Following its first report into the UK legal sector, the National Cyber Security Centre (NCSC) – part of GCHQ – has issued cyber security advice specifically for law firms.

Having worked closely with legal firms for more than 15 years, I wasn’t surprised to hear that lawyers are being targeted. The report found that in the last year, 60% of law firms had reported an information security incident. This is an increase of more than 20% on the previous year.

We would estimate that figures of unreported or unidentified incidents, will in fact be higher and the volumes of attacks are only set to rise.

It is well known that the most prolific threats tend to be posed through phishing, ransomware and client or supplier chain compromises.
However, these are not solely IT issues and we would advise firms (both inside and outside of the legal sector) to put in place a wider risk management system that covers much more than IT.

Naturally the NCSC advises law firms to put in place some basic protection before it’s too late. TecSec is a Certification Body for Cyber Essentials and IASME with GDPR – both of which are cyber security standards recommended by the UK government. We can help companies to integrate the basics, through to full certification.

Please don’t take the risk, contact us now to discuss how we can protect every part of your business: 0114 223 8000, or email us at riskmanagement@tecsec.co.uk