LoginSubscribe Now
Follow Us
Sign up to our free newsletter
Solicitors Journal LogoInforming the legal profession since 1856

Find the knowledge you need from the SJ library of over 20,000 legal articles

Search now
Solicitors Journal Logo
  • Legal News
  • Opinion
  • Features
  • Practice Notes
  • Business
  • International
  • Court Reports
  • AI Search
  • Digital Edition
  • Subscription Options
  • Advertise with Us
    • About Us
    • Contact Us
    • FAQ
    • Guide to Authors
Solicitors Journal

Informing the legal profession since 1856.

Follow us

Topics

  • Legal News
  • Opinion
  • Features
  • Practice Notes
  • Business
  • International
  • Court Reports

About

  • About Us
  • Contact Us
  • Advertise with Us
  • FAQ
  • Guide to Authors

Subscribe

  • Subscription Options
  • Digital Edition
  • Free Newsletter

Editorial

editorial@solicitorsjournal.com+44 (0)1223 750 755

Subscriptions

subscriptions@solicitorsjournal.com+44 (0)1223 750 755

Advertising

Advertise with usadvertising@solicitorsjournal.com+44 (0)1223 750 755

© 2026 Solicitors Journal in partnership with the International In-house Counsel Journal

ISSN 0038-1047  ·  Images: Freepix, Unsplash and by permission of the authors

Terms and ConditionsCookie PolicyPrivacy PolicyPLS Clear logoCopyright & permissions
Alastair MurrayAlastair Murray

Director, The Bureau

Quotation Marks
“As office technology becomes the driving force behind firms of all sizes, the need to protect it from cyber attack grows.”

Designing a cyber defence strategy for your firm

9 Nov 2022|Business|Add your comment
Share:
Designing a cyber defence strategy for your firm

By Alastair Murray

Alastair Murray presents measures to avoid incidents cyber-criminals can exploit

Firms large and small are struggling to know how to manage their cyber security and what’s best to protect themselves from phishing and ransomware attacks. Some are doing well through strict compliance with GDPR, but some are unwilling to grapple with the number one cause of cyber crime; human error.

As office technology becomes the driving force behind firms of all sizes, the need to protect it from cyber attack grows. The thought of a data loss incident, phishing fraud or ransomware is unthinkable, each with the potential to do untold damage to customer relations and levy heavy fines.

While phishing remains the number one threat to firms, some of the biggest frauds succeeded with no more than a simple email instruction, without any attachments or embedded links. All a cyber-criminal needs to do is write a convincing email it seems. Cyber security breaches are never the result of something that could not have been prevented.

Data security

While small firms imagine they are under the radar of cyber criminals, they are not. It is because so many small and medium enterprises (SMEs) think this way that cyber criminals are finding them such easy targets. Now is the time for all organisations and particularly SMEs to look at the many simple ways they can improve their security to ensure they comply with data protection regulations.

Data security should not be seen as a chore, but as a clear demonstration your firm is taking its data security responsibilities seriously, giving you a competitive edge over your more hesitant rivals.

To survive any of these incidents takes commercial strength and managerial vigilance to deal with the IT issues, the legal obligations and customer relations consequences. Not only will this kind of approach help solve the problem more quickly, it also demonstrates the firm has taken the necessary steps to defend itself and therefore more likely to recover from the possible actions by regulators and customers.

Designing a cyber defence strategy for your firm requires more than just IT. IT is certainly important, yet cyber-criminals avoid most of the security hard and software traps set for them and go for the humans, who continue to be the weakest link. This lack of appreciation of the threats is a dangerous security gap cyber criminals are successfully exploiting everyday; it needs to be plugged and quickly.

Defending your firm against all the usual threats requires a smart mix of IT hard and software, management commitment, staff training, Cyber Essentials type system controls and insurance. A defence package like this makes your firm a far more difficult target for the cyber criminal to break into.  

Cyber Essentials

The government has done a lot to create a large chunk of this with its own Cyber Essentials Certification Scheme. It is supported by industry and offers every business a simple and highly effective cyber security template. There is a self-assessment version and the Cyber Essentials Plus option, where you are independently audited.

