Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

IT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide

In short

Law firms hold exactly what criminals want: money and confidential client data. This guide explains, in plain English, how UK solicitors can protect client confidentiality, stop email fraud with DMARC, handle documents securely, back up properly and keep controls that stand up to SRA scrutiny — without needing to be technical.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

Why law firms are a prime target

Law firms sit on top of two things criminals want badly: money moving between parties and highly confidential information. Conveyancing completions, probate distributions and settlement payments all involve large sums changing hands, often to people the firm has never met in person. Add client files full of personal, financial and sometimes deeply sensitive details, and you have an attractive target.

The good news is that most attacks on solicitors are not sophisticated. They rely on a fake email, a reused password or an unpatched laptop. That means the defences are practical and affordable — and you do not need to be technical to understand them.

This guide walks through the controls that matter most for UK firms, and how they line up with your professional duties.

Most attacks on solicitors are not sophisticated. They rely on a fake email, a reused password or an unpatched laptop.

Client confidentiality is a security problem, not just an ethical one

Your duty of confidentiality under the SRA Standards and Regulations does not stop at not gossiping. It extends to making sure client information cannot be read, altered or stolen by anyone who should not have it. In the digital world that means asking some blunt questions:

  • Who can open which client files, and can we prove it?
  • What happens to that access when someone leaves the firm?
  • If a laptop is lost on the train, is the data on it readable?
  • Could a junior member of staff accidentally email the wrong file to the wrong person?

Getting these answers right is the foundation. Everything else in this guide supports it.

Access control and least privilege

Not everyone needs access to everything. Least privilege simply means people can reach the matters and systems they need for their role, and no more. Combine that with multi-factor authentication (MFA) — a code or prompt on top of a password — and even a stolen password becomes far less dangerous. MFA is now the single most effective control against account takeover, and it should be switched on for email, your practice management system and remote access without exception.

Encrypt the devices

Every laptop, phone and tablet that touches client data should have full-disk encryption enabled. On modern Windows and Mac devices this is built in; it just needs turning on and managing centrally. If an encrypted device is lost, the data is unreadable — turning a potential ICO-reportable breach into a lost lump of metal.

Email is where the money is lost

The classic attack on a law firm is conveyancing fraud: a criminal intercepts or imitates email correspondence and persuades a buyer to send their deposit to the wrong account, or persuades your firm to send completion funds to a fraudster. Once the money moves, it is very hard to recover.

There are three layers to defending against this.

1. Lock down your domain with DMARC

SPF, DKIM and DMARC are settings that control who is allowed to send email using your domain name. Without them, a criminal can send an email that appears to come from you@yourfirm.co.uk and most systems will let it through. DMARC, configured properly, tells the world to reject those fakes. It protects your clients from being impersonated in your name — a reputational risk as much as a financial one.

Setting DMARC up correctly takes some care so you do not block your own legitimate email, which is exactly the kind of task worth having managed for you.

2. Use secure, private email infrastructure

For firms that want stronger privacy and control, encrypted email and secure storage make a real difference. We genuinely use Proton at Dacros — its encrypted mail, password manager and secure file storage are a sensible fit for a profession built on confidentiality. Encrypted email means the contents are protected in transit, and secure sharing lets you send documents without dropping them into ordinary inboxes.

3. Change the human habits

Technology only goes so far. Put a simple, non-negotiable rule in place: payment details are never changed by email. Tell clients this in writing at the start of every matter, and verify any bank details by calling a known number — never a number supplied in the email itself. This one habit defeats the majority of conveyancing fraud attempts.

Secure document handling

Routine correspondence by email is fine. Sensitive documents deserve better. A secure client portal or encrypted file sharing lets clients upload and download documents through a protected channel, with access you can control and withdraw. It also gives you a record of who accessed what, which matters if a client ever questions how their information was handled.

Avoid the common trap of sensitive files scattered across personal cloud accounts, USB sticks and staff home computers. Keep firm data inside firm-managed systems where it can be secured, backed up and audited.

Backups: assume the worst will happen

Ransomware — where criminals encrypt your files and demand payment — is a genuine threat to firms of every size. The only reliable defence is backups you can actually restore from.

A sound approach follows the 3-2-1 principle: three copies of your data, on two different types of storage, with one kept off-site and offline. Crucially, at least one backup must be immutable or offline so that ransomware cannot encrypt your backups along with everything else — a mistake that has ended small firms.

And untested backups are just hope. Restores should be tested regularly so you know, before a crisis, that they work and how long recovery takes.

Making it stand up to scrutiny

When the SRA, your insurer or a commercial client asks about your security, you want more than good intentions. Two things help enormously:

  • Cyber Essentials — a UK government-backed certification covering five core controls (firewalls, secure configuration, access control, malware protection and patching). It is an affordable, recognised baseline that reassures clients and insurers alike.
  • Written policies people actually follow — a short, plain information security policy, an incident response plan, and evidence of staff training. Regulators care as much about whether controls are lived as whether they exist on paper.

If you want to understand the certification in more detail, our overview of Cyber Essentials for small businesses is a good starting point.

A sensible order to tackle this

If your firm is starting from a low base, do not try to fix everything at once. A practical order:

  1. Turn on MFA everywhere.
  2. Enable device encryption on every machine.
  3. Configure SPF, DKIM and DMARC.
  4. Get backups right and test a restore.
  5. Introduce the “never change bank details by email” rule.
  6. Work towards Cyber Essentials.

For a step-by-step approach, our 30-day security hardening playbook breaks this down into manageable chunks.

How Dacros helps law firms

We look after IT and cyber security for professional firms across Leeds and Yorkshire, and we understand the confidentiality and compliance pressures solicitors work under. From locking down email and DMARC to managed backups, Cyber Essentials and day-to-day IT support, we handle the technical detail so you can focus on your clients. You can read more about our work with law firms, or simply get in touch for a straight-talking conversation about where your firm stands today.

Frequently asked questions

Is my law firm legally required to have cyber security?

There is no single law naming specific tools, but you have clear duties. The SRA Standards and Regulations require you to keep client information confidential and to run your firm competently, and UK GDPR (enforced by the ICO) requires appropriate technical and organisational measures to protect personal data. In practice that means real controls — access management, backups, staff training and secure email — not just a policy in a drawer.

What is DMARC and why does it matter for solicitors?

DMARC is an email setting that stops criminals sending emails that appear to come from your firm's domain. Because conveyancing and probate involve large payments moving between parties, fraudsters love to impersonate solicitors. DMARC, together with SPF and DKIM, makes that impersonation far harder and is one of the highest-value, lowest-cost steps a firm can take.

How should we send confidential documents to clients?

Standard email is fine for routine correspondence but weak for sensitive files. Use a secure client portal or encrypted sharing so documents are protected in transit and access can be revoked. Avoid sending bank details by email at all, and warn clients in writing that you will never change payment details by email — a simple line that prevents a huge amount of fraud.

Does Cyber Essentials help with SRA and client due diligence?

Yes. Cyber Essentials is a UK government-backed scheme covering five core controls. Achieving it demonstrates to the SRA, insurers and increasingly to commercial clients that you take security seriously, and it often reduces cyber insurance friction. It is a sensible baseline for firms of any size.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.