- Primary risk
- Payment redirection fraud
- Drivers
- SRA, PII insurers, CQS
- Common finding
- No MFA on email
- Usual start
- Cyber Essentials
What attackers actually want
Two things: the client account, and the transaction. Payment redirection fraud around property completion — the attacker sits in a mailbox, watches a conveyancing matter progress, and intervenes at the moment funds move with altered bank details. It works because the email is genuine, the timing is right, and the client has no reason to doubt it.
The second target is confidential material itself. Commercial transactions, litigation strategy, family matters. Increasingly this is used for extortion rather than sale, because a firm facing publication of client files will often pay.
What we consistently find
- Mailbox rules quietly forwarding or hiding messages — the single clearest sign of an active compromise, and almost never checked.
- Multi-factor authentication missing or exempted for partners, which inverts the risk model entirely.
- Case management systems exposed to the internet for remote working without adequate access control.
- Legacy document management holding decades of client files with no meaningful access segregation.
- No verification process for changes to bank details, or one that exists on paper and is bypassed under deadline pressure.
Who is asking you for evidence
Professional indemnity insurers increasingly ask detailed security questions at renewal and price accordingly. Lender panels and conveyancing quality requirements bring their own expectations. Corporate clients send security questionnaires before instructing. And the SRA expects firms to take reasonable steps to protect client confidentiality and client money — a general obligation, but one that becomes very specific after an incident.
Where to start
For most firms: Cyber Essentials first, because it addresses the controls that stop the attacks that actually happen to law firms. Then an external infrastructure test and a Microsoft 365 configuration review, because email is where the money is lost. A full penetration test of a case management system matters, but it is rarely the highest-value first spend.
Alongside that, a documented and enforced process for verifying payment details — technically trivial, culturally hard, and the single most effective control against the thing most likely to happen to you.
Common questions
Does the SRA require penetration testing?
Not explicitly. The obligations around client confidentiality, client money and competence are general, and firms are expected to take reasonable steps. In practice, PII insurers and corporate clients are the ones asking for specific evidence, and independent accredited testing is what they usually mean.
Our IT is outsourced. Does that cover us?
Your IT provider manages the systems; the regulatory obligation and the reputational damage remain yours. Independent testing exists precisely to verify what your provider tells you. We work alongside IT providers routinely and write findings in a form they can action.
How do we handle client confidentiality during testing?
Under a signed engagement with confidentiality terms, minimum necessary access, evidence kept encrypted in the UK and deleted on an agreed schedule. Where a matter is especially sensitive we can exclude specific data sets from scope.
What about Friday afternoon fraud specifically?
It's a process failure as much as a technical one. The technical side is mailbox security, MFA and detecting rule creation. The process side is verified callback on any bank detail change, using a number you already hold rather than one in the email. We cover both.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day