Basilisk
BASILISK
[setor_juridico_seguros]LEGAL & INSURANCE

Offensive security for legal and insurance.

Law firms and insurers hold what clients handed over under a promise of confidentiality. A breach here is not an IT incident: it is a break of professional trust, with immediate legal consequences.

Concentration of sensitive information

Few sectors concentrate so much high-value information per square metre. Litigation strategy, corporate transactions under negotiation, medical reports supporting a claim, wealth history. This material interests both those looking to extort and those sitting across the negotiating table — and that second motive makes the attack targeted and quiet.

  • The content carries immediate strategic value to the opposing party in a dispute.
  • Professional privilege is a legal duty, not merely a contractual commitment.
  • Claims fraud combines social engineering with document manipulation.
  • Operations depend on constant file exchange with clients and external experts.

What we test in these environments

We follow the document: where it enters, where it rests, who can reach it and how it leaves.

// document management

Matter management and document repositories: object-level authorisation, isolation between clients and audit trails over who read what.

// client and policyholder portal

Authentication, password recovery, document upload and history access — including whether a policyholder can reach another's case.

// claims flow

Notification, report submission, assessment and payment: where the logic can be manipulated to approve what should be declined.

// mail and social engineering

Resistance to payment redirection fraud, including identity verification on requests that arrive by email.

// external sharing

File exchange with experts, correspondents and clients: forgotten public links, over-broad permissions and missing expiry.

// workstations and data egress

What access to one machine reaches in document volume, and which paths allow that material to leave without an alert.

Confidentiality as a requirement, not a recommendation

The report treats breach of privilege as its own severity category, above purely technical criteria.

Professional privilege
Legal professional privilege has its own statutory standing. Any path allowing improper access to client documents is classified as critical, regardless of the technical score.
GDPR
Case and claims data include special categories such as health and beliefs. We document data subject exposure and the lawful basis affected.
Insurance regulation
Insurers answer to their own internal control and operational risk requirements. The report fits as evidence of periodic testing.
Corporate client requirements
Large clients audit their legal suppliers. The attestation letter answers that questionnaire without exposing exploitable detail.

How we run under reinforced confidentiality

01

Agreement before first access

A reinforced NDA, with a specific clause covering third-party documents, is signed before any activity. We also define who on your side may see the report.

02

Proof without extracting content

We demonstrate improper access without exfiltrating the document: recording enough metadata and identifiers to prove it, leaving the content where it is.

03

Document fraud scenarios

We test the flow where a forged document would be accepted, because in claims and payments that is where the real loss sits.

04

Remediation and retest

We prioritise by exposure of privileged material, follow the remediation and retest before issuing the final version.

What you receive

  • Executive report on confidentiality risk
  • Reproducible technical report
  • Map of access to privileged material
  • Justified CVSS scoring
  • Document fraud scenarios tested
  • Evidence without content extraction
  • Retest of remediated findings
  • Attestation letter for clients

Sector FAQ

Will you read our clients' privileged documents?

+

We avoid it by design. Proving improper access does not require reading the content: it is enough to demonstrate the control failed, recording identifiers and metadata. Where content is unavoidable, it enters the evidence masked and the material is destroyed at the end of the cycle upon formal confirmation. The reinforced NDA is signed first.

Is claims fraud in scope?

+

It is, and it usually carries the highest financial value. We test the full flow: notification, report submission, assessment and payment release, looking for where the rule can be bent or where a forged document would be accepted without sufficient verification.

Can we use the report to answer a client audit?

+

Yes, and that is what the attestation letter exists for. It confirms scope, period and conclusion of the engagement without revealing exploitable detail — which is what a supplier questionnaire asks for. The full technical report stays restricted to whoever you nominate at kick-off.

How do you handle payment redirection fraud?

+

As a dedicated scenario, because it is the most recurring scam in the sector. We test the resilience of the process, not just the system: whether a request to change bank details arriving by email is verified through an independent channel, and whether a second approval exists for payments above a threshold.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.