Why Law Firms Are the Highest-Value Target in Professional Services
The economics of attacking a law firm are straightforward. A mid-sized UK solicitors practice holds, at any given time, client funds in its client account (sometimes millions of pounds in conveyancing transactions), confidential commercial information for multiple corporate clients (M&A details, litigation strategy, regulatory matters), and personal data for hundreds or thousands of individuals.
A successful attack on a law firm's systems can yield all three. The NCSC's legal sector threat assessment consistently places law firms among the highest-risk targets for financially motivated cybercrime in the UK. Conveyancing fraud alone — where attackers intercept or divert property transaction funds — costs UK consumers and firms tens of millions of pounds annually. UK Finance's data for 2024 showed conveyancing-related APP fraud as one of the largest single subcategories of authorised push payment fraud.
What a Pen Test for a UK Law Firm Should Cover
**The client portal and document management system.** Whether you use a dedicated legal DMS (Actionstep, Clio, LEAP, Osprey, Zola Suite) or a more general platform, the system holding client documents and matter information is the primary target. A pen test should assess authentication strength, MFA enforcement, session management, and whether access controls prevent one client or one fee earner accessing matters they should not.
**The practice management system.** Time recording, billing, and financial data live here. Access to billing records and client financial information is valuable both for fraud and for intelligence gathering. Check authentication, privilege separation between fee earner and admin roles, and how the system is accessed remotely.
**Email infrastructure and anti-spoofing configuration.** Conveyancing fraud and BEC attacks against law firms almost always involve email — either compromising a fee earner's email account directly, or spoofing the firm's domain to redirect client payments. DMARC, DKIM, and SPF configuration should be tested and enforced. A law firm whose domain lacks DMARC enforcement can be spoofed trivially; attackers can send emails from partner@yourfirm.co.uk that pass basic email authentication checks.
**The client-facing website and contact forms.** The public website is the lowest-hanging fruit and the most commonly neglected. Contact forms, client login portals embedded in the site, and document upload facilities are all attack surfaces. Standard web application testing applies: injection vulnerabilities, authentication weaknesses, file upload handling.
**Remote access and VPN.** Post-pandemic, most fee earners access practice systems remotely. VPN and remote desktop configurations should be assessed for known vulnerabilities, credential requirements, and MFA enforcement.
The SRA's Cybersecurity Expectations
The Solicitors Regulation Authority (SRA) does not mandate specific cybersecurity standards in the way that FCA-regulated firms face explicit technical requirements. However, the SRA Accounts Rules require firms to maintain adequate controls over client money, and the SRA's cybersecurity guidance makes clear that failure to implement reasonable security measures — and failure to recover properly after an incident — can constitute a breach of regulatory obligations.
The SRA has intervened in firms following cybersecurity incidents where client funds were lost and the firm's security controls were found to be inadequate. Conveyancing fraud cases have resulted in SRA investigations into whether firms had appropriate email verification procedures and client account controls.
Practically: the SRA expects firms to have a written cybersecurity policy, to train staff on phishing and email fraud, to have incident response procedures that include notifying affected clients and (where personal data is involved) the ICO, and to implement controls proportionate to the sensitivity of the data and money they handle.
Conveyancing Fraud: The Specific Technical Pattern
Conveyancing fraud is worth understanding in technical detail because it illustrates how a web application vulnerability can result in a direct financial loss.
The common pattern: an attacker gains access to a fee earner's email account (via phishing, credential stuffing, or a compromised device). They monitor incoming emails passively for weeks, identifying active conveyancing transactions. At the right moment — when completion is imminent and exchange of bank details is expected — they either send a fraudulent email from the compromised account redirecting client funds, or intervene in the email chain between the firm and the client to substitute their own bank details.
The email account compromise that enables this often starts with a phishing email to a fee earner, or with credentials that appeared in a breach database (the fee earner used the same password for their work Microsoft 365 account as for a personal service that was breached). The technical controls that prevent it: MFA on all email accounts (Microsoft 365 and Google Workspace both support this, and it is free), email authentication (DMARC, DKIM, SPF), and client verification procedures (callbacks to verify bank detail changes by phone).
The Personal Data Angle
Law firms process significant volumes of special category personal data — health information in personal injury matters, political opinions in employment tribunal cases, criminal records in crime matters. Data protection obligations under UK GDPR apply to all of it, and the ICO has issued enforcement notices to law firms following data breaches.
The specific obligation most commonly breached in law firm incidents: timely notification. UK GDPR requires notification to the ICO within 72 hours of becoming aware of a breach that poses a risk to individuals. Law firm incidents often go unreported for weeks because the firm is uncertain whether a breach occurred or does not want to trigger regulatory scrutiny. Failure to notify timeously is itself an aggravating factor in ICO enforcement decisions.
Two Actions with the Highest Impact for UK Law Firms
**Enforce MFA on Microsoft 365 or Google Workspace for every user, including partners.** Fee earner email account compromise is the root cause of most conveyancing fraud and BEC attacks against UK law firms. MFA on email accounts eliminates the vast majority of this risk. The rollout is free, takes an afternoon to configure in the admin console, and requires no external vendor.
**Implement DMARC enforcement on your domain.** Check your domain's DMARC record at mxtoolbox.com/dmarc. If there is no record, or if the policy is set to `p=none` (monitoring only), your domain can be spoofed. Moving to `p=quarantine` or `p=reject` prevents attackers sending emails that appear to come from your firm's domain. Your IT provider or email administrator can configure this; it is a DNS change, not a system deployment.
Yrzo AI's automated scan covers the client-facing components of your firm's digital infrastructure — website vulnerabilities, authentication weaknesses, email header configuration, and security policy implementation. From £99, under 20 minutes, at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →