Industries · Legal · Law Firms
Cyber security for Australian law firms.
Law firms hold years of privileged communications, financial records and personal information across LEAP, Microsoft 365 and shared documents. One compromised staff account can reach all of it in a single session.
IronSights works with commercial and general practice law firms across Australia. ISO 27001 certified, Microsoft certified security engineers, Sydney-based.
Threat context
Why law firms are targeted.
A law firm holds a dense record of client affairs: estate plans, commercial contracts, employment records, property files, dispute correspondence and trust account instructions. That is worth money to anyone running fraud or identity theft, and useful to anyone who wants to pressure a client or the firm. An attacker who gets into your Microsoft 365 tenant or LEAP does not need to know in advance which files will be useful.
Business email compromise is the most common attack we see in Australia, and commercial firms are a steady target. It almost always starts with a stolen password: a phishing email, a password spray against your M365 tenant, or credentials from an earlier breach sold online. Once in a staff inbox, an attacker can watch client communications, change payment instructions and quietly join a live transaction.
Ransomware against law firms keeps rising. When it hits, you lose every active matter at the same time: every open file, every thread, everything in the practice management system. The pressure to pay is high. Attackers also know legal files are confidential, so the threat to publish stolen client data carries a sting that most other business data does not.
LEAP and PracticeEvolve logins are a constant target. The phishing aimed at Australian firms turns up as DocuSign requests, court portal notices and Law Society emails. A stolen LEAP login exposes every matter that person can see, which in most firms means the full client list, trust account balances and the document history behind each matter.
Common risks
What we find when we work with law firms.
Compromised matter management credentials
One phished LEAP, PracticeEvolve or ActionStep password opens every matter that account can see. Trust account balances, document histories, client details and correspondence are all reachable from that single login. MFA is available on most platforms and is too often left switched off.
Ransomware and matter file encryption
Ransomware on your file server or document system freezes every active matter at once. Recovery from backup can take days, while court deadlines and settlement dates keep moving. Many groups now steal the files first and threaten to publish them if you do not pay.
Email account compromise and payment redirection
Inside a lawyer's Microsoft 365 inbox, an attacker can watch for an upcoming transaction and swap the payment details at the right moment, then send it from the lawyer's own address. MFA on every account, separate admin logins, and DMARC, DKIM and SPF on email are what stop it.
Broad internal access to privileged documents
In many firms, every staff member can read every file in SharePoint. So one compromised account reaches everything, with no further effort. Role-based access and sensitivity labelling through Microsoft Purview fix this, but only if someone sets them up.
Inadequate Privacy Act compliance controls
If the Privacy Act covers you, you have to show how personal information is collected, stored, used and disclosed. When the OAIC asks after a breach, you need a clear answer. A firm with no data classification, no access controls and no tested response plan is exposed no matter how the breach itself plays out.
How we help
Services for law firms and legal practices.
From a sole practitioner to a multi-partner firm, the controls that stop real attacks and meet your Privacy Act obligations are the same. We put them in place and show they work.
Fortify — managed security
We watch your endpoints, identities, email and cloud around the clock and step in fast when something looks wrong. You get steady improvement and a monthly report your partners can actually use. Built for firms with no in-house security team.
Microsoft 365 security
Most Australian firms run LEAP on top of , so we lock down M365 first: , , Defender for Business, DMARC and SPF, and to classify client documents, trust records and privileged correspondence. then block external sharing, printing and stray forwarding automatically, so staff do not have to decide file by file.
Penetration testing
External, internal and simulation testing. You get a risk-rated report your managing partner can read and your IT support can act on, plus a free retest within thirty days.
Audit and assurance
An gives you a documented baseline for your PI insurer renewal, Law Society correspondence and AML/CTF readiness. It is written in plain English, to be used rather than filed.
Compliance
Regulatory obligations for law firms.
Most firms answer to more than one framework. The Privacy Act sets the floor on how you handle data. The Legal Profession Uniform Law adds professional accountability on top.