Latest Articles

Firms large and small are struggling to know how to manage their cyber security and what’s best to protect themselves from phishing and ransomware attacks. Some are doing well through strict compliance with GDPR, but some are unwilling to grapple with the number one cause of cyber crime; human error.

As office technology becomes the driving force behind firms of all sizes, the need to protect it from cyber attack grows. The thought of a data loss incident, phishing fraud or ransomware is unthinkable, each with the potential to do untold damage to customer relations and levy heavy fines.

While phishing remains the number one threat to firms, some of the biggest frauds succeeded with no more than a simple email instruction, without any attachments or embedded links. All a cyber-criminal needs to do is write a convincing email it seems. Cyber security breaches are never the result of something that could not have been prevented.

Data security

While small firms imagine they are under the radar of cyber criminals, they are not. It is because so many small and medium enterprises (SMEs) think this way that cyber criminals are finding them such easy targets. Now is the time for all organisations and particularly SMEs to look at the many simple ways they can improve their security to ensure they comply with data protection regulations.

Data security should not be seen as a chore, but as a clear demonstration your firm is taking its data security responsibilities seriously, giving you a competitive edge over your more hesitant rivals.

To survive any of these incidents takes commercial strength and managerial vigilance to deal with the IT issues, the legal obligations and customer relations consequences. Not only will this kind of approach help solve the problem more quickly, it also demonstrates the firm has taken the necessary steps to defend itself and therefore more likely to recover from the possible actions by regulators and customers.

Designing a cyber defence strategy for your firm requires more than just IT. IT is certainly important, yet cyber-criminals avoid most of the security hard and software traps set for them and go for the humans, who continue to be the weakest link. This lack of appreciation of the threats is a dangerous security gap cyber criminals are successfully exploiting everyday; it needs to be plugged and quickly.

Defending your firm against all the usual threats requires a smart mix of IT hard and software, management commitment, staff training, Cyber Essentials type system controls and insurance. A defence package like this makes your firm a far more difficult target for the cyber criminal to break into.  

Cyber Essentials

The government has done a lot to create a large chunk of this with its own Cyber Essentials Certification Scheme. It is supported by industry and offers every business a simple and highly effective cyber security template. There is a self-assessment version and the Cyber Essentials Plus option, where you are independently audited. 

Most firms know they need to take control of their cyber security, but don’t know where to start. A new Readiness Tool developed by Information Assurance for Small and Medium Enterprises (IASME) is the first step in the journey towards becoming Cyber Essentials certified. It is designed to support and educate, shedding light on some of the technical terms and acronyms to create a tailored pathway for firms to follow. Over 100,000 firms have now been Cyber Essentials certified.

Research has shown when these Cyber Essentials techniques are applied, up to 80 per cent of cyber-attack threats are blocked. These tactics techniques and procedures (TTP) need not cost anything, requiring instead a set of administrative standards for office security, governing staff behaviour when online, cyber security policies for financial controls, password management, IT gateway configurations and the much talked about need for regular operating system patching.                                                             

Alongside the Cyber Essentials Accreditation comes cyber security awareness training. While classroom style training exists, the latest cyber security training, particularly for regulated industries, is now online and continuous.  Managed by the HR department or compliance, employees are set training that matches their risk level. A receptionist may be low risk, but someone in accounts would be high risk. Each would use a training platform tailored to their risk status, that is user friendly, intuitive, offering an affordable way to access highly effective cyber awareness training conveniently in the office, on the job, using continuous learning programmes.

In addition to cyber security training, a data security programme could examine and identify your data sources and how to protect them. At the same time your data and cyber policies will lay-down standards for how management and staff use office technology and their responsibility for identifying and reporting unusual activity. It is a simple way to lay-down the dos and don’ts when on the web and dealing with emails.

Even with the best security software IT budgets permit, Cyber Essentials Certification and cyber security awareness training, office networks are being penetrated. One click of a rogue email by an employee could infect one or more workstation, allow hackers in, cause a data breach or even a cyber ransom demand.

Risks and insurance

Most firms have smoke and fire alarms throughout their offices and hold regular fire drills, but they still insure the business against fire. The same should apply to your cyber risks, so even when you have taken all the steps to keep the business safe from a cyber-attack, you still need to insure against it.

