Law firms and solicitors

IT your COLP can sign off.

We look after multiple law firms across South Wales, doing probate, conveyancing, pre-litigation and criminal work. We’ve taken firms through Cyber Essentials and Cyber Essentials Plus, and we’ve sat with firms working out what had to go to the SRA. Understanding your obligations is our job, not something you should have to explain to your IT provider.

Talk to us 029 2111 1202

Multiple firmsprobate, conveyancing, pre-litigation, criminal

Both levelsfirms taken through CE and CE Plus

3 in 4firms in the SRA’s own review had been attacked

Why you’re here

Why do attackers target law firms?

Because you move other people’s money to a fixed date, you hold information that is worth something to somebody, and you work to deadlines that make people act quickly. Most small businesses offer an attacker one of those. A law firm offers all three.

  • Client money, moving to a known date

    Everybody in a transaction knows roughly when the money moves and how much it is. That’s a gift to anyone who has been reading the email traffic for a fortnight.

  • Files worth more than the balance

    A matter file, a client’s medical records, unused material in a criminal case, the terms of a settlement nobody has announced yet. Some of what you hold is worth more to the wrong person than the money in the client account.

  • The email arrives from a real account

    Your client gets breached, and the next message comes from their genuine mailbox, in the existing thread, with their own signature on it. There is nothing for a filter to find. We have cleaned up after exactly this.

  • Somebody has to answer for it afterwards

    Your COLP carries the compliance obligation. Your insurer has a schedule of what you told them you were doing. The SRA expects a report when an incident touches clients. Three people asking three versions of the same question, at the worst possible moment.

One we stopped

Social Engineering: they spent all day proving they were the bank

A Friday morning, and the finance director of a law firm we look after took a call from her bank. There was suspicious activity on the account, and the account had been frozen while they looked into it. This is a firm with several offices and turnover in the millions, so a frozen account is not a small thing to be told.

She was on and off the phone to them all day. They knew her transaction history. They knew the firm’s clients. They knew the sort of detail that only the bank could know, so there was nothing there to doubt. One of the firm’s own clients had been breached months earlier, and that is where the picture came from.

She was told she couldn’t make any transactions while the account was frozen, so she didn’t try. It was a Friday, which for a firm doing conveyancing is completions day.

At five o’clock she rang Tom, angry that a whole day had gone. By then the caller had a remote session open on her screen. View only, no control, and asking for more.

Tom asked to speak to him. Confident, plausible, very well spoken, and asking for full remote control plus some additional rights so that he could sort the problem out. Tom put questions to him. He wouldn’t answer any of them.

No bank will ever need access to your PC. Not to unfreeze an account, not to check a transaction, not for anything, ever.

Tom told the client in plain terms that this was not going to happen. She was furious with him and put the phone down. He rang the firm’s reception straight back and told them to get her on the line again, because she was in the middle of being defrauded.

When she came back to the phone she was crying. The caller had given up and gone. She had spent a day being handled by somebody who knew her firm better than most of her colleagues did, and she was certain she had given the business away.

She hadn’t. They went through everything she had told him, she rang the real bank, and nothing had been taken. The account had never been frozen at any point. Nobody had checked, because until Tom picked up the phone there had been no reason to.

On the Monday she handed her notice to the managing director. Nearly twenty years as their finance director, not a penny lost, and she was too ashamed to stay.

She talked her out of it. She took some time off and came back. That last part is the bit nobody puts in a case study, and it is why we run training designed to make people confident enough to check rather than embarrassed about being fooled. Anybody can be caught on the right day by somebody who has done months of homework first.

How we train people to make that call

The regulator

What does the SRA require law firms to do about cyber security?

There’s no single SRA cyber security rule, which is why the question is so hard to answer by searching for it. The duty sits inside the SRA Standards and Regulations, and the SRA then publishes separate advice naming the controls it expects to find.

Where the duty comes from

SRA Standards and Regulations.

The Code of Conduct for Firms requires effective governance structures, systems and controls, and that you identify, monitor and manage all material risks to the business. Cyber sits inside that, alongside the duty of confidentiality in the Principles and the protection of client money in the Accounts Rules. There is no separate cyber rulebook to comply with, which is precisely why firms find it hard to know when they’ve done enough.

The controls the SRA names

From its own published advice.

