info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Law Firm Business Outcome

    Strengthening Cyber Security and Recovery in a Law Firm

    Cyber resilience is broader than prevention. Law firms need the ability to prevent, detect, respond to and recover from cyber incidents — while protecting confidential client information and maintaining business continuity.

    The two-minute answer

    How should a law firm strengthen cyber security? By building coordinated controls across identity, devices, Microsoft 365, email, information, backup and recovery, incident response, staff awareness and governance — and by recognising that prevention alone is not enough.

    A practical approach covers multi-factor authentication, least-privilege access, privileged account management, endpoint protection, regular patching, Microsoft 365 security configuration, email security, information protection, verified backup and recovery, and a documented, exercised incident response plan.

    The objective is not simply to install security tools. It is to create a resilient organisation that can prevent incidents where possible, detect them quickly when they occur, respond effectively, recover information and operations, and continuously improve.

    Cyber resilience is broader than cyber prevention

    No security control can guarantee that every incident will be prevented. Law firms need the ability to detect incidents, respond quickly, recover information and operations, and learn from every event.

    Prevent

    Reduce the likelihood of incidents through strong controls.

    Detect

    Identify incidents quickly through monitoring and alerting.

    Respond

    Contain and manage incidents with a documented plan.

    Recover

    Restore information and operations to normal.

    Improve

    Learn from every incident and strengthen controls.

    Identity Attack Surface

    Cyber attacks against law firms often begin with identity. Understanding where your attack surface lies is the first step toward reducing it.

    Identity
    User Accounts
    Admin Accounts
    Email
    Remote Access
    Guest Users
    Shared Accounts
    Legacy Auth
    Third-Party Apps

    Identity and MFA

    Modern security starts with identity. If an attacker can access a user account, they can often access everything that user can access — including matter information, client correspondence and practice systems.

    Multi-factor authentication

    Enforce MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.

    Conditional access

    Use conditional access policies where appropriate to restrict access based on location, device, risk and context.

    User lifecycle

    Manage joiners, movers and leavers promptly. Dormant accounts create unnecessary access risk.

    Legacy authentication

    Block legacy authentication protocols that bypass MFA requirements.

    Shared accounts

    Avoid shared accounts where practical. Each user should have a uniquely identifiable account.

    Role changes

    Review and adjust access when staff change roles or leave the firm.

    Privileged access

    Administrative accounts represent the highest-risk identities in any environment. If compromised, they can provide broad access across systems, information and configuration.

    Separate admin accounts

    Administrators should use separate accounts for daily tasks and administrative functions.

    Least privilege

    Grant administrative access only to the specific systems and functions required.

    Regular reviews

    Review privileged access regularly and remove unnecessary elevation.

    MFA on admin accounts

    All administrative accounts must be protected with multi-factor authentication.

    Audit logging

    Ensure administrative actions are logged and reviewable.

    No shared admin

    Each administrator should have a uniquely identifiable account for accountability.

    Endpoint and device security

    Lawyers work from offices, homes, courts and client sites. Endpoint security must protect devices wherever they are used.

    Supported operating systems

    Ensure all devices run supported, currently patched operating systems.

    Endpoint protection

    Deploy modern endpoint protection across all firm devices.

    Encryption

    Enable device encryption where appropriate to protect information if a device is lost or stolen.

    Device management

    Use mobile device management or endpoint management to enforce security policies remotely.

    Security updates

    Apply security updates promptly across operating systems and applications.

    Screen lock

    Enforce automatic screen lock and require authentication to unlock.

    Patching and supported technology

    Unpatched and unsupported technology creates unnecessary vulnerability. The Australian Cyber Security Centre recommends patching applications and operating systems promptly and replacing unsupported technology.

    Operating system patching

    Apply OS security updates promptly across all devices.

    Application patching

    Patch third-party applications including browsers, PDF readers and productivity tools.

    Network device updates

    Update firmware on network devices including firewalls, routers and switches.

    Cloud configuration

    Review and update cloud platform security configurations as platforms evolve.

    Unsupported technology

    Replace unsupported operating systems and applications that no longer receive security updates.

    Visibility

    Maintain visibility of what devices and applications exist in the environment.

    Email and business email compromise

    Business email compromise is one of the most significant threats facing law firms. Criminals impersonate trusted parties — partners, clients, banks or conveyancers — to deceive staff into making payments, changing banking details or disclosing sensitive information. Law firms are particularly vulnerable because they handle trust accounts, settlements and client financial instructions.

    Email filtering

    Deploy email filtering, anti-phishing policies and spam protection.