GDPR requires an organisation to report a cyber breach where personal data has been compromised, within 72 hours. There are heavy fines and penalties for not reporting, so who are you going to call when this happens; your solicitors, your accountants, the police – who?

A cyber risks or commercial crime insurance policy is the answer. It gives you access to a 24/7 helpline to call when you suspect a cyber-attack. This will help with deciding whether personal data has actually been lost, stolen or otherwise compromised and whether to report it or not; help with contacting the firm’s clients where and when required; access to forensics; help with data restoration; help with legal expenses and help dealing with and managing possible fines and penalties.

This is the single most important reason for having a cyber risks insurance policy. The features and functions of most cyber risk insurance policies offer these core covers and give you the crucial lifeline when you suspect or have had a cyber breach incident.

What you least expect, sometimes happens!

Alastair Murray is director at The Bureau the-bureau.co.uk

 

 

Legal News desk contact: editorial@solicitorsjournal.com|PLS LogoCopyright & permissions
 

Most firms know they need to take control of their cyber security, but don’t know where to start. A new Readiness Tool developed by Information Assurance for Small and Medium Enterprises (IASME) is the first step in the journey towards becoming Cyber Essentials certified. It is designed to support and educate, shedding light on some of the technical terms and acronyms to create a tailored pathway for firms to follow. Over 100,000 firms have now been Cyber Essentials certified.

Research has shown when these Cyber Essentials techniques are applied, up to 80 per cent of cyber-attack threats are blocked. These tactics techniques and procedures (TTP) need not cost anything, requiring instead a set of administrative standards for office security, governing staff behaviour when online, cyber security policies for financial controls, password management, IT gateway configurations and the much talked about need for regular operating system patching.                                                             

Alongside the Cyber Essentials Accreditation comes cyber security awareness training. While classroom style training exists, the latest cyber security training, particularly for regulated industries, is now online and continuous.  Managed by the HR department or compliance, employees are set training that matches their risk level. A receptionist may be low risk, but someone in accounts would be high risk. Each would use a training platform tailored to their risk status, that is user friendly, intuitive, offering an affordable way to access highly effective cyber awareness training conveniently in the office, on the job, using continuous learning programmes.

In addition to cyber security training, a data security programme could examine and identify your data sources and how to protect them. At the same time your data and cyber policies will lay-down standards for how management and staff use office technology and their responsibility for identifying and reporting unusual activity. It is a simple way to lay-down the dos and don’ts when on the web and dealing with emails.

Even with the best security software IT budgets permit, Cyber Essentials Certification and cyber security awareness training, office networks are being penetrated. One click of a rogue email by an employee could infect one or more workstation, allow hackers in, cause a data breach or even a cyber ransom demand.

Risks and insurance

Most firms have smoke and fire alarms throughout their offices and hold regular fire drills, but they still insure the business against fire. The same should apply to your cyber risks, so even when you have taken all the steps to keep the business safe from a cyber-attack, you still need to insure against it.

GDPR requires an organisation to report a cyber breach where personal data has been compromised, within 72 hours. There are heavy fines and penalties for not reporting, so who are you going to call when this happens; your solicitors, your accountants, the police – who?

A cyber risks or commercial crime insurance policy is the answer. It gives you access to a 24/7 helpline to call when you suspect a cyber-attack. This will help with deciding whether personal data has actually been lost, stolen or otherwise compromised and whether to report it or not; help with contacting the firm’s clients where and when required; access to forensics; help with data restoration; help with legal expenses and help dealing with and managing possible fines and penalties.

This is the single most important reason for having a cyber risks insurance policy. The features and functions of most cyber risk insurance policies offer these core covers and give you the crucial lifeline when you suspect or have had a cyber breach incident.

What you least expect, sometimes happens!

