External security assessments · UK law firms · London
See your firm the way an attacker does.
We look at your firm from the outside, the way a criminal does, and hand you a two-page, plain-English letter: what they would find, how to close it, and a pass or needs-attention on the things clients and insurers ask about. Fixed price. Nothing installed, no access needed.
Start with your domain. Can your email be spoofed?
Instant. We only read public DNS records. No email captured.
- 200
- UK law firms checked
- 44%
- can have their email spoofed
- 74%
- have no enforced protection
Public DNS only, 2026-08-29, domains from the SRA register, Manchester postcode area (200 small firms). Aggregate figures; no firm is named. Method and full numbers →
Northloop Security
Independent External Security Assessment
Hartwell & Bramley LLP
hartwellbramley.co.uk
Summary: 1 item needs attention.
- Email spoofing protection (SPF & DMARC) needs attention
- Exposed admin & login interfaces pass
- Remote access exposure (VPN / RDP) pass
- Known-vulnerable / outdated software pass
- Encrypted web traffic (HTTPS) pass
- Breached credentials · lookalike domains full assessment
Written to be forwarded to a client, an insurer or your managing partner. An assessment of what an attacker can see, not a certification, and it says so.
The two-page letter, for a fictional firm. See the sample · PDF
Start free. Then only what you need.
Four steps, each a fixed price you see before you start. Most firms need steps 1 and 2. A firm with a panel questionnaire or a PII renewal coming takes step 3 or 4.
Prices are for a firm of up to about 25 staff and 3 domains; larger firms get a quote first. Built for firms of 2 to 50 people with no in-house security team. If you need an accredited penetration test instead, we will say so.
All services, incl. monthly monitoring →- 1
Free external snapshot
Back within 48 hours
Give us your domain. We map what is reachable from the internet, check your email against spoofing, and send a one-page, ranked summary in plain English.
Request it →Free
- 2
Fix Your Email Spoofing
One week
If step 1 says your email can be spoofed: we write the exact records, publish them with your IT provider, enforce, re-check, and give you a dated confirmation. Done, not advised.
How it works →£450
- 3
External Assessment
One week
An engineer verifies every finding by hand, adds the checks scanners cannot do, and writes the two-page letter you can forward to a client, insurer or managing partner.
What is included →£1,900
- 4
Law Firm Assurance
For law firmsOne week, then quarterly for a year
Step 3, plus a briefing for your IT provider and a re-check with a refreshed letter every quarter, so the answer to any questionnaire or renewal is always dated within three months.
For law firms →£2,900
You deal with Harry, start to finish.
Northloop Security is the security practice of Northloop, a London engineering studio that builds and runs production systems for businesses. Harry founded it and runs every assessment personally: the same external review he runs on the systems he builds and operates, written up for a non-technical reader. No sales team. The person who runs the scan writes the report and answers the phone.
We only test what you own and authorise in writing. We never contact your clients. Passive by default. How we test · Terms
Five questions, before you let anyone near your domain.
Is this legal?
Yes. We only test assets you own and have authorised in writing. The free snapshot is passive: we read public DNS records, look at what your systems already announce to the internet, and never attempt to log in, exploit anything, or contact your clients. Paid work runs under a short written authorisation that sets out exactly what is in and out of scope.
Will it disrupt us?
No. Nothing is installed, no one needs access to your systems, and denial-of-service or anything that risks availability is excluded. Your staff will not notice it happening. Most firms only learn the scan has run when the report arrives.
What do you need from us?
Your domain name, a work email to send the report to, and confirmation that you are authorised to represent the firm. That is it for the free snapshot. For a paid assessment, a signed one-page authorisation and, if you want your IT provider briefed, their contact details.
Who sees the results?
You, and whoever you choose to forward them to. Findings are confidential, stored in a UK/EU database, never shared, and never used in marketing. The only aggregate we publish is the anonymous spoofing statistic, which does not name any firm.
What happens after the free snapshot? Will you chase me?
You get the report by email within 48 hours, with a plain-English explanation of anything worth fixing. If it makes sense to talk, we say so once. There is no automated sequence, no calls unless you book one, and nothing you need to unsubscribe from.
Something else? Email security@northloopsystems.com and Northloop Security's founder replies personally.
Start with your domain.
One second, no signup. Then take the full free snapshot from the result.
Check my domainPrefer to talk it through first? Book 25 minutes