Criminal defence

IT that holds up at two in the morning.

Your working week happens in police stations, courts and prisons rather than at a desk, and the case file travels with you on a laptop. That laptop holds video of the offence, photographs, and statements from witnesses who did not choose to be involved. Encrypting that laptop is not good practice, it is a mandatory requirement of your Legal Aid contract, and so is holding Cyber Essentials.

Talk to us 029 2111 1202 Book a meeting

Mandatorylaptop encryption, under your LAA contract

Around the clockmonitoring, because your rota is too

Both levelsCyber Essentials and Plus

The contract you already signed

What does the Legal Aid Agency require on data security?

More than most firms realise, and a good deal of it is mandatory rather than advisory. The LAA publishes a specific set of data security requirements for providers, separate from anything the SRA asks of you, and holding a contract means agreeing to them.

Mandatory

Not optional, not risk based.

  • Hard drive encryption on every computer holding personal or sensitive information, laptops included
  • Encryption on removable media
  • Device encryption and access controls on mobiles and tablets
  • An incident policy that says who notifies the LAA, and when
  • An induction plan and an annual training plan for staff
  • Records of who accessed personal data, with an audit trail that somebody actually reviews
  • Secure destruction of records and of old electronic media
  • A remote and home working policy
  • Business continuity and disaster recovery plans
  • A valid Cyber Essentials Basic certificate, renewed every twelve months. Clause 16.19 of the 2025 Standard Crime Contract, checked at verification and again at annual review

Recommended

Where the LAA stops short of requiring it.

  • Cyber Essentials Plus. The level above the one you must hold, recommended by name in the data security requirements
  • Multi-factor authentication on email and on anything holding personal data
  • Controls selected from Annex A of ISO 27001
  • FIPS-140 for disk encryption and AES 128-bit or better on removable media
  • Access restricted to the minimum data a role actually needs

Sources: the 2025 Standard Crime Contract standard terms, and the LAA’s data security requirements for providers, version 4.1, September 2024. Both change, so check the current versions against your own contract.

The bit worth following through

The data security requirements list multi-factor authentication as recommended rather than mandatory, which makes it sound optional. It is not. Your contract requires you to hold Cyber Essentials, and since April 2026 missing multi-factor authentication on a cloud service that offers it is an automatic fail under Cyber Essentials. So MFA is a condition of the certificate, and the certificate is a condition of the contract. Anyone who certified before April 2026 renews against the stricter question set.

Where the risk actually is

The whole case file is on a laptop in a car park

Two in the morning, a police station somewhere, and one of your duty solicitors is on a callout. The laptop in the bag has the case on it. Not a summary of the case, the case: video of the offence, photographs, statements from witnesses, the lot.

Then it goes to court. Then to a prison visit. Then home, then back out again the next night, because that is what a rota looks like.

The people in those files did not choose to be in them. Witnesses, complainants, and in plenty of matters children.

Every business worries about losing a laptop. In most of them the honest answer is that somebody loses a spreadsheet and a fortnight of irritation. Here, an unencrypted laptop left on a train is a data breach involving special category personal data about identifiable people in an active criminal matter, and it is simultaneously an ICO notification, an LAA notification and a very difficult conversation with your regulator.

None of that is an argument for making solicitors work differently. Working out of a car at two in the morning is the job. It is an argument for the laptop being set up so that losing it is an inconvenience rather than an incident.

The question is not whether one of your laptops will go missing. It is what is true about that laptop on the day it does.

The five minutes that matter

What happens when a laptop goes missing?

If it is set up properly, you make one phone call and then you get on with your day. If it is not, you spend a fortnight finding out what was on it and explaining yourself. The difference is decided months earlier.

The disk is encrypted

Whoever picks it up gets a brick rather than a case file. This is the mandatory one, and it is also the cheapest thing on this page: on modern Windows machines it is a configuration decision, not a purchase. We check it is genuinely on and genuinely recording the recovery keys somewhere you can reach them.

The account is locked, not just the device

A laptop is a way into a mailbox and a case management system. Access gets cut centrally, sessions revoked, and the device wiped remotely the next time it sees a network. Conditional access means an unrecognised device does not get in even with the right password.

You can say what was on it

The single hardest question after a loss is what was actually stored locally. If the answer is "we think most of it was in the case management system", that is not an answer. Knowing where files live before the incident is what turns a two week investigation into a one page report.

Somebody is awake

Losses and compromises do not respect office hours, and neither does your rota. Bitdefender’s security operations centre reads the alerts around the clock. That does not mean our helpdesk answers at 3am, and we would rather say so than let you find out.

The other half of the problem

Where does the served evidence actually go?

Criminal defence generates the awkward files. Body worn video, CCTV, interview recordings, phone downloads, photographs. They arrive in bulk, they are enormous next to anything a conveyancer handles, and they end up in whatever place is easiest at the time.

