HomeBlogsFrom Confidentiality to Cybersecurity: Redefining...

From Confidentiality to Cybersecurity: Redefining the Solicitor’s Duty of Care

The short answer

A solicitor’s confidentiality duty under paragraph 6.3 of the Code of Conduct now depends on technical controls, and a cyber incident triggers several notification obligations at once. The ICO must be notified within 72 hours of the firm becoming aware of a personal data breach, unless it is unlikely to result in a risk to rights and freedoms. The SRA must be told about serious breaches, including where client money has been stolen, whether or not it is later recovered. Professional indemnity insurers should be notified early, and clients may need to be told separately.

The 72-hour clock starts at discovery

Not at the end of the business day, not once the incident is contained, and not once you understand what happened. The ICO reprimanded one firm that reported to the SRA and its insurers within 24 hours but reached the ICO 11 days later, saying it was concerned the firm was not immediately aware of the reporting requirements. Containing the damage first is understandable and it is not a defence.

72 hours To notify the ICO of a reportable personal data breach
£78,393 Average loss per residential conveyancing fraud case reported to Action Fraud
£60,000 ICO fine against DPP Law after 32GB of data reached the dark web

Where the duty actually comes from

There is no standalone cybersecurity rule for solicitors. The obligation is assembled from existing duties, which is why it is easy to overlook until something goes wrong.

  • Confidentiality. Paragraph 6.3 of the Code of Conduct for Solicitors, and paragraph 8.6 of the Code of Conduct for Firms, require the affairs of current and former clients to be kept confidential. A data breach is a direct contravention of that duty.
  • Systems and controls. The Code of Conduct for Firms requires effective systems and controls, records demonstrating compliance, and identification and management of material risks. A firm that cannot evidence its controls cannot evidence compliance.
  • Client money. The SRA Accounts Rules require client money to be safeguarded. Conveyancing fraud losses fall directly under those rules, and firms have been required to make good losses from their own funds where controls were inadequate.
  • Data protection. The UK GDPR requires appropriate technical and organisational measures, and imposes the breach notification duties set out below.

The practical consequence is that a cyber incident is simultaneously a confidentiality problem, a systems problem, potentially a client money problem, and a data protection problem, each with a different regulator.

Payment diversion fraud

This is the dominant cyber threat to the legal sector, and it is the one most commentary on solicitor cybersecurity omits.

The mechanics are consistent. An attacker gains access to or spoofs an email account, monitors a transaction, and intervenes near completion with fresh bank details. The client transfers to the fraudulent account. The money is gone within hours.

City of London Police reported 143 cases of conveyancing fraud to Action Fraud between April 2024 and March 2025, producing £11.7 million in losses, with an average loss of £78,393 per residential case.

Two features make it different from generic cyber risk. The loss is client money rather than data, which engages the Accounts Rules rather than only data protection. And the attack is timed to the transaction, typically late in the week and late in the day, when verification is least likely to happen.

The rule worth writing down

Any request to change payment details is verified by telephone using contact details the firm already holds, never a number supplied in the email requesting the change. Apply it without exception, including to requests that appear to come from a colleague, and make clear to clients at the outset that your bank details will never change by email.

What enforcement has looked like

The article’s usual claim that regulators “treat data protection as an essential professional responsibility” understates the position. There is an enforcement record.

DPP Law Ltd was fined £60,000 by the ICO in 2025 after attackers accessed 32 gigabytes of data including sensitive legal case files and privileged material, which subsequently appeared on the dark web.

Tuckers Solicitors was fined £98,000 following a 2020 ransomware attack in which nearly a million files were encrypted.

Those figures are modest against the ICO’s maximum powers, but the published decision is the durable consequence. It is searchable against the firm’s name, it is read by insurers and panel managers, and it describes in detail what the firm failed to do.

Subscribe to our newsletter

The notification problem

A single incident can trigger four separate notification obligations on four different timescales, and firms routinely handle them in the wrong order.

WhoWhenTrigger
ICOWithin 72 hours of becoming awarePersonal data breach, unless unlikely to result in a risk to rights and freedoms
SRAPromptlySerious breach, including theft of client money whether or not recovered
PII insurerAs early as possiblePolicy terms; early notification preserves cover and may unlock incident response support
Affected individualsWithout undue delayWhere the breach is likely to result in a high risk to their rights and freedoms

The SRA threshold is not the same as the ICO threshold, and in some cases it is lower. An incident that does not meet the ICO’s risk test can still be a serious breach requiring a report to the SRA, particularly where client money or confidentiality is involved.

The practical answer is a single incident response runbook covering all four, with named decision-makers and out-of-hours contacts, prepared before it is needed. A firm drafting its client notification during an incident has already lost days it did not have.

