Legal sector briefing

The technology problems that actually bite small law firms

A plain-English briefing on where IT goes wrong in a small practice, what it costs when it does, and what the fix usually looks like. Written for sole practitioners and firms of a few fee earners — the ones without an IT department.

Written for firms without an IT department
Every figure sourced and linked
Downloadable as a PDF

Most writing about legal-sector IT is aimed at firms with an IT director and a hundred fee earners. That is not much use if there are four of you, the case management system runs on a box in the back office, and IT is whoever is least busy on the day.

So this is the small-firm version. Nine problems I keep finding, why each one lands harder in a law firm than it would in any other business of the same size, and what a sensible fix looks like. No products, no scare stories, and every figure attributed so you can check it.

The briefing

Nine problems, and what each one really costs.

Problem 1 of 9

The completion-day transfer that goes to the wrong account

A conveyancing matter is days from completion. The client gets an email that looks exactly like the last twelve — same signature, same matter reference, same turn of phrase — saying the client account details have changed. They send the money. Nobody notices until the other side asks where it is.

Other businesses lose their own money. A law firm loses client money, and that is a different order of problem: an Accounts Rules failure, a report to the SRA, a claim on the PII policy, and a client whose purchase has just collapsed. The attacker often does not need to break into your systems at all. They are frequently sitting in the estate agent’s mailbox, or the buyer’s personal webmail, reading a chain you are only one participant in.

£11.7m

lost to conveyancing fraud in a year, across 143 reports to Action Fraud — an average of roughly £78,000 a case

City of London Police / Action Fraud — conveyancing and payment diversion fraud figures, April 2024 to March 2025
What good looks like
  • Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
  • Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
  • External-sender warnings, and impersonation protection tuned to your own partner and fee-earner names
  • SPF, DKIM and DMARC set to reject, so that someone else cannot send email as your domain
  • A written rule that bank details are confirmed by phone, on a number you already held — never a number from the email
Problem 2 of 9

The matter file is really just somebody’s Outlook

Ask where a matter lives and the honest answer is: some in the case management system, some in a folder on the server, and the parts that actually matter in an email thread in one fee earner’s inbox. When they are on holiday nobody else can pick it up. When they leave, it leaves with them.

Two obligations collide here. You have to be able to produce the file — for a subject access request, a complaint to the Legal Ombudsman, a costs assessment, or a negligence claim brought years later. And you have to keep it for a very long time: six years as a working minimum, commonly fifteen or more for property, and wills and deeds effectively for a lifetime. Microsoft 365 will not do that on its own. Deleted items empty after 30 days by default, and a deleted mailbox is gone in 30. A retention obligation measured in decades, sitting on a default measured in days, is not a policy — it is a gap nobody has looked at.

What good looks like
  • Matter-based filing people will actually use, because it sits where they already work rather than somewhere they have to remember to go
  • Retention labels that reflect your own retention schedule, applied automatically instead of by good intentions
  • Leavers’ mailboxes preserved and searchable rather than deleted to save a licence
  • The ability to answer “produce everything on matter 4471” without it depending on one person’s memory
Problem 3 of 9

Backups you have never actually restored

There is a backup. It runs overnight and emails a report. Nobody has read the report in a year, and nobody has ever restored anything from it.

The SRA’s own thematic review visited 40 firms. All of them backed something up — and 15 of them kept their disaster recovery plan on the very systems the plan existed to recover. The other gap people miss: Microsoft does not back up your Microsoft 365. Microsoft keeps the service running; keeping your data is your side of the bargain. If an intruder deletes a SharePoint library, or a leaver empties a mailbox, then past the retention window it is simply gone.

15 of 40

firms in the SRA’s cyber thematic review kept their disaster recovery plan on the same systems it was meant to recover

Solicitors Regulation Authority — Cyber Security: a thematic review (40 firms visited)
What good looks like
  • A separate backup of Microsoft 365 — mail, OneDrive, SharePoint and Teams — held outside the tenant it protects
  • A restore genuinely performed at least once, by someone who wrote down how long it took
  • A recovery plan that lives somewhere other than the thing that has just failed
Problem 4 of 9

Court deadlines do not move because your IT is down

The case management system is unavailable on the morning a bundle is due.

Most businesses that lose a day lose a day’s turnover. A firm that loses a day can lose a limitation date, miss a filing deadline or blow a court direction — and at that point it has stopped being an IT incident and become a negligence claim. It is also worth knowing that the standard ransomware playbook is to encrypt on a Friday evening, when nobody is watching. For a conveyancing practice, that is the worst hour of the week by some distance.

What good looks like
  • Working from cloud services, so that any device in any location gets you back to work
  • A spare, pre-built machine that can be in someone’s hands the same day rather than the same fortnight
  • Knowing in advance who you ring, what comes back first, and roughly how long it takes
  • Enough separation between systems that one compromised laptop is not the whole practice
Problem 5 of 9

The AI tab that is already open

A paralegal has a witness statement to summarise and forty minutes to do it in. There is a free tool one click away that will do it in thirty seconds.

The SRA has not banned AI and there is no good reason it should. But the solicitor stays responsible for the work, confidentiality still applies, and the moment client-identifiable material goes into a consumer service you have engaged a third-party processor with no data processing agreement and no idea what happens to the text afterwards. The realistic risk is not a dramatic leak. It is that when a client or your PII insurer asks whether client data has been put into AI tools, nobody in the firm can answer.

