Cyber Security for Solicitors and Conveyancers
Client account money, confidential files and time-pressured completions make law firms an unusually attractive target. The defences are as much process as technology.
Why are law firms targeted by cyber criminals?
Because they hold client funds and highly confidential material, and because conveyancing involves large, time-critical transfers. Payment redirection fraud against conveyancers — often called Friday afternoon fraud — remains one of the most costly attacks affecting UK small businesses.
Friday afternoon fraud, and why it works
The pattern is consistent. An attacker compromises a mailbox — the firm's, the client's or the estate agent's — and watches a transaction develop. Shortly before completion, usually late on a Friday when everyone is under pressure and banks are closing, a message arrives with updated account details. The money goes, and recovery is extremely difficult.
It works because of urgency and because the email is genuine in every respect that a filter can check — it comes from a real, compromised account, in a real thread, referencing real details. No technical control reliably catches that. The control that works is procedural: bank details are confirmed once, early, by telephone on a pre-agreed number, and never changed on the strength of an email.
- Confirm client bank details verbally at the outset, using a number obtained in person
- State clearly in your client care letter that details will never change by email
- Require a second fee earner to authorise any late change to payment instructions
- Avoid late-Friday completions where the timetable allows
- Train every member of staff, not just the conveyancing team
Confidentiality and the SRA
Confidentiality is a core professional obligation, not merely a data protection one. A breach that exposes client matter files engages both the SRA Code of Conduct and UK GDPR, and the SRA expects firms to have taken reasonable steps to protect client information and money.
In practice that means controlled access to matter files rather than a shared drive everyone can read, encryption on every device that leaves the office, secure file exchange with clients instead of emailed bundles, and a documented process for removing access when someone leaves.
- Matter-level access control in the document management system
- Full-disk encryption on all laptops and mobile devices
- Secure client portal or encrypted exchange for sensitive documents
- Same-day access revocation for departing fee earners and support staff
- Retention and secure destruction schedule for closed matters
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Legal Sector Security — your questions answered
What is Friday afternoon fraud?
How do we prevent payment redirection fraud?
Do we have to report a cyber incident to the SRA?
Does Cyber Essentials help with client and insurer due diligence?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about legal sector security?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.