Every Australian legal practice that holds client money runs a trust account under strict rules. Record-keeping and reconciliation obligations are detailed, and trust account audits are a standing feature of practice in every state and territory. Those rules were written with accounting risk in mind. Today the trust account is also a cyber target, and the two concerns now overlap.
How a cyber incident reaches the trust account
A trust account does not need to be hacked directly to be at risk. The path usually runs through the systems and people around it.
The first path is a compromised practice management credential. Firms run their trust ledgers in systems such as LEAP, PracticeEvolve, ActionStep or Clio. If an attacker obtains a staff login to one of those systems, they gain visibility of balances, client matters and transaction detail. That visibility is valuable on its own, and it sets up the next move.
The second path is . An attacker who is inside a firm's email, often through Microsoft 365, watches for a settlement or a payment in progress and sends a message redirecting the funds to an account they control. Trust payments are an obvious target because the amounts are large and the timing is predictable.
The third path is . An attack that encrypts a firm's systems can take the trust accounting records offline along with everything else, which leaves the practice unable to reconcile or report at exactly the moment it most needs to.
A regulatory problem as well as a financial one
If trust money is taken or trust records are compromised, the firm has lost client funds, which is serious in itself. It has also breached the rules that govern how trust money must be held and accounted for. That makes a trust account incident a regulatory matter on top of a financial loss.
The exposure does not stop at the money. A breach of trust records will usually involve client , which brings the Privacy Act and the into play. A single incident can therefore reach your trust obligations, your privacy obligations and your professional conduct duties at the same time.
The burden sits with the firm
Law Society auditors examine trust accounts against the trust rules. They are not forensic cyber investigators, and it is not their role to reconstruct how an attacker moved through your network.
That means the burden falls on the firm. After an incident you will need to explain what happened, when, and what was affected. You will also need to show which controls were in place at the time. A practice that can produce clear records of its security controls is in a far stronger position than one that cannot describe its own environment.
The controls that matter
A small number of controls do most of the work in protecting a trust account. None of them are exotic, and together they form a defensible baseline.
- on practice management systems and on , so a stolen password alone does not grant access.
- Separation of duties on payments, so that no single person can both set up and release a trust payment without a second check.
- Phone verification of any change to payment details, using a known number rather than the contact details supplied in the email requesting the change.
- Monitoring and logging across email and practice management systems, so suspicious activity is visible and you have a record to review later.
- Tested backups of trust accounting records, so that a ransomware attack does not leave you unable to reconcile or report.
These controls also map closely to the , the baseline maintained by the that the Law Societies of New South Wales and Victoria point their members toward. Putting them in place serves both purposes at once.
What you should be able to produce after an incident
Preparation is what separates a contained incident from a drawn-out one. After an event, a firm should be able to produce evidence of the controls it had running: confirmation that multi-factor authentication was enforced, records of who had access to the practice management system, payment approval trails, and logs from email and core systems.
You should also be able to show a clear account of the incident itself, supported by those logs, and evidence that backups were in place and had been tested. That record lets you meet your notification obligations under the NDB scheme, answer questions from your Law Society, and demonstrate to clients and to AUSTRAC, where the new AML/CTF obligations apply, that you took reasonable care.
IronSights helps Australian legal practices put these controls in place and, just as importantly, demonstrate them: enforcing MFA across practice management and Microsoft 365, tightening payment processes, setting up monitoring and tested backups, and making sure the evidence exists before it is ever needed. A security review is a practical way to see how your trust account stands today and where to strengthen it first.



