Industries · Legal · Criminal Defence
Cyber security for Australian criminal defence practices.
Criminal defence files hold material that causes real harm if it gets out: informant identities, covert operation detail, client confessions and material under suppression orders. A breach here is not just a Privacy Act matter.
IronSights helps criminal defence practices protect privilege, secure their most sensitive files, and build a breach response plan that covers their court obligations as well as the Privacy Act. ISO 27001 certified, Sydney-based.
Threat context
Why criminal defence practices face distinct risk.
Criminal practices carry the same baseline exposure as the rest of the legal sector: credential theft on LEAP and PracticeEvolve, ransomware on file servers, phishing that uses court notification and document portal lures, and Microsoft 365 tenants that were never hardened. Those risks apply whatever the practice area.
What differs here is what a breach means. The prosecution brief in a serious matter can hold informant identities, covert agent details, police methodology disclosed to the defence, and material subject to public interest immunity. Client communications hold privileged advice and instructions about conduct that has not been charged. Expert reports rest on instructions that are themselves privileged.
The motive can also differ. Most legal sector attacks are financial, but a party with an interest in a serious proceeding, a co-accused, an organised crime group or another actor, may see intelligence value in a defence practitioner's files that goes well past resale. Criminal practitioners, their insurers and the Law Societies all treat this as a live risk.
When a breach happens, the response has to weigh suppression orders, discovery undertakings, privilege and client safety at the same time as the standard NDB assessment and notification. Plan that process before the event, or you risk adding to your exposure while you work it out.
Common risks
What we find when we work with criminal defence practices.
Informant and covert witness file exposure
The prosecution brief can name informants and covert agents. If that reaches an attacker, the risk is to the people named, not just a privacy notice. The main control is restricting these files to the named individuals on the matter, not the practice's shared environment.
Legal professional privilege and evidence of intent
Client correspondence holds advice, instructions and case strategy. A compromised staff account can put that privileged material in the wrong hands at a sensitive point in proceedings. Contested matters run for years, so an attacker sitting in your email has plenty of time to watch and wait. MFA and tight account controls close that door.
Suppressed material and contempt exposure
Criminal matters regularly carry suppression orders. If suppressed material is accessed in a breach and then published, that can amount to contempt, and the practice whose security failed enabled the access. You would assess whether court orders cover any accessed files at the same time as your Privacy Act notification.
Discovery implied undertaking breaches
Prosecution discovery material may only be used for the proceedings it came from. If an attacker reaches that material in a breach, it raises whether the undertaking has been breached by the access itself. You would have to act on that as well as the NDB assessment.
Inadequate MFA on matter management systems
Most criminal matters run through LEAP or PracticeEvolve. Both support MFA, but it is often left off. One stolen credential then opens the matter list, document history and full correspondence record, which here means brief material, expert reports and privileged communications with counsel. Turning MFA on is the first fix.
How we help
Services for criminal defence practices.
The security a criminal practice needs comes down to what you hold, who wants it, and what happens if it gets out. We build it with you and test that it holds.
Microsoft 365 security
We lock down your tenant: enforced , , mapped to matter type, and permissions that keep sensitive files to named individuals. Informant material, suppressed evidence and brief documents get handling that fits how a criminal practice actually works.
Penetration testing
We test your external network and run simulations using the lures your staff actually see: court notifications, legal aid correspondence and document portal requests. You find out where the gaps are before an attacker does. Thirty-day free retest included.
Audit and assurance
We measure your practice against the and review your Privacy Act readiness, with the specific handling needs of criminal files in mind. You walk away with a documented baseline for your PI insurer and the Law Society guidance, and a clear roadmap for the gaps.
Incident response
Available 24 hours a day. When a breach hits a criminal practice, the response has to weigh privilege, suppression orders, discovery undertakings and client safety, not just the steps. We run the full response with you, from containment through to notification.
Compliance
Regulatory and court obligations for criminal defence practices.