  • Multi-factor authentication
  • Updates installed as soon as they’re released
  • Training for everybody, not only fee earners
  • Backups held somewhere safe and separate
  • DMARC, so nobody can send email as your firm
  • Cyber Essentials, which the SRA links to better practice

Sources: SRA cyber security advice for firms, and the SRA’s Cyber Security thematic review, published September 2020. The review visited 40 firms: 30 had been targeted, and 23 of them lost a combined £4,059,689, of which the firms themselves paid £393,890 that their insurers did not cover.

The question nobody publishes an answer to

When do you have to tell the SRA you’ve been attacked?

Promptly, and in more situations than most firms expect. Paragraph 3.9 of the Code of Conduct for Firms requires you to report a serious breach of the Standards and Regulations. The SRA’s guidance on cybercrime then goes further than that.

It expects a prompt report in every case where an attack has had, or could have, an impact on clients. A delayed transaction counts. A risk to client data counts.

It also asks firms to report significant or unusual attacks that did not succeed, so that the rest of the profession learns from them. Routine phishing your filter caught is not what it means. The report goes in through the form on the SRA’s website, with "Cybercrime incident" in the subject line.

That’s one of three clocks running at once. If personal data is involved, the ICO expects to hear within 72 hours. Your insurer will have its own notification condition buried in the policy, and missing that is one of the more common ways a claim gets refused.

In the SRA’s own review, seven significant incidents had never been reported to it, and nine incidents involving personal data had never reached the ICO.

Sources: SRA, reporting cybercrime incidents and the SRA’s reporting and notification obligations guidance. We’re an IT and security company, not your compliance adviser. Whether a given incident is reportable is your COLP’s decision. What we can do is make sure you have the facts to make it with.

What that looked like for one firm

A firm we look after received an email from a client they’d been corresponding with for weeks. Same thread, same address, same signature at the bottom. Somebody clicked the link in it, because there was no reason on earth not to. The client’s own mailbox had been compromised, so the message was genuine in every way that a filter can test.

We locked the affected accounts, revoked the active sessions, cleaned the environment and stripped out every mail rule the attacker had added to hide what they were doing. Then the part most IT providers are not much help with: working out what had actually been reached and when, so that the firm could make its report to the SRA with the technical detail already in it.

Your case management system

We’ve worked in the systems you actually use

We’re not your case management vendor and we’ve no interest in becoming one. We’re the people who make sure the environment it runs in, and the accounts that reach it, are set up the way they should be.

Systems we’ve supported firms on

LEAP, Redbrick Solutions, Hoowla and Tessaract, among others. Knowing how a firm genuinely works day to day in its case management system is the difference between a change that helps and a change that stops fee earners working on a Monday morning.

And everything around it

Microsoft 365 and the mailboxes, the shared drives, the laptops that go to court and to police stations, the joiners and leavers process, and the access rights nobody has reviewed since the last person left.

If you do conveyancing

What is Friday afternoon fraud?

It’s the theft of completion money by sending a change of bank details at the point in the week when everybody is trying to get finished. It carries that name for a reason.

The attacker has been reading the email traffic. They know the completion date, they know the amount, and they know that a message arriving at ten to three on a Friday is read by somebody who is tired, on the phone and already half out of the door.

The technical controls are settled and everybody agrees on them. Bank details verified by voice, against a number you already hold, never one taken from the email. Details do not change over email, ever, for anyone.

The hard part is cultural: holding that line on a Friday afternoon while the client is ringing to ask why their money hasn’t moved. That’s training, then training again, then training after that. It’s also why the security awareness training we run goes to everybody in the firm rather than to fee earners only. The person who takes the call is rarely the person on the file.

The controls are not complicated. Getting every single person to hold them on the worst afternoon of the week is the actual work.

The long version, including who carries the loss How we stop somebody sending email as your firm

Talk to us

Tell us what your firm is running

Practice areas, headcount, case management system, and whoever is asking you the awkward questions. We’ll tell you what we’d change, in what order, and what it costs. No obligation to do any of it with us.

The outcomes, not the acronyms

What we actually do for a law firm

The same four people who look after everything else, on one fixed monthly fee per user with each extra as its own line on the same invoice.

