Is Your Microsoft 365 Setup Actually Protecting Your Law Firm — or Leaving Client Data Exposed?

Business Evolution Radar Chart

Is Your Microsoft 365 Setup Actually Protecting Your Law Firm — or Leaving Client Data Exposed?

Microsoft 365 security for law firms is not the same thing as simply having Microsoft 365. That distinction matters more than most managing partners realise — and cybercriminals are counting on the confusion.

Conveyancing practices across Surrey and the Home Counties are being targeted with increasing regularity. Fraudsters know that property transactions involve large sums moving quickly, time-pressured fee earners, and email as the primary communication channel. That combination is, from an attacker’s perspective, close to ideal.

Having Microsoft 365 Is Not the Same as Being Protected

When a firm migrates to Microsoft 365, the default configuration is built for ease of use, not security. Microsoft does a reasonable job of protecting its own infrastructure. What it cannot do is make good decisions for your firm about who should have access to what, how login attempts are handled, or whether a suspicious email should reach your fee earner’s inbox.

Those decisions belong to whoever set up your tenancy. If that was a generalist IT supplier or a freelance technician without specific Microsoft security experience, there is a reasonable chance the hardening work was never done.

What ‘Default’ Actually Looks Like in Practice

A default Microsoft 365 setup typically has multi-factor authentication switched off or inconsistently applied. Legacy authentication protocols — older connection methods that bypass modern security controls — are often left enabled. Shared mailboxes may have weak or no credential requirements. Audit logging, which you would need in the event of a breach, may not be turned on at all.

None of this is unusual. It is actually the norm for smaller firms that have migrated without a structured security review. It just means that a credential stolen through a phishing email can, in many cases, open the door to your entire Office environment.

The Threats Targeting Conveyancing Firms Right Now

The most common attack against conveyancing practices is Business Email Compromise (BEC). A fraudster gains access to a legitimate email account — yours, your client’s, or a third party’s — and uses it to intercept or redirect a completion-day bank transfer. Because the email comes from a real account, it looks completely genuine.

Identity theft is the other significant risk. Client data gathered during the conveyancing process — proof of identity, bank account details, property information — has real value on criminal markets. A firm holding that data without adequate controls is a target worth pursuing.

For more context on why firms of this size and type are being singled out, it is worth reading our piece on why conveyancing firms in Surrey and the Home Counties are being targeted by cyber criminals.

What Microsoft 365 Security for Law Firms Should Actually Include

A properly hardened Microsoft 365 environment for a conveyancing firm looks quite different from a default one. The following are the controls that matter most.

Multi-factor authentication (MFA), applied universally. Every account, including shared mailboxes and admin accounts, should require a second form of verification. No exceptions. This single control blocks the vast majority of credential-based attacks.

Conditional access policies. These allow you to set rules around who can access your environment, from where, and on what kind of device. A login attempt from an unrecognised country at 3am can be blocked automatically rather than quietly allowed through.

Blocking legacy authentication. Older protocols like IMAP and SMTP authentication do not support MFA. Leaving them enabled creates a back door. They should be disabled unless there is a specific, documented reason to keep them.

Microsoft Defender for Office 365. The standard Microsoft 365 licence includes basic spam filtering. A more complete security configuration adds protection against phishing, malicious attachments, and unsafe links — the delivery mechanisms used in most BEC attacks.

Audit logging and alerting. If someone does access your environment without authorisation, you need to know about it — ideally in real time, not three months later. Audit logs also matter for SRA compliance and any subsequent investigation.

Privileged access management. Global admin accounts should be tightly controlled and used only when necessary. Too many firms have multiple accounts with full administrative rights that are used for day-to-day work.

SRA Expectations and What They Mean for Your Configuration

The Solicitors Regulation Authority expects firms to have appropriate systems and controls in place to protect client data and money. The SRA’s guidance on cybersecurity is not prescriptive about specific technical controls, but it is clear that firms bear responsibility for the security of client information and for any financial loss that results from a breach.

That responsibility extends to your IT configuration. If your Microsoft 365 tenancy was set up without adequate security controls and a client suffers a financial loss as a result, the question of whether your firm took reasonable steps will be examined carefully.

The National Cyber Security Centre publishes practical guidance for organisations handling sensitive data, including a Cyber Essentials framework that is a reasonable starting point for any small firm. It is free to use and worth reviewing.

Why Remote and Hybrid Working Increases the Risk

Most conveyancing firms now have fee earners working from home at least part of the week. That is not a problem in itself, but it does expand the attack surface if the underlying Microsoft 365 configuration has not kept pace.

A fee earner logging in from a personal laptop on a home network, with no MFA and no conditional access policy in place, is essentially accessing your client data with no meaningful security controls between them and the internet. If their credentials were harvested by a phishing email — and those emails are increasingly convincing — an attacker has everything they need.

This is one of the reasons microsoft 365 security for law firms needs to be treated as an ongoing discipline, not a one-time migration task.

What a Security Posture Review Involves

A security posture review is a structured assessment of your Microsoft 365 environment against a defined set of controls. It is not a sales exercise. The output is a clear picture of what is configured correctly, what is not, and what the practical risk of each gap looks like.

For a firm of 15-50 people using Microsoft 365, a thorough review typically covers authentication settings, email security configuration, user permissions and admin access, data loss prevention settings, and audit logging status.

The goal is to give you an honest view of where you stand — before an incident forces the question.

A Common Scenario Worth Recognising

A fee earner receives an email that appears to come from a client, asking for updated bank details before completion. The email address looks right. The tone is familiar. The request seems routine.

In a firm with properly configured email security and staff awareness training, that email is either blocked before it arrives or recognised as suspicious. In a firm running default Microsoft 365 settings, it lands in the inbox and looks like any other message.

The financial and reputational consequences of acting on it are significant. The SRA will want to understand what controls were in place. The client will want to know why their money is gone. Neither conversation is one any managing partner wants to have.

Microsoft 365 security for law firms is the difference between those two outcomes.

What Good IT Support Looks Like in This Context

Proactive, sector-aware IT support means your Microsoft 365 environment is monitored, maintained, and reviewed against current threat intelligence — not just fixed when something goes wrong. It means someone is watching for unusual login activity, keeping your security configuration current as Microsoft releases new controls, and helping your team stay alert to the latest phishing techniques.

That is a different proposition from a break-fix arrangement or a generalist freelancer. It is also a more manageable one for a practice manager who has enough on their plate without becoming a cybersecurity specialist.

Our process starts with understanding your current environment properly — evaluating what you have, reviewing what needs to change, and working with you on decisions that are grounded in your firm’s actual risk, not generic best practice.


If you would find it useful, we offer a free Microsoft 365 security posture review for conveyancing firms in Surrey and the surrounding area. No commitment, no sales pitch — just a clear picture of where your current setup stands and what, if anything, you would want to address.

If that is something worth a conversation, feel free to get in touch with the team at Computer Care.

Part of our guide to Why Conveyancing Firms in Surrey and the Home Counties Are Being Targeted by Cyber Criminals.