WhatsApp
← Blog·Guides·01/02/2026
Cybersecurity for UK solicitors — scales of justice on a laptop with shield, lock and phishing email icons.

Cybersecurity for solicitors: the 2026 UK guide.

The professional obligations to protect client information have not shifted in 2026 — the threat environment has. Law firms remain a routine target for ransomware, business email compromise and supply-chain attacks against practice management software, and the controls needed to meet SRA, ICO and insurer expectations are neither exotic nor expensive. This guide sets out the baseline, the failures that recur across firms of every size, and the questions a managing partner should be able to answer without opening a laptop.

Client confidentiality is a professional obligation; cybersecurity is how that obligation is delivered in practice. The SRA has been increasingly explicit that firms are expected to understand the technology holding their client data, and that outsourcing IT does not outsource the duty. The controls that meet the standard are well established — the failures we see are almost always failures of implementation, not of knowledge.

The baseline every firm should meet

  • Multi-factor authentication on every account, without exception — including partner mailboxes, practice management, cloud storage, and third-party portals.
  • Timely patching of client-facing systems and endpoints, with a documented cadence and a named owner.
  • Encrypted backups tested by actual restoration — not by the vendor's dashboard — held on a segment the primary domain cannot reach.
  • A written incident response plan with named roles, out-of-band contacts, and a retained forensic specialist and breach counsel identified in advance.
  • Short, mandatory, quarterly training on phishing and payment-diversion fraud, tailored to real examples the firm has seen.
  • Register of every third-party system holding client data, with a documented review of its security posture at onboarding and annually thereafter.

Where the 2026 threat picture actually sits

ThreatHow it presents at a firmPractical mitigation
Business email compromiseForwarding rule quietly set on a partner mailbox; conveyancing bank details altered in a client email.MFA everywhere, alerting on forwarding rule changes, out-of-band verification of any change in payment instructions.
RansomwarePractice management server encrypted overnight; backups found to be encrypted too.Immutable off-domain backups, tested restoration, segmented network, EDR on every endpoint.
Supply-chain compromiseCase management or document portal supplier breached; client data exposed via the firm's tenant.Vendor security review, contractual breach-notification, tenant-level audit logging enabled and monitored.
Payment diversion fraudFraudulent email intercepts a completion; funds routed to attacker-controlled account.Verified payee, mandatory callback on any account change, client education at engagement.
Insider misuseDeparting fee-earner exfiltrates client files to personal cloud or USB.Access logging, DLP on sensitive folders, exit process that includes device and cloud audit — see the insider-threat guide.

The failures we see most often

Shared accounts on legacy case management systems. MFA rolled out to fee-earners but not to the finance team or the outsourced IT provider. Unrestricted auto-forwarding rules on partner mailboxes, sitting for months. Backups that turn out to be encrypted by the attacker along with the primary. Incident response plans that name people who left the firm two years ago. Each of these is straightforward to fix in advance, and painful to explain in retrospect — to the client, to the insurer, and to the SRA.

The single control that prevents the largest share of solicitor-firm incidents we see is enforced MFA on every mailbox, plus alerting on forwarding-rule creation. It is cheap, well documented, and still not universal.

Regulatory and reporting duties

  1. 01
    ICO notification. A personal data breach likely to result in a risk to individuals must be notified to the ICO without undue delay and, where feasible, within 72 hours of the firm becoming aware of it.
  2. 02
    SRA notification. Firms should notify the SRA of any serious incident that materially affects their ability to provide services or the security of client information.
  3. 03
    Client notification. Where the breach is likely to result in a high risk to affected individuals, they must be told, in clear language and without undue delay.
  4. 04
    Insurer notification. Cyber policies almost always require prompt notification. Late notification is the single most common reason cover is contested at claim.
  5. 05
    Preservation. Preserve logs, images and communications from the moment the incident is suspected. The forensic timeline is decided in the first 72 hours.

What we would ask a managing partner to know

  • Where is our client data — which tenants, which providers, which jurisdictions?
  • Who has administrative access to those systems, and when was that list last reviewed?
  • When were our backups last restored end-to-end, and by whom?
  • Who do we call in the first hour of a serious incident — and is their number in a system the attacker cannot reach?
  • Is our cyber policy in force, and what does it actually cover?

Frequently asked questions

Is cyber insurance a substitute for the baseline controls?

No. Insurers now underwrite on the presence of MFA, EDR, tested backups and staff training; policies increasingly exclude claims where those controls were not in place. Cover complements controls; it does not replace them.

What must we tell the ICO, and when?

A personal data breach likely to result in a risk to individuals must be notified without undue delay and, where feasible, within 72 hours of the firm becoming aware. A short interim notification is acceptable and often necessary; the detail can follow.

Do small firms really need an incident response retainer?

A written plan with named external contacts is the minimum. A formal retainer with a forensic provider and breach counsel is inexpensive and shortens the response window from days to hours — which is where insurance outcomes are decided.

How often should we test backups?

At least quarterly for critical systems, by actual restoration to a clean environment. A backup that has never been restored is a hypothesis, not a control.

Who owns cybersecurity in a firm without a CIO?

A named partner, supported by the firm's outsourced provider under a defined scope. The duty cannot be delegated in full; the SRA expects a partner-level owner who can answer to it.