Skip to content
Commentary Legal & ProfessionalFinance

The Data That Nation-States Actually Want Is Sitting in Your Document Management System

Pick any major UK corporate law firm and consider what’s sitting in their document management system right now. Pre-announcement M&A terms. Litigation strategies that expose every weakness in a client’s position. Regulatory filings that describe, in detail, how a company has characterised its market position to the CMA. Dawn raid response communications. The full evidentiary picture in a contested commercial dispute.

None of this is a target because it can be encrypted and ransomed. It’s a target because it has intelligence value, and the actors who want it are not interested in making noise.

The Data That Actually Gets Collected

The framing most professional services firms use (“the real targets are banks and hospitals”) is correct if you’re thinking about disruption. It’s badly wrong if you’re thinking about collection.

Take a single cross-border acquisition involving a defence contractor or a technology company with export control implications. The deal team at the advising firm holds draft SPAs, heads of terms, board minutes, and due diligence reports. Every one of those documents has commercial value that depends entirely on it remaining confidential before announcement. A state actor with an interest in that transaction (perhaps because the target is strategically significant, perhaps because one of the acquirer’s backers is worth monitoring) has an obvious interest in reading those files before the market does.

Competition filings are just as valuable. How a company characterises its market position in a CMA filing, which arguments it ran and which it abandoned, what remedies are under negotiation: that’s a detailed map of competitive vulnerability that has nothing to do with ransomware economics.

Then there’s litigation strategy. In contested commercial matters, the file contains the client’s full settlement thinking, the weaknesses they’ve acknowledged in their own position, and the arguments they plan to run. An adversary in a live dispute, or a state with an interest in one of the parties, doesn’t need to win the litigation. They just need to read the file.

The CRM systems and business development records are a separate category entirely. They don’t describe individual matters. They map the relationship network: who is working with whom, on what, and through which firms. That’s intelligence infrastructure with value that extends well beyond any single transaction.

Espionage Doesn’t Look Like a Breach

This is where law firms’ threat model tends to fail. Criminal actors want leverage: they make noise, they demand payment, you know something happened. Nation-state actors want quiet collection, ideally for months or years, and they have every incentive to stay undetected.

The Chinese intelligence services have demonstrated sustained, patient interest in M&A transactions involving Western technology companies and defence assets. Not just in the final deal terms, but in the process: who is advising whom, what the financing structure looks like, what regulatory obstacles are anticipated, and who the key individuals are. Understanding that picture in advance provides strategic intelligence and, in some cases, a window to influence outcomes through regulators, counterparties, or selective disclosure at a damaging moment.

The NCSC has been direct about this, and the SRA has reinforced it through its own guidance: multiple major UK law firms have experienced intrusions assessed as nation-state attributable. Most haven’t been publicly disclosed. The commercial incentive to stay quiet is exactly the same thing that makes law firms attractive targets: reputational exposure is enormous, which means incidents get managed quietly, which means the broader sector doesn’t learn from them.

Privilege Creates a Response Problem

Legal professional privilege is a protection and, in incident response, a complication. Firms that have experienced intrusions affecting client files have, in documented cases, delayed forensic response because of genuine uncertainty about whether their own investigators could review privileged material without triggering waiver or other consequences.

This isn’t an edge case. It’s a foreseeable problem that every firm should have resolved before an incident, through pre-agreed waiver mechanisms, separate handling procedures for privileged material, and appropriately structured IR retainers with counsel familiar with both privilege law and forensic investigation. Firms that try to work this out during an active incident are doing it wrong.

The Partnership Governance Failure

Equity partners set risk appetite. In most professional services firms, they’ve set it (implicitly, by not engaging) at a level that treats cyber security as an IT overhead rather than a partnership-level governance matter.

That’s the wrong call, and the consequences are now material rather than theoretical. A significant breach involving pre-announcement M&A data, attributed to a sophisticated actor and disclosed under ICO obligations, is simultaneously a negligence claim, a regulatory action, and a client relationship crisis. The partners who find the technical conversation uncomfortable should consider that the legal and commercial consequences of a breach are entirely within their normal competence; they just haven’t been asked to apply that competence to this risk.

The conversation worth having at partner level isn’t about firewalls. It’s about what the firm holds, what it’s worth to an adversary, and what the firm owes to clients and regulators if it’s extracted. No technical background required. Someone just has to start it.

Controls That Actually Reduce Exposure

The effective controls here are not exotic. They’re consistently absent.

Access control on matter data. Broad read access across the DMS is a standard configuration that dramatically amplifies exposure in any compromise. Only the working team should touch a live matter file, and that access should be revoked when the matter closes.

Monitoring for anomalous data access. Large-volume document access outside normal working patterns, access to closed matters by accounts with no current involvement, privilege escalation on the DMS: these are detectable. They require an alerting capability that most firms don’t have configured.

Client-matter segmentation. Sensitive transactions (particularly cross-border M&A, regulatory investigations, and contested litigation) should sit in environments with enhanced controls, not alongside routine conveyancing.

IR planning that accounts for privilege. Pre-instructed IR providers. Pre-agreed legal advice on privilege handling during forensic review. A rehearsed decision tree for client and regulator notification. None of this can be improvised on the day.

Third-party access management. External counsel, experts, and data room administrators all have access to sensitive matter data. When was their access last reviewed? Their credentials are your attack surface, and you don’t control their security posture.