Cybersecurity for UK Legal Firms: SRA Requirements and Managed Security
UK law firms are prime targets for cybercriminals due to the sensitive financial and personal data they handle. The SRA expects firms to have appropriate cybersecurity controls in place. This guide covers the specific risks facing legal practices, SRA obligations and the managed security approach suited to firms from sole practitioners to multi-partner practices.
Nathan Hill-Haimes
Technical Director
UK law firms sit on the worst possible mix for an attacker: client money in client accounts, commercially sensitive matter data, and a duty of confidentiality that turns any breach into a professional-conduct problem. This guide sets out who is attacking firms, what the Solicitors Regulation Authority expects, and the controls that actually move the needle. For the full managed picture, see our managed cybersecurity for UK businesses pillar and our dedicated cybersecurity for law firms service.
Why do cybercriminals target law firms?
Law firms are targeted because they combine money, secrets and trust in one place. They hold client funds that can be diverted, commercially valuable data — M&A, IP, litigation strategy — and they sit as trusted intermediaries in transactions, which makes invoice and payment fraud lucrative. Historically many smaller firms underspent on security relative to the data they hold.
According to the SRA's cybercrime reporting, over £4 million was stolen from law firms through cybercrime in a single reporting year, with business email compromise diverting client funds as the dominant mechanism (SRA Risk Outlook data). The National Cyber Security Centre has published sector-specific guidance acknowledging legal services as a high-value target, which you can read in the NCSC's legal-sector advice.
The threat is also growing. Successful cyber attacks on UK law firms rose by 77% in 2024 — from 538 to 954 successful attacks in a single year *(Law Gazette, 2024)*. That trend tracks the wider UK picture set out in the government's Cyber Security Breaches Survey.
What are a law firm's SRA cybersecurity obligations?
The SRA does not prescribe specific technical controls, but its Standards and Regulations create clear duties with direct security implications. Firms must identify and manage material risks — including information-security risk — supervise work effectively, and protect client money and confidentiality. Failure here is a regulatory matter, not just an IT one.
- Code of Conduct, paragraph 6.1 — firms must identify, monitor and manage material risks to the business, which includes IT and information-security risk.
- Code of Conduct, paragraph 4.2 — firms must maintain effective systems for supervising work, including controls that stop criminals exploiting client-funds processes.
- Client money — firms holding client money carry an absolute obligation to protect it. A BEC attack that redirects client funds can trigger SRA intervention, professional indemnity claims and firm-ending reputational damage.
- Confidentiality and privilege — a breach exposing matter files carries heavier professional consequences than for a commercial business, including potential negligence claims from affected clients.
These obligations also overlap with UK data-protection law. Personal data inside legal files falls under UK GDPR, so the ICO's security guidance applies alongside the SRA Code.
What are the most common attacks against law firms?
The three attack types that cause the most damage to UK firms are business email compromise, ransomware, and supply-chain compromise. BEC goes after the money directly, ransomware goes after the data firms must recover fast, and supply-chain attacks hit the legal software vendors firms depend on. Each needs a specific, layered defence.
| Attack type | How it works | Primary controls |
|---|---|---|
| Business email compromise | Criminals compromise or spoof an email account, insert into a transaction thread, and change bank details before a transfer | MFA on all mailboxes, DMARC/DKIM/SPF, telephone verification of payment changes |
| Ransomware | Document and case-management systems encrypted; double extortion threatens to publish client files | Tested offline backups, endpoint detection and response, network segmentation, patching |
| Supply-chain / third-party | A breach at a practice-management or e-signature vendor reaches many firms at once | Vendor security assessment, contractual breach-notification, monitoring vendor advisories |
Business email compromise (BEC)
The most financially damaging attack. Criminals compromise a legitimate mailbox through phishing or credential theft, or spoof a domain, then change bank account details in an anticipated funds transfer. The single most effective defence is removing the conditions that let it happen — strong authentication and disciplined payment verification. Our phishing protection service is built around exactly this threat.
