A breach at a law firm is reputational before it is financial.

Attorneys hold privileged client information, they move client money through trust accounts, and they are trusted implicitly by everyone they email. That combination is why law firms are targeted more heavily than their size suggests.

What are the real IT risks for a South African law firm?

The three that matter most for an attorney practice are business email compromise around trust account payments, ransomware encrypting matter files and precedents, and unauthorised access to privileged client information. All three are worse for a firm than for an ordinary business, because the professional consequences of losing client confidentiality sit alongside the commercial ones.

The trust account exposure is the sharpest. An attacker who sits quietly in a conveyancing mailbox and waits for a transfer instruction does not need to break anything technical at all.

What does POPIA require of a law firm specifically?

POPIA applies to a law firm in full, and Section 19 requires appropriate and reasonable technical and organisational measures to secure the personal information the firm holds. For a practice that means documented access control over matter files, encryption on every laptop that leaves the office, backup that has been restored from, and a written incident response process. There is no small practice exemption.

Legal privilege does not replace the POPIA obligation and does not reduce it. A firm can breach POPIA without ever breaching privilege, simply by losing an unencrypted laptop.

Why do attackers target attorneys rather than their clients?

Because a law firm is a concentration point. One practice holds the transaction details, identity documents, banking information and correspondence for hundreds of clients, and every one of those clients will act on an email that appears to come from their attorney. Compromising the firm is more efficient than compromising the clients individually.

What is the single control that stops trust account fraud?

Verification of any change to banking details by telephone, on a number the firm already held, before any payment is released. Not a reply to the email, and not a number printed inside it, because both route back to whoever sent it. It is a process control rather than a technical one, and it is the control that actually works.

The full walkthrough of how this attack unfolds is in the compromised vendor story. It takes four minutes and it is the one to send to a bookkeeper.

What does LANTEK put in place for a legal practice?

Encrypted laptops with enforced multi-factor authentication, email security that flags behaviour rather than only checking addresses, independent backup of Microsoft 365 with tested restores, dark web monitoring for leaked firm credentials, awareness training aimed at the people who release payments, and the documented POPIA control set a client or an auditor can be shown on request.

Before you call

Do you work with practices that use a specific practice management system?
Yes. LANTEK supports the environment around the practice management system, meaning the devices, the network, the backups, the identity and the email, whichever product the firm has chosen. The system itself stays with its own vendor for application support.
Can you help with a client security questionnaire?
Yes, and this is one of the more common requests. Larger corporate clients increasingly send security questionnaires before instructing a firm, and a practice that cannot answer one loses work to a practice that can. The evidence LANTEK maintains is designed to answer those directly.
What happens to matter files if we are hit by ransomware?
That depends entirely on what was prepared beforehand. With tested backups, an immutable copy and a documented recovery order, a small practice is typically working again within one to two days. Without them, recovery runs into weeks and some material does not come back.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.