Berry Appleman & Leiden (BAL) is a corporate immigration law firm operating across 13 U.S. offices with coverage in more than 170 countries. The firm manages over 1,000 immigration programs spanning 12 administrations. Founded in 1980, BAL's core business sits at the intersection of legal expertise, client services, and proprietary technology - no small stakes when the deliverable is enabling people to legally work and live across borders.
The cybersecurity surface area here is worth examining. BAL built a proprietary case management platform that handles real-time immigration status data for corporate clients - a system that touches personally identifiable information (PII) at scale: passports, employment records, biometrics, legal filings. The threat model includes data exfiltration, unauthorized access to sensitive government filings, and supply chain risk across a global operational footprint. Any security team here would be defending a platform where a breach doesn't just mean leaked data - it means compromised legal processes and regulatory exposure across 170+ jurisdictions.
The firm operates under a unified structure: one team, one brand, one profit-and-loss center, one standard of excellence, one unifying technology. That consolidation matters for security - single technology stack, single security posture, no fragmented regional implementations to work around. For engineers and security practitioners, BAL represents an environment where the stakes are concrete: immigration law doesn't tolerate downtime, data loss, or compliance gaps, and the technology stack has to perform under those constraints.