    Verification processes

    Implement verification processes for changes to payment details, banking information and client instructions.

    Staff awareness

    Train staff to identify phishing and business email compromise attempts.

    DMARC/DKIM/SPF

    Configure email authentication to reduce spoofing and impersonation risk.

    Sensitive information

    Avoid emailing sensitive attachments where secure sharing alternatives exist.

    Monitoring

    Monitor for suspicious email activity including unusual forwarding rules.

    Microsoft 365 security

    Microsoft's official documentation details a wide range of security capabilities across Microsoft 365. Not all features are available in every licence — firms should confirm which capabilities are included in their subscription.

    Conditional Access

    Restrict access based on device, location, risk and user context.

    Microsoft Defender

    Deploy Defender for Office 365, Endpoint and Cloud Apps where licensed.

    Information protection

    Use sensitivity labels and data loss prevention where available.

    Audit and logging

    Enable audit logging and review privileged activity regularly.

    External sharing

    Configure external sharing defaults to reduce oversharing risk.

    Administrative roles

    Review and restrict administrative roles using least-privilege principles.

    Learn how LOOKUP helps law firms secure Microsoft 365 →

    Backup and recovery

    A backup strategy is incomplete until recovery has been tested appropriately. Backup exists does not mean recovery is verified. Law firms should be able to demonstrate that business-critical information can be recovered within their recovery objectives.

    Critical information

    Identify which information is business-critical and ensure it is included in backup planning.

    Restore testing

    Test recovery regularly. An untested backup is an assumption, not a capability.

    Separation

    Ensure appropriate separation between production and backup environments.

    Responsibilities

    Clarify responsibilities between cloud platforms and the organisation.

    SaaS considerations

    Assess whether Microsoft 365 and other SaaS platforms meet your recovery objectives.

    Recovery planning

    Document recovery objectives, priorities and procedures.

    Recovery Readiness Model

    Recovery readiness is a capability, not a checkbox. It requires planning, testing and continuous improvement.

    Identify

    What information is business-critical?

    Protect

    Ensure appropriate backup and separation.

    Test

    Verify recovery works in practice.

    Improve

    Review and strengthen after every test.

    Incident response

    An incident response plan helps a firm respond quickly and reduce the impact of a security incident. The plan should be documented, accessible and exercised regularly — not just filed away.

    Detection

    How will the firm detect an incident? What monitoring and alerting is in place?

    Escalation

    Who is notified, in what order, and how quickly?

    Containment

    What immediate steps contain the incident and prevent further damage?

    Technical response

    Who provides technical response — internal IT, MSP or specialist responders?

    Communication

    Who manages internal, client and external communications?

    Legal and professional advice

    Who provides legal, professional and regulatory advice? Notification obligations may apply.

    Recovery

    How does the firm restore systems and information to normal operations?

    Lessons learned

    Review every incident to identify improvements. Update the plan accordingly.

    Minimum Cybersecurity Expectations and jurisdiction

    The Victorian Legal Services Board + Commissioner has published Minimum Cybersecurity Expectations for law practices operating in Victoria. These expectations address areas such as multi-factor authentication, access controls, patching, backups and incident response.

    These are Victorian guidance and should not be generalised as universal Australia-wide legal requirements. Law firms in other jurisdictions should confirm which professional obligations apply to them through their relevant law society or regulatory body. The Law Society of New South Wales, Queensland Law Society, Law Society of South Australia and ACT Law Society each provide guidance relevant to their respective jurisdictions.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations in their jurisdiction.

    The Essential Eight

    The Australian Cyber Security Centre's Essential Eight is a recommended baseline of mitigation strategies designed to reduce cyber risk. It is not universally mandatory by statute for private law firms, but LOOKUP recommends it as an effective operational baseline for firms handling confidential client information.

    Application control
    Patch applications
    Configure Microsoft Office macro settings
    User application hardening
    Restrict administrative privileges
    Patch operating systems
    Multi-factor authentication
    Regular backups

    Learn how LOOKUP implements the Essential Eight →

    Cyber insurance as part of risk management

    Cyber insurance may form part of a law firm's broader risk management strategy, but it does not replace cyber security. Insurance may transfer some financial risk, but it does not prevent incidents or reduce operational risk.

    Insurance requirements, coverage and underwriting decisions vary by insurer, policy and organisation. Firms should confirm requirements with their insurer or broker and seek professional advice regarding their specific circumstances.

    Explore LOOKUP's Cyber Insurance Readiness Guide →

    How this maps to the LOOKUP Business Modernisation Framework™

    Strengthening cyber security and recovery follows the same structured approach as every LOOKUP engagement.

