Note: This case study is illustrative. Client details are anonymised and figures are representative of typical OAS engagements.
The challenge
A mid-sized law firm in the Western Cape, with several partners and a growing team of associates and support staff, had embraced hybrid working out of necessity. Advocates and attorneys needed access to matter files from court, from home, and from chambers — but the firm's tools had not kept pace.
In practice, sensitive documents were moving over personal email and consumer cloud storage. Laptops carried local copies of privileged case files. A single lost device or misdirected email risked a breach of legal professional privilege and a notifiable incident under the Protection of Personal Information Act (POPIA).
The firm also faced a practical problem: it had no centralised view of who was accessing what, from where. For a practice whose entire reputation rests on confidentiality, that lack of control had become untenable. Leadership wanted secure access from anywhere, without the data sprawl that came with it.
The approach
OAS began with a discovery audit of how the firm actually worked — which applications mattered, where files lived, and how staff accessed them day to day. The brief was clear: enable secure remote work without privileged data ever leaving the firm's control.
The solution centred on a virtual workspace built on Citrix. Rather than copying files to laptops, fee earners now access a published desktop and their practice-management and document applications as a secure session. The data stays in the firm's data centre; only encrypted screen pixels travel to the device. A stolen laptop no longer means stolen case files.
As a Citrix Platinum Partner since 1987, OAS designed the environment around the firm's real usage — court days, after-hours drafting, and access from a mix of firm-issued and personal devices. Access was layered with multi-factor authentication, and unmanaged personal devices were granted session access with download and copy restrictions rather than open access.
SentinelOne was deployed across every endpoint and server, replacing ageing antivirus with behavioural-AI endpoint detection and response. Cove Data Protection was introduced for immutable, off-network backup of the document store and Microsoft 365 mailboxes, so a ransomware event could never take the firm's matters with it.
The outcome
- Secure anywhere-access to matter files, with privileged data remaining in the firm's data centre rather than on devices
- Consumer file-sharing retired, closing the most common path to an accidental privilege or POPIA breach
- Endpoint detection and response across the estate, with autonomous containment replacing reactive antivirus
- Immutable, tested backups of documents and Microsoft 365 data, supporting the firm's confidentiality and continuity obligations
- Centralised visibility of access, giving the firm auditable evidence of who reached which matters and when
The firm now runs the environment under an ongoing managed service, with OAS handling monitoring, patching and backup verification — freeing the practice to focus on its clients rather than its infrastructure.