Cybersecurity posture strengthening & Law 25 compliance for a law firm
The challenge
A mid-sized law firm handling sensitive files had to become compliant with Law 25 before the deadline. The company lacked a structured security strategy, its data was scattered, and its employees were not trained on the risks.
Our tailored approach
- Comprehensive Diagnostic: Security maturity assessment and mapping of personal data flows.
- Prioritized Roadmap: Implementation of a governance framework (policies, records of processing), technical hardening of access controls and backups.
- Targeted Awareness: An engaging training program for all employees on client data protection.
Concrete, measurable results
- Compliance Achieved: A complete, auditable compliance dossier delivered on time for the Law 25 deadline, avoiding potential penalties.
- Risk Reduction: Attack surface reduced by 60% through system hardening and strict access management.
- Culture Shift: Employee reporting rate of suspicious emails increased by 40%, turning them into an active first line of defense.