Law Firm Cyber Attack Protection: Beyond Phishing

Law Firm Cyber Attack Protection: Beyond Phishing

Law firm cyber attack protection, as it is sold and as it is bought, nearly always means email: a filtering gateway, phishing simulations twice a year, a mandate fraud warning on the completion statement, and a cyber policy with a conveyancing fraud sub-limit. That half of the problem has had a decade of attention, and most UK firms have genuinely improved. The other half has had almost none. Nobody at renewal asks what happens when the client portal, the document exchange and the firm’s authoritative DNS all stop answering at three o’clock on a Friday afternoon.

That is the gap this piece is about: availability, how it fails, and how to buy and verify protection for it without taking a vendor’s word for anything.

What attackers actually target in a law firm, and the half nobody covers

The confidentiality attacks are familiar. Business email compromise, invoice and mandate redirection on completion funds, credential theft against Microsoft 365, ransomware that encrypts a file share and the backups sitting on the same domain. Firms have bought tooling and training against all of it, and insurers have pushed hard in the same direction.

Availability attacks sit outside that conversation entirely. They include volumetric floods against the public website; request-level attacks aimed at the login flow and search function of a client portal or document exchange; attacks on the authoritative nameservers that publish every hostname the firm uses; and extortion emails demanding payment in cryptocurrency to stop, sometimes preceded by a short demonstration burst against the marketing site.

Legal is an attractive target for both motives, and for different reasons. Work is deadline-bound, so an outage has a hard commercial edge that an attacker can time. Clients in litigation and corporate transactions are acutely sensitive to any sign that the firm is unstable. And high-value matters are often publicly visible, from planning objections to M&A announcements, which gives an aggrieved party a clear target and a clear window. One UK practice found its systems disrupted badly enough by a flood of inbound mail that it rebuilt its web security afterwards, which is a reminder that the trigger is not always sophisticated and rarely announces itself in advance.

Mapping your own exposure in an afternoon

Before anyone looks at a quote, build four columns. Every client-facing hostname the firm owns, including the ones marketing created and forgot; who hosts each one; who runs the DNS for the zone; and the name and mobile number of the person you would ring about it at two in the morning. Most firms cannot complete column four for at least one row. That blank is the finding.

The three surfaces law firm cyber attack protection has to cover

Network and transport floods

These are the attacks discussed in gigabits per second, occasionally terabits. A decent hosting provider or ISP absorbs the small end without telling you. What they will not do is carry a sustained attack aimed at your single public IP address, because at a certain point the economically rational move is to null-route you to protect everyone else on that segment. Blackholing is not mitigation. It is the provider agreeing with the attacker.

Application-layer attacks

This is where portals actually fall over. A few thousand well-chosen requests per second against a document search, a login endpoint that does a bcrypt hash on every attempt, or a matter-lookup page that runs an unindexed query, will exhaust the database long before anything registers on a bandwidth graph. Protection sized purely on gigabits of clean traffic will sail through a volumetric flood and still let the conveyancing portal die quietly. Understanding the gaps in application-layer defences matters more for a law firm than headline scrubbing capacity, because the valuable systems are all request-driven.

Authoritative DNS, the layer nobody has reviewed

Ask who controls the firm’s nameservers. In a worrying number of practices the answer is a web agency’s registrar account, sometimes a former IT supplier’s, on a single DNS provider, with no secondary nameservers and no monitoring. Lose that and nothing else in the stack matters: the portal, webmail, the marketing site and any MX-dependent mail flow all stop resolving at the same moment, and the shiny proxy in front of the website never sees a packet. Redundancy here is cheap and badly under-bought; a second authoritative DNS provider is usually the highest-value hour of work available to a firm this week.

Third-party dependencies you do not control

Practice management SaaS, e-signature platforms, hosted document portals and card payment pages all inherit someone else’s protection posture. Your Lexcel file says you have business continuity; your supplier’s contract may say they will use reasonable endeavours. Those are not the same sentence. Put the question in writing to each supplier at renewal and keep the answer.

