Skip to content
Equal Tech Solutions
Anonymized client engagement

How a 19-attorney litigation firm stopped partner email spoofing and rebuilt matter-based document security

Law firm2026

19-attorney litigation firm · 2 offices · Chattanooga, TN

Result 01
0
Spoofed partner emails delivered after DMARC
Result 02
100%
Laptop encryption + MFA coverage
Result 03
0
Billable hours lost during migration

The challenge

Where they started.

ABA Model Rule 1.6(c) and Formal Opinion 477R require reasonable efforts to protect client confidences — the firm couldn't demonstrate any. Matter files were spread across a flat file server, three personal Dropbox accounts, and attorney laptops. Email had no MFA, and anyone on the internet could send mail as a partner. A real-estate closing nearly wired funds to a spoofed instruction.

Specific pain points

  • Client matter files split across a flat share, personal Dropbox, and local laptop folders
  • No MFA on email; domain had no DMARC, so partners were trivially spoofable
  • Near-miss wire fraud on a real-estate closing from spoofed payoff instructions
  • No version control — associates overwrote each other's briefs with no recovery path
  • Departed associates still had file-share and email access months after leaving

The approach

What we did.

Email spoofing and wire risk were closed first — those were the active exposures. Document management came next, rebuilt around matters rather than folders, with the migration staged after hours and by practice group so no attorney lost a billing day. Ethics documentation was produced alongside the technical work.

What we delivered

  • Phishing-resistant MFA + Conditional Access on every attorney and staff account
  • DMARC, SPF, and DKIM published and moved to enforcement after a monitoring window
  • Matter-centric document management in SharePoint with per-matter permissions and ethical walls
  • Dropbox and local matter folders migrated, deduplicated, and retired; versioning enabled firm-wide
  • BitLocker full-disk encryption enforced and reported via Intune on all laptops
  • Written wire-verification procedure: callback to a known-good number before any disbursement
  • Immutable backups plus a documented offboarding checklist tied to the HR departure process

The outcomes

What changed.

Once DMARC hit enforcement, the spoofed-partner emails that had been reaching staff inboxes stopped arriving. Every matter now has a single authoritative location with access scoped to the team working it, and the firm has written evidence of the reasonable efforts Rule 1.6(c) expects. The staged cutover finished without an attorney losing a billing day.

  • 0
    Spoofed-partner emails delivered post-enforcement
  • 100% of devices and accounts
    Full-disk encryption + MFA coverage
  • 0
    Client matter files outside managed storage
  • Complete
    Rule 1.6 / Opinion 477R safeguards documentation
  • 0
    Billable hours lost during migration
The wire attempt is what woke us up. Equal Tech Solutions closed the email hole first, then gave us a document system organized the way we actually practice — by matter, not by whoever made the folder.
Managing Partner, litigation firm

Ready when you are

Let's talk about your IT.

A 30-minute call is all it takes to know whether we're the right partner. No pressure, no jargon, no obligation.

What to expect

  1. 1
    30-minute discovery call

    We listen first — your environment, pain points, and goals.

  2. 2
    Free IT assessment

    Senior engineer reviews your stack and flags real risks.

  3. 3
    Plain-English roadmap

    Clear scope, clear pricing. Walk away with a plan, not a pitch.