Law firms handle sensitive data belonging to their clients. With the wave of digitalisation, there are an increasing number of scenarios in which Data security plays a major role. At present, the property tax reform is posing a challenge for many law firms in their collaboration with clients. Important documents are constantly being sent back and forth. It is not uncommon for sensitive data to be stored in the cloud for individual projects. But how secure are such solutions? How can a law firm guarantee the security of its data – including to its clients? We discuss this with our guest Carsten Köhn, Sales Manager at C&P Capeletti & Perl Gesellschaft für Datentechnik mbH.
The Hamburg-based IT specialist C&P offers IT services, such as hardware and software consultancy. The company has been operating as a cloud provider for 15 years. Law firms form the company’s main source of business. In addition, many of these law firms’ clients are also served.
The IT sector is currently undergoing a transformation. Until now, software programmes – for example, those used by law firms – have run on their own servers. These were, or still are, located within the firm’s own office premises or at a service provider’s premises. However, the trend is towards an increasing number of programmes running in the browser. This means they are no longer hosted on a single server, but are accessed from various sources. This raises the question: how are these different programmes linked together so that work flows smoothly across all applications? Carsten sees this as a task for himself and his company: to create the necessary interfaces and guide users through the process.
Important for many: the server location
In 2007, C&P began providing server hosting services to its clients. Initially, there were still difficulties with low bandwidths. Now, however, speeds are consistently high enough to identify a clear trend towards outsourcing. Carsten sees the main reason for this as the advantage for law firms of not having to manage their own IT. Companies want to focus on their core business, not on the maintenance and operation of a server or similar tasks. C&P’s dbc (Germany’s Business Cloud) brings together more than 40 providers, many of whom, due to their small size, would be unable to offer outsourcing services on their own. By joining forces, they all benefit from sharing expertise and resources.
It also ensures that all providers operate their servers in Germany. This is a particular requirement for tax consultancy firms, which constantly handle sensitive data. There are various certifications and seals of approval to demonstrate compliance with certain security standards. But are firms even interested in this? Do they know exactly what each certificate entails? Carsten knows from experience that most clients do not look into the certificates in great detail. However, C&P has obtained ISO 27001 certification, as some clients had requested it. Carsten can use the benefits of such certification in client meetings to convince them of the product’s security measures.
More performance, higher costs
At this point, Paul interjects to say that a great deal of effort went into finding the right server for the Opti.Tax Cloud. For example, a solicitor was consulted to scrutinise data protection and related matters. Ultimately, hsp opted for a German provider whose servers are located in Munich. However, the more requirements a provider meets, the more expensive it becomes for the customer. What has been Carsten’s experience when it comes to pricing? Are law firms prepared to spend more money for a better service?
Generally speaking, law firms understand that greater data security entails additional costs. Especially when Carsten gets into the nitty-gritty of the discussion and gives specific examples, clients quickly realise that certain expenses are worthwhile in the long run. Is data backup required for a few days, a few weeks, or even a whole year? Depending on the timeframe, the storage capacity required varies – and so do the costs. Those who want more end up paying more, but know exactly what they’re paying for.
According to those interviewed, what many people do not realise is that Microsoft 365 still does not offer any data backup. This means that even with the simplest tasks, such as changing a licence, there is a risk of losing all data. That is why C&P also offers a data backup service for Microsoft 365. Another area that is often overlooked is one’s own computer. Individual aspects such as data backup are often still taken into account. However, when it comes to security measures, a great deal is neglected. Yet the next email or infected USB stick could leave malware on the computer without anyone noticing. That is why Carsten carries out a mandatory monthly computer check. During this check, all the computer’s security measures are reviewed.
A secure provider alone is not enough
However, none of the measures put in place by a service provider will help the law firm if staff do not play their part. This applies to backups and similar measures just as much as it does to small everyday details. For example, not simply clicking on every link or attachment that is sent to you. Spam and phishing emails are now designed and worded so convincingly that great caution is required when dealing with links and attachments. If such an email has not been announced in advance, it is always worth checking with the alleged sender to be on the safe side.
According to Paul, annual data protection training for staff is also helpful. At hsp, this took place a few days ago. During the session, the hsp team not only refreshed their knowledge but were also able to scrutinise certain processes, such as data storage. An event like this costs neither much time nor much money, but can ultimately save a lot of trouble and damage.