Easiest at the time usually means a personal OneDrive, a USB stick, a laptop desktop, or a folder somebody made once and named after a defendant.

That matters for three separate reasons. It is the material most likely to be missed by a backup, because it is not where the backup is pointed. It is the material a retention schedule never reaches, so it sits there years after the matter closed. And it is the material that makes an access audit trail impossible, because nobody can say who opened what.

The fix is not exciting and it is not expensive. Decide where evidence lives, make that place the path of least resistance, back it up, and put access controls and an audit trail on it. Then removable media stops being the default answer, which is helpful, because the LAA requires that to be encrypted too.

Every firm has a folder somewhere that nobody wants to open. This is the one where finding it early is worth the afternoon.

Talk to us

Tell us what your fee earners carry

How many of you there are, what devices go out on a callout, and where evidence ends up when it arrives. We will tell you which of the LAA’s mandatory requirements you would fail today, and what it takes to fix each one.

What we do

What a criminal defence firm actually needs from us

The same fixed monthly fee per user as everything else, with the extras itemised on the same invoice.

A helpdesk that understands a court list

Somebody who cannot get into their laptop at 8:45am with a hearing at ten has a different problem to somebody with a slow spreadsheet. There are four of us, so you get a named person rather than a queue position.

Devices set up for the job

Encrypted, patched, monitored, and configured so a lost one can be cut off and wiped. Hardware sourced and supplied by us rather than bought off a consumer site the week somebody starts.

Cyber Essentials, both levels

Your contract requires Cyber Essentials Basic and the data security requirements recommend Plus. We take firms through both, and tell you what would fail before anybody pays an assessment fee. How the scheme works and what it costs.

The training the contract asks for

Your LAA requirements include an induction plan and an annual training plan. Ours is short courses people finish, simulated phishing monthly, and an audit trail you can show at a contract review.

What we do for law firms generally What it costs, per user, published

Questions

The things firms ask first

Does the Legal Aid Agency require laptop encryption?

Yes. The LAA’s data security requirements for providers make hard drive encryption mandatory on every computer holding personal or sensitive information, laptops included, alongside username and password authentication. Removable media and mobile devices must be encrypted too. These are listed as mandatory rather than recommended, so they are a condition of holding the contract rather than a matter of judgement.

Do we need Cyber Essentials for a Legal Aid contract?

Yes. Clause 16.19 of the 2025 Standard Crime Contract requires providers to hold a valid Cyber Essentials Basic certificate as a minimum. It is checked when your contract is verified and again at annual review, and it lasts twelve months, so it is a renewal in your calendar rather than a one off. Cyber Essentials Plus is the level above and is recommended rather than required. Worth knowing that the certificate now brings multi-factor authentication with it: MFA has been an automatic fail under Cyber Essentials since April 2026, so a firm that passed comfortably a couple of years ago may not pass today without some work.

What do we have to tell the LAA if we lose data?

Your contract requires you to hold a policy for reporting, managing and recovering from information security incidents, and that policy has to define who is responsible for notifying the LAA. So the obligation is partly one you write yourself, which is exactly why it gets forgotten. Separately, a personal data breach is a 72 hour clock with the ICO, and the SRA expects a prompt report where an incident has affected or could affect clients. Three different notifications, and your COLP owns the decision on the SRA one.

Our fee earners work from police stations and courts. Does that make this harder?

It changes what matters rather than making it harder. Devices leave the building constantly, so encryption, remote wipe and conditional access do most of the work, and a written remote and home working policy is one of the LAA’s mandatory requirements anyway. What we would not do is make people work differently to suit the IT. Attending at two in the morning is the job, and the setup has to survive it.

Where should served evidence be stored?

Somewhere central, backed up, access controlled and covered by an audit trail, rather than on a laptop desktop or a USB stick. Video and phone downloads are large enough that people route around a system that makes them awkward, so the practical answer is to make the right place the easiest place. The LAA requires an audit trail of who accessed personal data, and that is impossible if half the material is in personal storage.

Do you already work with criminal defence firms?

Yes. We support criminal defence work alongside probate, conveyancing and pre-litigation firms across South Wales. We have taken firms through both Cyber Essentials and Cyber Essentials Plus, and helped a firm work out what had to go in its report to the SRA after an incident. The parts of your week that make criminal work different, the police station callouts, the evidence that arrives in bulk, and the laptop holding a live case file in a car park, are the parts we build the setup around.

Next step

Know what you would fail today

Book twenty minutes with Tom and bring three numbers: how many fee earners you have, how many laptops leave the building, and where served evidence gets saved. You get back a plain list of the LAA’s mandatory requirements you meet today and the ones you do not, with what each gap takes to close. If you are already fine, we will say so.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.