The five controls map cleanly onto how a modern firm works. Firewalls and secure configuration cover your office network and any hosted practice management environment. Security update management is where legacy legal software bites, unsupported Windows servers running an old PMS are the most common blocker we see, and under the 2026 rules they are an automatic failure if left in scope. User access control means fee earners work without admin rights and leavers lose access on their last day, not at the next IT visit. Malware protection and enforced MFA on email close off the phishing and payment-fraud route that causes most legal-sector losses.
Cloud-hosted case management platforms count as cloud services under the 2026 definition: they belong on your asset list, and MFA must be enabled where the platform supports it.
For most firms, the certification project doubles as the risk-reduction project they already knew they needed, with a certificate at the end that clients recognise.
Attackers target law firms because the economics are excellent: a single compromised mailbox during a conveyancing transaction can redirect a six-figure completion payment, and privileged material creates ransomware leverage most businesses don't face. Client account rules mean losses are not just financial but regulatory.
None of the common attacks are sophisticated. They exploit exactly the gaps the five controls close: no MFA on email, stale patching, everyone an admin, and no control over the devices partners use at home. That is why buyers of legal services now check for the certificate.
Every one of these is fixable in weeks, and every one has caused a real UK firm a real loss. Certification forces the fixes onto a deadline.
Register your interest for a confidential readiness review against the 2026 requirements. We’ll contact you the day our certification service goes live.