Skip to main content
Dig IT Solutions logo

Industry Guides

IT support for law firms: what solicitors need from their IT, and why

What UK law firms need from IT support: SRA and Lexcel expectations, conveyancing payment fraud controls, case management systems, cloud, backup and retention.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

Law firms need IT support that treats client confidentiality and client money as the priority: MFA on email and case management, protection against payment diversion fraud in conveyancing, tested backups that meet retention obligations, and a provider who understands the SRA's expectations, Lexcel and the practice management systems solicitors actually use.

Solicitors sit on two things criminals want: confidential information and access to client money. That makes law firms a different proposition from the average small office, and it changes what good IT support looks like. This guide sets out what a UK law firm of 5 to 100 people should expect from its IT, from regulatory expectations to the practical controls that stop the incidents the SRA most often sees.

Why law firms are targeted, and what usually goes wrong

Most incidents in small and mid-sized law firms are not sophisticated. They start with a phishing email, a reused password, or a mailbox with no multi-factor authentication. Once inside a fee earner's mailbox, an attacker reads correspondence for weeks, learns which matters are approaching completion, and then sends a message changing the bank details.

The GOV.UK Cyber Security Breaches Survey consistently finds phishing to be the most common type of attack on UK businesses, and professional services firms are no exception. Firms also lose data through simpler routes: a laptop left on a train, a server that fails with an untested backup, or a leaver whose access was never removed.

The commercial page for our IT support for law firms describes how we deliver that support. This article is about what you should be asking for, whoever provides it.

What the SRA and Lexcel expect from your IT

The Solicitors Regulation Authority does not publish a technical standard, but its Standards and Regulations create clear obligations that depend on IT:

  • Confidentiality. Client information must be protected. A compromised mailbox or an unencrypted lost laptop is a confidentiality breach, and the SRA expects firms to report serious breaches promptly.
  • Client money. The SRA Accounts Rules require client money to be safeguarded. A completion payment sent to a fraudster is a client money loss, and firms have had to make clients whole from their own funds.
  • Competence and supervision. Partners are expected to understand the risks the firm runs, including cyber risk. "The IT company handles that" is not an answer the SRA accepts.

Lexcel, the Law Society's practice management standard, goes further. It requires documented information management and business continuity arrangements, and assessors will ask for evidence: backup reports, an information security policy, a tested disaster recovery plan and records of staff training. The Conveyancing Quality Scheme has similar expectations for firms doing residential property work.

Under UK GDPR, a personal data breach that is likely to result in a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. The ICO's guidance for organisations is the primary source here, and your incident plan should reference it.

Stopping payment diversion fraud in conveyancing

Payment diversion fraud (often called Friday afternoon fraud) remains the single most damaging incident type for conveyancing firms. The controls are well understood and mostly inexpensive:

  1. Multi-factor authentication on every mailbox, with no exceptions for partners. Most successful diversions start with a mailbox that had no MFA.
  2. Email authentication and impersonation protection. Publish SPF, DKIM and DMARC records for your domain, and use a mail filter that flags lookalike domains and external senders impersonating your own staff.
  3. Conditional access. Block sign-ins from countries you do not operate in and from unmanaged devices. This stops a stolen password being used from abroad.
  4. Mailbox rule monitoring. Attackers create rules that forward or hide messages. Your provider should alert on new forwarding rules across the firm.
  5. A verification procedure that does not depend on IT. Any change to bank details, from a client or from the other side, is confirmed by phone on a number already held on file. Put this in engagement letters so clients expect it.
  6. Staff training with real examples. A short session every six months, using the actual phishing emails your filter has caught, works better than an annual video.

None of this is exotic. It is the combination, applied consistently across every user, that matters.

Case management systems: LEAP, Clio, Proclaim and the rest

Most firms run their practice through a case management or practice management system: LEAP, Clio, Actionstep, Proclaim (now part of Access Legal), DPS, Osprey or a similar product. Your IT support needs to understand three things about whichever you use.

Where it runs. LEAP and Clio are cloud-native. Proclaim and some older systems are commonly hosted on a server in your office or in a vendor data centre. On-premises hosting means your provider is responsible for the server, its patching, its backups and its performance. Cloud hosting shifts that to the vendor but makes internet reliability and identity security the critical controls.

How it integrates with Microsoft 365. Modern systems file emails against matters, store documents in SharePoint or their own document store, and use Outlook add-ins. When the add-in breaks after an update, staff stop filing correspondence and the matter record becomes incomplete. A provider who supports law firms will have seen this before and will handle the vendor ticket for you rather than pointing at the software company.

What the data export looks like. Before any migration, check your contract for how you get your data out and in what format. This affects backup design and any future change of system.

