Good cyber security is good business for law firms
Your firm needs access to its files, email and practice systems to serve clients and keep matters moving. It also holds information that clients trust it to protect. Cyber security is part of running the practice well, not simply an IT issue to deal with when something goes wrong.
For many small and mid-sized firms, the hard part is knowing where to start. There is no shortage of security products, warnings or offers of a free cyber assessment. What firms need is a clear view of what is already in place, what needs attention and what to do next.
A practical goal: SMB1001 Gold
SMB1001 is a tiered cyber security standard designed for small and medium businesses. It gives firms a way to improve their security in stages and seek certification against the standard. Gold, also known as Level 3, gives a law firm a defined goal rather than a vague promise to “take cyber security seriously”.
The Queensland Law Society recommends that its members work towards Gold as a reasonable standard for robust cyber security and professional assurance. While that recommendation comes from Queensland, the question it addresses is familiar to law firms across Australia: what practical steps should a firm take to protect its clients and its business?
What does better security look like in an ordinary working day?
Consider what happens when someone joins your firm, changes roles or leaves. Who decides which systems they can access? Does each person have their own account? Is access removed when they leave?
These sound like administrative details. They determine who can get into the firm’s email, client information and business systems. A structured approach to cyber security helps a firm make these decisions deliberately rather than assume they are being handled.
It also gives partners and practice managers a way to identify gaps, assign responsibility and plan improvements.
Why does this matter to the business?
Better security helps protect client information and reduces the chance that an avoidable IT problem will interrupt the firm’s work. A recognised standard also gives a firm a clearer way to explain its approach when clients or insurers ask about security.
For some firms, being able to demonstrate that work may affect future opportunities. The Law Council of Australia has highlighted the difficulty small legal practices face in improving cyber security with limited resources. It has warned that without support, smaller firms risk being excluded from government contracts and partnerships with larger businesses.
Certification is evidence of work done against a standard. It is not a guarantee that an incident will never happen. As the Queensland Law Society cautions, SMB1001 does not provide a legal “safe harbour”. Its value lies in helping firms take and demonstrate appropriate steps to protect their information and systems.
Skip the cyber questionnaire. Let’s get started.
Free cyber assessments and gap checks are everywhere. Some are useful. But a questionnaire that leaves a busy partner with a list of problems and no clear next step has not moved the firm much closer to better security.
The sensible starting point is to look at what can already be established about the firm’s IT environment. Identify what is in place and what needs attention. Ask the firm for information only it can provide. Then agree on the work that will make a difference.
Your managed service provider needs to be part of that process. Boab IT holds SMB1001:2026 Level 3 (Gold) certification. The Queensland Law Society’s guidance says firms seeking SMB1001 certification at Silver or above need to work with a provider certified to the same level.
If you’re already a Boab IT client, we can start with what we know about your IT environment and ask only for what we genuinely need. If you’re new to Boab IT, we’ll establish what is in place and work through the priorities with you.
You don’t need another checklist telling you cyber security matters. Let’s get started on the practical steps towards SMB1001 Gold.
