Two days before settlement, your client receives an email. It comes from your firm’s address, it is written in your conveyancing clerk’s voice, it references the correct matter and the correct figure, and it advises that the trust account details have changed. The client transfers the balance of the purchase price to an account controlled by somebody else.
Every principal reading that recognises it, and the reason it lands so hard is that the consequences are not merely financial. They run into confidentiality, into privilege, into your obligations around trust money, and into a conversation with your professional indemnity insurer that nobody wants to have.
The Essential Eight — eight mitigation strategies published by the Australian Signals Directorate — is the framework that clients, insurers and, increasingly, corporate counsel will name when they ask what you do about this. It is written for corporate IT, which is why it reads as though it belongs in someone else’s practice. This article translates it. If the framework itself is unfamiliar, start with our guide to what the Essential Eight is.
This is general information, not legal advice, and you will notice the irony. Professional conduct and trust account obligations vary between jurisdictions. Confirm your specific position with your state or territory law society or legal services regulator.
This is a professional obligations question before it is a technology question
The reason a firm should care about the Essential Eight is not that ASD says so. It is that the duties you already hold assume you can keep client information under your control, and a compromised mailbox is the most common way that assumption fails.
| Obligation | How it connects |
|---|---|
| Duty of confidentiality | Rule 9 of the Australian Solicitors’ Conduct Rules provides that a solicitor must not disclose information confidential to a client and acquired during the engagement to anyone outside the defined circle, except as permitted by Rule 9.2. The Rules apply in the Uniform Law jurisdictions of New South Wales, Victoria and Western Australia, and have been adopted in other jurisdictions according to local legislative requirements — the Northern Territory maintains its own conduct rules. The duty assumes control of the information; the controls below are what keep that assumption true. |
| Client legal privilege | The Victorian Legal Services Board and Commissioner notes that inappropriate disclosure of confidential information may harm a client’s interests or result in the client losing legal privilege, as well as exposing the practitioner to disciplinary and civil consequences. Whether unauthorised third-party access has that effect in a particular matter is a question for advice — but it is the reason a breach in a law firm is not simply an operational problem. |
| Trust money | Trust money is regulated, externally examined and unforgiving of error. Payment redirection around settlements is the point where a cyber incident becomes a trust account problem, and the regulatory consequences of that are not proportionate to the sophistication of the attack. |
| AML/CTF Act — Tranche 2 | From 1 July 2026, legal practices providing designated services under the AML/CTF Act are reporting entities. Conveyancing and property transactions, company and trust formation, acting as a nominee, and certain client-money services are captured; pure litigation practice generally is not. If you are in scope, the OAIC states that reporting entities must comply with the Privacy Act when handling personal information for, or in connection with, their AML/CTF obligations — including small businesses with turnover under $3 million. |
| Privacy Act 1988 | The OAIC states that most small businesses (turnover of $3 million or less) are not covered, but that certain businesses are covered regardless of turnover — including reporting entities under the AML/CTF Act and Commonwealth contracted service providers. For many firms, Tranche 2 has changed the answer to this question in the last twelve months. |
| ACSC Essential Eight | Not legally required of a private law firm. It is mandatory for Australian non-corporate Commonwealth entities under the Protective Security Policy Framework. For a firm it is a recognised, documentable way to show that the duties above have been supported by something more than good intentions. |
[VERIFY: whether to state any obligation to notify the law society, legal services regulator or professional indemnity scheme following a cyber incident or suspected trust account irregularity. These requirements differ between jurisdictions and between insurance schemes, and no version of them has been asserted above. Either confirm the position for the jurisdictions you want to address and add a row, or delete this note and leave the table as written.]
The loss a firm recognises immediately
The mechanics are always the same. Somebody gets into a mailbox: a principal’s, a conveyancing clerk’s, or the client’s. They do nothing for weeks. They read: the matter, the parties, the settlement date, the figure, the tone of the correspondence. Then, close to settlement, they send one email.
It works in both directions. A client is told your trust account details have changed and pays a stranger. Or your firm receives amended account details for a payout and sends trust money to a stranger. The second is materially worse for you.
