The typical estate

  1. 01

    Practice and matter management

    The system of record for engagements, and usually the oldest thing in the estate.

  2. 02

    Document management

    Where the actual work product lives, with retention and privilege obligations attached to every file.

  3. 03

    Time, billing and revenue

    Directly tied to cash. Integration errors here are noticed within a day.

  4. 04

    Microsoft 365

    Email is frequently the real system of record, whether or not anyone intends it to be.

  5. 05

    Client-facing portals

    Increasingly expected, and increasingly the subject of the client’s own security review.

Pressure

Where it strains.

  • Confidentiality boundaries between engagements have to be enforced in the tooling, not in policy documents.
  • Partner-level autonomy quietly multiplies the number of platforms in use.
  • Retention and legal hold obligations apply to systems nobody classified as records systems.
  • Clients increasingly send security questionnaires that the firm must answer about its own estate.
Worth knowing

Your clients’ auditors are also auditing you

In this sector the security review is not a procurement formality. It arrives from clients whose own regulators require them to assess their advisers. An estate that cannot produce evidence of access control and retention becomes a commercial problem, not just a technical one.

Our role

What Ferrafox would take on.

  • Identity and access, including confidentiality boundaries enforced in Entra and Microsoft 365
  • Integration between practice, document and billing systems
  • Client portals built to survive the client’s security review
  • Retention, legal hold and the evidence that both are working
09Contact

Tell us what your organization runs on.

The first conversation is about the environment as it stands today: what exists, what it costs to keep running, and where responsibility currently sits.