Solutions

Cyber Security for Solicitors and Conveyancers

Client account money, confidential files and time-pressured completions make law firms an unusually attractive target. The defences are as much process as technology.

PRIMARY THREAT
Payment Redirection Fraud
REGULATOR
SRA & ICO
CONTROLS
Verification Process + Email Security
BASELINE
Cyber Essentials
In short

Why are law firms targeted by cyber criminals?

Because they hold client funds and highly confidential material, and because conveyancing involves large, time-critical transfers. Payment redirection fraud against conveyancers — often called Friday afternoon fraud — remains one of the most costly attacks affecting UK small businesses.

Friday afternoon fraud, and why it works

The pattern is consistent. An attacker compromises a mailbox — the firm's, the client's or the estate agent's — and watches a transaction develop. Shortly before completion, usually late on a Friday when everyone is under pressure and banks are closing, a message arrives with updated account details. The money goes, and recovery is extremely difficult.

It works because of urgency and because the email is genuine in every respect that a filter can check — it comes from a real, compromised account, in a real thread, referencing real details. No technical control reliably catches that. The control that works is procedural: bank details are confirmed once, early, by telephone on a pre-agreed number, and never changed on the strength of an email.

  • Confirm client bank details verbally at the outset, using a number obtained in person
  • State clearly in your client care letter that details will never change by email
  • Require a second fee earner to authorise any late change to payment instructions
  • Avoid late-Friday completions where the timetable allows
  • Train every member of staff, not just the conveyancing team

Confidentiality and the SRA

Confidentiality is a core professional obligation, not merely a data protection one. A breach that exposes client matter files engages both the SRA Code of Conduct and UK GDPR, and the SRA expects firms to have taken reasonable steps to protect client information and money.

In practice that means controlled access to matter files rather than a shared drive everyone can read, encryption on every device that leaves the office, secure file exchange with clients instead of emailed bundles, and a documented process for removing access when someone leaves.

  • Matter-level access control in the document management system
  • Full-disk encryption on all laptops and mobile devices
  • Secure client portal or encrypted exchange for sensitive documents
  • Same-day access revocation for departing fee earners and support staff
  • Retention and secure destruction schedule for closed matters
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Legal Sector Security — your questions answered

What is Friday afternoon fraud?
Payment redirection fraud aimed at conveyancing completions, typically executed late on a Friday when time pressure is highest and banks are about to close. The attacker sends amended bank details from a compromised but genuine mailbox.
How do we prevent payment redirection fraud?
Confirm bank details once, early, by telephone on a number you obtained independently, and state in your client care letter that details will never change by email. Require second-person authorisation for any late change. Process defeats this attack where technology cannot.
Do we have to report a cyber incident to the SRA?
Firms must report serious matters including those affecting client money or confidentiality. Where personal data is involved the ICO 72-hour duty applies as well. We help firms assess both obligations quickly during an incident.
Does Cyber Essentials help with client and insurer due diligence?
Yes. It is increasingly asked for by professional indemnity insurers and by corporate clients running supplier due diligence, and it evidences the technical baseline without a bespoke questionnaire each time.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about legal sector security?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.