Conveyancing and estates are attractive because the transfers are large, the timing is public and predictable, deadlines create pressure that suppresses checking, the counterparties are often unsophisticated, and almost the whole process runs on email.
Three parts of the Essential Eight bear on it directly.
- Multi-factor authentication is what stops the mailbox being opened. At Maturity Level 1 it applies to your own online services and to third-party services holding your sensitive data — practice management, document management, email, cloud storage — and where you run a client portal holding sensitive information, to that too.
- User application hardening is the strategy most firms skip and the one that closes the delivery route. At Level 1 it requires Internet Explorer 11 disabled or removed, browsers that do not process Java from the internet, browsers that do not process web advertisements from the internet, and browser security settings staff cannot change. Credential phishing pages and malicious advertising are how the password gets taken in the first place; this is the control that reduces what a browser will run on a workstation.
- Restricting administrative privileges governs who can change a payee record, add a user, or alter access in the practice management and trust accounting systems.
And one control that is not in the framework but belongs in your practice anyway: no change to bank details is ever accepted or actioned on the basis of an email. Verification is by telephone to a number already on the file — never a number in the message — with a second person approving, and the request, verification and approval recorded on the matter. Tell clients at engagement, in writing, that your account details will not change and that any email saying otherwise should be treated as fraudulent until they have spoken to you. That one paragraph in a costs agreement has prevented more losses than any product.
What “your IT” covers in a firm
ASD states the Essential Eight was designed to protect internet-connected information technology networks, and was not designed for enterprise mobility or operational technology. For a law firm, essentially everything is in scope: email; practice management and document management; trust accounting; electronic conveyancing credentials; the file server or cloud storage holding matter files; dictation and transcription; court and lodgement portals; principals’ laptops and phones; and the archive.
The eight strategies in a law firm
| Strategy | What it means in practice |
|---|---|
| Multi-factor authentication | Email first, then practice management, document management, trust accounting, cloud storage and any remote access. Enforced across every user, not enabled for the principal and optional for everyone else — that distinction is the difference between meeting the requirement and not. |
| User application hardening | Internet Explorer 11 removed or disabled, browsers not processing Java or web advertisements from the internet, and browser security settings locked against user change. Locking the settings across the firm needs a device management capability, which is the real cost sitting inside this strategy. |
| Restrict administrative privileges | Who can add a user, change access levels, alter a payee record or export a matter list. Anyone doing administrative work needs a separate account used solely for that, kept off email and web browsing. In firms of this size the practical finding is usually that everyone is an administrator because it was easier that way in 2019. |
| Patch applications | Practice and document management, browsers and their extensions, email clients, PDF software and security products, patched within two weeks of release and within 48 hours where the vendor rates the flaw critical or an exploit exists. PDF software is named specifically by ASD, which matters in a profession that lives in PDFs. |
| Patch operating systems | Workstations within one month; anything internet-facing on a much tighter clock. Operating systems no longer supported by the vendor must be replaced — which in firms usually catches the machine kept alive to run a legacy practice management or dictation system. |
| Regular backups | Matter files, the document management repository, trust accounting records and the configuration around them — backed up, synchronised to a common point in time, held securely, restorable, tested, and out of reach of everyday user accounts. Retention has to be set against your file retention obligations, not against a default the software vendor chose. |
| Application control | Only approved software runs on firm machines, including in the folders where downloads and email attachments land. A firm receives attachments all day from parties it does not control, which is precisely the route this closes. |
| Restrict Microsoft Office macros | Macros disabled for anyone without a demonstrated business requirement, blocked in files that came from the internet, macro antivirus scanning on, and settings staff cannot change. Most firms have no genuine macro requirement outside precedent automation, which makes this quick to resolve. |
Electronic conveyancing and signing credentials
Electronic conveyancing platforms require your practice to hold and control digital signing credentials capable of authorising the transfer of land and money. Those credentials are, in practical terms, the most valuable thing your firm possesses.
