Less than most sector pages would have you believe. Multi-factor authentication, patching, backup that has been tested, somebody reading the security alerts, a proper joiners and leavers process: those are the same for a law firm, a letting agent and a firm of plumbers, and they are most of the work.
What genuinely changes is who asks you about it, what they ask, and what it costs you to be unable to work for a day.
A solicitor has a regulator with a reporting duty attached. An estate agent has HMRC supervision and a criminal offence sitting behind not registering. An architect has a main contractor deciding whether they are allowed to bid. A charity has a funder. Each of those turns the same underlying work into a different conversation, a different order of priority, and a different set of questions you need to be able to answer without ringing anyone.
So the security is not really sector specific. Knowing which question is coming at you, and from whom, very much is.
Law firms and solicitors
The regulator, the duty of confidentiality, and client money moving to a fixed completion date.
Criminal defence firms
A Legal Aid contract on top of the SRA, devices that live outside the building, and evidence files nothing was designed to hold.
Estate and letting agents
HMRC supervision, the customer records that go with it, and being one link in a chain an attacker is already watching.
Architects and design practices
File sizes, working away from a desk, and whoever is above you in the supply chain setting the security bar.
Charities and the third sector
Multiple sites, volunteer turnover, funder requirements, and beneficiary data that matters more than the money does.