- Breach reports to SRA
- 2,300+ in 2025
- Practice interventions
- 47
- Top 100 firms with an incident
- ~75%
- Highest-impact risks
- Phishing, conveyancing fraud, ransomware
The numbers
In 2025 the Solicitors Regulation Authority received over 2,300 reports of data breaches and cyber security incidents affecting practices across England and Wales. The regulator intervened in 47 practices that year, citing IT security failures as a primary factor.
Research cited by Infolegal suggests nearly 75% of the UK's top 100 firms have already experienced a cyber incident, while around 35% still lack adequate mitigation planning and most mid-market firms operate without any dedicated security capability.
The SRA's annual Risk Outlook has flagged cyber as a priority risk every year since 2020, identifying phishing, conveyancing fraud and ransomware as the three highest-impact risks to firms.
Why firms under-report, and why that matters
A breach that puts client confidential information on a leak site is not only a regulatory problem. It threatens professional indemnity cover, SRA standing, and the firm's ability to retain clients.
That pressure has an obvious consequence: firms are more likely to pay quietly and less likely to disclose. Which means 2,300 is a floor, not a ceiling, and the real figure is unknowable.
It also means the sector's shared understanding of what actually happens is worse than it should be, because the incidents that would teach the most are the ones least likely to be discussed.
The failure that keeps recurring
Across enforcement and reporting, the same control keeps appearing: multi-factor authentication, absent or exempted. The SRA has specifically noted MFA absence as a recurring factor in successful attacks on firms.
And the exemption is almost always the same person. Partners find it irritating, partners have the most access, and partners are therefore the highest-value account in the firm. Exempting them does not reduce friction, it relocates the entire risk model onto the accounts an attacker most wants.
The second recurring finding is subtler and worth checking today: mailbox rules quietly forwarding a fee earner's email. It is the clearest single indicator of an ongoing compromise, it costs nothing to check across a tenancy, and almost nobody does it.
Conveyancing is where the money moves
A single completion sees six-figure sums move between client accounts. Attackers concentrate there because that is where the return is.
The attack does not require breaking anything. It requires reading a real email thread for long enough to understand the transaction, then sending updated bank details from a real address at the right moment, in the right voice.
Verified callback processes are the correct control. The question worth asking honestly is whether yours is followed on a Friday afternoon when everyone is under deadline pressure and the message looks entirely normal. That is the moment the control has to work, and it is the moment it usually does not.
Where controls have been found inadequate, firms have been required to make good losses from their own funds.
What the SRA now expects
The regulator's position has hardened from awareness to evidence. Recent enforcement following client-money loss makes clear that firms are expected to demonstrate active, documented programmes rather than assurances.
The obligations sit across Principle 7, the Codes of Conduct on confidentiality, and the Accounts Rules on safeguarding client money. Where a firm holds Lexcel, documented information security policies including risk assessment, training, continuity and incident response are already required.
Under UK GDPR you have 72 hours to notify the ICO of a personal data breach, and you must separately consider whether Rule 3.9 self-reporting to the SRA is triggered. Those are different obligations with different clocks, and firms routinely conflate them.
What we would do first
- MFA everywhere, no exemptions. Including partners. Especially partners.
- Check mailbox forwarding rules across every account in the tenancy, today.
- Email authentication. SPF, DKIM and DMARC at enforcement. Many firms run DMARC at
p=none, which offers almost no practical protection against the spoofing used in conveyancing fraud. - Role-based access. Paralegals should not be able to reach every matter. Leavers should be deprovisioned the same day.
- Cyber Essentials, which covers most of the above and answers a good deal of what PII insurers and corporate clients now ask. See Cyber Essentials certification.
- Then test. External infrastructure, remote access, the client portal. Covered under penetration testing.
On confidentiality during testing
A reasonable objection from firms is that they cannot have outsiders in their systems. We work under a signed engagement with confidentiality terms, minimum necessary access, evidence encrypted and held in the UK, and deletion on an agreed schedule. Specific matters can be excluded from scope.
More on how we work with firms on our legal sector page, and if something has already happened, incident response comes before testing.
Common questions
Does the SRA require penetration testing?
No, it does not specify penetration testing. It requires firms to protect client data and client money, and its enforcement pattern shows it now expects documented, active programmes rather than assurances. Your PII insurer and your corporate clients increasingly ask for independent testing directly.
We have a verified callback process for payments. Is that enough?
It is the right control and it is necessary. Two honest questions: is it followed under deadline pressure on a Friday afternoon, and would you know if a mailbox rule was forwarding a fee earner's email? That second one is the most common finding we see in firms.
What do we report, and to whom?
A personal data breach goes to the ICO within 72 hours. A serious breach of the SRA Standards and Regulations triggers a separate self-report obligation under Rule 3.9. Financial fraud goes to Action Fraud. They are distinct obligations and firms routinely treat them as one.
Can you test without seeing client files?
Yes. Scope is agreed in advance and specific matters can be excluded. Most of the valuable testing concerns infrastructure, authentication and access control rather than the contents of any particular matter.
Our IT provider says we are fine.
They may be right. Independent verification is what your insurer and your corporate clients are asking for, and it is not a judgement on your provider. We write findings so they can action them directly.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day