The short answer
IT support for law firms is managed IT and cyber security built around the way a regulated practice actually works. That means keeping your case management system, document management and email running reliably, protecting client money and confidential matter data, and producing the evidence your firm needs for SRA obligations, Lexcel and your professional indemnity insurer.
For a small or mid sized firm in Kent or Medway, the practical baseline in 2026 looks like this: enforced multi factor authentication on every account, Cyber Essentials certification, email security tuned to catch payment redirection fraud, tested and immutable backups of your case management data, documented access controls, and an incident response plan you can actually follow at 4pm on a Friday. Most firms have some of this. Very few have all of it, and the gaps are almost always in the same three places: MFA coverage, backup testing, and the email rules that would catch a spoofed completion statement.
Why law firms are a much bigger target than they think
Law firms sit on an unusually attractive combination for criminals. You hold identity documents, financial records, sensitive personal data and, critically, you move large sums of client money on predictable dates.
The numbers back this up. In 2025 the SRA received more than 2,300 reports of data breaches and cyber security incidents from solicitor practices in England and Wales. Conveyancing fraud remains the most expensive single category: between April 2024 and March 2025, Action Fraud recorded 143 reported cases of conveyancing fraud with total losses of £11.7 million, an average of roughly £78,000 per residential case.
Those averages matter. A single successful payment redirection can exceed the annual IT budget of a five partner firm several times over, and that is before you account for the SRA report, the client complaint, the PI notification and the reputational damage in a market where most instructions come from referral.
The SRA's Risk Outlook has flagged cyber as a priority risk every year since 2020, and consistently identifies phishing, conveyancing fraud and ransomware as the highest impact threats to firms.

What has changed recently
Two shifts are worth understanding.
First, the attacks are better written. The old advice about spotting bad spelling and odd grammar no longer helps, because generative AI produces fluent, contextually accurate emails at scale. Attackers now reference real matter numbers, real fee earner names and real completion dates, usually because they have already been sitting quietly in a mailbox reading the correspondence. We cover the mechanics of this in our guide to AI powered phishing attacks on small businesses.
Second, the compliance floor is rising. Cyber Essentials changes again on 27 April 2026, moving to version 3.3 of the NCSC requirements under a new question set. The update tightens MFA rules with a clear push toward passkeys and passwordless authentication, closes a long standing loophole in how cloud services are scoped, and adds automatic failure conditions around security update management. Firms that scraped through certification previously will find the bar higher. Our breakdown of the Cyber Essentials 2026 changes explains what to fix first.
What does the SRA actually require on IT and cyber security?
This is where a lot of firms get stuck, because the SRA does not publish a technical checklist. The obligations are principles based and sit across the Standards and Regulations rather than in one place. In practice, three duties do most of the work.
Confidentiality and protection of client information. You must keep client affairs confidential. If your systems allow a former employee to retain access to a matter folder, or you have no record of who accessed what, you cannot evidence that you have met this.
Protection of client money and assets. The Accounts Rules require you to safeguard money entrusted to you. Payment redirection fraud is the most common way this fails, and the SRA expects firms to have controls that go beyond hoping a fee earner notices.
Reporting serious breaches promptly. A significant cyber incident is reportable, and a personal data breach may also require an ICO notification within 72 hours. That clock only works if you have monitoring that tells you a breach has happened and a documented process for who does what.
Cyber Essentials is not mandatory for law firms. It is, however, referenced within Lexcel, increasingly asked about by professional indemnity insurers, and widely treated as the practical baseline for demonstrating reasonable cyber hygiene. If your firm holds or is pursuing Lexcel, you also need documented information security policies covering risk assessment, staff training, business continuity and incident response.
Friday afternoon fraud: the one risk to design your IT around
If you only fix one thing this year, fix this.
Friday afternoon fraud, more formally payment redirection or business email compromise, works like this. An attacker gains access to a mailbox, usually through a phishing page that harvests credentials where MFA is missing or weak. They stay quiet, often for weeks, reading correspondence and setting up hidden inbox rules that divert replies. When a completion approaches, they send the buyer a revised set of bank details from a lookalike domain, or from the firm's own compromised account. The money leaves. It is usually unrecoverable within hours.
