Why Conveyancing Firms Are in the Crosshairs
Conveyancing cyber security has become one of the most pressing concerns for small and mid-sized law firms across the Home Counties — and for good reason. Cybercriminals know that conveyancing transactions involve large sums moving quickly, under time pressure, between parties who often communicate almost entirely by email. That combination makes your firm a genuinely attractive target, regardless of how modest your headcount is.
Firms with 15 to 75 staff are particularly exposed. You handle high-value client data and significant financial transactions, but you rarely have a dedicated IT or security team watching over your systems. That gap is exactly what attackers look for.
This article sets out the specific threats conveyancing firms face, what good protection actually looks like in practice, and how to assess where your own firm stands right now.
What Attackers Are Actually Doing
The most common attack type targeting conveyancing firms is business email compromise (BEC) — sometimes called Friday afternoon fraud. A criminal intercepts or spoofs email communication, inserts themselves into a thread, and redirects completion funds to a fraudulent account. By the time anyone realises, the money is gone and the damage is done.
These attacks do not require sophisticated hacking. Often, the criminal has had quiet access to an email account for weeks before acting. They read threads, learn the terminology, and wait for the right moment.
Identity theft is also a growing threat. Conveyancing files contain everything a fraudster needs: names, addresses, financial details, proof of identity documents. If that data is compromised, your clients bear the consequences — and your firm faces the regulatory fallout.
The National Cyber Security Centre publishes guidance specifically on email fraud and impersonation attacks. It is worth a read if you have not looked at it recently.
The Regulatory Consequences Are Real
A data breach at a conveyancing firm is not just a reputational problem. It triggers a chain of regulatory obligations that can be difficult to manage without specialist support.
The SRA expects firms to have appropriate cybersecurity measures in place and to report certain types of breach promptly. Failure to do so — or being found to have operated without adequate controls — can result in sanctions, fines, or intervention. The Information Commissioner’s Office also requires notification of personal data breaches that meet a certain threshold, usually within 72 hours of becoming aware.
Beyond the regulators, there is the question of client negligence claims. If client funds are misdirected because your email environment was compromised, and it can be shown that reasonable security measures were not in place, your exposure is significant. Professional indemnity insurance will not always cover losses where controls were clearly absent.
This is the environment in which conveyancing firms are operating. The good news is that most of the effective defences are not complicated or expensive to put in place.
What Conveyancing Cyber Security Actually Requires
Most small and mid-sized conveyancing firms use Microsoft 365 for email and document management. That is a sensible choice — but the default settings that come out of the box are not enough to protect a firm handling the kind of transactions you deal with.
Here is what a properly secured Microsoft 365 environment for a conveyancing firm should include:
Multi-factor authentication (MFA) on every account. This is the single most effective control against account takeover. If a password is compromised, MFA means an attacker still cannot get in without a second factor. It should be mandatory for everyone — partners, fee earners, and support staff alike.
Anti-spoofing and email authentication protocols. SPF, DKIM, and DMARC records tell receiving mail servers whether an email genuinely came from your domain. Without them, it is trivially easy for a criminal to send an email that appears to come from your firm. Many firms have these either missing or misconfigured.
Conditional access policies. These control who can log in to your systems, from where, and on what device. They can block login attempts from unexpected countries or unmanaged devices, which is particularly important if you have fee earners working remotely.
Audit logging and alerting. If a mailbox is accessed from an unusual location, or a large volume of emails are forwarded to an external address, you want to know about it. Microsoft 365 can generate these alerts — but only if someone has set them up and is monitoring them.
Regular security reviews. Your configuration today may be appropriate. In six months, after a software update or a new member of staff joins, it may not be. Security is not a one-time project.
For more detail on what this looks like in practice for firms of your size, our article on why conveyancing firms in Surrey and the Home Counties are being targeted by cyber criminals covers the threat landscape in more depth.
The Remote Working Risk
Post-pandemic working patterns have added a layer of complexity that many conveyancing firms have not fully addressed. When a fee earner logs in from home on a personal laptop, over a home broadband connection, the security controls that might protect them in the office often do not apply.
Unmanaged personal devices may not have up-to-date antivirus software, may be shared with other household members, and may have software installed that introduces vulnerabilities. If that device is used to access client files or email, it becomes part of your security perimeter — whether you intended it to or not.
Device management tools within Microsoft 365 can enforce minimum security standards on any device used to access firm data, including personal devices. This is not about being intrusive — it is about ensuring that a fee earner working from their kitchen table does not inadvertently become the weakest link in your security chain.
What a Freelance or Break-Fix Arrangement Cannot Provide
Many smaller conveyancing firms rely on a single freelance technician or a break-fix arrangement for IT support. That model works reasonably well for fixing a printer or setting up a new laptop. It is not designed to protect you from an active, motivated attacker.
A freelance technician is typically reactive. They respond when something goes wrong. Conveyancing cyber security requires proactive monitoring — someone who notices that a mailbox has been behaving unusually before the fraudulent bank details email is sent, not after.
There is also the question of continuity. If your freelance contact is unavailable on a completion day when something goes wrong, the consequences fall on your staff and your clients. A managed IT support arrangement provides a team, not a single point of failure.
How to Assess Where Your Firm Stands
If you are not sure how well-protected your Microsoft 365 environment currently is, there are a few straightforward questions worth asking:
- Is multi-factor authentication switched on for every user, with no exceptions?
- Do you know whether your email authentication records (SPF, DKIM, DMARC) are correctly configured?
- Does anyone review security alerts from your Microsoft 365 environment?
- Do you have a written procedure for what happens if you suspect an account has been compromised?
- When did someone last check whether former staff members still have active accounts?
If the answer to any of those is "I don’t know" or "I’m not sure", that is not unusual — but it is worth addressing before you find out the hard way.
The National Cyber Security Centre’s Small Business Guide is a practical starting point for any firm that wants to take stock without getting lost in technical detail.
A Practical First Step
Conveyancing firms across the Home Counties are managing real and growing cyber risk, often without the internal resource to do much about it. The firms that handle this well are not necessarily spending more — they are making sure the tools they already have are properly configured and actively monitored.
If you would like an independent view of where your firm currently stands, Computer Care offers a free security posture review for conveyancing firms in the region. It is not a sales pitch disguised as an audit — it is a practical assessment of your Microsoft 365 environment, with a clear summary of what is working well and what is not.
If that sounds useful, get in touch and we can take it from there at whatever pace suits you.
Part of our guide to Why Conveyancing Firms in Surrey and the Home Counties Are Being Targeted by Cyber Criminals.
