High-floor professional-services office with a panoramic city view and glass meeting rooms
Home / Industries / Legal, Accounting & Advisory
Industries · Professional firms

IT support for law, accounting and advisory firms

We look after the systems your firm runs on: Microsoft 365, document and practice platforms, secure access and backup, with clear evidence of controls when insurers or clients ask.

Sydney & Newcastle Engineering-led, security built in Essential Eight-aligned evidence
1 Jul 2026AML/CTF Tranche 2 obligations now in force for affected firms
7-yearrecord retention for AML/CTF customer records
Essential Eightevidence expected by insurers and larger clients
Professional firms we support

Firms like yours

Professional firms share the same pressures: client confidentiality, deadlines, document-heavy work, external collaboration, insurance evidence, access control, backup and vendor complexity. The details differ by practice type, so we support the technology environment around the way each firm actually works.

Law firms

Matters · Confidentiality · Evidence

Law firms run around matters, deadlines, client confidentiality, partner oversight, document control and fee-earner access.

We look after the matter files, email, secure sharing, client portals and discovery material around them, plus the evidence your insurer asks for and the controls around AI use.

Microsoft 365LEAPActionstepiManageNetDocumentsSharePointTeams
Common areas we support
  • Matter-level access and permission control
  • LEAP, Actionstep and practice-system support pathways
  • iManage, NetDocuments, SharePoint or hybrid document environments
  • Secure client, barrister and external adviser sharing
  • Cyber insurance evidence aligned to Essential Eight expectations
  • Governed AI, AML/CTF and APP 1 evidence support
The practical outcome: better matter access, less evidence scramble, stronger client confidentiality, and document-heavy work that stays manageable.
How Inlight IT helps

What we look after for your firm

Professional firms don't need more technology noise. They need the systems around client work to be secure, understandable, well run and easier to evidence. We help with the practical operating layer: access, documents, identity, Microsoft 365, security, backup, recovery, workflow, AI and the vendors around the firm.

AML/CTF intake, screening and evidence capture

AML/CTF Tranche 2 obligations now apply to certain services provided by lawyers, conveyancers, accountants and trust and company service providers. For most firms the operational impact sits at intake: due diligence, PEP and sanctions screening, approvals, transaction monitoring, suspicious activity reporting and seven-year record retention.

We design the technology layer around that workflow: Microsoft 365, SharePoint, Lists, Teams, Power Automate, practice systems and controlled integration with screening tools.

Cyber insurance evidence and Essential Eight alignment

Insurers and larger clients now ask for evidence, not assurance: MFA, privileged access, patching, endpoint protection, backup, restore testing, incident response and broader Essential Eight alignment. A firm can hold the right controls and still lose days assembling proof from screenshots and partner-by-partner email trails.

We keep the evidence current: MFA coverage, Conditional Access, patching position, backup and restore evidence, Microsoft 365 posture and incident-response documentation.

Governed AI inside firm-controlled systems

AI is already inside professional work: summarisation, drafting, research, briefing notes, correspondence and knowledge retrieval. The risk isn't that AI is useful; it's unmanaged AI touching client data or old document stores with permissions no one has reviewed for years.

We help define approved tools, data boundaries, access controls, retention and monitoring. Before Microsoft 365 Copilot or similar tools land, we review permissions, SharePoint structure and sensitivity controls first.

Matter, client and project access control

Firms have constant access movement: partners, fee earners, graduates, contractors, external counsel, outsourced bookkeepers and vendors. Access that made sense during a matter or engagement becomes a risk after the work changes.

We structure access across Microsoft 365, Teams, SharePoint, document platforms and practice systems: MFA, Conditional Access, role-based permissions, guest access, onboarding, offboarding and stale-account cleanup.

Microsoft 365, document systems and email security

Microsoft 365 is usually the operating layer: email, documents, Teams, SharePoint, OneDrive and external sharing, with practice platforms like LEAP, Actionstep, iManage, NetDocuments, FYI Docs, Xero, MYOB or NetSuite layered around it. Client work moves between platforms, not inside one system.

We make that connected environment easy to run: structure, permissions, secure email, endpoint protection, identity, backup and vendor coordination.

Backup, recovery and continuity for client work

Backup needs to cover what the firm actually depends on: Microsoft 365, email, document platforms, matter files, client records, finance data and practice systems. The practical question isn't whether backups exist: it's whether the firm can recover the right data fast enough to keep client work moving.

We review coverage, restore evidence, recovery priority, Microsoft 365 backup, identity recovery, incident response and continuity planning.

