Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Strait of Hormuz closed over ceasefire violations, says Iran

      Aerial view of ships navigating the strategic Strait of Hormuz, highlighting its importance to global maritime trade routes

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Platitudes in women’s sport are empty, patronising and offensive

      Business professionals in a conference room discussing strategy with a presentation screen displaying key market trends.

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Fogo de Chao nominated for Best Casual Dining Toast award

      Fogo de Chão restaurant exterior with vibrant signage and bustling entrance at popular city location

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Saturday 18 May 2024 9:30 am  |  Updated:  Saturday 18 May 2024 9:38 am

UK’s legal sector needs to improve its cybersecurity, say experts

By: Maria Ward-Brennan

Professional Services Editor

Add as a preferred source on Google
UK's legal market is vulnerable to data breaches, experts say it needs robust cybersecurity
Photo by David Pupaza

One in ten data breaches over 2023 occurred in the UK legal sector, showing that UK law firms are attractive targets for cybercriminals. Experts told CityAM that the sector needs better cybersecurity.

A recent analysis of the Information Commissioner’s Office (ICO) data by a data breach law firm, Hayes Connor, revealed the legal sector is one of the worst-performing sectors for data breaches.

Its analysis of the data showed that nearly 86 per cent of the incidents within the legal sector involved breaches of basic personal identifiable information, with instances also prominently affecting sensitive economic and financial data.

Meanwhile, 80 cases of breaches in the legal sector last year involved breaches of children’s data, which Hayes Conner stated raises serious concerns given the vulnerability of such information.

The findings also showed the different incident types behind the data breaches, with the number one reason being emails sent to the wrong recipient.

Last November, a prolific cybercriminal LockBit targeted legacy magic circle firm Allen & Overy (now known as A&O Shearman).

Despite this influx, Jon Bartley, partner at RPC, did point out that the ICO data also shows an increase in reported cyber incidents across the legal sector. In 2023, 70 per cent more phishing incidents and 268 per cent more ransomware incidents were notified to the ICO compared to the previous year.

In addition to notifying the ICO, if law firms or their clients are directly affected by a cyberattack, they must report the incident promptly to the legal regulator, the Solicitors Regulation Authority (SRA).

But why are law firms such a target?

The legal regulator stated that in the first half of 2020, law firms reported that nearly £2.5m of money held by firms had been stolen by cybercriminals, over three times the amount reported in the first half of 2019.

Richard Forest, legal director at Hayes Connor, outlined that law firms are particularly susceptible due to the sensitive nature of the information they handle, such as personal details, business intel, and legal documents.

Read more

Everton ‘surprised and angered’ at losing £40m legal case with Burnley

GettyImages 2272351712 showing a business meeting with diverse professionals discussing strategies around a conference table

Bartley explained that a key vulnerability is the information on law firms’ systems regarding ongoing transactions in which payments might be due.

“Access to those systems provides an opportunity to attempt to divert payment by impersonating the lawyer and instructing payment to a changed bank account. This can be a quick method for a threat actor of obtaining funds,” he added.

Forest also added the issues with law firms often prioritising legal expertise over cybersecurity, which may lead to gaps in their digital defences.

What do firms have to do in order to protect themselves?

On Wednesday, the Law Society and the Bar Council said they had updated their cybersecurity questionnaire in response to feedback from the legal sector. This questionnaire is designed to help law firms better assess the cybersecurity arrangements of the chambers and barristers they instruct.

Commenting on that, Nick Emmerson, president of the Law Society said: “We know that no one tool can offer complete protection against cyber threats but this updated questionnaire will help reassure clients that data is kept as secure as possible.”

“Firms will need to continue to take other precautions, but the development of the questionnaire is an important step in the right direction,” he added.

Forest pointed out that “robust cybersecurity measures and continuous staff training are essential for law firms to protect themselves and their clients’ confidential information.”

Bartley also highlighted that law firms need to take a proactive approach to cybersecurity.

“This includes investing in robust security measures such as encryption, multi-factor authentication and regular security audits. Also, implementing comprehensive data protection policies and providing regular training for staff on cybersecurity best practices are essential steps in mitigating the risk of data breaches,” he explained.

Read more

Business doesn’t want a ‘partnership’ with the state

Rachel Reeves speaking at an IOD event.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Legal

People & Organisations

  • cybersecurity
  • data breach
  • Legal

Trending Articles

  • As it happened: Stocks sink after Fed and Bank of England opt for hawkish hold; Oil price tumbles

  • FTSE 100 Live: Pound dips and stocks slip as Andy Burnham victory triggers political uncertainty

  • City investors raise alarm on Burnham’s Chancellor pick

  • Inheritance tax enquiries surge to six-year high after HMRC clampdown

  • More Big Four blues as Deloitte plans to slash UK audit roles

More from CityAM

  • Everton ‘surprised and angered’ at losing £40m legal case with Burnley

    Sport Business
    GettyImages 2272351712 showing a business meeting with diverse professionals discussing strategies around a conference table
  • Business doesn’t want a ‘partnership’ with the state

    Opinion
    Rachel Reeves speaking at an IOD event.
  • Harbor Acquires CE Global Partners, Expanding HCM Advisory Practice with Specialist HR and Payroll Transformation Capabilities

    Business Wire
  • ‘We cannot regulate cyber threats away,’ top lawyer warns

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • City law firms ‘sleepwalking into a crisis’ over AI overreliance

    Legal
    Generative AI technology transforming business insights with advanced data analytics on digital interface
  • Revolut deploys AI to scrutinise law firms in major shake-up

    Legal
    Sleek modern design of Revoluts new office space featuring open workstations and collaborative meeting areas
  • Pinsent Masons is not the only City law firm walking a dangerous AI tightrope

    Legal
    Breaking news update with stock market analysis and financial data graphs on a digital interface, highlighting global trends
  • Southampton sponsors could sue over £170m Spygate verdict

    Sport Business
    Business professionals discussing strategy in a modern office setting, highlighting collaboration and corporate decision-m...

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies