Skip to content

IT and cybersecurity for Australian law firms.

Privilege, trust accounts, matter files, conveyancing settlements. The assets are valuable, the regulators are paying attention, and the email fraud aimed at your clients gets better every month. We've worked with firms like yours long enough to know which of those risks turn into real losses, and which controls mitigate them.

What's actually different

The threats aimed at law firms, and where they start.

If you do conveyancing, the most common real loss we see in Western Australia is invoice redirection. A fraudster compromises a client's email, watches the settlement, and sends revised bank details at the right moment. Your practice-management software doesn't see it. Your conveyancing clerk does, and they believe it because it's from the right person.

Larger corporate clients are starting to audit you too. Before renewing an engagement letter they want evidence of multi-factor authentication (MFA), offboarding controls and data-handling practices. The questions are basic. Proving your answers when someone asks is the work.

Affinity, LEAP, Smokeball, FilePro and Actionstep each secure their own platform differently. What matters more is the environment around them: identity, devices, network, backup, offboarding. Most incidents start there, not in the practice-management software.

Live right now

The 2026 pressure points we're actively working on with clients.

The specific asks, deadlines and enforcement actions shaping 2026 conversations in your sector.

AML/CTF Tranche 2, now in force

If your firm provides a designated service under the anti-money laundering and counter-terrorism financing (AML/CTF) rules, the obligations started on 1 July 2026. AUSTRAC enrolment closed on 29 July 2026. The deadline is now an operating requirement: a written AML/CTF program, know-your-customer procedures, record-keeping and reporting, with the evidence produced on request. Underneath the legal work, most of it is an IT and data-handling project.

Mandatory ransomware payment reporting, 72 hours

Pay a ransom, and the Cyber Security Act gives you 72 hours to report it to the Australian Signals Directorate (ASD). That applies to any firm with turnover above $3M, and it commenced on 30 May 2025. So your incident-response plan now has a legal deadline, not just a commercial one. Most firms we assess don't have one at all.

Privacy Act exemption gone for designated services

If part of your practice provides an AML/CTF designated service, the small-business exemption stopped applying to that work on 1 July 2026. Turnover under $3M no longer helps: you are an Australian Privacy Principles (APP) entity for it. Tranche 1 of the Privacy Act reforms is also live, bringing a statutory tort for serious invasions of privacy and a children's privacy code. The second tranche, which would remove the exemption entirely, is still under consultation with no bill passed and no commencement date.

Professional indemnity claims from conveyancing fraud

PEXA multi-factor authentication is mandatory on every practitioner account, and has been for some time. Invoice-redirection fraud aimed at conveyancers is still the biggest driver of professional indemnity claims in Western Australia. Preventing one of those pays for years of proper IT.

Frameworks and regulators

Industry frameworks, regulations and audit standards for legal in Australia.

Law Society and Bar Association rules
Privacy Act 1988 and the Australian Privacy Principles
Legal professional privilege
Essential Eight
Conveyancing obligations

Common questions

The things legal clients ask us first.

Our current IT person says we're 'fine' because we have MFA. Are we?
Can you run our practice-management software (Affinity, LEAP, Smokeball, etc.)?
Our clients are starting to send us security questionnaires. Can you help?
We had a suspicious email go to a partner. What do we do?
Can our lawyers use Microsoft 365 Copilot or Claude for Work on matter data?
AML/CTF Tranche 2 is in force. How much of this is an IT problem?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit