Skip to main content

Seven Cyber Gaps in Sydney Law Firms

13 August 2026 | By Birender Chahal

Most firms we meet believe their IT is in reasonable shape. There is antivirus on the machines, the documents are in the cloud, and someone set things up a few years ago. On paper, it looks handled.

Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because a law firm holds exactly what attackers want: privileged client data, matter files, and a trust account that moves real money. The legal sector is a high-value target precisely because it holds sensitive information and often runs weaker controls than the corporate clients it advises. If you have read what your PI insurer asks, this is the practical list of where firms actually fall short.

Gap 1: Trust Account Payment Redirection

The single most damaging attack on a law firm is not data theft. It is the redirection of a trust account payment. An attacker who gets into one mailbox watches a settlement or a payout conversation, then strikes at the right moment with an email that looks genuine, asking to update bank details before funds move.

Because the request appears to come from a real party in the matter, it passes the usual checks, and the money is often gone before anyone notices. The defence is part technical and part process: MFA on every mailbox to make the initial break-in much harder, plus a firm rule that any change to payment details is confirmed by a phone call to a known number, never by replying to the email. This pattern, business email compromise, does the most damage in this sector by a wide margin.

Lawyer working at a desk with documents and laptop
In a law firm, the trust account and the privileged file are both the prize.

Gap 2: Client Confidentiality and Privilege at Risk

Confidentiality is not just good practice in law, it is a professional obligation, and privilege is something clients trust you to protect. A breach of matter data is therefore far more serious than an ordinary IT incident.

The gap we see is that sensitive matter files are often more exposed than the firm realises, sitting in mailboxes, on shared drives, and in personal folders with little control over who can reach them. The fix is to know where matter data actually lives, restrict access so staff only see the matters they work on, and treat client confidentiality as a security requirement, not just an ethical one.

Gap 3: PI Insurer Questions the Firm Cannot Answer

Professional indemnity insurers now ask about multi-factor authentication, backups, access controls, and incident response on renewal questionnaires. Many firms cannot answer convincingly, which can mean a higher premium, conditions, or a declined cyber claim.

The gap is not negligence, it is a lack of visibility into the firm’s own controls. The fix is to be able to demonstrate, not assume, that the basics are in place: MFA enforced everywhere, backups tested, access reviewed, and a short incident response plan that staff know exists. If you cannot answer the question, that is the starting point.

Gap 4: Document Management Access Too Broad

In most firms, access to documents grew organically. Folders were created as matters came in, permissions were set loosely to avoid blocking anyone, and over time far more people can see far more than they should.

Every person who can reach a matter is another way that matter can leak or be exposed in a breach. The fix is permission-based access in your document management system or file server, so not everyone can see everything, reviewed periodically rather than set once and forgotten. For most firms this is a one-off cleanup followed by a simple ongoing process.

Gap 5: MFA Missing on Practice Systems

Almost every firm has multi-factor authentication on something. Very few have it on everything. We routinely find it switched on for email but missing from the practice management system, the document management system, or remote access used to work from home or court.

An attacker looks for the one login still protected by a password alone. The fix is to inventory every system that holds firm or client data and confirm MFA is enforced on all of them, with no exceptions for a partner who finds the extra step inconvenient.

Gap 6: Departing-Staff Access Left Active

Solicitors, paralegals, and support staff move between firms regularly, and each departure is a small security event that is easy to miss when the workload is heavy.

The common gap is access that never gets removed. A departed lawyer keeps a login to the document system or remote access long after their last day. Months later, that forgotten account is a quiet way in, and in a confidentiality-bound profession that is a serious exposure. The fix is to disable accounts on the day someone leaves, as a defined step, not an afterthought.

Gap 7: Untested Backups of Matter Files

Backups are “running”, the dashboard is green, and everyone assumes the matter files and the practice database are safe. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.

For a firm, losing live matter files would stall cases, miss court deadlines, and breach client expectations all at once. A backup you have never restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You can read more in our guide to immutable backup.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one, and most of them map straight to Essential Eight, the baseline published by the Australian Cyber Security Centre. The hard part is knowing which ones apply to you, because they stay invisible until someone looks.

Where to Start

If you recognised your firm in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista, and we work with law firms across the metro area. We understand the confidentiality and trust obligations your practice carries, and we secure it without getting in the way of the work. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.