IronSights

Industries · Legal · Family Lawyers

Cyber security for Australian family lawyers.

Family law files hold the most sensitive material in legal practice: violence disclosures, children's arrangements, medical records and financial affidavits. A breach here almost always crosses the line for mandatory NDB notification, and the people affected are often already doing it tough.

We help Australian family law practices keep that information secure, plan for breach notification, and meet their Privacy Act and Legal Profession obligations. ISO 27001 certified, Sydney-based.

Threat context

Why family law practices face distinct risk.

Family law practices face the same exposure as any firm: credential theft, ransomware, business email compromise and weak Microsoft 365 setup. What sets them apart is what they hold. In the wrong hands, this material has direct consequences for the safety of people who are often already in crisis.

A single file can hold violence disclosures, the addresses of protected parties, financial affidavits, mental health assessments, school reports and exhibits filed in Federal Circuit and Family Court proceedings. Any one of these would meet the NDB serious-harm threshold on its own. Together, the assessment is rarely in doubt.

There is also a threat most commercial practices never see: in a contested matter, the opposing party has a direct reason to want the file. The OAIC has received complaints where the concern was targeted access by an opposing party, not a criminal group after data to sell. That access can come through social engineering of admin staff, phishing aimed at the firm, or compromise of the client's own email.

So a family law practice has to handle file access, breach planning and staff training differently from a commercial firm with a client list the same size. It is not about volume. It is about what the files contain.

Common risks

What we find when we work with family law practices.

Files containing family violence disclosures

These files hold police reports, AVO applications, statements from protected persons and the safety arrangements for children and carers. If any of it reaches an opposing party, the harm goes well beyond a privacy breach. Any unauthorised access to this material clears the NDB serious-harm threshold, and you do not need proof of harm, only a reasonable view that it is likely.

Targeted access by opposing parties

Contested custody and property matters can turn adversarial outside the courtroom too. An opposing party or their associates may try to reach a file through social engineering, phishing your staff or compromising the client's own account, usually after settlement positions or parenting documents. Limiting file visibility to the staff on each matter reduces what any one compromised account can reach.

Broad sharing of sensitive exhibits

Medical records, school reports, mental health assessments and FACS documents are often tendered as exhibits. Third parties hand these over in confidence, and some carry their own handling obligations. Dropped into a shared SharePoint folder with broad access, they sit in an environment that does not match how sensitive they are.

No NDB response plan

Most practices have no tested breach response plan, let alone one built around protected parties, suppression orders and clients in crisis. Writing it under pressure after a breach is too late. The plan should be written, tested and in the hands of whoever has to act on it.

Credential-based access to years of closed files

Matter management systems keep closed files for years. A compromised credential opens not just live matters but every concluded one that staff member could see. For a long-serving employee, that is years of highly sensitive records from resolved proceedings.

Compliance

Regulatory obligations for family law practices.

Privacy Act

APP obligations and the NDB serious harm threshold

If your turnover is above $3 million, the Privacy Act and the Australian Privacy Principles apply to you, and so does the NDB scheme. It requires you to notify when a breach is likely to cause serious harm. Given what a family law file holds, violence disclosures, children's arrangements, financial affidavits and medical records, that threshold is almost always met.

Legal Profession

Confidentiality and the Uniform Law

The Legal Profession Uniform Law in NSW and Victoria requires you to keep protecting client confidentiality. A cyber failure that exposes family law files or court documents can amount to unsatisfactory professional conduct before the Legal Profession Conduct Commissioner. The Law Societies of NSW and Victoria have both published cyber guidance pointing to the Essential Eight as the baseline.

Court Orders

Suppression orders and handling obligations

Family law proceedings often produce orders restricting publication of identifying information about parties and children. Files under a suppression order need handling controls beyond standard security. If a breach leads to that information being published, you can face contempt on top of the breach notification and any disciplinary fallout.

Common questions

Asked by family lawyers like you.

Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.

  1. Does a family law breach always trigger NDB notification obligations?

    Not automatically, but the bar is low. The NDB scheme requires notification when a breach is likely to cause serious harm. Family law files hold violence disclosures, children's arrangements, financial affidavits and medical records, so a breach almost always clears that bar. You need to make the assessment promptly once you know or suspect a breach has occurred.

  2. Can client confidentiality obligations prevent proper disclosure after a breach?

    No. The Privacy Act and NDB scheme require you to notify the OAIC and affected clients, and privilege does not override that. What confidentiality does shape is the wording: you have to notify without exposing protected parties, children's information or anything subject to a suppression order. The real question is what you can say to the affected client, and how. We help structure the notification so it meets the obligation without breaching the orders in the matter.

  3. Are family law practices targeted specifically, or is it general legal sector exposure?

    Both. Family law practices face the same general threats as any firm: credential theft against LEAP and PracticeEvolve, phishing, ransomware and business email compromise. They also face one that most commercial practices do not. An opposing party in a contested custody or property matter may have a direct motive to get at the file, and the OAIC has received complaints where the concern was exactly that, not a criminal group after data to sell. Controls that limit who can read which files inside the practice matter most here.

  4. What does role-based access control mean in practice for a family law firm?

    It means a staff member working on one matter cannot open another unless they have a reason to. Most practices leave shared folders with broad internal permissions, so a paralegal can read files for matters they have no part in. When one account is compromised, the attacker sees everything that person can see, which is often the whole client list. Setting SharePoint folder permissions and Microsoft Purview sensitivity labels closes that off, without staff having to make a call on each file.

  5. What happens in the period between a breach and NDB notification?

    A lot, and quickly. The NDB scheme requires you to assess the breach as soon as practicable, and to notify promptly if serious harm is likely. In that window you have to contain the breach, work out what was accessed, identify who is affected, draft the notifications and tell your PI insurer. In family law the client notifications need extra care, because they can reach people in protected or vulnerable situations. We help you plan for this in advance and run the process if it happens.

Start with a review

A structured security review tells you exactly where your practice stands.

We check your Microsoft 365 environment, file access controls, breach notification readiness and where you stand against your Privacy Act and Legal Profession obligations. The findings are written for the kind of information family law practices actually hold.

ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.