Client confidentiality is a professional obligation; cybersecurity is how that obligation is delivered in practice. The SRA has been increasingly explicit that firms are expected to understand the technology holding their client data, and that outsourcing IT does not outsource the duty. The controls that meet the standard are well established — the failures we see are almost always failures of implementation, not of knowledge.
The baseline every firm should meet
- Multi-factor authentication on every account, without exception — including partner mailboxes, practice management, cloud storage, and third-party portals.
- Timely patching of client-facing systems and endpoints, with a documented cadence and a named owner.
- Encrypted backups tested by actual restoration — not by the vendor's dashboard — held on a segment the primary domain cannot reach.
- A written incident response plan with named roles, out-of-band contacts, and a retained forensic specialist and breach counsel identified in advance.
- Short, mandatory, quarterly training on phishing and payment-diversion fraud, tailored to real examples the firm has seen.
- Register of every third-party system holding client data, with a documented review of its security posture at onboarding and annually thereafter.
Where the 2026 threat picture actually sits
| Threat | How it presents at a firm | Practical mitigation |
|---|---|---|
| Business email compromise | Forwarding rule quietly set on a partner mailbox; conveyancing bank details altered in a client email. | MFA everywhere, alerting on forwarding rule changes, out-of-band verification of any change in payment instructions. |
| Ransomware | Practice management server encrypted overnight; backups found to be encrypted too. | Immutable off-domain backups, tested restoration, segmented network, EDR on every endpoint. |
| Supply-chain compromise | Case management or document portal supplier breached; client data exposed via the firm's tenant. | Vendor security review, contractual breach-notification, tenant-level audit logging enabled and monitored. |
| Payment diversion fraud | Fraudulent email intercepts a completion; funds routed to attacker-controlled account. | Verified payee, mandatory callback on any account change, client education at engagement. |
| Insider misuse | Departing fee-earner exfiltrates client files to personal cloud or USB. | Access logging, DLP on sensitive folders, exit process that includes device and cloud audit — see the insider-threat guide. |
The failures we see most often
Shared accounts on legacy case management systems. MFA rolled out to fee-earners but not to the finance team or the outsourced IT provider. Unrestricted auto-forwarding rules on partner mailboxes, sitting for months. Backups that turn out to be encrypted by the attacker along with the primary. Incident response plans that name people who left the firm two years ago. Each of these is straightforward to fix in advance, and painful to explain in retrospect — to the client, to the insurer, and to the SRA.
The single control that prevents the largest share of solicitor-firm incidents we see is enforced MFA on every mailbox, plus alerting on forwarding-rule creation. It is cheap, well documented, and still not universal.
Regulatory and reporting duties
- 01ICO notification. A personal data breach likely to result in a risk to individuals must be notified to the ICO without undue delay and, where feasible, within 72 hours of the firm becoming aware of it.
- 02SRA notification. Firms should notify the SRA of any serious incident that materially affects their ability to provide services or the security of client information.
- 03Client notification. Where the breach is likely to result in a high risk to affected individuals, they must be told, in clear language and without undue delay.
- 04Insurer notification. Cyber policies almost always require prompt notification. Late notification is the single most common reason cover is contested at claim.
- 05Preservation. Preserve logs, images and communications from the moment the incident is suspected. The forensic timeline is decided in the first 72 hours.
What we would ask a managing partner to know
- Where is our client data — which tenants, which providers, which jurisdictions?
- Who has administrative access to those systems, and when was that list last reviewed?
- When were our backups last restored end-to-end, and by whom?
- Who do we call in the first hour of a serious incident — and is their number in a system the attacker cannot reach?
- Is our cyber policy in force, and what does it actually cover?
Frequently asked questions
No. Insurers now underwrite on the presence of MFA, EDR, tested backups and staff training; policies increasingly exclude claims where those controls were not in place. Cover complements controls; it does not replace them.
A personal data breach likely to result in a risk to individuals must be notified without undue delay and, where feasible, within 72 hours of the firm becoming aware. A short interim notification is acceptable and often necessary; the detail can follow.
A written plan with named external contacts is the minimum. A formal retainer with a forensic provider and breach counsel is inexpensive and shortens the response window from days to hours — which is where insurance outcomes are decided.
At least quarterly for critical systems, by actual restoration to a clean environment. A backup that has never been restored is a hypothesis, not a control.
A named partner, supported by the firm's outsourced provider under a defined scope. The duty cannot be delegated in full; the SRA expects a partner-level owner who can answer to it.
