Search

 
 

Law firm strengthens cyber resilence and earns ISO 27001 certification 

 

58%

Reduction in security gaps against the NIST Cybersecurity Framework, reflecting measurable improvement in program maturity.

 

57

Security gaps resolved to prepare the firm for internal audit and ISO 27001 certification.

 

100%

Successful ISO 27001 certification audit completed with zero non-conformities and no opportunities for improvement identified.

 
 

At a glance

 

Client

Top 50-ranked Am Law global law firm

 

Industry

Professional services & law firms

 

Our role

Cyber risk advisory

 

Our solution

Cyber maturity and ISO readiness

 
 
 

End-to-end cyber risk and ISO certification support

 
folder icon

Scenario

A global law firm needed to strengthen its information security program to build trust with clients and firm leadership by achieving ISO certification.

gears icon

Approach

We conducted year-over-year cyber risk and maturity assessments, identified and resolved security gaps and supported readiness for ISO 27001 certification.

graph icon

Result

The firm strengthened its information security program maturity, reduced key risks and achieved ISO 27001 certification with zero deficiencies.

 
 

Scenario

 
 

Meeting rising client demands for cyber assurance

 

For professional services firms, cybersecurity is no longer just an internal IT concern. It’s become a core measure of trust between teams and the clients who rely on them. Law firms in particular are entrusted with highly sensitive client data, making their security posture critically important to protect their clients’ interests. As cyber incidents continue to rise across client-facing industries, many clients now view formal, third-party validation of cybersecurity practices as table stakes.

 

These concerns led a leading global law firm to strengthen its cyber assurance. The organization’s CISO, deputy CISO, and head of governance, risk and compliance, backed by the firm leadership team, engaged Grant Thornton to support its journey to provide independent validation of its cybersecurity program to clients. That meant aligning with widely recognized standards: achieving ISO 27001 certification while strengthening risk management practices aligned with the NIST Cybersecurity Framework.

 

“Early on, it became clear that while the firm had received prior security assessment support from other providers, however, they had struggled to turn those recommendations into actionable solutions across their teams,” said Tito Chatterjee, Cyber & Privacy Advisory Services Senior Manager. “We knew this would require closer collaboration with their key stakeholders to not only identify risks but also mitigate them in a way that met international standards and reinforced trust with their clients. The annual risk assessment report is ultimately shared with some of their biggest clients — large, industry‑leading organizations that require this level of assurance.”

 
 

Approach

 
 

Building an actionable path to cyber assurance

 

Chatterjee and his team understood that they needed to take a practical and collaborative approach to their work: advancing the firm’s information security maturity without disrupting day-to-day operations.

 
Tito Chatterjee

“By meeting the team where they were — translating standards and assessments into practical steps the teams could actually execute — we were able to complete the needed background assessments so the firm could work toward ISO certification in time, without impeding or slowing down their business operations and priorities.”

Tito Chatterjee 

Senior Manager, Cyber & Privacy Advisory Services
Grant Thornton Advisors LLC

 

Re-evaluating risks

 

The team began with an information security assessment aligned to the NIST Cybersecurity Framework. Grant Thornton evaluated the firm’s current-state controls, identifying opportunities for improvement and rating the maturity of the program.

 

At the same time, the team performed external and internal network penetration testing, which provided insight into vulnerabilities and misconfigurations and helped inform remediation decisions.

 

Working closely with key stakeholders, the team helped define remediation priorities and develop the firm’s cyber risk register to track and manage key risks year over year.

 

Mapping current state to requirements

 

From there, Grant Thornton assessed how the firm's existing security practices mapped to ISO 27001 requirements, focusing on finding gaps that could affect audit readiness and translating those gaps into actionable remediation steps with step-by-step advisory and technical support along the entire journey.

 

Preparing for audit

 

Before the firm pursued external certification for ISO 27001, Grant Thornton’s Internal Audit team conducted an internal audit, which helped identify any nonconformities or opportunities for improvement and validating the appropriate corrective action plans from firm management, providing the firm a clear view of what they needed to address before certification.

 

How we can help you

 
 

INDUSTRY

Services -->

 

 

Ready to talk? We’re ready to listen.

Request a meeting -->
 
 

Result

 
 

Reduced risk and first-time certification with no findings

 

When Grant Thornton first performed its information security assessment, it identified 57 issues that could have prevented ISO 27001 certification. But after remediating those issues and validating audit readiness through an internal audit, all were resolved. The firm successfully achieved its ISO 27001 certification with zero nonconformities and zero opportunities for improvement.

 

“While many organizations can achieve certification on their first audit if they’re well-prepared, it's rare to have zero non-conformities and zero opportunities for improvement on the first attempt,” said John Pearce, Grant Thornton Cyber & Privacy Advisory Services Partner.

 

Through ongoing assessments and remediation efforts, the firm also reduced its overall cyber risk footprint, cutting open risks in its cyber risk register by more than half and remediating 58% of the security observations initially identified against the NIST Cybersecurity Framework. By advancing its information security program maturity and providing audit-backed, internationally recognized documentation, the firm reinforced trust across the organization and with its clients.

 

Connect with our team

 

Arlington, Virginia

Industries

  • Insurance
  • Technology, Media & Telecommunications
  • Transportation & Distribution
  • Banking

Service Experience

  • Advisory Services
 
 

Content disclaimer

This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.

Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.

 

Ready to talk? We’re ready to listen.

 

Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.

 

Want to submit an RFP? Please submit your request through our RFP submission page.

 
 
 

Trending topics

 

Follow us