A NSW law firm facing a failed security audit and compliance gaps was fully uplifted to Essential Eight Maturity Level 2, closed ISO 27001 control gaps, and renewed cyber insurance at improved terms.

When this NSW law firm approached Extranet Systems, they were running legacy antivirus, untested backups, and no threat detection capability, in a practice handling sensitive client funds and confidential legal matters.
Every compliance obligation pointed to gaps they could not close with their existing tools. A failing security audit, an approaching cyber insurance renewal, and Law Society trust accounting requirements they could not evidence made the situation urgent. The risks were clear:
When ACT XM approached Extranet Systems, they were running three separate platforms in parallel, a client relationship tool, a transaction management system, and a reporting platform. None of these systems shared data natively.
Every time a client detail changed, a staff member had to update it in three places. Every compliance report required manually pulling exports from each system and combining them in spreadsheets. The risks were clear:
Our first priority was mapping their obligations, not deploying tools. Before we recommended a single control, we spent time understanding the firm’s compliance requirements, their audit findings, and the specific threats facing legal practices in Australia.
What became clear was that the solution wasn’t to bolt on more software. It was to deploy a fully managed security stack where every control mapped directly to a real requirement. Essential Eight, ISO 27001, or Law Society obligation. No shelfware. No over-engineering. This meant the firm got exactly what they needed to evidence compliance, renew their insurance, and close their audit gaps without disrupting their day-to-day practice.
""We were staring down a failed audit, a cyber insurance renewal, and Law Society obligations we couldn't evidence. Extranet Systems resolved all three without disrupting the practice for a single day." "Practice Manager, a NSW Law Firm
We worked in focused phases with clear deliverables at each stage. The firm could see progress against their audit findings and compliance obligations from week one. Nothing was deployed without a mapped requirement behind it.
We reviewed their existing environment, documented every control gap against Essential Eight, ISO 27001, and Law Society requirements, and built a remediation roadmap that prioritised the highest-risk exposures first.
EDR, 24/7 SOC, advanced email security, Microsoft 365 and endpoint backup, and RMM patching were deployed and configured to each specific compliance requirement. Every control was evidenced and documented as it went live.
Independent penetration testing was conducted to validate the controls in place. Compliance evidence was packaged for the Law Society of NSW trust accounting obligations and structured to support the cyber insurance renewal at improved terms.
The impact was visible before the engagement closed. A practice that had failed its security audit now had a documented, evidenced, and independently tested security posture that satisfied every obligation in front of them. The anxiety around renewal and compliance was gone.
Key outcomes from the engagement:
Tell us what you're trying to solve. We'll tell you honestly whether we're the right team for it.
No commitment required. Just an honest chat about what you're building and whether we can help.
or call 1300 290 196Real engineers, response within one business day.