Cyber Essentials for Law Firms

Win the work that now asks for it. For law firms, Cyber Essentials is increasingly required by corporate clients, the SRA lens and PII insurers — and we get you there without the jargon, fast.

Delivered by
Certified IASME assessor
Levels
Cyber Essentials & CE Plus
Built for
Law Firms
Coverage
UK-wide (remote)

Why law firms and chambers get certified

Law firms hold privileged, confidential client information and move client money, which makes them both a prime target and a subject of intense client scrutiny. Clients, regulatory duties and insurers increasingly expect Cyber Essentials as evidence of the basics.

  • Client security audits. Corporate clients audit their law firms' security, and Cyber Essentials, often Plus, is a common requirement to stay on panels.
  • Confidentiality duties. Protecting client confidentiality is a regulatory obligation; certification evidences the technical baseline.
  • Client money and fraud. Conveyancing and client-account fraud are rampant; the controls Cyber Essentials checks are exactly the ones attackers exploit.
  • Lexcel and PII. Cyber Essentials complements Lexcel and is increasingly expected by professional-indemnity insurers.

The security benefit is real and worth having. But the honest reason most law firms and chambers certify is commercial: work, funding or clients increasingly depend on it.

Prepared properly, passed first time

We scope it with you, tell you plainly what needs to change, and prepare a clean submission so you pass first time rather than paying to resubmit. You are guided by a certified IASME assessor for both Cyber Essentials and Cyber Assurance, someone who knows exactly what the assessment checks, not an account manager and not a junior with a checklist.

Cyber Essentials and Cyber Essentials Plus

Cyber Essentials is a verified self-assessment against five technical controls, certified annually. Cyber Essentials Plus covers the same five controls but adds an independent, hands-on technical audit of your systems: the level a growing number of buyers now specify. We will tell you which one your buyers actually require, rather than pushing the higher tier by default.

What it covers

Five controls that block the great majority of commodity attacks: firewalls, secure configuration, security update management, user access control, and malware protection. Straightforward for most organisations, provided someone tells you honestly what needs changing before you submit.

How it works

Certification is largely remote, so it adds no travel to your invoice. We agree the scope with you, we help you get the controls in order and support you through the assessment on the IASME portal. Where Cyber Essentials Plus applies, the technical audit is scheduled around you. Turnaround is days rather than weeks when your controls are already in order.

Where it fits

For most law firms and chambers Cyber Essentials is the right first step. Where clients or funders want evidence of more than the baseline, Cyber Assurance is the next rung and stands in for ISO 27001 at SME cost. If you hold anything genuinely sensitive, test it with a proper penetration test.

Common questions

Clients are asking about our security before instructing us - does Cyber Essentials cover it?

It covers the technical baseline they are checking for and answers most of a standard client security questionnaire. Larger corporate clients increasingly require Cyber Essentials Plus specifically to keep firms on their panels.

Do we need Cyber Essentials or Cyber Essentials Plus?

Whatever your buyer specifies. Many requirements accept Cyber Essentials; larger clients, primes and some public bodies require the audited Plus. We check the actual wording rather than pushing the higher tier by default.

How quickly can we be certified?

If your controls are already in order, Cyber Essentials can often be turned around within days. If they are not, we tell you exactly what to fix first. See our urgent certification page if you are against a deadline.

How do you actually help us get certified?

We scope it with you, tell you plainly what needs to change, help you close the gaps, and — with a certified IASME assessor for both schemes guiding you on exactly what the assessment checks — get you through it first time rather than resubmitting.

Related

Turn the requirement into won work

Tell us the client, funder or contract asking for Cyber Essentials and your deadline. Scoping is free, and we'll tell you honestly what you need.