacting to it.

Why does a legal practice carry more risk than a business in another sector?

Because of what we hold and what people expect of us. Clients assume a higher standard of confidentiality and a higher standard of cyber resilience from a legal practice than they would from a retailer. Data protection and GDPR are among our highest priorities and we are held to that standard by our regulator and by our clients.

Conveyancing is the sharp end of it. Conveyancing departments in law firms see more attempted cyber activity than any other part of the business, because that is where the money moves and sadly, criminals know that. So the bar for us is higher than it would be almost anywhere else.

Why FortiClient and why with Netprotocol?

We already had Fortinet in place as our firewall and it had done its job very well for years. When Netprotocol told us about FortiClient, it sounded like exactly what we needed.

Mike Batters, Technical Director at Netprotocol gave us a great demo and it ticked every box. We could roll things out across every device. We could control what people connect to their laptops. And we could still be intuitive about it, shaping the policy around what individual staff genuinely need rather than applying a blanket rule.

On Netprotocol, the thing worth saying is that when they put a product in front of us, it is because the engineers rate it and they think it solves a problem we actually have. There is never any obligation attached and it never feels like we are being sold to. Over the years we have worked with them, every product they have recommended has exceeded our expectations. The level of trust and the level of support we get from them is exceptional.

You mentioned control. What does that look like in practice?

It is controlled down to the smallest detail and it is fast.

If we decide to change what people can connect to or tighten how they log in, we can raise a ticket. Within about 15 minutes it is confirmed and rolled out across every single device we own. If a director comes back from an SRA update or a security event and says we need to change something, it's the same process.

Web filtering was one of the first things you turned on. How did that go?

It was one of the very first things we did and no, it was not popular.

We locked down sites we knew people were using at work on the office Wi-Fi. It only takes one compromised link on one site, clicked on a work laptop that is docked and connected to our network and you have a serious incident. If you recover from something like that, you are lucky.

Working in IT, you see the darker side of things. Most staff do not and that is not a criticism, it is just the reality. So when we see something downloading over the work network, we can be more nervous and other people do not always understand why. Netprotocol helped us put the controls in and we also set up a separate guest Wi-Fi, so personal devices sit away from the corporate network. That way the risk is split.

How does it feel now that it is in place?

A massive relief, genuinely.

It is the reliability and the control together. When it comes to security you do have to be a bit of a control freak and this lets us be one without it becoming a burden. Our staff know they are protected. They know they can work from home, connect, and not spend the day worrying that one wrong click will bring everything down. Our directors definitely sleep better at night! 

It also grows with us. It fits into where we want to take our cyber security over the next few years rather than being a fix for where we are today.

What would you say to another legal practice weighing up FortiClient?

Cyber security is a crowded market at the moment and a lot of people are jumping on the bandwagon. Fortinet has been around for a long time and has proven itself. From an IT perspective, FortiClient is the best we have seen. There are newer products that do some of what it does, but they are not as versatile and they do not command the same reliability.

Our advice is to have a demo. You will be surprised how far into the detail you can actually get.

And to anyone still asking whether it is worth the spend?

You need it. Not just FortiClient necessarily, but you need reliable cyber security and as a legal practice you will not survive without it. There are already too many horror stories of businesses that have gone under. We see it in the clients who come to us. It is awful and AI is going to make it worse.

If a practice has nothing in place today, they need to seriously consider it now otherwise they will not last the next few years.