Why the proxy gets bypassed: origin IP leakage, not attack size

When a protected site goes down, the cause is far more often that the attacker found the origin than that they out-muscled the scrubbing network. The firm’s real server address leaks through routes nobody audits: the MX record, SPF entries listing the mail server, historical DNS records archived by passive DNS services, TLS certificate transparency logs that publish every hostname you have ever certificated, a webmail or VPN endpoint sitting on the same /24 as the web server, or a staging site at new.firmname.co.uk that resolves straight to the origin and has done since 2021.

The test is one question, and it is a yes or no. Does the origin accept TCP connections on 80 and 443 from anything other than the protection provider’s published IP ranges? If yes, the protection in front of the site is decorative. Three fixes, in order: allow-list the provider’s ranges at the host firewall or security group and drop everything else; validate the host header and a shared secret header at the web server so direct hits are rejected; and rotate the origin IP address after onboarding, because the old one is already in a passive DNS database somewhere.

Attack volume is the part vendors like to talk about. Reachability is the part that decides the outcome.

Extortion and the first hour

Triage before escalation

Not every Friday outage is an attack. A bad deployment, an expired certificate, a hosting provider’s own incident and a legitimate traffic spike from a press mention all look identical from reception. Check from outside the network, not from a machine on the office LAN; compare the web server’s request logs against the load balancer’s; look at whether the source addresses are geographically scattered and hitting one expensive URL repeatedly. Having a short, written routine to tell a DDoS from an ordinary outage saves the twenty minutes that usually get burned arguing.

If a ransom demand arrives

Paying achieves nothing reliable. Payment marks the firm as responsive to pressure, and the group that sent the email may not be the group capable of stopping the traffic. Preserve instead: the email with full headers, the exact timestamps of the first and peak traffic, sample requests and source data from the logs, and the provider’s post-attack report with its vector breakdown. That evidence is what makes any later legal or law enforcement route viable rather than theoretical.

Reporting duties

Four obligations sit in different places and a firm should know which apply before the day arrives:

  • The SRA Standards and Regulations require prompt reporting of serious breaches of the regulatory arrangements, which can include an incident that materially affects the firm’s ability to act for clients;
  • UK GDPR requires notification to the Information Commissioner’s Office within 72 hours of becoming aware of a personal data breach where there is a risk to people’s rights and freedoms, and the ICO is explicit that a loss of availability counts as a breach, not just unauthorised disclosure;
  • Clients on live matters need telling, in plain terms, where a deadline or completion is affected, and that message is better coming from the partner than from an estate agent;
  • Action Fraud takes the crime report, and the National Cyber Security Centre should be notified where the incident is significant.

Denial of service is a criminal offence in the UK under section 3 of the Computer Misuse Act 1990, which covers unauthorised acts intended to impair the operation of a computer. Useful to know, and worth stating to staff who assume this is a grey area. Realistically it does not shorten your outage by a second, and attribution is slow, so treat the criminal route as evidence preservation rather than recovery.

Buying protection: deployment models, managed meaning, and the cost case

Three models, and the choice is mostly determined by what the firm owns. Reverse proxy suits the common case: one marketing site, a client portal, a document exchange, all behind DNS you can repoint, with no IP space of your own. BGP scrubbing is for firms announcing their own prefix, typically those running an on-premises data room or legacy case system, and it protects everything in the range including mail and VPN. Hosting-level filtering is the cheapest and the weakest; it tends to stop at the volumetric tier and leaves the application layer to you.

On always-on versus on-demand: on-demand diversion is cheaper and adds a detection window plus a BGP announcement and propagation window before mitigation begins. For a firm whose work turns on 16:00 filing cut-offs and completion days, those minutes are a commercial decision, not a technical footnote. Decide now who is authorised to trigger a diversion at 23:00 on a Sunday without a partner’s sign-off, and write the name in the runbook.

What “managed”has to mean in the contract

Managed is a word, not a service level. The dividing line is simple. If a human on the provider’s side is not empowered to change a rate limit or a WAF rule at 16:40 on a Friday while the conveyancing portal is being hammered, without waiting for someone at the firm to raise a ticket, you have bought monitoring, not management. Get four things in writing: the onboarding and rule tuning done before the first attack rather than during it; named escalation contacts on both sides with out-of-hours numbers; explicit authority to change policy mid-incident; and a written post-attack report with timestamps, vectors and actions taken.

