Law firm penetration testing is a controlled, authorised attack on your systems, run by a specialist who tries to break in the way a criminal would and then tells you exactly how they did it. The SRA does not name a fixed testing interval for solicitors, but it does expect firms to “identify, monitor and manage all material risks”. For most firms holding client money and confidential files, a regular test is the most direct way to show you have done that.
This guide explains what a test covers, what it costs you in time and disruption, and how to get real value from it. It is written for partners, practice managers and IT leads who are not security specialists.
Table of Contents
Why are law firms such an attractive target?
Solicitors sit on two things criminals want: sensitive information and large sums of money in transit. A conveyancing file might hold passports, bank details and a completion date. An attacker who reads a few emails can learn when a client is about to move money, and then pose as the firm to redirect it.
The NCSC has published a cyber threat report for the UK legal sector because firms of every size are being targeted, from sole practitioners to large practices. Our own coverage of how two major law firms paid after a ransomware gang simply phoned in shows that the weak point is often a person or a process, not clever malware.
The wider picture is no kinder. The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses reported a breach or attack in the previous 12 months, and phishing was the most common type, hitting 38% of businesses.
What does the SRA actually expect from your firm?
There is no rule that says “test every year”. What the regulator publishes is guidance, and it is fairly direct. The SRA’s cyber security advice says firms should run health checks on their systems and assess how damaging a threat could be.
Then the same page reports what SRA staff found on visits. Only 47% of the firms visited had a system inventory to check that updates had been applied. Twenty-three firms had taken no steps to test their procedures at all. Those are the gaps a tester finds on day one, and they are why pen testing for solicitors is so often recommended.
Two reporting duties matter too. The SRA says firms should tell it about successful attacks, and only 70% of firms had done so. Also, personal data breaches must go to the ICO within 72 hours of discovery. A penetration test will not replace either duty, but it does make a breach less likely and your response faster.
Does a penetration test make a firm SRA compliant?
No, and any provider who implies otherwise is overselling. But a test gives you independent evidence that you looked for weaknesses and fixed them. That evidence is useful to the regulator, your insurer and your corporate clients. Compliance still depends on your policies, training and incident handling.
The SRA also notes that firms holding Cyber Essentials Plus were more likely to have good policies and procedures in place. If you are choosing between schemes, our comparison of Cyber Essentials and Cyber Essentials Plus explains the difference. Treat the certificate as a floor, and a test as the proof that sits above it.

What should law firm penetration testing cover?
Scope should follow your risk, not a generic package, so good law firm penetration testing starts with a conversation about how you work. For most firms, five areas deserve attention.
- External network and internet-facing services. Remote access, VPNs, webmail and any portal clients use to upload documents.
- Internal network. What an attacker can reach after one laptop is compromised: file shares, the case management server, the accounts system.
- Cloud and email. Microsoft 365 or Google Workspace settings, mailbox rules, multi-factor authentication gaps and sharing permissions.
- Web applications. Client portals, online forms and any bespoke tools. See our page on web application testing.
- People. Phishing and phone-based social engineering, aimed at the staff who handle payments and client instructions.
So ask the tester to include a scenario around payment redirection. It is the attack most likely to cost a firm real money, and it is often a process failure rather than a technical one.
How is this different from a vulnerability scan?
Many firms mix the two up, so here is the difference. A scan is automated. It lists missing patches and known flaws. Law firm penetration testing adds a human who chains weaknesses together, tries to reach client data and judges which problems matter. Many firms need both, with scans run often and a test run on a schedule.
So, government data suggests testing is still uncommon. In the same survey, 18% of businesses had carried out a vulnerability audit and 13% had done penetration testing. A firm that tests regularly is ahead of most of its peers.
How often should law firm penetration testing happen?
Once a year is the usual starting point for law firm penetration testing, with an extra test after a major change such as a new case management system, an office move, a merger or a move to the cloud. Firms with a high volume of client money, or those serving regulated corporate clients, may be asked to test more often by insurers or clients.
Cyber insurers increasingly ask what testing you have done. Our guide on whether you need a penetration test for cyber insurance covers what they tend to look for.
What should you ask a provider before you hire one?
- Who will do the work, and what are their qualifications?
- Will the scope reflect how a law firm works, including client money and email?
- How will they handle client data they happen to see during testing?
- Will the report be written for a non-technical partner as well as for IT?
- Is a free retest included once you have fixed the findings?
Confidentiality deserves special attention. Your duty of confidentiality to clients does not pause during a test, so the engagement terms should say what the tester can access, where evidence is stored and when it is deleted.
How do you get the most from the results?
Fix the critical findings first, because that is where law firm penetration testing pays for itself. Then retest to confirm they are closed. Give the report to your compliance officer as well as your IT team, because several findings will be about process. Keep a short record of what was found, what you changed and when. That record is what you show a regulator or insurer later.
If you would like a test scoped around how your firm actually works, Aardwolf Security’s penetration testing service is built for exactly that, and you can get in touch for a no-obligation conversation about scope.
Frequently asked questions
Is penetration testing mandatory for solicitors?
No rule names it directly. The SRA expects you to manage material risks, and testing is a recognised way to do that.
How long does a test take?
That depends on scope. A small firm’s external and internal test usually runs for days rather than weeks, plus time for reporting.
Will testing disrupt our work?
It should not. Testers agree timing and rules in advance, and risky actions can be held back or run out of hours.
What if the tester finds client data?
Good providers limit what they view, handle evidence securely and delete it on a stated date. Put this in writing before work starts.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.