Alastair Murray is director at The Bureau the-bureau.co.uk

 

 

Related Topics

  • Technology

Comments

Managing director conflicts in joint ventures
Solicitors Journal

Managing director conflicts in joint ventures

How UK company law shapes director conflicts, quorum rules and governance in joint venture structures
Feature22 Jul 2026
ACL proposes online portal for disputes resolution
Solicitors Journal

ACL proposes online portal for disputes resolution

The Association of Costs Lawyers argues for a pre-action protocol to better resolve lower-value costs disputes effectively
News22 Jul 2026
Legal aid reforms need urgent attention
Solicitors Journal

Legal aid reforms need urgent attention

The new Legal Aid Bill consultation seeks to address vital legal access challenges within Scotland's justice system
News22 Jul 2026
Supreme Court rules main housing duty ends automatically on acceptance or refusal of private rented offer in Bano case
Solicitors Journal

Supreme Court rules main housing duty ends automatically on acceptance or refusal of private rented offer in Bano case

Supreme Court dismisses homelessness appeal, confirming councils need not issue a separate decision ending their housing duty.
Court Report22 Jul 2026
Commercial Court refuses joinder of WeLink group companies seeking to bring £80m counterclaims against Chinese contractor
Solicitors Journal

Commercial Court refuses joinder of WeLink group companies seeking to bring £80m counterclaims against Chinese contractor

Deputy judge allows most defence amendments but declines to join additional companies to pursue separate counterclaims.
Court Report22 Jul 2026
Court of Appeal rejects Al Hashimi's human rights challenge to British Overseas Citizenship refusal on jurisdiction grounds
Solicitors Journal

Court of Appeal rejects Al Hashimi's human rights challenge to British Overseas Citizenship refusal on jurisdiction grounds

Court of Appeal finds claimant living abroad falls outside UK jurisdiction under Article 1 ECHR despite discrimination claim.
Court Report22 Jul 2026
Supreme Court confirms buyers can claim loss of bargain damages under Norwegian Saleform clause 14 without repudiatory breach
Solicitors Journal

Supreme Court confirms buyers can claim loss of bargain damages under Norwegian Saleform clause 14 without repudiatory breach

Supreme Court dismisses sellers' appeal, holding cancelling buyers can recover market-price damages under standard ship sale form.
Court Report22 Jul 2026
EAT confirms right to be accompanied requires an actual request, even where employer withheld meeting's purpose
Solicitors Journal

EAT confirms right to be accompanied requires an actual request, even where employer withheld meeting's purpose

Employment Appeal Tribunal rules statutory right to a companion cannot arise without a request, however unfair the circumstances.
Court Report22 Jul 2026
Unfair prejudice petition succeeds in Re BS Enterprises over below-market pub rent to family companies
Solicitors Journal

Unfair prejudice petition succeeds in Re BS Enterprises over below-market pub rent to family companies

ICC Judge finds director breached her duties by letting company property to connected businesses at undervalue.
Court Report22 Jul 2026
High Court confirms Environment Agency's power to prosecute Southern Water executive for conspiracy to defraud
Solicitors Journal

High Court confirms Environment Agency's power to prosecute Southern Water executive for conspiracy to defraud

Divisional Court refuses judicial review and lifts anonymity order over former Southern Water chief executive Matthew Wright.
Court Report22 Jul 2026
High Court continues $3.9m proprietary injunction in Ciright v Centili despite disclosure failure
Solicitors Journal

High Court continues $3.9m proprietary injunction in Ciright v Centili despite disclosure failure

Court maintains freezing order over disputed funds despite finding Ciright breached full disclosure duty.
Court Report22 Jul 2026
High Court dismisses Colak's extradition appeal after Türkiye provides Uckak-style assurance
Solicitors Journal

High Court dismisses Colak's extradition appeal after Türkiye provides Uckak-style assurance

The High Court has ruled that Türkiye's revised prison assurance removes any real risk of inhuman treatment under article 3 ECHR.
Court Report22 Jul 2026
New Lord Chancellor faces justice challenges
Solicitors Journal

New Lord Chancellor faces justice challenges

Mark Evans highlights the urgent need for reform, support and investment in the justice system
News22 Jul 2026
SJ Interview: Sohail Ali
Solicitors Journal

SJ Interview: Sohail Ali

Sohail Ali is a Disputes partner at DLA Piper, advising clients on complex cross-border litigation and arbitration matters. Alongside his practice, is also is a...
Interview7 Jul 2026
Matters of judgement
Solicitors Journal

Matters of judgement

Foreword1 Jul 2026