Conocimiento para despachos
Virus scanning on uploads: matter files as an attack surface
Por Jonas Maximilian Regul
Why email attachments and client portals stay risky - and the minimum controls firms should keep.
Firms receive files daily from clients, opponents, experts and courts. That openness makes document intake an attack surface. Virus scanning is not an IT affectation; it is part of protecting clients - and the systems that hold matter files.
Risk sits in ordinary mail, not only “suspicious” senders
Malware rarely arrives with an obviously criminal subject line. More often: spoofed senders, compromised client accounts and nested archives. Macro-bearing Office files and exploit-laden PDFs remain relevant. Treating only “strange USB sticks” as risk underestimates email.
At least two layers help: scanning at the mail gateway or endpoint, plus extra caution before opening unusual formats. Cloud processing tools with their own scan reduce the chance of local code execution - they do not replace endpoint hygiene.
Control checklist
- Do not “just run” attachments from preview.
- Block unexpected archives and EXE/JS content consistently.
- Verify client portals and share links for authenticity.
- Escalate suspects to IT/security; do not privately “test” them.
- Keep separate work accounts and current patches.
- Bring external typists into the same standard.
Join document workflow and security
OCR and PDF steps should ideally accept files that already passed a security check - or scan before deeper processing starts. LexLogik checks uploads in the processing context; the firm remains responsible for email and endpoint defence.
Organisationally, a clear rule matters: when in doubt, do not open - isolate. It sounds strict and prevents the moment where “a quick look” compromises the firm share.
Bring suppliers and experts in
Ask frequent senders to use known file types and naming. Healthy suspicion of unexpected archives remains. A compact incident plan belongs next to scan rules.
Ten minutes of phishing examples per quarter beat abstract policies. Partners must visibly follow.
Join workflow and security
OCR and PDF steps should accept already-checked files - or scan before deeper processing. When in doubt, do not open - isolate.
Training with examples
Abstract security policies achieve little. Better: two real phishing examples and the internal reporting chain. Partners must visibly follow; otherwise culture says “only IT is paranoid”.
Explain upload quarantine to the team
Tell clients and assistants why files may sit briefly in review: not distrust, but protection of the matter file. One sentence in the internal guide stops scan warnings being bypassed as “annoying”.
Stop risky file types at the door
Define which file types the firm accepts at all (PDF, DOCX, common images) and which stay in quarantine (executables, macro containers). Tell clients at engagement. Fewer case-by-case arguments, clearer expectations. Security becomes part of client communication, not only IT.
Log quarantine hits anonymised (file type, source, outcome) to see patterns. Repeated macro attachments from the same client group justify a conversation - not only one-off deletions.
Malware scanning on uploads is matter protection, not friction for its own sake. Suspect attachments from email and messengers need a clear review loop before they enter the file. Separating scan and filing cuts attack surface without blocking the deadline calendar.
Pruebe LexLogik en su despacho
Todas las funciones desbloqueadas. Sin tarjeta de crédito. Sin suscripción automática.