A consultancy reviewing a third party’s records, for example a failed company’s data on behalf of its administrators, handles that data securely by keeping it within a managed, protected environment, separating each engagement’s data and limiting access to those who need it, working under clear confidentiality obligations, and disposing of it properly when the work ends. Because the data belongs to someone else and is highly sensitive, careful handling is both a professional duty and a reputational necessity. This is part of managed IT at about £45 to £100 per user per month. Here is how to do it right.
Reviewing another party’s records places real responsibility on a consultancy. The data is confidential, often belongs to a third party, and must be handled to a high standard throughout. Here is what good handling looks like.
Keep it in a protected environment
Third-party data should be stored and worked on inside your managed, secured systems, your document environment and protected servers, rather than copied onto personal laptops, USB sticks or unmanaged cloud storage. Keeping it within a controlled, backed-up and secured environment is the foundation of handling it responsibly.
Separate each engagement
Different engagements should be kept properly separated, so the data from one matter is not mixed with another and access can be controlled per engagement. Clear separation protects each client’s confidentiality and makes it straightforward to manage, and later dispose of, the data for a specific piece of work.
Limit access to those who need it
Access to confidential third-party data should follow the principle of least privilege, only the people working on that engagement can reach it. Controlling access tightly, with each person having their own account and the right permissions, limits exposure and gives you a clear picture of who can see what.
Work under clear confidentiality
This work usually comes with confidentiality obligations and sometimes formal non-disclosure agreements, including for any third party, such as your IT provider, who might touch the systems. Working under clear confidentiality, with everyone understanding their obligations, is part of being a trusted consultancy, and a good provider will sign and respect an NDA without hesitation.
Dispose of it properly
When an engagement ends, the third party’s data should be handled or securely disposed of according to your obligations, rather than left lying around indefinitely. Dealing with data properly at the end, with secure deletion where required, closes the loop and protects both the data owner and your firm long after the work is finished.
What to ask a provider
A specialist for construction claims and quantity surveying consultancies should be able to answer:
- Have you supported document-heavy consultancies and systems like M-Files, including the SQL back end, before?
- How do you keep our case archive fast to search as it grows?
- How do you help us receive and handle confidential client and third-party data securely, through data rooms, SFTP and VPN?
- Can you support secure remote and RDS working, and our Cyber Essentials or IASME accreditation?
- Is the price clear and per user, with security included rather than charged separately?
Where to start
If you are not sure where your practice stands, a short review is the quickest way to find out: check that your document management and its server are sized and backed up properly, that confidential client and third-party data is received and stored securely, that remote access is secure and reliable, and that your Cyber Essentials or IASME accreditation is genuinely covered. Those few checks show where a consultancy-aware managed setup would pay off.
The bottom line
For a construction claims or quantity surveying consultancy, good IT comes down to two things: being able to find and work with huge volumes of case documents instantly, and keeping confidential client and third-party data absolutely secure. When the document system is fast, the data is safe, and people can work securely from anywhere, the practice can focus on the cases rather than the technology.
That reliability comes from a setup built around how a document-heavy, confidentiality-bound consultancy actually works, a well-run document management system, secure data handling, solid backups and recognised accreditation, rather than generic office IT. For a small practice whose reputation rests on protecting clients’ information, a predictable per-user cost for that dependability is far cheaper than a breach, a lost case file, or a day locked out of the archive.
Why construction consultancies choose First Stop IT
First Stop IT has supported businesses since 2002, including professional and consultancy firms, and we understand how a construction claims and quantity surveying practice works: M-Files and other document management on a SQL back end, secure handling of confidential client and third-party case data, RDS remote working, and the Cyber Essentials and IASME accreditation that clients increasingly expect. We support consultancies across Essex, Hertfordshire and London. Our credentials include:
- Cyber Essentials Certified
- IASME Cyber Assurance (Gold)
- NCSC Assured Service Provider (Cyber Advisor for Cyber Essentials)
- Microsoft Partner
- Crown Commercial Service Supplier (G-Cloud)
- Quality Principles Certified
We look after more than 2,000 endpoints across 50 companies, we have been named a Top 50 UK MSP for three years running, and we support organisations with 10 to 100 employees across Essex, Hertfordshire and London.
Book a free IT and cyber security review
Want confidential case data handled the way your clients expect? Book a free IT and cyber security review with First Stop IT.