All guides
Solicitors and law firms

IT & Cyber Security Compliance Guide for Solicitors

Law firms hold exactly what criminals want: large completion payments, confidential client files and sensitive personal data. That combination makes IT security a regulatory duty, a client-trust issue and an insurance condition all at once.

Why IT is a compliance issue for law firms

The SRA's rules expect firms to protect client confidentiality and client money and to run effective systems and controls. Weak IT security makes both harder to demonstrate: a compromised mailbox or a stolen password can expose privileged material or redirect funds.

Clients, lenders and professional indemnity insurers increasingly ask firms directly about security measures such as multi-factor authentication, backups and staff training.

The biggest threat: payment diversion fraud

The most damaging attacks on law firms are often not technical. Criminals watch or hijack email conversations, then send convincing messages changing the bank details for a completion payment, or impersonate the firm to a client.

  • Confirm any change of bank details by phone, using a number you already held, never one in the email.
  • Put multi-factor authentication on every mailbox so a stolen password isn't enough.
  • Use advanced email filtering and warning banners for external senders.
  • Tell clients in advance how you will and won't communicate bank details.

UK GDPR and data protection

Firms are data controllers for the personal data they hold. That includes keeping it secure, only holding it as long as needed, paying the ICO's data protection fee, and reporting notifiable personal data breaches to the ICO within 72 hours of becoming aware of them.

Practical readiness means knowing where client data lives, who can access it, whether it's encrypted, and having a tested way to detect and respond to a breach.

Insurance and certification

Check how your professional indemnity and cyber policies treat cyber incidents, and what controls they expect. Cyber Essentials certification demonstrates a baseline of five technical controls and is frequently requested in tenders and by corporate clients.

Your practical checklist

  • Multi-factor authentication on email, case management and remote access
  • Bank-detail changes always verified by phone on a known number
  • Managed endpoint protection and patching on every device
  • Encrypted laptops and phones, with remote wipe
  • Offline or immutable backups, with restores tested
  • Role-based access, so staff only see matters they work on
  • Annual security awareness training with phishing tests
  • A written incident response plan, including who reports a breach and how
  • A documented data retention and secure-disposal process
  • Cyber Essentials (or equivalent) in place and renewed annually

Go to the source

This guide is general information, not legal advice. Requirements change and depend on your circumstances, so check with your regulator or professional adviser.

Want your IT to stand up to scrutiny?

We help regulated firms put the right controls in place and keep the evidence ready.