BY FULTON MAY SOLUTIONS

In legal services, confidentiality is not a best practice. It is a professional obligation, and it is the foundation of the attorney-client relationship.

Client information, from case strategy and legal analysis to correspondence and privileged communications, is the most sensitive data a law firm handles. A breach does not just expose data. It affects your clients’ cases, their legal positions, and their outcomes.

That is why the System and Organization Controls (SOC) 2® Type II report matters for legal services IT providers, and why Fulton May Solutions’ recently completed SOC 2 Type II examination matters for the law firms we serve.

The Legal Services IT Reality

Law firms face pressure on several fronts at once.

  • Professional liability. You are responsible for protecting client confidentiality. If client data is compromised because your IT systems were not secure, that exposure falls on your firm: to clients, to courts, and potentially to regulators.
  • Client trust. Clients share sensitive information with you because they trust you to protect it. A breach breaks that trust, and trust is hard to rebuild.
  • Regulatory expectations. Bar associations and courts increasingly ask how law firms protect confidential information. They expect documented, verified security, not assurances.
  • Cyber threats. Law firms are targets. Attackers know you hold valuable information, and they know firms have paid to recover it.
  • Client expectations. Corporate clients, in-house counsel, and referring attorneys now ask about law firm security as a standard due diligence question.
  • Competitive pressure. Other firms are upgrading their security. You need to keep pace.
  • Operational demands. Case management, billing, client communications, and document storage all need to be secure and accessible at the same time. Confidentiality cannot get in the way of client service.

In this environment, your IT provider is not just a vendor. They are part of how you meet your professional responsibility.

Why a SOC 2 Type II Report Means Something Different in Legal Services

Legal services carries confidentiality requirements few other industries match. Attorney-client privilege is a legal protection, and it cannot be waived without client consent.

That creates a specific IT requirement: your systems must protect privileged communications with the same rigor the legal system does.

A SOC 2 Type II examination addresses this directly.

A SOC 2 Type II report explicitly covers confidentiality. Many security assessments focus only on technical protection. The SOC 2 Trust Services Criteria treat confidentiality as a distinct category, and an independent CPA firm examines whether confidential information is protected from unauthorized access and disclosure. For a law firm, that is the core requirement.

The report type matters. A SOC 2 Type I report evaluates whether controls are suitably designed at a single point in time. A SOC 2 Type II report tests whether those controls operated effectively across a full 12-month period. Confidentiality is not a one-time implementation. It is an ongoing obligation, and only a Type II report demonstrates sustained protection.

A SOC 2 Type II report is independent. You would not assess your own compliance with ethics rules or professional standards. Confidentiality controls deserve the same standard. In a SOC 2 Type II examination, an outside auditor reviews the controls and tests whether they work. The provider does not grade its own work.

A SOC 2 Type II report covers information in every state. Client information needs protection in transit (email, file transfers), at rest (storage, backups), and during processing (case management, document review). The examination spans all of it.

What a SOC 2 Type II Report Means for Client Confidentiality

When your IT provider has completed a SOC 2 Type II examination, here is what that means in practice:

  • Client information lives on independently examined systems. Case files, client communications, and strategy documents sit behind controls a third-party CPA firm tested over 12 months.
  • Client information in transit is protected. Email with clients, file transfers to opposing counsel, and document sharing all move through verified controls.
  • Access is controlled and monitored. Only authorized firm members can reach specific client matters. Access is logged, and unauthorized attempts are detected.
  • Backups do not create new risk. Confidential information is backed up securely, and those backups fall within the examination scope.
  • Privilege is preserved when systems touch client data. Your case management platform, document review tools, and research systems can work with client information without compromising it.
  • You have evidence when someone asks. When a court, bar association, or client asks how you protect confidentiality, your IT provider’s SOC 2 Type II report is part of the answer.

How Verified Confidentiality Enables Firm Growth

A SOC 2 Type II report does not just reduce risk. It creates room to grow.

You can pursue larger, more sophisticated clients. Corporate legal departments and institutional clients demand verified security from outside counsel. Your IT provider’s SOC 2 Type II report helps you meet that bar.

You can take on more sensitive matters. Intellectual property, trade secrets, mergers and acquisitions: high-value matters require demonstrated confidentiality.

You can adopt new technology with confidence. Cloud case management, AI-assisted research, digital signature platforms. When your IT foundation is independently examined, you can evaluate new tools on their merits.

You can answer the security question before it is asked. When a prospective client’s due diligence questionnaire arrives, you already have a documented answer.

Verified confidentiality is not overhead. It is a growth enabler.

What Fulton May Solutions’ SOC 2 Type II Examination Means for Law Firms

Fulton May Solutions recently completed a SOC 2 Type II examination of our controls relevant to security, availability, processing integrity, confidentiality, and privacy.

For law firms, that means:

  • Your client information is managed by a provider whose confidentiality controls have been independently examined over a full 12-month period.
  • Confidentiality is a core requirement in every system we implement, from email and case management to document storage and client portals. It is foundational, not an add-on.
  • We understand legal services. We have served law firms for 23 years. We understand attorney-client privilege and the professional responsibility behind it.
  • Your professional liability exposure is reduced. Your IT provider’s SOC 2 Type II report is evidence that you take your obligation to protect client confidentiality seriously.
  • You are ready when the questions come. When courts, bar associations, or clients ask about confidentiality controls, you have independent evidence to point to.

Ethics and IT Are Now the Same Conversation

In legal services, ethics and IT used to be separate. Ethics belonged to the lawyers. IT was infrastructure.

Today they are connected. Your ethical obligations require that confidential information stays protected, and protecting it requires verified IT systems. A SOC 2 Type II report from your IT provider is evidence that your technology supports your ethical obligations.

Next Steps

If your firm is evaluating IT providers, whether you are choosing a new partner or auditing your current one, ask whether the provider has completed a SOC 2 Type II examination. Treat the answer as evidence of how seriously the provider takes confidentiality.

Fulton May Solutions has completed its SOC 2 Type II examination. We have served law firms for 23 years, and our 98% client satisfaction rate is verified through ConnectWise CSAT.

If you want to talk about what verified confidentiality looks like for your firm, let’s schedule a call.

Schedule a 15-Min Call


Related Resources


About Fulton May Solutions

Fulton May Solutions is an IT partner for law firms. Our SOC 2 Type II examination means the controls behind our confidentiality and security practices have been independently examined by a third-party CPA firm.

Founded in 2003. 23 years serving legal services, 800+ projects delivered, 98% client satisfaction verified through ConnectWise.

Oak Brook, IL | Chicago, IL | Short Hills, NJ