APP entity obligations and the NDB scheme
If your turnover is over $3 million, the Privacy Act and the 13 Australian Privacy Principles apply. Smaller firms working under a Commonwealth contract, including Legal Aid and government panels, are covered too. A breach of client files will almost always meet the serious harm threshold, so you notify under the NDB scheme. The 2024 amendments raise penalties and add automated decision-making obligations from December 2026.
Competence and confidentiality under the Uniform Law
The Legal Profession Uniform Law in NSW and Victoria requires you to act competently and keep client information confidential. A breach that exposes privileged communications or lets someone into trust funds is not just a Privacy Act problem. It can become a conduct matter before the Legal Profession Conduct Commissioner. The Law Societies of NSW and Victoria point to the Essential Eight as the technical baseline, and that is what you would be measured against.
Law Society audit obligations
Law Society trust account audits are a fact of legal practice: keep records, reconcile, protect the funds. An incident that hits trust records or lets an unauthorised payment through puts you offside straight away. If you cannot show what was accessed, when, and what controls you had, you face audit consequences on top of the breach.
Common questions
Asked by firms like yours.
Not in this list? Call us on 1300 004 766 or book a 30-minute consultation. No obligation.
Does a law firm's LEAP environment need to be specifically secured, or is Microsoft 365 hardening enough?
You need both, because they are connected. LEAP integrates with Microsoft 365, so a compromised M365 account can often reach your matter files. Hardening M365 (MFA, Conditional Access, no legacy authentication) closes off the most common path into both. We also review LEAP's own MFA and access settings as part of the engagement.
What does mandatory NDB notification look like in practice for a law firm?
When a breach happens, you assess whether it is likely to cause serious harm. With client legal files, it usually does. If the threshold is met, you notify the OAIC and the affected clients directly, telling them what happened, what was involved and what they can do. Have a breach response plan that names who makes the call and who signs off, and test it before you need it.
What is the typical Secure Score for a law firm that has not had a dedicated security engagement?
Most firms we start with sit between 25 and 40. The usual findings are legacy authentication still on, MFA not enforced across the tenant, no Conditional Access, admin accounts used for daily work, and DMARC missing or monitor-only. None of it is exotic. These are the default gaps in any M365 tenant nobody has hardened yet.
Are smaller law firms below the $3 million turnover threshold exempt from the Privacy Act?
Often no. The $3 million threshold has exceptions that catch smaller practices. Firms working under a Commonwealth contract, including Legal Aid, government panels and court-appointed work, are covered regardless of turnover, as are firms handling tax file numbers. And even outside the Privacy Act, the Legal Profession Uniform Law still requires you to keep client information confidential. Treat it as covered either way.
How does IronSights handle confidential client information during a security engagement?
We do not read your client files. Our work sits at the configuration layer: tenant settings, access controls and policies, not file content. Where we need to check classification or permissions, we use metadata or sample data. Every engagement runs under a confidentiality agreement and we are ISO 27001 certified. We agree the scope with you before any commitment.
Further reading
Related insights.
Cyber security obligations for Australian legal practices
What the Privacy Act, Legal Profession Uniform Law and AML/CTF Tranche 2 reforms require from Australian law firms.
Read more →ComplianceProtecting trust accounts from cyber attack
How trust account access via compromised matter management credentials creates regulatory exposure and what the controls look like.
Read more →Threat intelligenceRansomware in Australian law firms
Legal practices are consistent targets. Why attackers go after legal data and what the NDB obligations look like when it happens.
Read more →TechnicalThe Essential Eight for Australian legal practices
Law Societies in NSW and Victoria have cited the Essential Eight as the relevant baseline. What each control means for a law firm.
Read more →Also in legal
IronSights works across the legal sector.
Start with a review
A structured security review tells you exactly where your firm stands.
We check your Microsoft 365 setup, identity controls, how client data is stored, and whether your incident response would actually hold up. You get a prioritised roadmap you can act on.
ISO 27001 and ISO 9001 certified. NSW Master Security Licence 000109187. Microsoft certified security engineers. Australian-owned. Sydney-based.