JJC SystemsBook a Consultation
Legal · Managed IT & Security

AI adopted without exposing a single client matter

A large personal injury practice, United States. The firm wanted a competitive edge from generative AI while protecting highly sensitive client data. Sophisticated attacks had already bypassed multi-factor authentication.

The situation

What the organization was dealing with

The firm wanted a competitive edge from generative AI while protecting highly sensitive client data. Sophisticated attacks had already bypassed multi-factor authentication.

For a firm holding sensitive client matters, the AI question and the security question are the same question. The risk is not that a drafting tool produces a poor first draft — it is that client information leaves a controlled environment, which is a professional obligation issue rather than a technical one.

What was done

The work, and the part that was actually hard

Microsoft 365 was deployed first as the foundation, then Copilot alongside a legal drafting add-in, with Defender, Intune and Entra ID hardening identity and devices underneath.

The sequencing matters here. The firm adopted the productivity platform two years before the AI layer, which meant identity, devices and information protection were already in place when Copilot arrived. Firms that reverse that order end up pausing the AI programme to fix the foundation, usually after a security review has already flagged it.

Results

What was published

These are the figures exactly as reported in the source. Nothing has been rounded, extrapolated or restated.

Foundation before AI2 yrs
Legal professionals250+
Client data exposed to the internet0

What changed

  • Documents drafted from firm data and a trusted legal database without external exposure
  • Email drafted on mobile from short prompts, expanded into full messages
  • Identity and device security raised after attacks that had bypassed MFA
  • Capacity and performance increased across the existing team rather than by hiring
Platforms involved

What each product was doing here

Modern work

Microsoft 365

Email, files, meetings, identity and the information-governance controls that most organizations license and only partly deploy.

Copilot

Microsoft 365 Copilot

Generative AI inside Word, Excel, Outlook and Teams, grounded in the organization's own content and bounded by each user's existing permissions.

Security

Microsoft Defender

Threat protection across endpoints, identity, email and cloud, correlated into single incidents rather than four separate alerts.

Security

Microsoft Intune

Device management and compliance policy, used as a condition of access rather than as a reporting exercise.

Security

Microsoft Entra ID

Identity, multi-factor authentication and conditional access — the control that stops most of the attacks organizations actually experience.

What transfers

If you were to attempt this

The order of operations — platform, then identity and device hardening, then AI — is the most portable thing in this story and the one most often skipped.

Where it usually gets harder than expected: The firm noted that sophisticated attacks had bypassed multi-factor authentication before the hardening work. That is a useful corrective to the assumption that MFA is a finished control rather than a starting one.

How we would take it on

Our approach to Managed IT & Security work

1

Map coverage honestly

Endpoints, identity, email and cloud — including the gaps. Most organizations have less coverage than they believe, particularly across identity and SaaS.

2

Deploy in audit mode first

Blocking policy on an untuned estate breaks something visible and costs the programme its sponsorship in the first week.

3

Tune until alerts are worth reading

An untuned console is functionally the same as no detection. Tuning is the deliverable, not the deployment.

4

Rehearse the response

Who can isolate a machine at two in the morning, and whether they need permission, is a conversation for a Tuesday afternoon.

Recognise the problem?

If any of the above describes your organization, tell us where it hurts most. We will tell you what the same platforms could realistically do in your environment, what we would measure, and whether we think it is worth doing at all.

Talk to our teamMore Managed IT & Security storiesWe reply to every message within one business day.
Related reports

Others you may want to read

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.