Skip to content
Professional services · Australia

Client confidentiality is the whole business.

Your clients trust you with their data. Your insurer and your reputation depend on you protecting it. Most professional-services breaches begin with a single compromised credential — we close that door and prove it stays closed.

Dossier 05 / 10

Professional Services

Your clients trust you with their data. Your insurer and your reputation depend on you protecting it.

  • Privacy Act 1988 / APPs
  • Client contractual obligations
  • Professional indemnity conditions
Named obligations

What the obligation actually requires of you.

  1. 01

    Privacy Act 1988 / APPs

    Where the Privacy Act applies, personal information in client files, engagement letters and deliverables requires reasonable protection; commercially sensitive information also needs contractual and professional safeguards.

  2. 02

    Client contractual obligations

    Larger clients now write specific security requirements into engagement contracts, and audit against them before renewal.

  3. 03

    Professional indemnity conditions

    Professional-indemnity insurers are beginning to ask what controls you actually run before they renew, and to adjust terms when the answer is thin.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Consulting partnership, NSW

A departing consultant's laptop retaining access.

Illustrative scenario — In this example, A consultant's employment ended, but an offboarding gap left their laptop with active access to shared client folders for eleven days. Access-log review flagged file activity from that device after the departure date.

Example response — A suitable response is to disable the departing user, revoke active sessions, review file-access logs and confirm that client folders no longer inherit unnecessary access.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, then see the priorities.

Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Professional Services Cybersecurity Checklist

0 / 7 reviewed0%

MFA enforced on every system holding client files

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: MFA enforced on every system holding client files.

An offboarding checklist that revokes access the same day, every time

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: An offboarding checklist that revokes access the same day, every time.

PI insurer security conditions matched line-by-line against your actual controls

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: PI insurer security conditions matched line-by-line against your actual controls.

Client data classified and access-limited on a need-to-know basis

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Client data classified and access-limited on a need-to-know basis.

Endpoint protection and patching on a managed, monitored cadence

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Endpoint protection and patching on a managed, monitored cadence.

Annual phishing simulation and awareness training completed

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Annual phishing simulation and awareness training completed.

A written incident response plan naming who calls the insurer, and when

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: A written incident response plan naming who calls the insurer, and when.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Before you call us

The questions this vertical always asks.

Find out exactly where your client confidentiality is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au