Case Studies //Cyber Security //Data Protection //

Chambers and Partners

NormCyber’s has been partnering with this leading legal research company since 2018, delivering comprehensive managed cyber security and data protection services to reduce risk and boost resilience

city scape with chamber and partners logo

Founded in 1990, Chambers is a leading independent professional legal research company, which provides rankings and insight into the world’s leading lawyers, law firms, and law departments. Spanning 70 countries and 200 different jurisdictions – and leveraging in-depth research methodologies – its rankings and research have become the de facto standard for the global legal industry, and are a vital source of intelligence to any organisation requiring legal support.

In brief

  • Working in partnership since 2018 to continuously manage Chambers’ exposure to risk
  • NormCyber’s comprehensive suite of Cyber Security Managed Services provide Chambers with complete visibility and control over its IT estate
  • Norm’s Data Protection Managed Service, serves as Chambers’ on-demand Data Protection Officer (DPO), ensuring the company always meets its data protection obligations

Growth Opportunity

In 2018, following external investment from a private equity fund, Chambers began a major transformation. Moving away from its small business model of 300 employees with limited in-house expertise, the company set out to professionalise its operations and technology.

The company looked to redefine its IT and cyber strategy by appointing its first CTO, James Lee. He shared, “given our limited in-house capabilities, we needed a specialist who could provide a comprehensive suite of services — from awareness training and data protection expertise to 24/7 threat monitoring. We also needed someone who could make sense of the complex security landscape in clear, manageable terms”.

Partnership

Chambers launched a competitive tender process to find a cyber security and data protection service provider that could not only meet its immediate requirements but also support the company’s long-term digital transformation plans. Norm was selected for its proven expertise and because it could provide Chambers and Partners with a single point of contact, via a dedicated Focal Analyst.

“During our RFP process, we engaged with several large providers, but it quickly became clear they weren’t the right fit,” the CTO explained. “Their size and complexity would have required us to bring in deep in-house security expertise just to manage the relationship.”

Norm stood out for its ability to demystify cyber security, offering both breadth and depth of services under one roof. The CTO commented, “With Norm, we knew we’d get a fully integrated, end-to-end service. From day one, Norm offered a clear path forward, a dedicated and expert Focal Analyst, backed up by a team that genuinely understood how to tailor their capabilities to our business.”

Since the beginning of the relationship, Norm has delivered a comprehensive suite of services that have significantly elevated Chambers’ cyber security programme giving them full visibility over its risk landscape and a structured path toward continual improvement.

Services delivered include:

  • Managed Detection and Response (MDR): 24/7 protection through Norm’s UK-based Security Operations Centre, covering threat detection, response, and recovery with clear, actionable reporting.
  • Vulnerability Management: Norm continuously monitors Chambers’ network, devices, and web applications to identify and prioritise vulnerabilities by criticality for their in-house team to address.
  • Human Risk Management: Norm offers comprehensive training and testing to Chambers expanding team to enhance employee awareness and create a lasting security culture.
  • Penetration Testing: Norm regularly conducts penetration tests to assess the resilience of Chambers’ IT operations, particularly during new service and infrastructure roll outs, and provides actionable advice on addressing any identified security gaps.
  • Cyber Essentials / Cyber Essentials Plus accreditation: Guiding Chambers through these accreditation processes has helped both the company and its customers gain confidence in its security posture.
  • Data Protection: Norm’s specialist team of privacy experts serve as Chambers’ on-demand Data Protection Officer, handling SARs, breach classification, reporting, and governance support.

Norm acts as a strategic adviser as Chambers evolves its digital operations guiding the migration to standardise security on Microsoft platforms including Microsoft Sentinel and Microsoft Defender. This partnership ensures that security configurations align with technical requirements and business objectives.

All services are integrated through Smartbloc, Norm’s performance dashboard, providing real-time visibility into vulnerabilities and overall risk posture. Monthly review sessions with the CTO and the Focal Analyst ensure the programme evolves continuously and that security intelligence is translated into clear, actionable insights for senior leadership, enabling informed, strategic decision-making.

The results

Over six years, Chambers and Partners has nearly doubled in size, growing to almost 600 employees. With greater scale and rising client expectations, cyber security and data protection have become central to its operations.

Norm has enabled Chambers and Partners to:

  • Establish a mature, layered, and adaptive security programme
  • Embed governance and risk reduction into business operations
  • Achieve measurable results, including:
    • 95% employee completion of Human Risk Management training, with mandatory refreshers for higher-risk roles
    • A 90% reduction in phishing link clicks
    • Continuous vulnerability monitoring, benchmarked against industry peers, with Chambers and Partners consistently outperforming the industry average

In closing, the CTO said, “I’d describe working with Norm as easy. The company is easy to do business with, while our day-to-day contacts are always knowledgeable, helpful, responsive, and exceptionally proactive. This long-term partnership has enabled us to continuously enhance the way we protect our systems, people and data. Not only has Norm helped us improve our resilience, its team has enabled us to take a phased approach to our security investments, helping us keep costs under control while continuously reducing risk.”

Get in touch to take a
different approach to cyber security.