The controls that matter are ones the Essential Eight already asks for, applied with more care than elsewhere: multi-factor authentication on the account, no credential sharing between staff, individual accounts so the audit trail means something, prompt removal of access when someone leaves, and patching on the machines those credentials are used from. A shared login used by three people is not a convenience, it is an unallocatable risk. It will be the first question asked if a transaction is ever disputed.
The archive problem
Every firm carries an archive that is larger, older and less examined than anything else it owns. Closed matters going back years. Wills and deeds in safe custody. Old email. Backups of a system replaced two upgrades ago, sitting on a drive in a cupboard. It is privileged material, it is rarely accessed, and it is frequently held on systems nobody has patched since they stopped being the live system.
This is where three Essential Eight requirements collide usefully. Operating systems no longer supported by the vendor must be replaced, including the one running the legacy archive. Backups must be retained in accordance with business criticality and business continuity requirements, which for a firm means retention set against file retention obligations rather than a vendor default; those obligations vary by jurisdiction and matter type, so confirm them with your law society rather than guessing. And everyday user accounts must not be able to reach or delete backups, which is exactly what happens when the archive lives on a shared drive everybody can browse.
The practical first step is an inventory: what do we hold, where does it live, what runs it, and who can reach it. Most firms find at least one answer they do not like, and a portion of the archive that could simply be destroyed under their retention policy, reducing the risk and the cost in one move.
What to say when a client or an insurer asks
Corporate clients now run supplier due diligence on their external lawyers, and professional indemnity renewals increasingly ask about controls. The weak answer is a general assurance. The strong answer is a documented position: the framework you assess against, the level you are working to, what is in place, what is scheduled and by when, and the date you last assessed.
CyberSmart360 produces that. The platform holds 186 controls across the Essential Eight and the ACSC Security Principles, translated for 44 industries. Working through the legal set, you answer questions about your practice management system, your document management repository and your trust accounting, not about executables, software libraries and control panel applets. The output is a compliance score, a gap report ranked by priority, evidence tracking against each control, and a costed 12-month remediation plan in a dated PDF report. That report is the artefact you point a client, an insurer or a broker to. Our Maturity Level 1 guide sets out what it measures against.
Frequently asked questions
Is the Essential Eight mandatory for law firms?
No. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For a private practice it is not legally required. It is, though, increasingly asked about by corporate clients, insurers and government panel arrangements, and it is a defensible way to evidence the confidentiality and security expectations that do apply to you.
Does the Privacy Act apply to our firm?
It depends on what you do. The OAIC states most small businesses under $3 million turnover are not covered, but that reporting entities under the AML/CTF Act are covered regardless of turnover. Since 1 July 2026 many practices providing conveyancing, company and trust formation or client-money services are reporting entities, which changes the answer. Confirm your own position. The AUSTRAC guidance on designated services is the starting point, and your law society will have jurisdiction-specific material.
What maturity level should a small firm target?
Maturity Level 1 across all eight strategies, unless a client contract or panel arrangement specifies otherwise. ASD advises achieving the same level across all eight before moving up, and its assessment guidance says you should not be assessed against Level 2 until Level 1 has been demonstrated.
Does cloud practice management make us compliant?
No. The vendor patches their own platform and usually offers multi-factor authentication, access controls and audit logs. Enabling and enforcing those, deciding who holds administrative access, patching your own devices, controlling what runs on them, and backing up what the vendor does not hold all remain the firm’s responsibility.
What is the most valuable thing to do first?
Enforce multi-factor authentication across every user on email, then put the bank-detail verification rule in writing: in your costs agreement to clients, and as a standing instruction to staff. Together they address the loss most likely to actually happen to a law firm, and neither costs more than an hour.
Assess it, document it, and keep the report
The uncomfortable part of a cyber incident in a law firm is not the downtime. It is explaining to a client, a regulator and an insurer what you had in place beforehand. A firm that can produce a dated assessment with evidence against each control is in a materially different position from one that cannot. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. Detail is on the plans and pricing page.
This article is general information about a cyber security framework and the professional obligations commonly surrounding it in Australian legal practice. It is not legal advice and does not replace advice specific to your firm or jurisdiction.