Industries · Legal
Cyber security for Australian legal professionals.
Law firms hold information that causes real harm if it gets out: trust account details, privileged advice, family law files. We help Australian practices keep it secure and meet their Privacy Act and Law Society obligations.
IronSights works with law firms, conveyancers, family lawyers and criminal defence practices across Australia. ISO 27001 certified, Microsoft certified, and based in Sydney.
Threat landscape
Why legal practices are targeted.
Most attacks on legal practices start with a stolen password. Attackers phish login details for Microsoft 365 or your practice management system, LEAP, PracticeEvolve, ActionStep or Clio, then quietly read everything that account can reach. In most firms that one login opens every active matter, years of email, and the trust account records. They go after legal data because it is sensitive, not just because there is a lot of it.
Conveyancing has its own version. Attackers watch the email thread on a property settlement and, days before completion, send fresh payment instructions with a different BSB and account number. The message looks like it came from the firm and quotes the right details. A Sydney or Melbourne settlement is usually $500,000 to $1.5 million, and once the money moves it rarely comes back. Ransomware is the other constant, and law firms are a favoured target because the files are sensitive enough to force a payment. Law firms have featured in NDB breach reporting, and the OAIC has taken complaints about poor data security in the sector.
How we help
How IronSights supports legal practices.
Practices come to us for plain answers: where they are exposed, what to fix first, and how to show the Law Society, their PI insurer and their partners that cyber risk is under control.
Fortify — managed security
We monitor your systems around the clock and step in fast when something looks wrong. You get steady improvement and a monthly report your managing partner and practice manager can actually use. Built for firms with no in-house security team.
Microsoft 365 security
Most Australian practices run on and LEAP. We lock both down: on every account, , Defender, properly configured DMARC, DKIM and SPF, and on client files and trust records. The result is fewer ways in and a you can show your insurer.
Penetration testing
External, internal and web application testing to a method. You get a plain-English report your managing partner can read and clear fixes your IT support can action. A free retest 30 days later confirms the gaps are closed.
Audit and assurance
We measure your practice against the and the Law Society cyber guidance for NSW and Victoria. You walk away with a documented baseline for your PI insurer and a clear view of your AML/CTF position before the Tranche 2 changes start on 1 July 2026.
Incident response
Available 24 hours a day for , email fraud and data breaches. We handle containment, notification and your insurance paperwork, and we know what you can and can't say about a breach that touches privileged files.
Security reviews
Where most firms start. We find your biggest gaps, show you where you stand against your Privacy Act and Law Society duties, and tell you what to fix first. No obligation to go further.
Compliance
Understanding your cyber security obligations.
Several frameworks apply to Australian legal practices, and most firms sit under at least two of them.
APP obligations and the NDB scheme
If your practice turns over more than $3 million a year, the Privacy Act 1988 and the Australian Privacy Principles apply to you. Smaller practices are often caught too, usually through Legal Aid work or a government panel appointment.
The Notifiable Data Breaches scheme means you have to tell the OAIC and your clients when a breach is likely to cause serious harm. With legal files, it almost always does: income records, family violence disclosures, identity documents and financial positions all qualify. The 2024 changes to the Privacy Act lifted the penalties for getting this wrong.
Uniform Law obligations and Law Society requirements
The Legal Profession Uniform Law in NSW and Victoria requires you to keep client information confidential and to act competently. A breach that exposes privileged communications or lets someone into your trust account is not only a privacy problem. It can become a disciplinary matter before the Legal Profession Conduct Commissioner.
The Law Societies in NSW and Victoria have both published cyber guidance pointing to the Essential Eight. That is the standard you would be measured against if a breach led to a complaint.
Tranche 2 reforms from 1 July 2026
From 1 July 2026, the AML/CTF rules extend to legal practices providing services like conveyancing, company and trust formation, and estate administration. Those practices become reporting entities under AUSTRAC.
That brings an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. Privacy Act duties apply to the information you collect for it, whatever your turnover. If your service mix puts you in scope, start before the date, not on it.
