Cybersecurity

Cybersecurity for UK Legal Firms: SRA Requirements and Managed Security

UK law firms are prime targets for cybercriminals due to the sensitive financial and personal data they handle. The SRA expects firms to have appropriate cybersecurity controls in place. This guide covers the specific risks facing legal practices, SRA obligations and the managed security approach suited to firms from sole practitioners to multi-partner practices.

NH

Nathan Hill-Haimes

Technical Director

9 min read·Mar 2026

UK law firms sit on the worst possible mix for an attacker: client money in client accounts, commercially sensitive matter data, and a duty of confidentiality that turns any breach into a professional-conduct problem. This guide sets out who is attacking firms, what the Solicitors Regulation Authority expects, and the controls that actually move the needle. For the full managed picture, see our managed cybersecurity for UK businesses pillar and our dedicated cybersecurity for law firms service.

Why do cybercriminals target law firms?

Law firms are targeted because they combine money, secrets and trust in one place. They hold client funds that can be diverted, commercially valuable data — M&A, IP, litigation strategy — and they sit as trusted intermediaries in transactions, which makes invoice and payment fraud lucrative. Historically many smaller firms underspent on security relative to the data they hold.

According to the SRA's cybercrime reporting, over £4 million was stolen from law firms through cybercrime in a single reporting year, with business email compromise diverting client funds as the dominant mechanism (SRA Risk Outlook data). The National Cyber Security Centre has published sector-specific guidance acknowledging legal services as a high-value target, which you can read in the NCSC's legal-sector advice.

The threat is also growing. Successful cyber attacks on UK law firms rose by 77% in 2024 — from 538 to 954 successful attacks in a single year *(Law Gazette, 2024)*. That trend tracks the wider UK picture set out in the government's Cyber Security Breaches Survey.

What are a law firm's SRA cybersecurity obligations?

The SRA does not prescribe specific technical controls, but its Standards and Regulations create clear duties with direct security implications. Firms must identify and manage material risks — including information-security risk — supervise work effectively, and protect client money and confidentiality. Failure here is a regulatory matter, not just an IT one.

  • Code of Conduct, paragraph 6.1 — firms must identify, monitor and manage material risks to the business, which includes IT and information-security risk.
  • Code of Conduct, paragraph 4.2 — firms must maintain effective systems for supervising work, including controls that stop criminals exploiting client-funds processes.
  • Client money — firms holding client money carry an absolute obligation to protect it. A BEC attack that redirects client funds can trigger SRA intervention, professional indemnity claims and firm-ending reputational damage.
  • Confidentiality and privilege — a breach exposing matter files carries heavier professional consequences than for a commercial business, including potential negligence claims from affected clients.

These obligations also overlap with UK data-protection law. Personal data inside legal files falls under UK GDPR, so the ICO's security guidance applies alongside the SRA Code.

What are the most common attacks against law firms?

The three attack types that cause the most damage to UK firms are business email compromise, ransomware, and supply-chain compromise. BEC goes after the money directly, ransomware goes after the data firms must recover fast, and supply-chain attacks hit the legal software vendors firms depend on. Each needs a specific, layered defence.

Attack typeHow it worksPrimary controls
Business email compromiseCriminals compromise or spoof an email account, insert into a transaction thread, and change bank details before a transferMFA on all mailboxes, DMARC/DKIM/SPF, telephone verification of payment changes
RansomwareDocument and case-management systems encrypted; double extortion threatens to publish client filesTested offline backups, endpoint detection and response, network segmentation, patching
Supply-chain / third-partyA breach at a practice-management or e-signature vendor reaches many firms at onceVendor security assessment, contractual breach-notification, monitoring vendor advisories

Business email compromise (BEC)

The most financially damaging attack. Criminals compromise a legitimate mailbox through phishing or credential theft, or spoof a domain, then change bank account details in an anticipated funds transfer. The single most effective defence is removing the conditions that let it happen — strong authentication and disciplined payment verification. Our phishing protection service is built around exactly this threat.

Ransomware

Document management systems, case platforms and email archives are data firms are under extreme pressure to recover quickly, and ransomware crews price ransoms accordingly. Tested offline backups, endpoint detection on every device, and segmentation between workstations and file servers blunt both the encryption and the double-extortion lever. AMVIA delivers this through managed detection and response — Microsoft Defender for Endpoint monitored by our in-house 24/7 SOC.

Supply-chain and third-party risk

Attacks on legal software vendors, cloud document systems and e-signature platforms can hit multiple firms at once without touching your network directly. Assess vendor security before onboarding, demand contractual incident-notification obligations, and act on vendor advisories promptly.

Which cybersecurity controls should a UK law firm prioritise?

Prioritise the controls that defend client money and privileged data first: multi-factor authentication everywhere, email authentication, and tested backups. Then layer endpoint detection, encrypted document exchange and a documented payment-verification procedure. These map directly to the SRA's duty to manage material risk and to the most common real-world attacks.

  • MFA on every account — Microsoft 365, case and document management, banking portals. BEC depends on account access; MFA is the primary defence. See Microsoft 365 security for hardened identity.
  • Email authentication (DMARC, DKIM, SPF) — stops criminals spoofing your domain to impersonate partners in external email.
  • Endpoint detection and response (EDR) — enterprise-grade detection on every device used for legal work, including BYOD.
  • Secure email and document exchange — encrypted email or controlled portals for privileged communications, never plain attachments. This is covered in our email security guidance.
  • Documented payment-verification procedure — telephone verification to a known number before any bank-detail change is actioned, no matter how legitimate the email looks.
  • Staff training — legal-specific training on BEC indicators, payment verification and social engineering aimed at matter information.
  • Cyber insurance — cover for business interruption, forensics, ransom (where applicable) and third-party liability, reviewed annually.
  • Tested incident response — a rehearsed plan so the firm acts fast when an incident hits. See our incident response service.

Is Your Law Firm Protected Against BEC and Ransomware?

AMVIA provides a legal sector cybersecurity assessment covering BEC controls, email authentication, endpoint protection and readiness — tailored to the specific risks facing UK legal practices.

Frequently Asked Questions