Cybersecurity Training for Law Firms: What UK and Ireland Solicitors Need to Know

The SRA found 75% of firms it reviewed had been targeted by cyberattacks, many with no staff training at all. Here's what UK and Ireland law firms actually need to do.

Learnsignal Education Team
Updated

Law firms sit on two things cybercriminals want most: large sums of client money moving through their accounts, and sensitive, confidential information they're duty-bound to protect. That combination makes them a prime target — and both UK and Irish regulators have recently published findings that show most firms are underprepared for it. It's a risk that sits alongside other regulatory training duties employers are already juggling, including GDPR staff training requirements, which overlaps closely with cybersecurity once a breach involves personal data. Here's what the evidence actually shows, and what it means for training.

The UK: what the SRA's cybersecurity review found

The Solicitors Regulation Authority visited 40 firms as part of a thematic review into cybersecurity, covering a three-year period. The headline finding: 75% of those firms — 30 out of 40 — had been directly targeted by a cyberattack, with the remaining 10 reporting that criminals had targeted their clients during live transactions instead.

The financial damage was substantial: across 23 firms, total client money losses exceeded £4 million, with firms left to repay £393,890 directly out of their own funds after insurance covered the rest. Our guide to cyber incident and data breach response for law firms covers what a firm actually needs to do in the hours and days after an attack like this succeeds.

The training and preparedness gaps were just as striking. One in five firms (20%) had never provided any specific cybersecurity training to staff, and only around two-thirds of staff said they felt "knowledgeable" about cybersecurity — with even some senior figures unable to answer basic terminology questions. More than half of firms kept no record of who had completed training at all. The technical gaps behind those numbers — patchy two-factor authentication, unencrypted laptops, untested disaster recovery plans — are covered in full in our practical guide to cybersecurity for law firms, alongside the specific controls that close them.

The SRA's Standards and Regulations don't prescribe a fixed number of cybersecurity training hours. Instead, firms are expected to run their business "in accordance with proper governance and risk management principles," protect client money and assets, report serious breaches to the SRA, and meet the separate 72-hour personal data breach reporting duty to the Information Commissioner's Office where personal data is involved. The review makes clear that training gaps are treated as a governance weakness in their own right, even without a named CPD-style hours requirement.

Ireland: Law Society guidance and personal liability for client money

The Law Society of Ireland takes a similarly practical, if less quantified, approach. Its guidance recommends firms build a documented cybersecurity policy that includes "regular IT updates and annual staff training," alongside a business continuity plan for responding when an incident does occur. As with the UK guidance, the emphasis lands heavily on people rather than technology: the Society notes that "most cybersecurity attacks require human interaction, meaning that you and your staff are your main defence."

What makes the Irish position particularly sharp is the personal financial exposure involved. The Law Society's Regulation of Practice Committee has established that any deficit arising in client moneys held by a practice is the personal responsibility of the partners or principal — regardless of whether the loss was caused by cybercrime rather than conventional misconduct. That sits within the existing Solicitors Accounts Regulations framework, and it means a successful phishing or invoice-redirection attack that drains a client account isn't just a firm-level embarrassment; it's a personal liability question for the partners. Data protection reporting obligations apply on top of this wherever a cyber incident involves personal data, echoing the UK's 72-hour ICO duty.

Real-world cost: two cases that show what's at stake

The UK's National Cyber Security Centre has highlighted specific incidents that illustrate the scale of disruption a single successful attack can cause. Simplify Group, a large conveyancing firm, was left unable to process house moves for weeks following an attack that is reported to have cost the company £6.8 million. Separately, Tuckers Solicitors LLP had data relating to 60 court cases stolen and leaked on the dark web after falling victim to a ransomware attack. The NCSC notes that the sensitive information and large sums of money firms routinely handle make them "particularly attractive targets," and that the shift to hybrid working has widened the attack surface further.

What effective training actually looks like

Taken together, the UK and Irish findings point to the same practical priorities. Because most successful attacks rely on a person clicking, opening, or approving something they shouldn't, staff-facing training — recognising phishing and invoice-redirection attempts in particular — matters more than any single piece of technology. Multi-factor authentication should be the default for everyday systems access, not an opt-in extra. Disaster recovery and incident response plans need to be tested, not just written, and stored somewhere that survives the very outage they're meant to help recover from. And given how often the SRA's review found no training records at all, simply logging who completed what training, and when, closes a gap that shows up repeatedly in regulatory findings on both sides of the Irish Sea. Learnsignal's Legal CPD training resources cover how this fits alongside a firm's wider compliance calendar, including the same "policy plus evidence of training" logic that underpins CPD requirements for solicitors in Ireland.

FAQ

Is cybersecurity training a mandatory legal requirement for solicitors?
Neither the SRA nor Irish regulation names a fixed number of mandatory cybersecurity training hours, but the two regulators lean differently: the SRA's own review treats a lack of training as a governance weakness it actively assesses firms against, while the Law Society of Ireland goes further and explicitly recommends annual staff training as a named part of a firm's cybersecurity policy. Either way, training is expected as part of a firm's wider duty to protect client money and data.

How often should law firm cybersecurity training be refreshed?
The Law Society of Ireland's guidance specifically recommends annual staff training as part of a documented cybersecurity policy. Neither regulator sets a shorter mandatory interval, though firms handling higher transaction volumes or more sensitive data may reasonably train more frequently.

Who is personally liable if a law firm loses client money to a cyber attack?
In Ireland, the Law Society's Regulation of Practice Committee has confirmed that any deficit in client moneys is the personal responsibility of the partners or principal, regardless of whether cybercrime caused the loss. UK firms face a related exposure through their duty under the SRA Standards and Regulations to protect client money and assets, with serious losses reportable to the SRA.

What's the single most effective step firms can take to reduce cyber risk?
Both the SRA's review and the Law Society's guidance point to the same answer: staff training. The SRA found that firms without any cybersecurity training, without multi-factor authentication, and without tested incident response plans were the ones most exposed — and the Law Society notes that most attacks succeed because of human interaction, not a technical failure.

The pattern across both jurisdictions is consistent: the technology gaps matter, but the training gaps are what regulators keep coming back to. A firm that trains its people, tests its plans, and can show a record of having done both is in a materially different position than one relying on a policy document nobody's read. Explore Learnsignal's full range of CPD courses for more on building a defensible compliance training programme.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans