top of page
web banner Fika Friday.png

Security Has Levels. Most Firms Are Standing On The Bottom One

  • Writer: Will Whawell
    Will Whawell
  • 10 minutes ago
  • 7 min read

Or Why "we're end-to-end encrypted" and "our vendor holds ISO 27001" are not the same thing as being secure


A number of headlines have caught my eye in the legal press of late. Aside from a seemingly endless litany of funders unable to invest wisely, sensibly, or both, it is the stories about security and AI that reliably bring a smile to my morning espresso.


Security for law firms is paramount. And yet the volume of open information sent daily by email never ceases to amaze me. Attachments left right and centre e-mails to the entire office including the office puppy just in case its missed.


Like all things in life, there are levels. Security is not a box that is either ticked or not. It is like having decent tyres on your car or a password that isnt your birthday. It is essential and I for one don’t want part used or worn tyres on my car. I want, indeed have, Pirelli All Seasons that just grip.


So what are the levels here :

Level 1 :what you personally leak


Start with the individual, because that is where most of it actually happens.


Contrary to popular folklore, WhatsApp being end-to-end encrypted does not make you invisible on it. Far From it. Indeed it can scrap away at your data to its hearts content. The content of your messages is protected. Your number, your profile photo, your status text and the simple fact that you are on the platform are not. Researchers at the University of Vienna and SBA Research showed last November that they could extract more than 100 million phone numbers an hour through contact discovery, along with profile photos and "about" text. Meta has since tightened the rate limiting, but the underlying point stands: encryption protects what you said, not who you were talking to.


I can vouch for that personally. On one matter I worked within a WhatsApp group with the client and a fee earner in it. Within days Facebook — a platform I barely touch, and then only for local travel groups, which are genuinely excellent — was cheerfully suggesting I add both of them as friends. Nobody had shared a thing. The numbers alone were enough. Now imagine that suggestion landing in front of someone on the other side of the matter.


Then there is working on the move. Yes, we need better wifi on trains. But working on open wifi with a totally open laptop and an unlocked phone, while the passenger behind you reads your screen, is not a triumph of agile working. And we have all heard them the booming voice stating the obvious as to being on the train and suggesting that the Part 36 Offer on Mrs Y vs Dunny on the Wold NHS Trust is £x .Your car is not much safer. China and the MoD spring to mind. Cars are for listening to music and enjoying the drive, concentrating also helps and can you really concentrate and have a conversation that is important.


Level two: what the firm assumes is handled


Move up a rung and you find the things everyone believes are somebody else's job.


Transferring documents needs to be secure. Password protection is fine, provided the password travels by a different route — a text message rather than the same email thread, or better still a phone call to a named person whose number you already know. Sending the password in the covering email is the digital equivalent of taping the key to the door asking the burglar to come in and steal your home.


I could go on at length about the lack of a Data Protection Officer at many firms. Strictly, a DPO is only mandatory where you are a public authority, or your core activities involve large-scale systematic monitoring or large-scale processing of special category data. Firms then spend considerable energy arguing they fall outside all three, which rather misses the point. Law firms handle vast quantities of sensitive data by definition, so whether or not a regulator would force your hand, the function needs to exist and needs to be competent. For most firms an external expert is the sensible answer — a route the Law Society accepts, with the caveat that you cannot outsource the compliance itself.


And IT departments need to wake up to the fact that there are alternatives to Richmond Washington State for shared drives.


Level three: the chain you bought and never checked


This is the rung that gets skipped almost universally. Your choice of provider is a security decision, and it is a two-way street.


Confirming that your vendor holds ISO 27001 does not cut it if you yourself believe Cyber Essentials is a security package. It is not. Cyber Essentials covers five technical control themes — firewalls, secure configuration, user access control, malware protection and security update management — assessed by self-completed questionnaire and renewed annually. A good baseline; not a management system. ISO 27001 runs to 93 controls across organisational, people, physical and technical themes, wrapped in an ISMS with risk treatment and a Statement of Applicability behind it.


More importantly: how many lawyers could tell you what 27001 actually requires? I mean many believe that the Chat GPT app on your desktop means you can use it talk to your system and your fully enclosed. No there are a few more stages to go through for it to be secure. And how many understand the difference between the consultant who helps you implement it and the body that issues the certificate? Those are two different organisations, deliberately — nobody can impartially audit work they sold you. The certificate that counts comes from a UKAS-accredited body. One from an unaccredited body is a nicely designed PDF.


Level four: understanding the standard, not filing it


Which brings me to the view I am most often challenged on in that there is still an arrogance within some legal circles who believe that anybody who hasnt work in a law firm can possibly understand how they work - sadly dear reader they still do exist.


ISO needs to be understood, not dismissed as something other people do. And in my view ISO is a considerably higher standard than Lexcel where information security is concerned. I am well versed in both as I have been there got the t-shirt and ISO far harder than Lexcel which is lightweight, so I am happy to state that.


The reasoning is structural, not tribal. Lexcel is a quality management standard across seven domains — client care, risk management, people management, structure and strategy, financial management, information management, and file and case management. Information management is one seventh of it, and assessment starts from a self-assessment checklist. ISO 27001 is about nothing but information security, audited in full by an accredited third party against a risk assessment you have to keep it alive in far more depth than Lexcel.


Lexcel is a good practice management standard. It was never designed to be an information security standard, and using it as one is a category error. And on that note it needs a huge update as well to bring it vaguely into the 2020s.


Why all of this matters more now


AI now sits so close to everything we do that data security should be at the front of every mind in the office. It isn't yet.


Training on systems is not a nice to have. It is essential — and increasingly it is an underwriting question. Professional indemnity insurers have made AI one of the biggest emerging PI themes of 2026: does the firm use AI, who reviews the output, is a human signing off the advice. Those answers shape both what an insurer will decline to pay out on and how it prices your premium. With hallucinated case law now a recurring court story and solicitors' PI capacity already under strain, that is not theoretical it is a hard reality.


There is a commercial angle too, and not the one the profession keeps worrying about. Fret less about AI killing the billable hour and more about how you intend to charge for the additional work AI generates — and hoovers up.


The horse, and the hobby


Andrew Macdonald — "Mac" — is Uber's president and chief operating officer. He told The Times this month that he has a six-year-old, a three-year-old and a one-and-a-half-year-old, and that "I don't think any of them are going to get driving licences". People will still ride horses, he reckons, because they enjoy them, rather than because a horse is how you get anywhere. Uber is putting $10 billion behind a fleet of at least 120,000 vehicles, and driverless trips are due on the London app within weeks. He even allows that governments outlawing driving is "probably not off the table" eventually.


The horse became a pastime once the car arrived. So:

"Doing anything nice today, dear?" "Yes, off to watch the 2.15 at the Old Bailey. That newly silked KC is performing."


I jest. Probably. Though am sure someone somewhere would like to address the jury with an "Are you not entertained" .We are safe from lawyers becoming a hobby thing, probably, though maybe only afforded by an elite , possibly if juniors salaries keep going up the way they do and AI can do so much of the leg work, and as a petrolhead I can promise you my car will always be considerably more than a fun hobby.


The serious version of the analogy is this: as AI becomes central to how we work, the devices we use and the places we use them need to be more controlled, not less. Convenience is running ahead of control, and the gap is where the loss happens.


Security starts with each person, following a pattern that is led from the top of the organisation to the bottom. Everyone needs to know what the measures are and, more importantly, why they exist. Get that right and the certificates take care of themselves.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page