APP obligations and the NDB scheme
Practices with turnover above $3 million are covered by the Privacy Act. When criminal files are accessed without authorisation, the NDB serious harm threshold is usually met without much argument. Police methodology, instructions about prior offending, witness statements and expert reports all carry immediate harm if they reach the wrong party, which means notifying the OAIC and the people affected.
Uniform Law obligations and the LPCC
The Legal Profession Uniform Law in NSW and Victoria requires you to protect client confidentiality. A cyber failure that exposes privileged communications can be treated as unsatisfactory professional conduct before the Legal Profession Conduct Commissioner. The Law Societies of NSW and Victoria point to the Essential Eight as the technical baseline, so that is what any disciplinary review measures you against.
Suppression orders and discovery undertakings
Criminal matters routinely carry suppression orders and discovery obligations that sit alongside your Privacy Act duties. A breach can expose you to contempt if suppressed material is accessed and published, and to questions about discovery undertakings. Your response plan has to handle these court obligations and the NDB notification at the same time.
Common questions
Asked by criminal defence practitioners.
Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.
Can a cyber breach affecting a criminal defence file give rise to contempt of court?
Yes, it can. Criminal matters often run under suppression orders covering parties, witnesses or police methodology. If suppressed material is exposed in a breach and then published, that can amount to contempt. You would be dealing with that alongside the Privacy Act notification the same event already triggers.
Are criminal defence practices at greater risk than other law firms?
The baseline risk is similar; what differs is what a breach means. The same threats apply: credential theft, ransomware, business email compromise and weak Microsoft 365 settings. But a criminal file can hold informant identities, covert agent details and material under discovery implied undertakings. If that reaches the wrong party the harm goes well past a regulatory notice, and some attackers go after these files for the intelligence in them, not the resale value.
How does legal professional privilege interact with a cyber security incident response?
Privilege does not excuse you from NDB notification, but it shapes what you can say and to whom during the response. Working out what was accessed and disclosed raises questions about whether material stays privileged or whether privilege has been waived. Bringing in external forensic investigators can raise the same waiver questions. Work these through with counsel before a breach, not during one.
What are discovery implied undertakings and how do they affect data breach obligations?
Documents produced on discovery may only be used for the proceedings they came from. If that material is accessed without authorisation in a breach, the implied undertaking can be engaged on top of your Privacy Act duties. You then need to check that the breach, and how you investigate and notify, sit within your obligations to the court. This matters most where the prosecution has produced a large volume of material.
What should a criminal defence practice's breach response plan specifically address?
More than the standard NDB steps. The plan should cover how to check whether suppression orders touch any accessed material, who can be told what about the breach and the files involved, how to reach clients in custody or under bail conditions that limit contact, what discovery undertakings apply, and when to notify your PI insurer and any legal assistance bodies. Keep it specific to your practice and test it with whoever would have to run it.
Further reading
Related insights.
Cyber security obligations for Australian legal practices
Privacy Act, Legal Profession Uniform Law and AML/CTF Tranche 2 reforms. What each framework requires and who it applies to.
Read more →ComplianceLegal professional privilege and cyber breach response
How privilege interacts with breach notification obligations, what can be said to whom, and where external forensic investigation creates risk.
Read more →Threat intelligenceRansomware in Australian law firms
Legal practices are consistent ransomware targets. Why attackers go after legal data and what the NDB obligations look like when it happens.
Read more →TechnicalThe Essential Eight for Australian legal practices
Law Societies in NSW and Victoria have cited the Essential Eight as the relevant baseline. What each control means for a criminal defence practice.
Read more →Also in legal
IronSights works across the legal sector.
Start with a review
A structured security review tells you exactly where your practice stands.
We check your Microsoft 365 environment, file access controls, breach notification readiness and where you sit against your Privacy Act and Legal Profession obligations. For criminal practices, the review also takes in suppression orders, privilege and the court obligations that run alongside your data protection duties.
ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.