    Discover

    Map where confidential information lives, what controls exist and where gaps remain.

    Secure

    Strengthen identity, MFA, access controls, endpoint security and recovery capability.

    Modernise

    Replace unsupported technology and address legacy systems that create security risk.

    Standardise

    Create consistent security policies, permissions and governance practices.

    Optimise

    Improve Microsoft 365 configuration, email security and monitoring.

    Prepare

    Establish incident response plans, staff awareness and governance for future technology.

    Implement

    Deploy security controls, monitoring and recovery capabilities deliberately.

    Improve

    Review controls, test recovery, exercise incident response and continuously improve.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    What success looks like

    Strong cyber security and recovery create qualitative business outcomes — not just technical compliance.

    Better visibility

    Leadership understands what controls exist and where gaps remain.

    Stronger identity

    MFA, conditional access and least privilege reduce unauthorised access risk.

    Reduced unnecessary privilege

    Administrative access is restricted, reviewed and justified.

    Verified recovery

    Backup and recovery is tested, documented and aligned to business objectives.

    Clear incident responsibilities

    Everyone knows their role during an incident.

    Improved cyber resilience

    The firm can prevent, detect, respond to and recover from incidents.

    Research and professional guidance

    The Law Society of New South Wales provides guidance to solicitors on professional obligations, technology and cyber security. The Law Council of Australia maintains policy resources addressing AI and the legal profession.

    The Victorian Legal Services Board + Commissioner has published Minimum Cybersecurity Expectations (Victorian guidance, not a nationwide requirement). Lawcover provides professional indemnity insurance and risk management guidance for NSW law practices.

    The Australian Cyber Security Centre provides the Essential Eight as a recommended baseline for reducing cyber risk. The Office of the Australian Information Commissioner oversees the Privacy Act and the Notifiable Data Breaches scheme.

    See how information protection connects to cyber security for law firms →

    Illustrative business outcome

    Illustrative Scenario

    This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges law firms may encounter and demonstrates how a structured technology approach could be applied.

    Business challenge

    A growing law firm has inconsistent MFA coverage, admin accounts that have accumulated over years, untested backups, no documented incident response plan, and no clear security ownership. The firm is approaching a cyber insurance renewal and needs to demonstrate stronger controls.

    Structured approach

    Discover the current environment. Secure identity and enforce MFA. Review and reduce privileged access. Test backup recovery. Document and exercise incident response. Standardise security policies. Establish clear ownership. Improve continuously.

    Potential business outcomes

    • • Better understanding of current security controls and gaps
    • • Reduced unnecessary access and stronger identity security
    • • Verified recovery capability through tested restore procedures
    • • Clearer incident response responsibilities and documentation
    • • Better prepared insurer and broker discussions
    • • Stronger ongoing cyber governance and resilience

    Frequently asked questions

    Why are law firms targeted by cyber criminals?

    Law firms hold confidential client information, matter details, financial records, identity documents and commercially sensitive material. This makes them attractive targets for ransomware, business email compromise and data theft. The Australian Cyber Security Centre consistently identifies professional services firms as targets in its annual threat reports.

    What cyber security controls should law firms use?

    Priority controls include multi-factor authentication, conditional access, least-privilege access, endpoint protection, regular patching, email security filtering, controlled external sharing, verified backup and recovery, and a documented incident response plan. The ACSC Essential Eight provides a useful baseline for reducing cyber risk.

    Do law firms need MFA?

    Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. Administrative accounts, remote access and cloud services should all be covered.

    What is the Essential Eight?

    The Essential Eight is a set of eight mitigation strategies published by the Australian Cyber Security Centre designed to reduce cyber risk. The strategies cover application control, patching, Microsoft Office macro settings, user application hardening, restricting administrative privileges, operating system patching, multi-factor authentication and regular backups.

    Do law firms have to comply with the Essential Eight?

    The Essential Eight is not universally mandatory by statute for private law firms. It is ACSC-recommended guidance for reducing cyber risk. LOOKUP recommends the Essential Eight as an effective operational baseline for law firms handling confidential client information, but it should not be confused with a universal legal obligation.

    What are Victoria's Minimum Cybersecurity Expectations?

    The Victorian Legal Services Board + Commissioner has published Minimum Cybersecurity Expectations for law practices operating in Victoria. These expectations address areas such as MFA, access controls, patching, backups and incident response. They are Victorian guidance and should not be generalised as universal Australia-wide legal requirements.

    Do those expectations apply to every Australian law firm?