QuestionOn-premises case managementCloud-hosted case management
Who patches the serverYour IT providerThe vendor
Who backs up matter dataYour IT provider (must be tested)The vendor, but check retention and export rights
Working from court or homeNeeds VPN or remote desktopBrowser or app, protected by MFA
Internet outage at the officeLocal work continues, email may notWork stops unless you have a 4G or second line failover
Typical cost modelServer capital cost plus supportPer-user monthly subscription

Cloud, remote working and court days

Fee earners work from home, from court and from client premises. Since HM Courts and Tribunals Service moved civil and family work onto digital platforms, solicitors need reliable access to bundles and filing systems wherever they are. The practical requirements are:

  • Managed laptops with disk encryption, so a lost device is an inconvenience rather than a reportable breach.
  • Single sign-on through Microsoft 365 so that one account, protected by MFA, controls access to email, documents and the case management system.
  • Mobile device management that can remotely wipe a phone with the firm's email on it.
  • A resilient office connection. Firms that have moved to the cloud are entirely dependent on their broadband. A second line or 4G failover costs little compared with a day of lost fee earning.

Our Microsoft 365 services cover this setup, but the principles apply whichever provider you use.

Backup, retention and file destruction

Two separate problems are often confused. Backup is about recovering from loss: a deleted folder, a failed server, a ransomware attack. Retention is about keeping closed matter files for the period your policy requires, then destroying them.

For backup, the important questions are whether Microsoft 365 data (mailboxes, SharePoint, OneDrive) is backed up independently of Microsoft, whether at least one copy is offline or immutable so ransomware cannot encrypt it, and when a restore was last tested. Microsoft's own service documentation makes clear that the platform provides availability, not a substitute for your own backup policy.

For retention, closed files belong in a document management system or archive with a retention date, not in a backup set. Backups should be kept long enough to recover from an incident discovered late, typically months, but they are not the place to hold a probate file for twelve years.

Our backup and disaster recovery service is built around test restores for exactly this reason.

Choosing IT support that understands law firms

A generalist provider can keep a law firm's computers running. What it often cannot do is anticipate the specific failures that matter: an email compromise the week before a large completion, a case management add-in that stops filing correspondence, a Lexcel assessor asking for evidence nobody kept.

Look for a provider that can answer these questions without hesitation:

  • Which legal practice management systems do you support today, and can we speak to a firm that uses ours?
  • What happens in the first hour after we suspect a mailbox has been compromised?
  • How do you evidence patching, backups and access reviews for Lexcel, CQS or a cyber insurance renewal?
  • Who attends site, and how quickly, if a server or network fails?
  • How do you handle a leaver on the day they go, including their mailbox, their phone and their case management licence?

Firms in Hertfordshire and north London can also read our guide to switching IT provider, which covers the handover risks specific to regulated practices.

What to do next

If you are unsure whether MFA is enforced on every mailbox, whether your backups have been restored recently, or how you would evidence your controls to the SRA or an insurer, an independent review is the fastest way to find out. Book an IT health check and we will report on the gaps in plain English, with the fixes prioritised by risk to client money and confidentiality.

Frequently asked questions

Does the SRA require law firms to have specific IT security in place?
The SRA does not publish a technical checklist, but the SRA Standards and Regulations require firms to protect client confidentiality, safeguard client money and report serious breaches. In practice that means firms are expected to have proportionate controls such as multi-factor authentication, patched systems, staff training and reliable backups, and to be able to show what they have done if something goes wrong.
What is payment diversion fraud in conveyancing?
Payment diversion fraud is where a criminal, usually after compromising an email account, sends a convincing message changing the bank details for a completion payment or deposit. The buyer or firm sends funds to the fraudster's account. It is often called Friday afternoon fraud because completions cluster then. Controls include MFA, email impersonation protection, and verifying bank details by phone on a known number.
Should a small law firm move its case management system to the cloud?
For most firms of 5 to 100 staff, a cloud-hosted case management system such as LEAP, Clio or a hosted Proclaim reduces server costs, supports working from court and home, and shifts patching to the vendor. The decision depends on the age of your server, your practice areas, internet reliability and how your fee earners work. A migration should be planned around quiet periods and your data export rights checked first.
How long should a law firm keep backups of client files?
Retention depends on the matter type and your file retention policy, with many firms keeping conveyancing and probate files for years after closure. Backups are a separate question: they exist to recover from loss, not to act as an archive. Keep backups long enough to recover from a ransomware incident that went unnoticed for weeks, and store closed files in a proper document management system with its own retention rules.
Does Lexcel accreditation affect our IT?
Yes. Lexcel, the Law Society's practice management standard, includes requirements around information management, risk management and business continuity. Firms need documented policies for data protection, information security and disaster recovery, and evidence that they are followed. Your IT provider should be able to supply the technical evidence, such as backup reports, patching status and access reviews, that assessors ask for.
What should a law firm ask a prospective IT support provider?
Ask which legal practice management systems they support today, how they handle vendor tickets on your behalf, what happens during a suspected email compromise, how backups are tested and how quickly a matter file could be restored. Ask for the names of the engineers who would attend site and whether they have worked through a Lexcel or cyber insurance questionnaire before.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us