Industry Guides
IT support for law firms: what solicitors need from their IT, and why
What UK law firms need from IT support: SRA and Lexcel expectations, conveyancing payment fraud controls, case management systems, cloud, backup and retention.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Law firms need IT support that treats client confidentiality and client money as the priority: MFA on email and case management, protection against payment diversion fraud in conveyancing, tested backups that meet retention obligations, and a provider who understands the SRA's expectations, Lexcel and the practice management systems solicitors actually use.
Solicitors sit on two things criminals want: confidential information and access to client money. That makes law firms a different proposition from the average small office, and it changes what good IT support looks like. This guide sets out what a UK law firm of 5 to 100 people should expect from its IT, from regulatory expectations to the practical controls that stop the incidents the SRA most often sees.
Why law firms are targeted, and what usually goes wrong
Most incidents in small and mid-sized law firms are not sophisticated. They start with a phishing email, a reused password, or a mailbox with no multi-factor authentication. Once inside a fee earner's mailbox, an attacker reads correspondence for weeks, learns which matters are approaching completion, and then sends a message changing the bank details.
The GOV.UK Cyber Security Breaches Survey consistently finds phishing to be the most common type of attack on UK businesses, and professional services firms are no exception. Firms also lose data through simpler routes: a laptop left on a train, a server that fails with an untested backup, or a leaver whose access was never removed.
The commercial page for our IT support for law firms describes how we deliver that support. This article is about what you should be asking for, whoever provides it.
What the SRA and Lexcel expect from your IT
The Solicitors Regulation Authority does not publish a technical standard, but its Standards and Regulations create clear obligations that depend on IT:
- Confidentiality. Client information must be protected. A compromised mailbox or an unencrypted lost laptop is a confidentiality breach, and the SRA expects firms to report serious breaches promptly.
- Client money. The SRA Accounts Rules require client money to be safeguarded. A completion payment sent to a fraudster is a client money loss, and firms have had to make clients whole from their own funds.
- Competence and supervision. Partners are expected to understand the risks the firm runs, including cyber risk. "The IT company handles that" is not an answer the SRA accepts.
Lexcel, the Law Society's practice management standard, goes further. It requires documented information management and business continuity arrangements, and assessors will ask for evidence: backup reports, an information security policy, a tested disaster recovery plan and records of staff training. The Conveyancing Quality Scheme has similar expectations for firms doing residential property work.
Under UK GDPR, a personal data breach that is likely to result in a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. The ICO's guidance for organisations is the primary source here, and your incident plan should reference it.
Stopping payment diversion fraud in conveyancing
Payment diversion fraud (often called Friday afternoon fraud) remains the single most damaging incident type for conveyancing firms. The controls are well understood and mostly inexpensive:
- Multi-factor authentication on every mailbox, with no exceptions for partners. Most successful diversions start with a mailbox that had no MFA.
- Email authentication and impersonation protection. Publish SPF, DKIM and DMARC records for your domain, and use a mail filter that flags lookalike domains and external senders impersonating your own staff.
- Conditional access. Block sign-ins from countries you do not operate in and from unmanaged devices. This stops a stolen password being used from abroad.
- Mailbox rule monitoring. Attackers create rules that forward or hide messages. Your provider should alert on new forwarding rules across the firm.
- A verification procedure that does not depend on IT. Any change to bank details, from a client or from the other side, is confirmed by phone on a number already held on file. Put this in engagement letters so clients expect it.
- Staff training with real examples. A short session every six months, using the actual phishing emails your filter has caught, works better than an annual video.
None of this is exotic. It is the combination, applied consistently across every user, that matters.
Case management systems: LEAP, Clio, Proclaim and the rest
Most firms run their practice through a case management or practice management system: LEAP, Clio, Actionstep, Proclaim (now part of Access Legal), DPS, Osprey or a similar product. Your IT support needs to understand three things about whichever you use.
Where it runs. LEAP and Clio are cloud-native. Proclaim and some older systems are commonly hosted on a server in your office or in a vendor data centre. On-premises hosting means your provider is responsible for the server, its patching, its backups and its performance. Cloud hosting shifts that to the vendor but makes internet reliability and identity security the critical controls.
How it integrates with Microsoft 365. Modern systems file emails against matters, store documents in SharePoint or their own document store, and use Outlook add-ins. When the add-in breaks after an update, staff stop filing correspondence and the matter record becomes incomplete. A provider who supports law firms will have seen this before and will handle the vendor ticket for you rather than pointing at the software company.
What the data export looks like. Before any migration, check your contract for how you get your data out and in what format. This affects backup design and any future change of system.
| Question | On-premises case management | Cloud-hosted case management |
|---|---|---|
| Who patches the server | Your IT provider | The vendor |
| Who backs up matter data | Your IT provider (must be tested) | The vendor, but check retention and export rights |
| Working from court or home | Needs VPN or remote desktop | Browser or app, protected by MFA |
| Internet outage at the office | Local work continues, email may not | Work stops unless you have a 4G or second line failover |
| Typical cost model | Server capital cost plus support | Per-user monthly subscription |
Cloud, remote working and court days
Fee earners work from home, from court and from client premises. Since HM Courts and Tribunals Service moved civil and family work onto digital platforms, solicitors need reliable access to bundles and filing systems wherever they are. The practical requirements are:
- Managed laptops with disk encryption, so a lost device is an inconvenience rather than a reportable breach.
- Single sign-on through Microsoft 365 so that one account, protected by MFA, controls access to email, documents and the case management system.
- Mobile device management that can remotely wipe a phone with the firm's email on it.
- A resilient office connection. Firms that have moved to the cloud are entirely dependent on their broadband. A second line or 4G failover costs little compared with a day of lost fee earning.
Our Microsoft 365 services cover this setup, but the principles apply whichever provider you use.
Backup, retention and file destruction
Two separate problems are often confused. Backup is about recovering from loss: a deleted folder, a failed server, a ransomware attack. Retention is about keeping closed matter files for the period your policy requires, then destroying them.
For backup, the important questions are whether Microsoft 365 data (mailboxes, SharePoint, OneDrive) is backed up independently of Microsoft, whether at least one copy is offline or immutable so ransomware cannot encrypt it, and when a restore was last tested. Microsoft's own service documentation makes clear that the platform provides availability, not a substitute for your own backup policy.
For retention, closed files belong in a document management system or archive with a retention date, not in a backup set. Backups should be kept long enough to recover from an incident discovered late, typically months, but they are not the place to hold a probate file for twelve years.
Our backup and disaster recovery service is built around test restores for exactly this reason.
Choosing IT support that understands law firms
A generalist provider can keep a law firm's computers running. What it often cannot do is anticipate the specific failures that matter: an email compromise the week before a large completion, a case management add-in that stops filing correspondence, a Lexcel assessor asking for evidence nobody kept.
Look for a provider that can answer these questions without hesitation:
- Which legal practice management systems do you support today, and can we speak to a firm that uses ours?
- What happens in the first hour after we suspect a mailbox has been compromised?
- How do you evidence patching, backups and access reviews for Lexcel, CQS or a cyber insurance renewal?
- Who attends site, and how quickly, if a server or network fails?
- How do you handle a leaver on the day they go, including their mailbox, their phone and their case management licence?
Firms in Hertfordshire and north London can also read our guide to switching IT provider, which covers the handover risks specific to regulated practices.
What to do next
If you are unsure whether MFA is enforced on every mailbox, whether your backups have been restored recently, or how you would evidence your controls to the SRA or an insurer, an independent review is the fastest way to find out. Book an IT health check and we will report on the gaps in plain English, with the fixes prioritised by risk to client money and confidentiality.