Law Society audit exposure
Trust account audits are a fact of life in every state and territory. The rules are strict: keep the records, reconcile on time, protect client money.
A cyber incident that reaches your trust account, through a hacked practice management system, a redirected payment or ransomware, is an immediate regulatory problem. Law Society auditors are not cyber investigators, so the burden is on you to show what happened and what controls you had in place.
Common risks
What we see when we work with legal practices.
Settlement payment fraud
Attackers watch a conveyancing email thread and, days before settlement, send new payment details from what looks like the firm's address. A residential settlement is usually $500,000 to $1.5 million, and the money rarely comes back. DMARC, MFA and a phone-call check on every payment change are what stop it.
Matter management credential theft
LEAP, PracticeEvolve, ActionStep and Clio all hold your live client files, and all of them can take MFA. It is often switched off. One stolen password then opens every open matter and years of closed ones.
Privileged communications in uncontrolled environments
Counsel opinions, settlement instructions and trust correspondence sit in shared inboxes and SharePoint folders that most of the firm can open. When one account is compromised, the attacker reads all of it, with nothing flagging the access. Sensitivity labels and tighter permissions fix this, but only if someone sets them up.
Inadequate offboarding
Someone leaves, their Microsoft 365 account is switched off, but they still have access to LEAP and your file-sharing tools because nobody closed those. Former staff keep a door into live matters. We see it in firms of every size.
No tested incident response plan
Most practices have a breach plan written down. Few have ever run it. When an incident hits, you don't want to be hunting for a document to learn who calls the insurer, when the OAIC clock starts, and who tells the clients.
Third-party platform risk
Signing tools, accounting software, client portals and counsel collaboration apps all connect into your Microsoft 365. Each one is a possible way in. Most firms have no list of what is connected or what those apps are allowed to touch.
Who we work with
Legal practices we work with.
Law firms
General and commercial practices juggle matters across contracts, corporate work, estates and employment. Between Microsoft 365, LEAP and outside document tools, the ways in add up fast, and one compromised account can reach live matters, trust instructions and privileged advice together.
Conveyancers
Conveyancers move the biggest single payments most clients will ever make, which makes settlement fraud the headline risk. Attackers slip into the email thread and swap bank details just before settlement, and the loss is usually gone for good. DMARC, MFA and a verify-by-phone habit are the controls that matter most.
Family lawyers
Family files hold the most sensitive material in legal practice: violence disclosures, children's arrangements, medical records and financial affidavits. A breach here almost always crosses the serious-harm line for mandatory notification, and the people affected are often already doing it tough.
Criminal defence practices
Criminal files can hold informant identities, covert operation detail and privileged instructions. A breach can mean more than a privacy notice: it can raise contempt risk, disciplinary exposure and, in the worst case, danger to people named in the brief.
Further reading
Related insights.
Cyber security obligations for Australian legal practices
Privacy Act, Legal Profession Uniform Law and the AML/CTF Tranche 2 reforms. What each framework requires and who it applies to.
Read more →Threat intelligenceSettlement fraud in Australian conveyancing
Attackers monitor email threads and substitute payment details before settlement. How the attack works, what it costs, and the controls that stop it.
Read more →ComplianceProtecting trust accounts from cyber attack
Trust account access via compromised matter management credentials is a direct regulatory exposure. What the controls look like and what auditors expect.
Read more →Threat intelligenceRansomware in Australian law firms
Legal practices are consistent ransomware targets. Why attackers go after legal data, what NDB obligations look like when it happens, and how firms recover.
Read more →TechnicalThe Essential Eight for Australian legal practices
No mandatory cyber framework applies to legal practices, but Law Societies in NSW and Victoria have both cited the Essential Eight as the relevant baseline.
Read more →Common questions
Asked by practices like yours.
Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.
Does the Privacy Act apply to my law firm?
