Law firm cyber security: what the SRA requires and what its review found
“You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.”
The SRA does not prescribe a cyber security standard for law firms. What it does is set duties — systems and controls, confidentiality, reporting — that a firm cannot meet for digital information without one. This page quotes those duties, sets out what the SRA found when it looked at firms that had been targeted, and shows where Cyber Essentials and ISO 27001 come in.
The Code of Conduct for Firms
| Para | Subject | Text |
|---|---|---|
| 2.1 | Systems and controls | “You have effective governance structures, arrangements, systems and controls in place that ensure:” (compliance with the SRA's and other regulatory and legislative requirements, among others) |
| 3.9 | Reporting serious breaches | “You report promptly to the SRA, or another approved regulator, as appropriate, any facts or matters that you reasonably believe are capable of amounting to a serious breach of their regulatory arrangements by any person regulated by them (including you) of which you are aware.” |
| 3.10 | Informing the SRA | “Notwithstanding paragraph 3.9, you inform the SRA promptly of any facts or matters that you reasonably believe should be brought to its attention in order that it may investigate whether a serious breach of its regulatory arrangements has occurred or otherwise exercise its regulatory powers.” |
| 6.3 | Confidentiality | “You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.” |
Systems and controls
Paragraph 2.1 is the one an information security management system speaks to: governance, arrangements, systems and controls that ensure compliance. A firm that can show how it decides on, operates and checks its controls has evidence for 2.1; one that cannot has only its policies.
Confidentiality
Paragraph 6.3 applies whatever the medium, so it covers client information held in email, document systems and cloud services as much as on paper. Paragraph 6.5 adds rules on confidential information when acting against a former client.
Reporting
Paragraphs 3.9 and 3.10 require prompt reports to the SRA of facts that may amount to a serious breach. A cyber incident affecting client money or confidentiality can be one; the decision belongs in the firm's incident process. Personal data breaches also have UK GDPR reporting rules, which are separate.
What the SRA found: the 2020 thematic review
The SRA published “Cyber Security — A thematic review” on 2 September 2020. It looked at firms that had reported being targeted, so its figures describe that sample, not the whole profession:
| Finding | |
|---|---|
| Sample | During 2019, we visited 40 firms across England and Wales. |
| Targeted | Three quarters (30) of the firms we visited reported that they had been the target of a cyberattack. |
| Losses | 23 of the 30 cases in which firms were directly targeted saw a total of more than £4m of client money stolen. |
| Training | Eight firms (20%) we visited had never provided specific cybersecurity training to their staff. |
| Audit | “23 firms had never had their IT policies and/or processes audited” |
| Reporting | “73% of firms (29) had reported incidents to us”; “seven significant incidents were not reported, despite clear and significant breaches” |
| Cyber Essentials Plus | We found that firms with Cyber Essentials Plus accreditation were more likely to have good policies and procedures in place and have taken effective steps to protect themselves from future cyber security incidents. |
Read it with its date
The visits were in 2019. The review is the SRA's most detailed published look at law firm cyber security we could read; it is not a current measure.
The audit finding
“23 firms had never had their IT policies and/or processes audited” is the finding most directly answered by a management system, which audits its own controls every year. See internal audit.
Legal aid: the one hard certification requirement
Firms with the 2025 Standard Crime Contract must hold Cyber Essentials or an equivalent the LAA agrees, and the LAA's guidance names whole-firm, UKAS-accredited ISO 27001 as highly likely to count. Detail on legal aid and Cyber Essentials.
Where ISO 27001 and Cyber Essentials fit (our reading)
| SRA duty or finding | ISO element |
|---|---|
| Code 2.1: effective systems and controls | A management system with documented controls, internal audit and management review (ISO/IEC 27001 clauses 6 to 10) |
| Code 6.3: client confidentiality | Access control, classification and supplier controls selected in the Statement of Applicability |
| Code 3.9/3.10: reporting | An incident management process that includes the regulatory decision to report |
| Review finding: IT never audited | ISO/IEC 27001 clause 9.2 internal audit, every year |
| Review finding: no specific training | ISO/IEC 27001 clause 7.3 awareness; ISO/IEC 27002 control 6.3 |
Cyber Essentials
Five technical controls, certified annually. It is what the legal aid contract names and the scheme the SRA's review associated with better practice. See ISO 27001 vs Cyber Essentials.
ISO 27001
A management system that covers people, process and technology and is audited externally every year. It is heavier, and it answers paragraph 2.1 directly. Whether it is worth it depends on who is asking for it.
Three questions for the partners
Who would we report a cyber incident to, and who decides? When were our IT controls last checked by someone independent? Does any client, panel or contract ask us for Cyber Essentials or ISO 27001?
We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The SRA texts are quoted from sra.org.uk; the ISO mapping is our reading.
Where this fits
Common questions
What does the SRA require on cyber security?
The Code of Conduct for Firms does not name a cyber security standard. It requires effective systems and controls (2.1), client confidentiality (“You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.”, 6.3) and prompt reporting of serious breaches (3.9, 3.10). Cyber security is how a firm meets those duties for digital information.
Does the SRA require Cyber Essentials or ISO 27001?
Not in the Code of Conduct for Firms. Its 2020 thematic review noted: “We found that firms with Cyber Essentials Plus accreditation were more likely to have good policies and procedures in place and have taken effective steps to protect themselves from future cyber security incidents.” Legal aid firms are a different case: the LAA's crime contract requires Cyber Essentials or an agreed equivalent.
Should a law firm report a cyber attack to the SRA?
If it amounts to, or may amount to, a serious breach of the SRA's regulatory arrangements, paragraphs 3.9 and 3.10 require prompt reporting. The 2020 review found “seven significant incidents were not reported, despite clear and significant breaches”. Personal data breaches have separate reporting rules under UK GDPR.
How common are cyber attacks on law firms?
The SRA's 2020 review, of firms that had reported being targeted: “Three quarters (30) of the firms we visited reported that they had been the target of a cyberattack.” It is a sample of firms that had already reported incidents, and it is from 2019 visits, so it is not a prevalence figure for the profession.
Is ISO 27001 worth it for a law firm?
It depends on who is asking for it. The SRA does not; the LAA treats a whole-firm, UKAS-accredited certificate as a likely equivalent to Cyber Essentials; clients and other contracts may. Our reading.
Sources cited on this page
- SRA, Code of Conduct for Firms
- SRA, Cyber Security — A thematic review (published 2 September 2020)
- Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- ISO/IEC 27002:2022, official preview (contents, foreword, introduction, clauses 1–3), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A law firm looking at Cyber Essentials or ISO 27001?
Say your size, whether you do legal aid, and who is asking for it.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.