Support that answers first time

A helpdesk answered by the people who do the work, not a first line team reading from a script. You’ll know the name of whoever picks up. Fee earners lose less of the day to it, which is the only measure of IT support that a partner cares about.

Security that someone is actually watching

Managed detection and response with Bitdefender’s security operations centre reading alerts around the clock, email security inside Microsoft 365, and alerting on the mail rules an attacker adds to a compromised mailbox to hide their tracks. That last one is how the client email story above gets caught earlier next time.

Certification that satisfies the panel

We’ve taken firms through Cyber Essentials and Cyber Essentials Plus, and we hold Cyber Essentials ourselves. You get told what would fail today before anybody pays an assessment fee, and the certification body’s fee is in the number from the start.

Training that stops the risky click

For everybody in the firm. Reception, accounts, paralegals, trainees and partners. The SRA’s own review found staff knowledge was the single biggest vulnerability firms identified in themselves, and that one firm in five had never run specific training at all.

Worth knowing

If your professional indemnity insurer or a client’s panel questionnaire has asked you something you couldn’t answer confidently, send us the question. Working out what the honest answer is takes us a lot less time than it takes you, and you’ll know where you stand before you write anything down.

Questions

The things firms ask us first

Do you actually work with law firms, or are we the first?

No, you would not be the first. We look after firms across South Wales doing probate, conveyancing, pre-litigation and criminal work, and we’ve taken multiple firms through both Cyber Essentials and Cyber Essentials Plus. We’ve also stopped a live social engineering attack on a firm’s finance director while it was happening, and helped a firm work out what had to go in its report to the SRA after an incident. Plenty of providers will tell you they work with law firms. Ask them which of those conversations they have actually had.

What does the SRA require us to do about cyber security?

There is no standalone SRA cyber security rule. The duty comes from the SRA Standards and Regulations: the Code of Conduct for Firms requires effective governance, systems and controls, and that you identify, monitor and manage all material risks. The SRA’s own published advice then names the controls it expects to see, including multi-factor authentication, prompt patching, staff training, backups, DMARC and Cyber Essentials.

When do we have to report a cyber attack to the SRA?

Promptly, and in more cases than firms expect. Paragraph 3.9 of the Code of Conduct for Firms covers a serious breach of the Standards and Regulations, and the SRA’s cybercrime guidance goes further: it expects a prompt report in any case where an attack has had, or could have, an impact on clients, including a delayed transaction or a risk to client data. It also asks to hear about significant or unusual attacks that failed. Reports go through the form on the SRA’s website with "Cybercrime incident" in the subject line. If personal data is involved that is a separate 72 hour clock with the ICO, and your insurer will have its own notification condition. Whether a specific incident is reportable is your COLP’s decision, not ours.

Do law firms need Cyber Essentials?

It isn’t mandatory for SRA regulated firms, but it’s increasingly what a client panel, a tender or an insurer asks for, and the SRA’s own thematic review found that firms holding it had better policies and controls in place. If nobody is asking you for the certificate yet, the five controls behind it are still the things you should be doing.

Do you support LEAP, or our case management system?

We’ve supported firms running LEAP, Redbrick Solutions, Hoowla and Tessaract, among others. We’re not the vendor and we don’t replace your support contract with them. What we look after is everything around it: the Microsoft 365 tenant, the devices, the accounts and access, the backup, and making sure a change on our side never breaks a system your fee earners live in all day.

What is Friday afternoon fraud and how do we stop it?

It’s the theft of completion funds by sending a change of bank details late on a Friday, when everyone is trying to finish before the weekend and the attacker has been reading the email traffic long enough to know the date and the amount. The controls are verbal verification of bank details against a number you already hold rather than one from the email, and a firm rule that details never change over email. The technical part is straightforward. Getting every person in the firm to hold the line on a Friday afternoon is the work, and that’s what the training is for.

We already have an IT provider. What does moving involve?

We audit what’s there before touching anything, and you get told what we found including the awkward parts. Unlicensed software goes, multi-factor authentication goes on, and clearing up what the last provider left is part of taking you on rather than a separate invoice. Minimum term is twelve months. Nothing moves during a completion week.

Next step

Who’s asking, and by when?

A client panel, an insurer, a tender, or your own COLP. Tell us what the question is and what you’re running, and we’ll tell you where you’d currently fall short and what it takes to fix it.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.