iso27001partnersUK certification, costed Get a cost estimate

Law firm cyber security: what the SRA requires and what its review found

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 2 October 2026
By the iso27001partners.co.uk editorial team · Published 2 October 2026 · Last reviewed 2 October 2026 · 8 min read
5 primary sources cited on this page. How we check what is on this site
SRA Code of Conduct for Firms, 6.3 Client confidentiality

“You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.”

The SRA does not prescribe a cyber security standard for law firms. What it does is set duties — systems and controls, confidentiality, reporting — that a firm cannot meet for digital information without one. This page quotes those duties, sets out what the SRA found when it looked at firms that had been targeted, and shows where Cyber Essentials and ISO 27001 come in.

The Code of Conduct for Firms

SRA Code of Conduct for Firms: the paragraphs behind cyber security (verbatim)
ParaSubjectText
2.1Systems and controls“You have effective governance structures, arrangements, systems and controls in place that ensure:” (compliance with the SRA's and other regulatory and legislative requirements, among others)
3.9Reporting serious breaches“You report promptly to the SRA, or another approved regulator, as appropriate, any facts or matters that you reasonably believe are capable of amounting to a serious breach of their regulatory arrangements by any person regulated by them (including you) of which you are aware.”
3.10Informing the SRA“Notwithstanding paragraph 3.9, you inform the SRA promptly of any facts or matters that you reasonably believe should be brought to its attention in order that it may investigate whether a serious breach of its regulatory arrangements has occurred or otherwise exercise its regulatory powers.”
6.3Confidentiality“You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.”

Systems and controls

Paragraph 2.1 is the one an information security management system speaks to: governance, arrangements, systems and controls that ensure compliance. A firm that can show how it decides on, operates and checks its controls has evidence for 2.1; one that cannot has only its policies.

Confidentiality

Paragraph 6.3 applies whatever the medium, so it covers client information held in email, document systems and cloud services as much as on paper. Paragraph 6.5 adds rules on confidential information when acting against a former client.

Reporting

Paragraphs 3.9 and 3.10 require prompt reports to the SRA of facts that may amount to a serious breach. A cyber incident affecting client money or confidentiality can be one; the decision belongs in the firm's incident process. Personal data breaches also have UK GDPR reporting rules, which are separate.

What the SRA found: the 2020 thematic review

The SRA published “Cyber Security — A thematic review” on 2 September 2020. It looked at firms that had reported being targeted, so its figures describe that sample, not the whole profession:

SRA, Cyber Security — A thematic review (2020): findings (verbatim)
Finding
SampleDuring 2019, we visited 40 firms across England and Wales.
TargetedThree quarters (30) of the firms we visited reported that they had been the target of a cyberattack.
Losses23 of the 30 cases in which firms were directly targeted saw a total of more than £4m of client money stolen.
TrainingEight firms (20%) we visited had never provided specific cybersecurity training to their staff.
Audit“23 firms had never had their IT policies and/or processes audited”
Reporting“73% of firms (29) had reported incidents to us”; “seven significant incidents were not reported, despite clear and significant breaches”
Cyber Essentials PlusWe found that firms with Cyber Essentials Plus accreditation were more likely to have good policies and procedures in place and have taken effective steps to protect themselves from future cyber security incidents.

Read it with its date

The visits were in 2019. The review is the SRA's most detailed published look at law firm cyber security we could read; it is not a current measure.

The audit finding

“23 firms had never had their IT policies and/or processes audited” is the finding most directly answered by a management system, which audits its own controls every year. See internal audit.

Firms with the 2025 Standard Crime Contract must hold Cyber Essentials or an equivalent the LAA agrees, and the LAA's guidance names whole-firm, UKAS-accredited ISO 27001 as highly likely to count. Detail on legal aid and Cyber Essentials.

Where ISO 27001 and Cyber Essentials fit (our reading)

SRA duties and review findings, and the ISO/IEC 27001 / 27002 elements that address them (our reading)
SRA duty or findingISO element
Code 2.1: effective systems and controlsA management system with documented controls, internal audit and management review (ISO/IEC 27001 clauses 6 to 10)
Code 6.3: client confidentialityAccess control, classification and supplier controls selected in the Statement of Applicability
Code 3.9/3.10: reportingAn incident management process that includes the regulatory decision to report
Review finding: IT never auditedISO/IEC 27001 clause 9.2 internal audit, every year
Review finding: no specific trainingISO/IEC 27001 clause 7.3 awareness; ISO/IEC 27002 control 6.3

Cyber Essentials

Five technical controls, certified annually. It is what the legal aid contract names and the scheme the SRA's review associated with better practice. See ISO 27001 vs Cyber Essentials.

ISO 27001

A management system that covers people, process and technology and is audited externally every year. It is heavier, and it answers paragraph 2.1 directly. Whether it is worth it depends on who is asking for it.

Three questions for the partners

Who would we report a cyber incident to, and who decides? When were our IT controls last checked by someone independent? Does any client, panel or contract ask us for Cyber Essentials or ISO 27001?

We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The SRA texts are quoted from sra.org.uk; the ISO mapping is our reading.

Where this fits

Common questions

What does the SRA require on cyber security?

The Code of Conduct for Firms does not name a cyber security standard. It requires effective systems and controls (2.1), client confidentiality (“You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.”, 6.3) and prompt reporting of serious breaches (3.9, 3.10). Cyber security is how a firm meets those duties for digital information.

Does the SRA require Cyber Essentials or ISO 27001?

Not in the Code of Conduct for Firms. Its 2020 thematic review noted: “We found that firms with Cyber Essentials Plus accreditation were more likely to have good policies and procedures in place and have taken effective steps to protect themselves from future cyber security incidents.” Legal aid firms are a different case: the LAA's crime contract requires Cyber Essentials or an agreed equivalent.

Should a law firm report a cyber attack to the SRA?

If it amounts to, or may amount to, a serious breach of the SRA's regulatory arrangements, paragraphs 3.9 and 3.10 require prompt reporting. The 2020 review found “seven significant incidents were not reported, despite clear and significant breaches”. Personal data breaches have separate reporting rules under UK GDPR.

How common are cyber attacks on law firms?

The SRA's 2020 review, of firms that had reported being targeted: “Three quarters (30) of the firms we visited reported that they had been the target of a cyberattack.” It is a sample of firms that had already reported incidents, and it is from 2019 visits, so it is not a prevalence figure for the profession.

Is ISO 27001 worth it for a law firm?

It depends on who is asking for it. The SRA does not; the LAA treats a whole-firm, UKAS-accredited certificate as a likely equivalent to Cyber Essentials; clients and other contracts may. Our reading.

Sources cited on this page

  1. SRA, Code of Conduct for Firms
  2. SRA, Cyber Security — A thematic review (published 2 September 2020)
  3. Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
  4. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  5. ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

A law firm looking at Cyber Essentials or ISO 27001?

Say your size, whether you do legal aid, and who is asking for it.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now