SOC status:Duty analyst on shift

UK Cyber Defence

Sectors · Legal services

Client confidentiality,defended around the clock.

Solicitors, barristers' chambers and legal service providers hold other people's secrets and other people's money. We watch the estate, test it and help you answer the SRA, your PI insurer and your largest clients' security questionnaires.

SRALaw Society guidanceLexcelCyber Essentials PlusClient questionnaires

01The threat picture

Law firms are targeted for what they hold and for the money that passes through them.

Two threats dominate. The first is payment diversion: business email compromise aimed at conveyancing and completion funds, increasingly with AI-generated voice pretexts purporting to be a partner authorising a transfer. The second is data extortion: ransomware operators such as INC Ransom and Qilin have run sustained campaigns against UK and EU firms, and document-management platforms — SharePoint in particular — are exploited at scale within days of a disclosure. Initial access is bought as often as it is earned: credentials to Microsoft 365 tenants purchased from initial-access brokers, then used quietly to read matters before anyone notices. Our weekly legal-sector report tracks the operators, the vulnerabilities and the defensive actions, in the order that matters.

Regulators
SRA · Bar Standards Board · ICO
Frameworks
Law Society cyber guidance · Lexcel · ISO 27001 · Cyber Essentials Plus
Typical estate
Microsoft 365 · practice and document management · case portals · remote working
Weekly report
Legal — solicitors, barristers and legal services — every Friday

What we watch for

The ways into a law firm

01BEC

Completion-funds fraud

Inbox rules, look-alike domains and voice pretexts aimed at the moment money moves.

02Identity

Bought credentials

Initial-access brokers selling M365 logins to ransomware affiliates who read before they encrypt.

03Data extortion

Document-platform exploitation

SharePoint, DMS and file-transfer defects used to lift client-matter files without touching a workstation.

04Initial access

Remote-access appliances

VPN and gateway vulnerabilities exploited faster than most firms patch.

05Pretexting

Remote-support tooling

Legitimate remote-management tools installed by a 'helpdesk' caller and used for hands-on-keyboard access.

06Supply chain

Supplier compromise

IT providers and case-management vendors as the route into many firms at once.

Weekly report

Legal services threat intelligence

All insights →

Questions

What firms ask us

We are a twelve-partner firm. Is a SOC really for us?

Firms of that size are exactly who the payment-diversion crews target, and a managed SOC costs a fraction of one diverted completion. SOC365 is priced on the estate we monitor, not on headcount tiers designed for banks.

Can you help with a client's security questionnaire?

Yes. Our virtual CISO service exists partly for this: the questionnaires, the evidence behind the answers, and the controls that turn a 'no' into a 'yes' before the next one arrives.

What happens if we are hit before we have a contract?

Call us. We help firms that are not clients on an emergency basis; an Incident Response Retainer simply guarantees the response time and removes the negotiation from the worst day.

Start a conversation

Thirty minutes, no slides.

Tell us how matters, money and mail move through the firm and we will tell you where we would look first.