Standard cyber-security form to aid solicitors instructing barristers


Cyber security: Encouraging a culture of change

A standardised form for solicitors to assess the cyber-security arrangements of chambers they instruct has been launched by the Law Society and Bar Council.

Introducing it at the Law Society’s risk and compliance conference on Friday, Andrew McWhir – the society’s technology policy adviser – said the aim was to “promote a culture of change” and for both law firms and chambers, and chambers and their individual barristers, to have “earlier and more intelligent conversations” about security.

It should also reduce the administrative burden for both law firms and chambers. The National Cyber Security Centre was among those consulted on the questionnaire’s contents.

It does not cover barristers’ individually owned and managed devices, or IT services they procure directly.

After ascertaining what central IT systems a chambers provides for its barristers, the questionnaire features 25 ‘yes/no/don’t know’ questions on risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management, and supplier security.

The joint Law Society and Bar Council working group that drafted the document said it had been “mindful of problems associated with inappropriate and/or irrelevant questions being asked of barristers’ chambers”.

For that reason, it recommended avoiding supplementary questions where possible, or at least separating them from the primary questionnaire.

The working party recommended that chambers review their answers every six months.

At the conference, Bar Council policy and programmes manager Stuart McMillan said there had been a debate about whether to make training compulsory, but as the goal was a culture change, “we came down on the side of ‘encourage’”.

Law firms could still mandate training as part of their contractual arrangements with chambers.

Law Society president I Stephanie Boyce added: “We know that no one tool can offer complete protection against cyber threats, so firms will need to continue to take other precautions, but the development of the questionnaire is an important step in the right direction.”

Mark Fenhalls QC, chair of the Bar Council, said: “This valuable new tool will help reassure clients that data is kept as secure as possible.

“The joint work of the Law Society and the Bar Council will make it easier for solicitors and barristers to defend themselves against cyber attacks.”

The questionnaire can be found here and here.




Blog


The AI governance gap in law firms and why it matters now

A third of law firms are already using AI tools with no formal policy in place to govern how AI gets used, what data goes into it, or who’s accountable when something goes wrong.


Information isn’t oversight – lessons from the PM Law review

The PM Law review’s real findings perhaps point to a failure mode applying to any organisation sitting on scattered risk information.


AI can do the work but it cannot inherit the lawyer’s duty

What happens when lawyers delegate cognitive work to AI but remain personally responsible for judgements they may no longer have independently reasoned through?


Loading animation