Personal devices unmanaged and uncounted
Start with app protection rather than enrolment. It achieves the security outcome without the fight and can be deployed in days.
Twenty checks on whether client confidences are protected on devices your firm does not own or control.
Every firm has a policy about personal devices, and in most firms the practice is that a partner in an airport reads a matter email on their own phone.
A control that depends on senior people behaving differently from how they demonstrably behave is not a control.
Risk partner
IT lead
A partner who genuinely uses their own phone for work
Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.
What is actually happening, as opposed to what policy states.
What is applied to firm data on a device you do not manage.
The scenario the whole arrangement exists for.
Whether you could evidence any of this.
These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.
Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.
Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.
The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.
Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.
The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.
Start with app protection rather than enrolment. It achieves the security outcome without the fight and can be deployed in days.
Test it on a real device. Discovering it does not work during a partner's departure is the worst possible timing.
Rewrite the policy to match observed behaviour and then control it. An unfollowed policy is worse than none in a negligence context.
Read the compliance report. The gap between policy and applied state is usually meaningful.
We will assess your current position against what your professional indemnity insurer asks, and demonstrate app protection working on a real personal phone.
Twenty checks on whether your matter content is reachable only by the people who should reach it — including through search.
Describe the situation in your own words.