If your annual turnover is over $3 million, yes. You're a covered entity and the 13 Australian Privacy Principles apply. Many smaller practices are caught too, usually through Legal Aid agreements, government panel work, or because they handle tax file numbers for clients. If you're not sure which side of the line you sit on, it's worth checking.
What is the Notifiable Data Breaches scheme and when does it apply to a legal practice?
The NDB scheme requires you to tell the OAIC and the people affected when a breach is likely to cause serious harm. For a law firm, client files clear that bar easily: financial records, family violence disclosures, identity documents and privileged advice all qualify. Once you've assessed that serious harm is likely, you need to notify promptly rather than sit on it.
Can a cyber security failure lead to disciplinary action under the Legal Profession Uniform Law?
Yes, it can. The Legal Profession Uniform Law requires you to act competently and keep client information confidential. If weak security exposes privileged communications or lets someone into client funds, that can become a conduct matter before the Legal Profession Conduct Commissioner. The Law Society guidance in NSW and Victoria is the yardstick you'd be measured against.
Which legal practices will be covered by the AML/CTF Tranche 2 reforms from 1 July 2026?
From 1 July 2026, practices providing designated services, conveyancing, company and trust formation, estate administration and some trust account work, become reporting entities under AUSTRAC. That means an AML/CTF program, customer due diligence, suspicious matter reporting and record-keeping. Privacy Act duties apply to the information you collect for it regardless of your turnover.
What is settlement payment fraud and how does it work?
It's the most common financial attack on Australian conveyancers. Someone gains access to the settlement email thread, waits, then sends new payment instructions with a different BSB and account just before settlement. The email looks like it came from the firm and quotes the right property details, so the buyer pays without checking. With settlements at $500,000 to $1.5 million, the loss is large and usually unrecoverable.
What does a law firm's trust account exposure look like after a cyber incident?
It depends what the attacker reached. If they only viewed balances and transactions, you likely have a notifiable breach. If they redirected a payment, you have a financial loss and a regulatory problem at once. Either way, your Law Society auditor will want to know what happened, when you spotted it, and what controls were in place.
What matter management systems do you work with?
We work with LEAP, PracticeEvolve, ActionStep and Clio, plus older document systems. Most of our work sits at the Microsoft 365 layer, because that's where the majority of breaches start. Where your practice platform has its own MFA and access settings, we check those too.
Is the Essential Eight mandatory for Australian legal practices?
No law forces it on private practices. But the Law Societies in NSW and Victoria both point to the Essential Eight in their cyber guidance, and PI insurers increasingly ask about it. A practice that can't show it's working towards Essential Eight maturity is harder to defend after a breach.
How quickly can a security review be completed for a legal practice?
Usually two to three weeks from first conversation to report. A single-office practice on one Microsoft 365 tenant with LEAP can be quicker. We're clear about scope and timing before we start.
What does IronSights actually do during a Microsoft 365 security engagement for a law firm?
We start with your Secure Score and tenant settings: legacy authentication, MFA coverage, admin account separation, and whether DMARC, DKIM and SPF are set up on your domains. From there we work through Conditional Access, Defender, and Purview sensitivity labels for client files. For legal practices we pay particular attention to SharePoint external sharing and which third-party apps can reach your data.
What happens during a ransomware attack on a law firm?
By the time files start encrypting, the attacker has usually been inside for days or weeks, mapping the network and often copying client data first. When it hits, you lose active matters, trust records and email at once, and the attacker may threaten to publish what they took. Containment, restoring from backup and assessing the breach all have to happen together, which is why having us on call matters.
Do you work with sole practitioners or only with larger firms?
Both. We work with sole practitioners through to multi-office practices. Smaller firms usually start with a security review, then fix the gaps that matter most. Not everyone needs a managed service; some just need the holes closed and a clear way to keep things tidy after.
Start with a review
A structured security review tells you exactly where your practice stands.
We look at your Microsoft 365 setup, your logins, how client data is stored, and whether your breach plan actually covers your Privacy Act and Law Society duties. You get a clear, ordered list of what to fix.
ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.