Ransomware
Document management systems, case platforms and email archives are data firms are under extreme pressure to recover quickly, and ransomware crews price ransoms accordingly. Tested offline backups, endpoint detection on every device, and segmentation between workstations and file servers blunt both the encryption and the double-extortion lever. AMVIA delivers this through managed detection and response — Microsoft Defender for Endpoint monitored by our in-house 24/7 SOC.
Supply-chain and third-party risk
Attacks on legal software vendors, cloud document systems and e-signature platforms can hit multiple firms at once without touching your network directly. Assess vendor security before onboarding, demand contractual incident-notification obligations, and act on vendor advisories promptly.
Which cybersecurity controls should a UK law firm prioritise?
Prioritise the controls that defend client money and privileged data first: multi-factor authentication everywhere, email authentication, and tested backups. Then layer endpoint detection, encrypted document exchange and a documented payment-verification procedure. These map directly to the SRA's duty to manage material risk and to the most common real-world attacks.
- MFA on every account — Microsoft 365, case and document management, banking portals. BEC depends on account access; MFA is the primary defence. See Microsoft 365 security for hardened identity.
- Email authentication (DMARC, DKIM, SPF) — stops criminals spoofing your domain to impersonate partners in external email.
- Endpoint detection and response (EDR) — enterprise-grade detection on every device used for legal work, including BYOD.
- Secure email and document exchange — encrypted email or controlled portals for privileged communications, never plain attachments. This is covered in our email security guidance.
- Documented payment-verification procedure — telephone verification to a known number before any bank-detail change is actioned, no matter how legitimate the email looks.
- Staff training — legal-specific training on BEC indicators, payment verification and social engineering aimed at matter information.
- Cyber insurance — cover for business interruption, forensics, ransom (where applicable) and third-party liability, reviewed annually.
- Tested incident response — a rehearsed plan so the firm acts fast when an incident hits. See our incident response service.
Is Your Law Firm Protected Against BEC and Ransomware?
AMVIA provides a legal sector cybersecurity assessment covering BEC controls, email authentication, endpoint protection and readiness — tailored to the specific risks facing UK legal practices.
Frequently Asked Questions
Act immediately. Contact your bank to recall or freeze the fraudulent payment — speed is everything. Report to Action Fraud, notify the SRA under its mandatory reporting obligation, and alert your professional indemnity and cyber insurers. Engage a qualified incident-response firm to preserve evidence. Do not investigate internally while the incident is live.
Sending privileged client documents as unencrypted attachments is not adequate protection under most professional standards. Use encrypted email (such as Microsoft Purview Message Encryption) or controlled portals like SharePoint with access controls for sensitive communications. This also supports your UK GDPR obligations for personal data held in legal files, in line with ICO guidance.
The SRA does not mandate named technical controls. Instead, its Code of Conduct requires firms to identify and manage material risks (paragraph 6.1) and supervise work effectively (paragraph 4.2), both of which include information-security risk. In practice, that means firms must implement proportionate controls — MFA, backups, training and payment verification — and be able to evidence them.
Cyber insurance typically covers incident-response costs, forensic investigation, business-interruption losses and third-party liability from a breach. Professional indemnity insurance covers client negligence claims. A serious incident can trigger both. Notify your cyber insurer promptly, because delayed notification can affect coverage, and review exclusions around nation-state activity and unencrypted data.
They are common and rising sharply. UK government breach data shows attacks against professional-services firms increasing year on year, and the legal sector is specifically flagged by the NCSC as a high-value target because of the client money and confidential data firms hold. Sector reporting points to a steep jump in successful attacks during 2024.
Multi-factor authentication on every account, paired with a telephone payment-verification rule. Together they remove the two conditions BEC depends on — easy account takeover and unverified bank-detail changes. They cost little, take days to deploy, and stop the attack type that causes the largest financial losses to UK firms.
Related Reading
Phishing Protection for UK Businesses | AMVIA Guide
How to protect against phishing and BEC attacks — the most common threat to UK law firms.
2025 Cybersecurity Compliance Guide | UK & EU Regulatory Landscape
Navigate the UK and EU regulatory requirements relevant to legal practices in 2025.
Email Encryption for Business | AMVIA Guide
Why email encryption matters for legal practices and how to implement it for client communications.
Protect your business → Get Cybersecurity Assessment