Proven in professional-services environments
A five-stage recovery review

Architecture, resilience, restore evidence and sequenced remediation.

A live BEC event, contained

Responded to a real business email compromise event, then hardened the path so the next is caught earlier.

Restore evidence, not backup reports

Recovery tested against cyber-attack conditions, not job-success logs.

Why Inlight IT

Why firms stay with us

We run the systems behind client work: Microsoft 365, document and practice platforms, access to matters and engagements, and the security evidence insurers and clients ask for, kept current as the firm changes.

01

Practical experience with professional-firm workflows

We understand environments built around matters, clients, working papers, lodgements, data rooms, email, Teams, SharePoint and document systems. Support is shaped around the way firms actually work, not just the devices they use.

02

Engineering-led support, not ticket passing

Recurring issues go to senior engineers, who fix the cause, whether it's access, Microsoft 365 or a vendor system.

03

Security-led design across identity and access

MFA, Conditional Access, permissions, external sharing, guest access, email security, endpoint protection and offboarding are structured so client and matter access stays controlled as people change.

04

Essential Eight and cyber insurance evidence

Firms are increasingly asked to prove controls, not just claim them. We make security settings, backup coverage, recovery capability, MFA, patching and Microsoft 365 protections easier to explain to insurers, clients, partners and auditors.

05

Governed AI and secure productivity improvement

AI and automation help, but only when information access is understood first. We review where tools touch client data, documents, emails and workflows so productivity gains don't create unmanaged exposure.

06

Clear visibility for decision-makers

Owners, partners, practice managers and operations leaders get a clear view of the environment: where the risks sit, what needs improvement and which actions matter most. Practical visibility, not reporting overhead.

Common questions

What firms usually ask us

On AML/CTF intake, practice and document platforms, cyber insurance evidence, governed AI, privacy readiness and where our work meets the platform vendors.

What changed at client intake on 1 July 2026?
Since 1 July 2026, AML/CTF Tranche 2 obligations apply to certain services provided by lawyers, conveyancers, accountants and trust and company service providers. For affected firms, the impact sits directly in client intake: customer due diligence, PEP and sanctions screening, approvals, transaction monitoring, suspicious activity reporting and seven-year record retention. We help with the IT and workflow layer around those obligations: intake pathways, evidence capture, Microsoft 365 structure, access, retention, automation, reporting and vendor coordination.
Can you help law firms with LEAP, Actionstep, iManage or NetDocuments?
Yes, around the IT environment those systems depend on: identity, device access, Microsoft 365, email, permissions, secure sharing, backup, recovery, vendor coordination and support pathways. Configuration inside the legal application or document platform may remain with the relevant vendor, but we support the surrounding technology layer and coordinate where issues cross into IT.
Can you help accounting practices using Xero, MYOB, QuickBooks or FYI Docs?
Yes. We support the IT layer around those platforms: Microsoft 365, identity, access, endpoint security, client document exchange, backup, recovery, workflow automation and vendor coordination. Where the issue sits inside the accounting application itself, we work with the relevant vendor or practice-system owner.
How do you support cyber insurance evidence?
We keep operational evidence current rather than assembled at the last minute: MFA coverage, Conditional Access, privileged access review, endpoint protection, patching position, email security, backup and restore evidence, incident response documentation and Microsoft 365 security configuration. Firms answer renewal questionnaires from evidence, not memory.
Can you help with governed AI for client work?
Yes. We help firms define approved AI tools, data boundaries, access controls, retention settings, user permissions, monitoring and internal usage rules. Where Microsoft 365 Copilot or similar tools are introduced, we review the underlying Microsoft 365 permissions and information structure first. AI should not expose client data because old permissions were never cleaned up.
Can you help with APP 1 disclosure readiness?
Yes, on the technology evidence side. We help firms understand and document the systems, permissions, data locations, retention settings, external sharing, AI tool access and auditability that support privacy disclosure and operational evidence. Legal wording should sit with the firm or its privacy adviser. Our role is to make the technology position clear, controlled and easy to run.
Can you help when a fee earner, adviser or contractor leaves?
Yes. We help with onboarding, offboarding, role-based permissions, mailbox access, document access, Teams and SharePoint permissions, guest access, Conditional Access, MFA, device access and stale-account cleanup. Matter, client and project access remains controlled after people change role, leave the firm or finish an engagement.
Work with Inlight IT

Let’s talk about your firm

Tell us what’s on your plate: a renewal, an office move, a security questionnaire. We’ll tell you where we’d start.

Contact us