For independent Australian law firms

Your clients trust you with secrets, money and judgement. Protect all three.

The next pressure may arrive as an obligation, insurer renewal, client questionnaire, cyber near miss or question about AI. Tier 1 connects GRC, cybersecurity and AI governance so partners can see what matters, who must act and what the firm can prove.

Work directly with Michael. No sensitive matter details are required for the first call.

Scroll to explore
02Start with what reached the partners

Start with what reached the partners

What brought the issue onto the partners' agenda?

You do not need to solve the legal, technical and AI questions before calling. Bring the trigger. Tier 1 will define the control work and keep regulated or technical advice with the appropriate specialist.

An obligation or client request

The PI renewal or a client questionnaire now asks exactly which controls operate, with evidence. Guessing on the form has become its own risk.

A cyber concern or near miss

An email asked to change payment details near settlement and it nearly worked. Or a mailbox was compromised and nobody is sure what was read.

An AI decision

Lawyers are drafting and researching with AI tools nobody formally approved. Privileged material may already sit in systems the firm has never assessed.

An ownership gap

The IT provider operates the technology and closes tickets, but no senior person owns the complete risk, obligation and assurance picture.

03Tier 1

Section 03

A small firm can still hold a large prize

Privileged matters, settlement money and client identities make a law firm useful to criminals. The National Anti-Scam Centre recorded $166.8 million in Australian payment-redirection scam losses in 2025, and the attack pattern is documented step by step in Tier 1's trust account fraud analysis. The response needs to fit legal practice rather than copy an enterprise program.

A closed matter folder, phone and pen on a lamp-lit desk at night.

Payment and trust account fraud

Attackers use compromised or convincing email to redirect a payment at the point when time pressure is highest.

Email compromise

A partner or staff inbox can expose confidential threads and let an attacker communicate as the firm.

Ransomware and disruption

Loss of access to matters and documents can stop billable work and create difficult client obligations.

Confidentiality breach

Disclosure can create privacy, professional, insurance and client consequences at the same time.

04Tier 1

Section 04

What Tier 1 does for law firms

One operating model connects obligations and risk decisions, the controls in the firm's systems and the rules around AI. Partners see one priority view instead of separate compliance, IT and AI projects.

The work starts with identity, email, devices, backups, payment verification, privacy, client assurance, cyber insurance accuracy, safe AI use and incident readiness.

Tier 1 already provides security support to Australian law firms including Indigo Lawyers and LegalByte. You work directly with Michael, not a junior passed to the account.

05Tier 1

Section 05

Govern AI before it touches privileged work

Lawyers and staff need an approved route to use AI without moving privileged or confidential material into systems the firm has not assessed. Tier 1 makes the tools, data boundaries, review duties and decisions visible.

Approved tools and uses

Record which tools may be used for defined legal and business tasks, who owns them and what remains prohibited.

Client-data boundaries

Set clear rules for privileged matters, personal information, client instructions, drafts and security information.

Qualified review

Require an appropriate lawyer or specialist to check output before it informs advice, filing, negotiation or a client decision.

Supplier controls

Review terms, data use, retention, location, deletion, access and material changes before relying on a service.

06Tier 1

Section 06

A sensible first engagement for a law firm

Begin with the information, payment and access pathways that could cause the most immediate harm. The result should give partners a short priority view and give the firm's providers a clear delivery brief.

Review critical pathways

Examine email, identity, devices, backups, matter access and payment changes across the people and providers involved.

Test what is claimed

Check whether important controls and insurer answers match current settings, processes and retained evidence.

Set partner decisions

Separate technical fixes from risk decisions that require leadership authority, resources or an accepted exception.

Build the response path

Make responsibilities and trusted contacts clear before a suspicious payment, account compromise or disclosure creates urgency.

07Questions

Straight answers

Common questions

We are only a few people. Are we really a target?

Yes. A small firm can still hold privileged matters, personal information and trust account funds. Size does not make that information less useful to an attacker. Strong fundamentals can materially reduce the opportunity.

Do we need an expensive certification?

Usually not to begin. Most firms should first improve access, email, devices, backups, payment verification and incident readiness. A formal standard becomes relevant when a client, contract, insurer or strategic goal justifies it.

Does Tier 1 replace our IT provider?

No. Your IT provider operates technology and support. Tier 1 sets the security direction, checks the important controls and helps partners make risk decisions. The two roles should work together with clear accountability.

How much time will this take from our lawyers?

We keep partner and staff time focused on decisions only they can make. Tier 1 handles the assessment, planning, coordination and evidence work, then works with your providers to put the agreed controls in place.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call