The technical controls that actually stop it are unglamorous:
- MFA on every mailbox, with no exceptions for partners. Phishing resistant methods such as passkeys or number matching, not SMS codes.
- Alerting on mailbox forwarding and inbox rule creation. Attackers almost always create a rule. Most firms have no alert configured for this.
- Impersonation protection and lookalike domain detection on inbound mail, tuned to your fee earner names and your own domain.
- Outbound DMARC enforcement so criminals cannot convincingly spoof your firm to your own clients.
- Conditional access rules blocking sign ins from unexpected countries and unmanaged devices.
- A verified callback process for any change of bank details, using a number held on file rather than one in the email.
That last one is a process control rather than a technical one, but a good IT partner will help you build it into your matter workflow instead of leaving it as a line in a policy nobody reads. Our cyber security services are built around exactly these controls.
Generic IT support versus IT support built for a law firm
Plenty of providers will keep your laptops running. Fewer understand what happens when a practice management system goes down on a completion day. The difference tends to show up in these areas.
| Area | Generic IT support | IT support built for law firms |
|---|---|---|
| Case and practice management | Treated as "third party software, contact the vendor" | Supported directly, with an escalation relationship with vendors such as Clio, LEAP, Osprey, Proclaim or Actionstep |
| Email security | Standard spam filtering | Impersonation and lookalike domain protection, inbox rule alerting, DMARC enforcement |
| Backups | Nightly backup, rarely tested | Immutable backups of case data and email, with documented restore tests you can show an insurer |
| Access control | Accounts created and forgotten | Documented joiners, movers and leavers process, matter level permissions, access reviews |
| Compliance evidence | Not offered | Cyber Essentials support, Lexcel aligned policy documentation, asset and patch reporting |
| Incident response | "Log a ticket" | Named plan covering SRA and ICO reporting timelines, out of hours escalation |
| Completion day risk | No awareness | Change freezes and priority handling around known completion dates |
The last row is the one firms mention most often after switching. Nobody should be running a firmware update on the network at 11am on the busiest completion Friday of the month.
Case management, document management and the cloud
Most Kent firms have now moved case management to a hosted or SaaS platform, which removes a lot of server risk but creates a different set of jobs.
Your data being in someone else's cloud does not make it someone else's responsibility. Under the shared responsibility model, the vendor guarantees the platform is available. You remain responsible for your data, your user accounts, your permissions and your retention. That is why an independent backup of Microsoft 365 and, where the vendor allows it, of your case management data, is not optional. Microsoft's own retention periods are far shorter than the file retention periods a law firm needs.
Two practical points that come up repeatedly:
Scoping for Cyber Essentials. The April 2026 update introduces a clear definition of cloud services and closes the loophole that let some organisations leave applications out of scope. If your fee earners access a service with business credentials and it stores or processes firm data, it is in scope. Firms with a long tail of unmanaged SaaS subscriptions should audit this now rather than in the week before assessment.
Document retention. Deeds, wills and files held for decades sit awkwardly with cloud tools designed around a seven year default. Get the retention policy written before you migrate, not after.
Our cloud services and backup services are usually deployed together for regulated clients for exactly this reason.
How much does IT support for a law firm cost?
Pricing in this sector is normally per user per month, and for a UK firm the realistic range is roughly £45 to £95 per user per month for fully managed support including security tooling. Where a firm lands in that range depends on how many users are on the practice management system, whether you need out of hours cover for completions, and how much compliance evidence you need produced.
On top of that, budget separately for Cyber Essentials certification, and for Cyber Essentials Plus if an insurer or a large commercial client requires it. Published guidance for a typical five partner practice puts total annual cyber spend, including certification, an encrypted client portal, managed detection and response with conveyancing fraud rules, and a tested incident response plan, in the region of £8,000 to £20,000 per year.
Set against an average conveyancing fraud loss near £78,000 before you count the SRA report and PI excess, the maths is not difficult. You can see our published rates on the ITMS pricing page.
Should we use an in house IT person or an external provider?
