IronSights

Industries · Legal · Criminal Defence

Cyber security for Australian criminal defence practices.

Criminal defence files hold material that causes real harm if it gets out: informant identities, covert operation detail, client confessions and material under suppression orders. A breach here is not just a Privacy Act matter.

IronSights helps criminal defence practices protect privilege, secure their most sensitive files, and build a breach response plan that covers their court obligations as well as the Privacy Act. ISO 27001 certified, Sydney-based.

Threat context

Why criminal defence practices face distinct risk.

Criminal practices carry the same baseline exposure as the rest of the legal sector: credential theft on LEAP and PracticeEvolve, ransomware on file servers, phishing that uses court notification and document portal lures, and Microsoft 365 tenants that were never hardened. Those risks apply whatever the practice area.

What differs here is what a breach means. The prosecution brief in a serious matter can hold informant identities, covert agent details, police methodology disclosed to the defence, and material subject to public interest immunity. Client communications hold privileged advice and instructions about conduct that has not been charged. Expert reports rest on instructions that are themselves privileged.

The motive can also differ. Most legal sector attacks are financial, but a party with an interest in a serious proceeding, a co-accused, an organised crime group or another actor, may see intelligence value in a defence practitioner's files that goes well past resale. Criminal practitioners, their insurers and the Law Societies all treat this as a live risk.

When a breach happens, the response has to weigh suppression orders, discovery undertakings, privilege and client safety at the same time as the standard NDB assessment and notification. Plan that process before the event, or you risk adding to your exposure while you work it out.

Common risks

What we find when we work with criminal defence practices.

Informant and covert witness file exposure

The prosecution brief can name informants and covert agents. If that reaches an attacker, the risk is to the people named, not just a privacy notice. The main control is restricting these files to the named individuals on the matter, not the practice's shared environment.

Legal professional privilege and evidence of intent

Client correspondence holds advice, instructions and case strategy. A compromised staff account can put that privileged material in the wrong hands at a sensitive point in proceedings. Contested matters run for years, so an attacker sitting in your email has plenty of time to watch and wait. MFA and tight account controls close that door.

Suppressed material and contempt exposure

Criminal matters regularly carry suppression orders. If suppressed material is accessed in a breach and then published, that can amount to contempt, and the practice whose security failed enabled the access. You would assess whether court orders cover any accessed files at the same time as your Privacy Act notification.

Discovery implied undertaking breaches

Prosecution discovery material may only be used for the proceedings it came from. If an attacker reaches that material in a breach, it raises whether the undertaking has been breached by the access itself. You would have to act on that as well as the NDB assessment.

Inadequate MFA on matter management systems

Most criminal matters run through LEAP or PracticeEvolve. Both support MFA, but it is often left off. One stolen credential then opens the matter list, document history and full correspondence record, which here means brief material, expert reports and privileged communications with counsel. Turning MFA on is the first fix.

Compliance

Regulatory and court obligations for criminal defence practices.

Privacy Act

APP obligations and the NDB scheme

Practices with turnover above $3 million are covered by the Privacy Act. When criminal files are accessed without authorisation, the NDB serious harm threshold is usually met without much argument. Police methodology, instructions about prior offending, witness statements and expert reports all carry immediate harm if they reach the wrong party, which means notifying the OAIC and the people affected.

Legal Profession

Uniform Law obligations and the LPCC

The Legal Profession Uniform Law in NSW and Victoria requires you to protect client confidentiality. A cyber failure that exposes privileged communications can be treated as unsatisfactory professional conduct before the Legal Profession Conduct Commissioner. The Law Societies of NSW and Victoria point to the Essential Eight as the technical baseline, so that is what any disciplinary review measures you against.

Court Obligations

Suppression orders and discovery undertakings

Criminal matters routinely carry suppression orders and discovery obligations that sit alongside your Privacy Act duties. A breach can expose you to contempt if suppressed material is accessed and published, and to questions about discovery undertakings. Your response plan has to handle these court obligations and the NDB notification at the same time.

Common questions

Asked by criminal defence practitioners.

Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.

  1. Can a cyber breach affecting a criminal defence file give rise to contempt of court?

    Yes, it can. Criminal matters often run under suppression orders covering parties, witnesses or police methodology. If suppressed material is exposed in a breach and then published, that can amount to contempt. You would be dealing with that alongside the Privacy Act notification the same event already triggers.

  2. Are criminal defence practices at greater risk than other law firms?

    The baseline risk is similar; what differs is what a breach means. The same threats apply: credential theft, ransomware, business email compromise and weak Microsoft 365 settings. But a criminal file can hold informant identities, covert agent details and material under discovery implied undertakings. If that reaches the wrong party the harm goes well past a regulatory notice, and some attackers go after these files for the intelligence in them, not the resale value.

  3. How does legal professional privilege interact with a cyber security incident response?

    Privilege does not excuse you from NDB notification, but it shapes what you can say and to whom during the response. Working out what was accessed and disclosed raises questions about whether material stays privileged or whether privilege has been waived. Bringing in external forensic investigators can raise the same waiver questions. Work these through with counsel before a breach, not during one.

  4. What are discovery implied undertakings and how do they affect data breach obligations?

    Documents produced on discovery may only be used for the proceedings they came from. If that material is accessed without authorisation in a breach, the implied undertaking can be engaged on top of your Privacy Act duties. You then need to check that the breach, and how you investigate and notify, sit within your obligations to the court. This matters most where the prosecution has produced a large volume of material.

  5. What should a criminal defence practice's breach response plan specifically address?

    More than the standard NDB steps. The plan should cover how to check whether suppression orders touch any accessed material, who can be told what about the breach and the files involved, how to reach clients in custody or under bail conditions that limit contact, what discovery undertakings apply, and when to notify your PI insurer and any legal assistance bodies. Keep it specific to your practice and test it with whoever would have to run it.

Start with a review

A structured security review tells you exactly where your practice stands.

We check your Microsoft 365 environment, file access controls, breach notification readiness and where you sit against your Privacy Act and Legal Profession obligations. For criminal practices, the review also takes in suppression orders, privilege and the court obligations that run alongside your data protection duties.

ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.