The business case, built from downtime rather than fear

Do the arithmetic openly. Take the fee earners who would be unable to work for an afternoon, multiply by the hours lost and by your own charge-out rates, and you have the cost of that single incident in lost recoverable time, before you count a missed completion, an abortive lender drawdown or the partner hours spent on client calls. Compare that number to an annual managed protection quote. Do not compare quotes to each other, which is how firms end up buying the cheapest version of the wrong thing. The structure of UK pricing varies by model, so check current figures with providers directly rather than relying on anything published months ago.

Judging providers on evidence rather than sales decks

Much of what is marketed in the UK as DDoS-protected hosting resells someone else’s scrubbing network. That is not disqualifying, but you need to know it. Ask whose capacity you are buying, which points of presence serve UK traffic (London is not a complete answer if the only nodes are in Frankfurt and Amsterdam), and who physically answers the phone at three in the morning, because that determines both the real capacity and who is accountable mid-incident.

Then press on the SLA. What does it pay out, what triggers it, how is time-to-mitigate measured, and who measures it? A service credit worth one month of fees against a lost afternoon of fee earner time is a gesture, not a remedy. And ask for a redacted report from a real incident. Report quality tells you more about the operations team than any capacity figure on a slide: whether they identified vectors, when a human intervened, and what they changed.

Run this short list alongside Cyber Essentials, Lexcel and the insurer’s questionnaire. Note that Cyber Essentials and Cyber Essentials Plus, for all their value, assess firewalls, secure configuration, access control, malware protection and update management. None of those five controls test whether your site stays reachable under attack. Availability is the box nobody ticks because nobody asks, which is precisely why it is still the weak point in most firms’ answers. Effective law firm cyber attack protection closes it by naming the surfaces, locking the origin, and putting a human with authority on the other end of the phone before the first demand email arrives. Background reading on how these attacks are structured and resourced is collected across DDoSInfo, and the case of the firm that hardened its web security after an attack is a reasonable place to start with partners who need convincing.

Frequently Asked Questions

What does law firm cyber attack protection need to cover beyond email security?

Availability of every client-facing system: the public website, client login portals, document exchange, and the authoritative DNS that publishes all of them. Email controls address confidentiality and fraud; they do nothing if the portal is unreachable on a completion day. Treat network floods, application-layer request attacks and DNS as three separate surfaces with separate owners.

Can a small law firm’s website really be taken offline by a DDoS attack?

Yes, and it rarely takes a large attack. A booter service costs very little and a few thousand requests per second aimed at a login page or document search can exhaust the database behind it. Smaller firms are often more exposed because their site and portal share one modest origin server with no filtering in front of it.

What should a firm do if it receives a ransom demand threatening to take its site down?

Do not pay and do not reply. Preserve the email with full headers, confirm whether an attack is actually in progress, notify your protection provider and hosting supplier, and report to Action Fraud and, if the incident is significant, the NCSC. Payment marks the firm as responsive to pressure and offers no reliable guarantee the traffic stops.

Does a law firm have to report a denial of service attack to the SRA or the ICO?

It depends on effect, not on the label. The SRA Standards and Regulations require prompt reporting of serious breaches, which can include an incident that materially affects the firm’s ability to act for clients. Separately, the ICO treats loss of availability of personal data as a personal data breach, so a 72-hour notification may be required where there is a risk to individuals. Take advice from the COLP rather than deciding on the day.

Is always-on or on-demand mitigation better for a firm with court filing deadlines?

Always-on, in most cases. On-demand diversion is cheaper but adds detection, announcement and propagation time before mitigation starts, and those minutes land badly against a filing cut-off or a lender’s close of business. If budget forces on-demand, agree the out-of-hours authorisation route in advance and name the person who can trigger it without a partner’s approval.

How much should a UK firm expect to spend on managed DDoS protection?

Pricing varies by model: reverse proxy plans are usually billed per protected hostname or per volume of clean traffic, while BGP scrubbing is priced against committed capacity and the size of the prefix. Get current quotes directly, since published figures date quickly. The useful comparison is not quote against quote but quote against your own downtime cost, calculated from fee earner hours lost in a single three-hour outage.