Legal

From failing the audit to insurance-grade in 90 days

A NSW law firm facing a failed security audit and compliance gaps was fully uplifted to Essential Eight Maturity Level 2, closed ISO 27001 control gaps, and renewed cyber insurance at improved terms.

2×
2x Essential Eight maturity levels gained from baseline to Level 2 Measurable uplift
Immediate improvement
0×
Successful phishing or BEC incidents since go-live
Superior Security
3×
Compliance frameworks achieved: Essential Eight, ISO 27001, Law Society NSW
On time, on budget
Case study
From failing the audit to insurance-grade in 90 days
On this page

Challenges

When this NSW law firm approached Extranet Systems, they were running legacy antivirus, untested backups, and no threat detection capability, in a practice handling sensitive client funds and confidential legal matters.

Every compliance obligation pointed to gaps they could not close with their existing tools. A failing security audit, an approaching cyber insurance renewal, and Law Society trust accounting requirements they could not evidence made the situation urgent. The risks were clear:

When ACT XM approached Extranet Systems, they were running three separate platforms in parallel, a client relationship tool, a transaction management system, and a reporting platform. None of these systems shared data natively.

Every time a client detail changed, a staff member had to update it in three places. Every compliance report required manually pulling exports from each system and combining them in spreadsheets. The risks were clear:

  • No endpoint detection or response capability against modern threats
  • Untested backups with no verified recovery process in place
  • Unable to evidence trust accounting compliance to the Law Society of NSW
  • Exposed to trust account fraud, business email compromise, and ransomware

Our Approach

Our first priority was mapping their obligations, not deploying tools. Before we recommended a single control, we spent time understanding the firm’s compliance requirements, their audit findings, and the specific threats facing legal practices in Australia.

What became clear was that the solution wasn’t to bolt on more software. It was to deploy a fully managed security stack where every control mapped directly to a real requirement. Essential Eight, ISO 27001, or Law Society obligation. No shelfware. No over-engineering. This meant the firm got exactly what they needed to evidence compliance, renew their insurance, and close their audit gaps without disrupting their day-to-day practice.

 

""We were staring down a failed audit, a cyber insurance renewal, and Law Society obligations we couldn't evidence. Extranet Systems resolved all three without disrupting the practice for a single day." "
Practice Manager, a NSW Law Firm

Strategy & Execution

We worked in focused phases with clear deliverables at each stage. The firm could see progress against their audit findings and compliance obligations from week one. Nothing was deployed without a mapped requirement behind it.

 

Phase 1 , Security assessment and gap analysis

We reviewed their existing environment, documented every control gap against Essential Eight, ISO 27001, and Law Society requirements, and built a remediation roadmap that prioritised the highest-risk exposures first.

Phase 2, Managed security stack deployment

EDR, 24/7 SOC, advanced email security, Microsoft 365 and endpoint backup, and RMM patching were deployed and configured to each specific compliance requirement. Every control was evidenced and documented as it went live.

Phase 3, Penetration testing and compliance evidencing

Independent penetration testing was conducted to validate the controls in place. Compliance evidence was packaged for the Law Society of NSW trust accounting obligations and structured to support the cyber insurance renewal at improved terms.

Outcomes

The impact was visible before the engagement closed. A practice that had failed its security audit now had a documented, evidenced, and independently tested security posture that satisfied every obligation in front of them. The anxiety around renewal and compliance was gone.

Key outcomes from the engagement:

 

  • Essential Eight uplift from baseline to Maturity Level 2
  • ISO 27001 control gaps identified and closed in full
  • Trust accounting compliance evidenced for the Law Society of NSW
  • Cyber insurance renewed at improved terms
  • Zero successful phishing or BEC incidents since go-live

Key Results

Measurable outcomes achieved within the first 8 weeks of go-live

3
Compliance frameworks evidenced in a single engagement
2
Essential Eight maturity levels gained from baseline to Level 2
0
Successful phishing or BEC incidents since go-live
90days
From initial engagement to insurance-grade security posture

More case studies

View all projects
Legal
NSW Law Firm

Every solicitor. Every device. One secure desktop.

Financial Services
Global bank

The bank that can’t go down, no longer can

Healthcare
National Healthcare Provider

We made every system in the business talk to each other

Ready to write your own success story?

Tell us what you're trying to solve. We'll tell you honestly whether we're the right team for it.

Start the conversation

No commitment required. Just an honest chat about what you're building and whether we can help.

or call 1300 290 196
Social media & sharing icons powered by UltimatelySocial