    No. The Victorian Minimum Cybersecurity Expectations apply to legal practices regulated in Victoria. Law firms in other jurisdictions should confirm which professional obligations, conduct rules and regulatory guidance apply to them through their relevant law society or regulatory body.

    Should Microsoft 365 be secured differently for law firms?

    Microsoft 365 security configuration should reflect the firm's risk profile, information sensitivity and professional obligations. Law firms should pay particular attention to conditional access, external sharing defaults, SharePoint and Teams permissions, administrative roles, sensitivity labels and audit logging. The underlying security capabilities are the same, but the configuration should be tailored to legal practice requirements.

    Do law firms need backups?

    Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.

    What is recovery testing?

    Recovery testing is the process of verifying that information can actually be restored from backup within the firm's recovery objectives. An untested backup is an assumption, not a capability. Regular restore testing helps confirm that recovery will work when it is genuinely needed.

    What is business email compromise?

    Business email compromise is a type of cyber attack where criminals impersonate a trusted party — such as a partner, client or supplier — to deceive staff into making payments, changing banking details or disclosing sensitive information. Law firms are particularly vulnerable because they handle trust accounts, settlements and client financial instructions.

    How should law firms manage admin accounts?

    Administrative accounts should be restricted to authorised personnel, separated from daily-use accounts, protected with MFA and reviewed regularly. Shared admin accounts should be avoided where practical. Privileged access should follow least-privilege principles — administrators should have only the access they need to perform their role.

    What should a law firm incident response plan include?

    An incident response plan should cover detection, escalation, containment, technical response, communication, legal and professional advice, recovery, and lessons learned. It should identify who makes decisions, who contacts the insurer or broker, who manages client communications, and where the plan is stored. The plan should be exercised regularly, not just filed.

    Does cyber insurance replace cyber security?

    No. Cyber insurance may transfer some financial risk, but it does not prevent incidents or reduce operational risk. Strong cyber security supports business continuity, client confidence and resilience regardless of insurance outcomes. Insurance requirements also vary by insurer and policy — firms should confirm requirements with their insurer or broker.

    Where should a law firm start?

    Start by understanding where confidential information lives, who has access to it, and how it is shared. Then review MFA coverage, privileged accounts, Microsoft 365 sharing settings, endpoint security, patching and backup recovery. Prioritise the highest-risk gaps first and build a practical improvement roadmap.

    What business leaders should do next

    1.Map where confidential information resides and who has access.
    2.Review MFA coverage across all user and administrative accounts.
    3.Review privileged access and remove unnecessary elevation.
    4.Review patching and replace unsupported technology.
    5.Assess backup and recovery — and test it.
    6.Review Microsoft 365 security configuration and external sharing.
    7.Review email security and phishing protection.
    8.Document and exercise an incident response plan.
    9.Review cyber insurance requirements with your insurer or broker.
    10.Create a cyber security improvement roadmap. For a structured approach, see our guide on building a technology roadmap for a law firm.

    How LOOKUP can help

    LOOKUP helps law firms strengthen cyber security, improve Microsoft 365 governance, verify recovery capability and build incident readiness — through practical, business-first technology leadership.

    Sources & Further Reading

    Australian Cyber Security Centre

    Essential Eight Explained

    Recommended baseline of mitigation strategies for reducing cyber risk.

    View Source

    Victorian Legal Services Board + Commissioner

    Minimum Cybersecurity Expectations

    Victorian guidance on cybersecurity expectations for legal practices — applicable to Victoria, not universal nationally.

    View Source

    Law Society of New South Wales

    Professional obligations and technology guidance

    NSW solicitor guidance on professional conduct, technology and cyber security.

    View Source

    Lawcover

    Professional indemnity insurance and risk management

    NSW professional indemnity insurance provider with risk management guidance for law practices.

    View Source

    Law Council of Australia

    AI and the legal profession

    National policy resources addressing AI adoption and professional obligations.

    View Source

    Office of the Australian Information Commissioner

    Notifiable Data Breaches Scheme

    Guidance on privacy obligations and eligible data breach notification.

    View Source

    Microsoft

    Microsoft 365 Security Documentation

    Official documentation on Microsoft 365 security, compliance and information protection capabilities.

    View Source

    Evidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice. Law firms should obtain appropriate professional advice regarding their specific obligations in their jurisdiction.

    Stronger Cyber Security Starts with Better Governance

    LOOKUP helps law firms strengthen cyber security, verify recovery capability, improve Microsoft 365 governance and build incident readiness through practical, business-first technology leadership.

    Avatar
    Hi there! Have a question? Chat with us here.