UK law firms have become one of the most targeted sectors in the country for cybercrime. The legal sector saw a 77% increase in cyberattacks in 2025, according to threat intelligence published by the NCSC in their sector-specific guidance. The reasons aren’t hard to understand: law firms hold client account funds, often handling large property transactions and business deals; they store sensitive personal data including medical records and family court documents; and their communications are privileged, meaning compromised email accounts can produce intelligence that’s worth money to competitors or foreign intelligence services.
The challenge for smaller practices is that they face the same threat profile as Magic Circle firms but with a fraction of the security budget. A sole practitioner or a five-person conveyancing firm is a meaningful target — they handle property transactions worth hundreds of thousands of pounds and typically have less security infrastructure than their larger counterparts.
Why Law Firms Are Targeted
The specific attacks affecting the legal sector break into a few categories:
Conveyancing and property fraud. This is the most financially damaging attack type for smaller practices. Criminals compromise a firm’s email system, monitor conveyancing transactions in progress, and at the critical moment of funds transfer send fraudulent bank detail change instructions to either the client or the client’s lender. The Solicitors Regulation Authority (SRA) has published multiple warnings about this, and the losses are significant — clients who transfer funds to fraudulent accounts often have limited recourse.
Ransomware. Law firms’ reliance on document management systems and case management software makes ransomware particularly disruptive. A firm that can’t access its matter files cannot do its work. The combination of data encryption and data exfiltration (attackers stealing client files before encrypting them, then threatening to publish) is increasingly common in attacks on professional services firms.
Credential theft and account takeover. Phishing campaigns targeting solicitors are sophisticated and often law-firm-specific — fake Law Society communications, fake HMCTS portals, fake Land Registry notifications. Stolen credentials are used to access email, case management systems, and client portals.
Supply chain attacks. Law firms rely on a range of software vendors — case management, conveyancing portals, document automation, e-signature platforms. Compromise of these vendors can provide attackers with access to multiple law firms simultaneously.
SRA Obligations
The SRA’s Standards and Regulations place obligations on firms that have direct cybersecurity implications. Under the Code of Conduct for Firms (Paragraph 6.3), firms must have appropriate risk management systems and controls. Cybersecurity is explicitly within scope of that obligation.
More specifically:
- Client account protection: Firms have a duty to protect client money held in client account. A conveyancing fraud that results in client funds being transferred to criminals puts the firm in breach of its regulatory duties and potentially triggers SRA investigation and compensation fund claims.
- Data breaches: As data controllers, law firms must report certain personal data breaches to the ICO within 72 hours of becoming aware of them. This includes ransomware attacks that encrypt or exfiltrate personal data.
- Practising certificate risk: SRA investigations following a significant breach can result in suspension or conditions on practising certificates, particularly if the firm is found to have failed to implement basic security controls.
The SRA has signalled it will treat cybersecurity failures more seriously than it has historically. A firm that suffers a conveyancing fraud but had no email authentication controls (SPF, DKIM, DMARC) configured, no client verification procedures, and no cyber insurance is in a much worse regulatory position than one that was targeted despite having reasonable controls in place.
What Small Practices Need to Do
Email authentication is non-negotiable. Configuring SPF, DKIM, and DMARC for your firm’s domain prevents criminals from sending emails that appear to come from your firm’s email address. Many conveyancing frauds rely on spoofed emails from law firm addresses — this one control makes that specific attack harder. If you’re using Microsoft 365 or Google Workspace, these can be configured without specialist IT knowledge, though it’s worth having someone check the configuration is correct.
Multi-factor authentication on everything. Email accounts especially, but also your case management system, client portal, and any remote access VPN or desktop solution. MFA doesn’t prevent all phishing (adversary-in-the-middle attacks can capture session tokens) but it stops the most common credential-stuffing and simple phishing attacks.
Staff awareness training. Specifically for conveyancing fraud: staff handling property transactions should be trained to treat any late-stage change of bank details as suspicious by default and to verify by telephone using a number independently obtained (not from the email requesting the change). This single procedural control is the most effective defence against conveyancing fraud.
Cyber Essentials certification. Cyber Essentials and Cyber Essentials Plus give you a structured baseline of the technical controls the UK government considers fundamental. For a law firm, achieving Cyber Essentials is also increasingly expected by larger business clients and insurers. The certification process itself helps identify gaps.
Cyber insurance. Legal professional indemnity insurance does not typically cover cybercrime losses. Specialist cyber insurance, covering incident response costs, legal costs, client notification, and financial losses from cyber fraud, is now considered a basic requirement for law firms. Premiums have risen, but the coverage gap without it is significant.
Incident response planning. Know what you’ll do if your systems go down. Who do you call? How do you keep serving clients? Who handles ICO notification? Having even a basic written plan means these decisions don’t have to be made under pressure during an active incident.
Sector-Specific Resources
The NCSC provides free resources aimed specifically at professional services and legal sector organisations. Their Cyber Action Plan tool generates a prioritised list of recommended controls based on your firm’s size and setup — it’s a practical starting point if you’re not sure where to begin.
The SRA publishes conveyancing fraud guidance with specific procedural controls, available through the SRA website. Law Society Lawhubs and local law societies increasingly run cybersecurity awareness sessions — worth attending to understand what the current attack patterns targeting solicitors actually look like.
The legal sector’s cyber risk isn’t going away, and the regulatory and reputational consequences of a serious breach are serious enough that treating security as a compliance checkbox rather than an operational priority is increasingly risky. For smaller practices especially, the controls that make the biggest difference — email authentication, MFA, staff training on conveyancing fraud — are not expensive or technically complex. They’re largely a matter of deciding to do them.