What the SRA’s Own Review Reveals About Penetration Testing for Law Firms

by Rebecca Sutton

Penetration testing for law firms means paying a qualified, accredited tester to attack your own systems first. They probe your email, your practice management system and any client-facing app the way a criminal would. Then you fix what they find. Solicitors handle client money and confidential case files together. That combination makes a single successful attack far more costly than a typical small business breach. When the Solicitors Regulation Authority reviewed the sector, three in four firms it looked at had already been targeted.

Two colleagues reviewing a penetration testing for law firms report and findings together at a desk

What the regulator found when it looked closely

The SRA’s own thematic review gives the clearest picture available of how the legal sector actually handles this. Across the firms it visited, over £4 million in client money had been stolen through cybercrime. £3.6 million was eventually recovered through insurance. Firms repaid the rest themselves. One firm lost £150,000 in billable hours alone dealing with a ransomware incident.

Despite that, less than half the firms in the review had commissioned an external penetration test. Fourteen firms had done no testing or auditing of their security at all. Nine firms also failed to report personal data breaches to the Information Commissioner’s Office when the law required it. Seven significant incidents went unreported to the SRA itself.

Why email is usually the weakest point

Email modification fraud was the most common attack the SRA identified. A criminal quietly alters the bank details in a live email thread, so a client’s payment goes to them instead of the firm. Conveyancing is especially exposed. Large sums move on a predictable schedule, and clients already expect a payment request by email.

A test that only probes the office network misses this entirely. It needs to check email configuration, multi-factor authentication and staff awareness too. Otherwise it skips the attack that actually costs law firms the most.

What regulators and quality marks actually require

Neither the SRA nor Lexcel, the Law Society’s practice quality mark, names penetration testing as a mandatory line item on a fixed schedule. What they require instead is proof. A firm has to show it identifies and manages cyber risk in a documented, ongoing way, not just on paper.

Lexcel points firms toward Cyber Essentials and penetration testing working together as a recognised baseline. Cyber Essentials Plus goes further, adding independent technical verification instead of a self-assessed questionnaire. The SRA’s review found the small number of firms holding it were noticeably better prepared than the rest.

Building a scope that fits a law firm

A generic network test is not the same thing as proper penetration testing for law firms. Ask a provider to cover these areas specifically:

  • Email and collaboration platform configuration, including how multi-factor authentication is enforced.
  • The practice management system holding case files, billing records and client communications.
  • Any online client portal used for identity checks, document sharing or payments.
  • Remote access for fee earners working from home or client sites.
  • How far an attacker who compromises one laptop could actually reach across the network.

A useful report connects each finding to what it would actually let an attacker do. It should not just list a technical flaw with a severity score attached.

Accreditation, insurance and who is actually doing the work

Cyber insurers increasingly write CREST accreditation into policy wording. A claim can be challenged if the underlying test was not carried out by an accredited tester. Check your policy’s exact wording before you commission anything, since assumptions here are expensive to get wrong.

CREST’s own accreditation standards cover how a testing company scopes, executes and reports an engagement. Member firms are reassessed periodically to keep that status. When you compare quotes for penetration testing for law firms, ask any shortlisted provider to name the individual tester assigned to your firm. Confirm their accreditation directly, rather than relying on the company’s general marketing.

Deciding how often to test

The SRA deliberately leaves the interval for penetration testing for law firms to each firm’s own judgement. It does not fix a rule. An annual test is the common baseline for small and mid-sized practices, ideally timed around Cyber Essentials Plus renewal for firms that hold it.

Test again outside that cycle whenever something changes materially. A new client portal goes live. The firm merges with another practice. Offices move, or the practice management system changes. Waiting for the next scheduled annual test to catch a change made eight months ago leaves a long, avoidable gap. This is the same reasoning behind why annual testing on its own often isn’t enough for a fast-changing environment.

Who should actually commission this

Any firm handling client money or confidential case files qualifies, regardless of headcount. Conveyancing and probate practices carry the sharpest exposure, because of the sums moving through client accounts. But corporate, family and immigration teams hold data that is just as attractive to a criminal willing to sell it or hold it to ransom.

Partners sometimes assume a managed IT provider already covers this ground. It usually does not. Day-to-day IT support and penetration testing for law firms are different services with different goals. One keeps systems running. The other tries to break them on purpose, to find what would fail under real attack. If your practice needs that kind of scoped, independent penetration test, it is worth getting a firm that understands the legal sector’s specific risks to talk through your scope before you commit to a provider.

A short checklist before you sign

  • Does the scope explicitly name email and any client-facing portal, not just the internal network?
  • Is the tester assigned to your engagement individually accredited, and can the provider prove it?
  • Does your cyber insurance policy require a specific accreditation, and does this provider meet it?
  • Will retesting confirmed fixes cost extra, and how quickly can it happen?

The cost of having no evidence at all

The SRA’s review looked past the headline testing figures. It also checked what happened to firms without evidence when something went wrong. Nine firms had failed to report personal data breaches to the Information Commissioner’s Office, as required. Seven significant incidents never reached the SRA, despite clear evidence they should have.

Twenty-three firms in the review kept no incident logs at all. That meant they could not show a pattern of attacks, even when their own staff already suspected one. Penetration testing for law firms will not fix a broken reporting culture by itself. But it gives a firm a documented starting point to work from, instead of reconstructing events from memory during a live incident.

Frequently asked questions

Is penetration testing for law firms a legal requirement?

Not by name. The SRA requires firms to manage cyber risk and demonstrate that they do. Penetration testing is the evidence most reviewers and insurers recognise, even though no rule mandates it on a fixed schedule.

What is the difference between Cyber Essentials and Cyber Essentials Plus for a law firm?

Basic Cyber Essentials is a self-assessed questionnaire. Cyber Essentials Plus adds independent technical verification of the same controls, which is closer in spirit to what a penetration test checks.

Our firm is small. Do we really need this?

Size does not reduce the risk. A sole practitioner or small firm holds the same client money and confidential files as a larger one, usually with less dedicated IT support to catch mistakes.

How much should a firm budget for this?

It depends on how many systems are in scope. A focused engagement covering email, the practice management system and remote access is typically far cheaper than recovering from even one successful fraud.

What happens if we skip testing and get breached anyway?

Beyond the direct financial loss, the SRA’s review found firms without documented testing or incident logs struggled to explain their decisions afterwards. That complicates both regulatory reporting and any insurance claim.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like