Site navigation

CyberSecurity For Lawyers: A How To

Andrew Hamilton

,

Law Society of Scotland published the Cybersecurity Guide

Solicitors now have access to a baseline guide outlining the threats and consequences surrounding cyber-security.

As the digital landscape transforms, many industries will struggle to keep up. New transformative official regulations such as GDPR are only outpaced by the attackers who find new ways to breach them. But one practice where there is no room for negotiation is law. As a result, the Law Society of Scotland (LSoS) has published the Guide to Cybersecurity, aimed at helping solicitors establish a baseline of protection and company-client confidence when and where it is needed most.

The price to pay for lax security can be steep

The report, divided into three sections, details the threats, consequences and solutions that face solicitors practicing law in today’s world. According to the LSoS, 46% of British businesses experienced a cyber-security breach last year. The cost of this fraud in 2016 alone is estimated to be over £1.1 billion, with individual breaches costing SMEs up to £300,000.

Alongside the increased frequency and severity of cyber-attacks is the changing landscape of the law. GDPR is fast approaching and any and all businesses that handle the personal data of EU citizens will be subject to tighter regulations and enhanced options for EU citizens surrounding identifiable information. The penalties are also steep, with firms – legal or not – facing fines of up to €20 million or 4% of their global turnover if they break the rules.

Valarie McEwan of the Law Society of Scotland said to DIGIT: “We carried out research last year which suggested that cyber security is one of the biggest issues facing solicitors. Almost half of survey respondents, at 42% stated that cyber security was a challenge. More generally, in the UK, there have been clear increases in the numbers of businesses that have been affected by frauds and scams – the figures have shown a year on year rise. We have a section on cybersecurity on our website as well as the new guide to alert our members to any current scams.”

According to the Law Society, common ‘risk areas’ – untrained staff, sub-contractors, remote working, personal IT equipment – are just as prominent in law as in any othe8r industry. The report states: “In developing a security strategy, you should consider all types of information. And in all forms – emails, databases, text documents, spreadsheets, voicemail messages, pictures, video and sound recordings. Also, the risk exists whether held on your own systems and devices, or on third-party hosted systems, such as the cloud.”

A ‘security culture’ is essential for firms and employees concerned about security

To prevent breaches occurring, the report recommends adopting a ‘security culture’ by all individuals in and out of the office. Because of the communication-aspect of the industry, the LSoS identifies emails as a point that is particularly susceptible to attack. They advise asking a series of probing questions when confronted by unexpected emails. These include asking if an email was anticipated from the sender (as email addresses can be compromised) and being wary of attachments and links if these too are unexpected.

The Law Society also noted that physical equipment and paperwork can pose a particular threat when personal and confidential information is on the line. The report advises having employers approve the use of personal IT equipment such as USB devices, securing and disposing of paperwork safely, and watching out for eavesdroppers when on the phone. These simple tasks, according to the LSoS, can significantly improve crucial confidentiality at the office and at home.

Similarly, employers can nurture a security culture, beginning by conducting a risk assessment of their firms. The Law Society claims that by identifying the financial and information assets that are most critical to the company, the threats can be better-understood – for example if a merger is announced, financial information between the organisations may be targeted. A clear digital protection policy should be given to employees, which advises them on the use of business facilities for their personal use, and policies on bring your own device (BYOD).

Valarie said on data protection: “The guide fits with the bigger picture around data protection. There is no doubt that regulations will be getting tougher when GDPR comes into effect in 2018. The legislation for this was adopted last year and is expected to be implemented in May 2018. The requirements under GDPR are broadly similar to DPA but they give additional weight to the rights of the subjects of any data collection, most obviously, in terms of penalties.”

Tim Musson, Law Committee Convener of the Law Society if Scotland, said to DIGIT: “The precise implications of the GDPR for law firms (and others) are still unclear.” He noted, however, that there were some sureties. “Large firms will probably require a statutory Data Protection Officer, sole practitioners will almost certainly not need one.  The requirement is unclear between these extremes. Firms can perhaps expect greater interest, concern and exercise of rights from data subjects, probably coupled with a greater knowledge of data protection issues. Firms will [also] likely have to prepare and store documentation demonstrating their compliance with GDPR.” In short he explained: “Information security (cyber and otherwise) will need particular attention.” Tim has provided data protection CPD training for the Law Society for several years and he has noticed an ‘enormous’ increase in the number of solicitors attending recent seminars.

When liaising with customers, the Law Society recommends solicitors consider adopting ‘digital signatures’ when signing documents. While not perfect, signatures offer a greater certainty when handling digital paperwork, and ‘lock’ documents not in-use to prevent their manipulation. The LSoS also advises adopting a cyber-crime disclaimer at the bottom of correspondences, for example notifying the customer that the firm will not change its bank account details throughout the transaction.

There are a number of more sophisticated avenues also open to explore

For increased protection and credibility, the LSoS suggests law firms explore becoming ISO-compliant. The International Organisation for Standardisation is an amalgamation of 163 national standards bodies which aims to promote consensus among industry practices, thereby also improving the credibility of companies in the process. Statutes include ISO27001, which advises firms on how to better-secure information. Other initiatives include Cyber Essentials and Cyber Essentials PLUS, which audit and accredit companies based on how robust their digital protections are.

Valarie concluded: “It is essential to get to grips with the basics in this area. According to insurers, it is the practical basics that can let firms down and expose them to most risk. This guide therefore looks at the basic tips for best practice in this area so that, where necessary, solicitors and law firms can make appropriate changes to safeguard their information and reputation.

“[The Law Society of Scotland] have an overarching objective of leading legal excellence, and strive to excel and to be a world-class professional body, understanding and serving the needs of our members and the public. We set and uphold standards to ensure the provision of excellent legal services and ensure the public can have confidence in Scotland’s legal profession.

“The Law Society also has a statutory duty to work in the public interest, a duty which we are strongly committed to achieving through our work to promote a strong, varied and effective legal profession working in the interests of the public and protecting and promoting the rule of law. We seek to influence the creation of a fairer and more just society through active engagement with the Scottish and United Kingdom governments, parliaments, wider stakeholders and our membership.”

For more information, individuals and firms can visit the Law Society of Scotland on www.lawscot.org.uk/cyber

Andrew Hamilton

Andrew Hamilton

PR & Content Executive at Hutchinson Networks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data