For most firms under about 60 people, an external managed provider gives better coverage per pound, because you are buying a team rather than a person. One in house IT manager cannot cover holiday, sickness, out of hours completions, security monitoring and a Cyber Essentials submission at the same time.
Larger firms with an existing IT manager often get the best result from a co managed arrangement, where the internal person keeps ownership of systems and user relationships while an external team provides the security monitoring, patching and after hours cover. We explain how that split works in our guide to co managed IT services. If managed IT is new to you entirely, start with what managed IT support actually is.
Seven questions to ask any IT provider before you sign
- Which case and practice management platforms do you support directly, and can you name a firm you support on ours?
- What is your response time for a system outage on a completion day, and is it contractual?
- How do you alert on mailbox forwarding rules and impersonation attempts?
- When did you last test a restore of a client's data, and can you show me the report?
- Will you help us achieve and maintain Cyber Essentials, and what does that cost?
- What is your documented process if we suffer a breach that is reportable to the SRA or the ICO?
- Do you carry Cyber Essentials certification yourselves?
If a provider cannot answer question four with a date, keep looking.
Why local matters for Medway and Kent firms
Legal work in Medway, Maidstone, Sittingbourne and the wider Kent corridor still runs heavily on local relationships, and IT is no different. There are things that only work with an engineer who can be on site: a failed switch in a Chatham office, a server decommission, structured cabling in a listed building, a new office fit out in Rochester.
IT Manager Services is based on Railway Street in Chatham, works with regulated firms across Medway and Kent, and is Cyber Essentials certified. We already support firms in the financial and professional services sector, where the compliance pressures closely mirror those facing solicitors. If your practice is closer to accountancy than litigation, our companion guide on IT support for accountants may be a better starting point.
Next step
If you are a solicitor, conveyancer or legal practice manager in Kent or Medway and you are not certain your firm would survive a spoofed completion email, we will tell you where the gaps are.
Book a no obligation IT and cyber review or call 01634 218362. We will review your MFA coverage, email security configuration, backup restore evidence and Cyber Essentials readiness, and give you a short written summary you can take to your partners or your insurer.
Frequently asked questions
What is IT support for law firms? IT support for law firms is managed IT and cyber security tailored to a regulated legal practice. It covers day to day helpdesk support, maintenance of case and document management systems, protection of client money and confidential matter data, and the documentation firms need for SRA obligations, Lexcel and professional indemnity insurance.
Is Cyber Essentials mandatory for solicitors in the UK? No. Cyber Essentials is not a mandatory requirement for law firms. It is referenced within the Law Society's Lexcel standard, increasingly requested by professional indemnity insurers and larger commercial clients, and widely treated as the practical baseline for demonstrating reasonable cyber security. The scheme updates on 27 April 2026 with tighter MFA and cloud scoping rules.
What is Friday afternoon fraud? Friday afternoon fraud is a form of payment redirection fraud targeting conveyancing transactions. Criminals compromise or spoof a law firm's email, then send the buyer altered bank details shortly before completion, usually late in the week when there is least time to verify. Action Fraud recorded 143 conveyancing fraud cases totalling £11.7 million in the year to March 2025, an average of about £78,000 per residential case.
How much does IT support cost for a small law firm? Fully managed IT support for UK law firms typically costs between £45 and £95 per user per month, depending on the level of security tooling, out of hours cover and compliance reporting included. Cyber Essentials certification is normally priced separately.
Do we need to report a cyber attack to the SRA? Yes, if it is serious. Firms must report material breaches and serious incidents to the SRA promptly. Where personal data is affected, a separate notification to the ICO may be required within 72 hours of becoming aware. Both timelines depend on having monitoring in place that tells you an incident has occurred.
Can our existing IT provider support our case management system? Ask them directly and ask for a named reference. Many general IT providers treat case management platforms such as LEAP, Clio, Osprey, Proclaim or Actionstep as third party software outside their remit, which leaves your firm making the vendor calls during an outage.
Is Microsoft 365 backed up automatically? No, not in the way law firms need. Microsoft protects the platform, not your data. Retention periods in Microsoft 365 are far shorter than legal file retention requirements, and deleted or ransomware encrypted items can be permanently lost. An independent third party backup is required.