The controls regulators expect to see

Generic IT policies do not satisfy the obligation. What regulators and insurers look for is documentation specific to the practice.

  • A written risk assessment addressing threats specific to the firm’s practice areas, including conveyancing fraud exposure where relevant. Reviewed, dated and actioned.
  • An incident response plan naming decision-makers, typically the managing partner, the COLP and an IT lead, and tested rather than written once.
  • Multi-factor authentication across systems, since stolen credentials remain a leading cause of breaches.
  • Tested backups. A backup that has never been restored is an assumption, not a control.
  • Staff training with records. The evidence of who completed training and when is what makes the control demonstrable.
  • Secure remote access, with client files not accessible from unmanaged personal devices.
  • Pre-agreed client notification templates, available before an incident rather than drafted during one.

Cyber Essentials certification is a reasonable baseline and is increasingly expected by insurers and by institutional clients. The COLP should own the annual risk assessment, since it falls within the general compliance duty, and our guide to the COLP role sets out where that sits.

AI tools and the new confidentiality risk

A confidentiality exposure has emerged that no firewall addresses, and it comes from inside the firm.

In R (Munir) v Secretary of State for the Home Department [2026] UKUT 81, the Upper Tribunal observed that putting client letters and decision letters into an open AI tool can amount to placing that information in the public domain. A fee earner pasting a witness statement into a consumer chatbot has created a confidentiality problem regardless of how secure the firm’s network is.

That makes an approved tools list part of the cybersecurity policy rather than a separate AI question. Firms need a stated position on which systems may receive client material, communicated before staff are working to a deadline. Our guide to AI in legal practice covers the wider position.

Incident response readiness

  • Name the decision-makers: managing partner, COLP, IT lead, with out-of-hours contacts
  • Write down the 72-hour ICO obligation and who owns it
  • Record your insurer’s notification requirements and the panel incident response contact
  • Prepare client notification templates in advance
  • Document the payment details verification rule and brief every fee earner on it
  • Test a backup restore and record the result
  • Keep training completion records, since the training is only evidenced by them
  • List the AI tools approved to receive client material, and the ones that are not

Frequently asked questions

Do solicitors have a specific cybersecurity duty?

Not as a standalone rule. The obligation is assembled from the confidentiality duty at paragraph 6.3 of the Code of Conduct for Solicitors, the systems and controls requirements in the Code of Conduct for Firms, the SRA Accounts Rules where client money is involved, and UK GDPR requirements for appropriate technical and organisational measures.

How quickly must a law firm report a data breach?

The ICO must be notified within 72 hours of the firm becoming aware of a personal data breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms. The clock runs from discovery, not from containment or from the end of the working day.

Must a cyber incident be reported to the SRA?

Serious breaches must be reported, and firms are required to notify the SRA where client money has been stolen irrespective of whether it is later recovered. The SRA threshold is separate from the ICO threshold and in some cases lower.

What is payment diversion fraud?

An attack where a criminal intercepts or spoofs transaction correspondence and supplies fraudulent bank details near completion. City of London Police reported 143 conveyancing fraud cases to Action Fraud between April 2024 and March 2025, with £11.7 million in losses and an average of £78,393 per residential case.

Has the ICO fined law firms over cyber attacks?

Yes. DPP Law Ltd was fined £60,000 in 2025 after 32 gigabytes of data including privileged material appeared on the dark web, and Tuckers Solicitors was fined £98,000 following a 2020 ransomware attack that encrypted nearly a million files.

Can a firm be liable for client money lost to fraud?

The SRA Accounts Rules require client money to be safeguarded, and firms have been required to make good losses from their own funds where controls were inadequate. Being the victim of the crime does not by itself answer the question of whether the firm protected client money properly.

The key points

  • Four notifications, four timescales: ICO, SRA, insurer and clients, with different triggers
  • 72 hours runs from discovery: containment first is understandable and not a defence
  • Payment diversion is the dominant threat: £78,393 average loss per residential case
  • The fix is procedural: verify bank detail changes by phone on a number you already held
  • Documentation is the control: untested backups and unrecorded training are not evidence

The practical takeaway

The confidentiality duty has not changed; what discharges it has. The gap in most firms is not technology but process: no named owner for the 72-hour clock, no tested restore, no written rule on verifying payment details, and no list of which tools may receive client material.

All four are cheap to fix and all four are the things a regulator asks to see after an incident. The firms that come through one well are the firms that wrote them down before it happened.

Don’t Miss Key Legal Updates

Get SRA rule changes, SDT decisions, and legal industry news straight to your inbox.
Blogs
Related news