What good looks like
  • Give people a sanctioned tool inside your own tenant, so that the convenient option is also the compliant one
  • A short, readable AI policy saying what may and may not go in — one page, not twelve
  • Visibility of which AI services staff are signing into with work accounts
  • Being clear with clients about where AI is used, which is what the SRA expects
Problem 6 of 9

The compliance requirements are stacking up, and they have gone technical

Cyber Essentials for the legal aid contract. An information management section for Lexcel. A lender’s panel questionnaire. And now the PII renewal is asking whether you have MFA.

These used to be paperwork exercises a COLP could absorb. They are now technical assertions that somebody has to be able to evidence — and increasingly they are pass/fail rather than best endeavours. Four dates worth having in view:

  • Since 1 October 2025, holding a criminal legal aid contract requires a valid Cyber Essentials certificate.
  • From 26 April 2026, Cyber Essentials v3.3 makes missing MFA on cloud services an automatic fail — as is failing to apply critical and high-risk updates within 14 days.
  • Lexcel or SQM remains a condition of LAA work, and information management is one of the assessed sections.
  • PI insurers increasingly ask cyber questions at renewal, and the answers affect the terms you are offered.
What good looks like
  • Treat the controls as something that runs all year, rather than a fortnight of panic before the audit
  • Collect the evidence continuously, so the questionnaire becomes an export rather than an investigation
  • Get the gap review done early enough that falling short is private, cheap and fixable
Problem 7 of 9

The server under the desk that runs the case management system

There is a box in the corner of the back office. It runs the practice management system, it holds the shared drives, and it has been there since before the current partner joined.

It is the single point of failure for the entire practice, it sits in the same building as any fire, flood or burglary, and if the operating system has gone out of support it will fail Cyber Essentials on its own account. It is also precisely where ransomware wants to land, because every workstation in the office has a drive mapped to it.

What good looks like
  • Honestly: most small firms should not have one any more, and the case management vendor almost certainly offers a hosted option
  • If it stays — a supported operating system, patched on a schedule, backed up off-site, and not reachable from the internet
  • Either way, a decision made deliberately rather than arrived at by drift
Problem 8 of 9

Everyone is an administrator, and the password is on a note

Four people, one shared login for the portal everybody needs, and the secretary knows the partner’s password because otherwise nothing would get done on a Friday.

You lose attribution. When something goes wrong — a file altered, a payment authorised, a document sent to the wrong party — you cannot say who did it, and in a regulated practice that is precisely the answer you most need to have. Shared accounts also cannot be properly protected with MFA, and they are never removed when someone leaves. Cyber Essentials fails you on this, and it is right to.

What good looks like
  • Named accounts for every person on every service, with no exceptions for convenience
  • Everyday accounts that are not administrators, and separate admin accounts used only for admin work
  • A password manager, so that “it has to be memorable” stops being an argument
  • A leaver checklist that actually runs on the day they leave, not the month after
Problem 9 of 9

Your supply chain is other small firms

The costs draftsman. The outsourced cashier. The typing service. The agent covering the hearing. Chambers. The estate agent on the other side of the transaction.

Confidential material moves between all of them constantly, mostly by email, and their security is not something you control. The NCSC lists supply chain compromise among the principal threats to the legal sector for exactly this reason: an attacker does not need to get into your firm if they can get into a smaller supplier that emails you every day. And a property transaction email chain routinely includes people whose mailboxes you have no visibility of whatsoever.

What good looks like
  • Know who holds your client data and on what basis — a short list, kept current, is enough
  • Data processing agreements where they belong, and a straight question about MFA and backups where they do not
  • Secure file transfer for anything sensitive, instead of attachments and hope
  • The out-of-band verification habit again, because it remains the only thing that reliably beats a convincing email
Where to start

Seven questions worth asking on Monday morning

You do not need a consultant to work through these. If the answer to any of them is “I am not sure”, that is where I would start.

  1. 1Is MFA on every single account — and is legacy authentication actually blocked, or just discouraged?
  2. 2Are there mailbox forwarding rules that nobody in the firm put there?
  3. 3Is your DMARC record set to reject, or is it sitting on “none” and doing nothing?
  4. 4Has anyone ever restored a file from your Microsoft 365 backup — and is there one at all?
  5. 5Where does a matter file actually live, and could a colleague find all of it tomorrow?
  6. 6What is the oldest unsupported thing still switched on and connected?
  7. 7If the office were unavailable on Monday, what happens to Monday’s deadlines?

Which of these actually apply to you?

None of this needs a large project. Most of it is configuration that should have been set correctly on day one, plus a couple of habits that have to be agreed rather than bought.

If you would like a second opinion, I will spend half an hour on your setup and tell you which of these actually apply to you. Not a report full of red traffic lights designed to sell you something — just a straight answer about where you stand.

Get in touch

Half an hour, and a straight answer.

Tell me roughly how many of you there are, what your case management system is, and which of the nine above made you wince. I’ll come back within one working day. I work with small businesses across Lancashire and the North West, and I am the person you will actually speak to.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.