The legal sector keeps turning up in Australia's breach reports. Here's why
Twice a year, the Office of the Australian Information Commissioner publishes a report on data breaches: how many, who, and how. It’s one of the more useful documents in Australian cyber security, because it’s not vendor marketing or scare stats. It’s what actually happened. And the sector grouping that includes law firms keeps turning up near the top of it.
In the January to June 2024 report, the OAIC recorded 527 breach notifications, the highest in three and a half years. Health and government led the list, and the grouping of legal, accounting and management services was once again among the top five sectors reporting breaches (OAIC Notifiable Data Breaches Report, January to June 2024). Law firms don’t appear there by chance. But the reasons they do are also the reasons it’s very fixable.
Why law firms keep showing up
Three things put a firm in the frame:
- You hold a concentration of the most sensitive data there is. Financial records, family matters, disputes, identity documents, commercial secrets. A single firm can hold more valuable personal information than a business ten times its size. That makes you a target worth the effort.
- Money moves through you. Settlement funds, trust accounts, large transfers. Criminals follow money, and a firm sits right on top of it.
- The basics often lag the obligations. Law is a demanding profession, and IT security is rarely anyone’s day job inside a practice. The duty to protect client information is high. The defences sometimes haven’t caught up.
The good news is in the same data
Here’s the part worth sitting with. When you look at how those breaches happen, they’re not exotic. In that same report, two thirds (67%) came from malicious or criminal attacks, and most of those were ordinary cyber incidents. Another 30% came down to plain human error. And 12% of all breaches started with phishing, someone clicking a link or opening an attachment they shouldn’t have.
None of that is sophisticated. A stolen password, a convincing fake email, a file sent to the wrong person. The attacks that put firms in the report are, overwhelmingly, the ones the basics are designed to stop. Which means staying out of the report is mostly within your control.
What actually keeps a firm out of it
You don’t need a security department. You need the unglamorous things done consistently:
- Multi-factor authentication everywhere. It’s the single most effective defence against the stolen-password attacks that dominate the malicious-attack numbers. A leaked password alone won’t get anyone in.
- Staff who can spot a phish. That 12% is your team’s inboxes. A little training, and a culture where it’s fine to double-check a suspicious email, removes a surprising share of the risk.
- Least-privilege access. Not everyone needs to reach everything. When access matches the role, a single compromised account can’t open the whole firm.
- Encryption and tested backups. So that if something does get out or get locked up, the damage is contained and you can recover.
- A breach plan you’ve actually read. If client information is exposed, you have duties under the Notifiable Data Breaches scheme, and likely to clients and your regulator on top. Knowing the steps in advance turns a crisis into a procedure. This isn’t legal advice on your specific obligations, but it’s a plan worth having before you need it.
The takeaway
The breach report isn’t a list of unlucky firms. It’s a list of the same handful of preventable causes, repeating. The practices that stay off it aren’t the ones with the biggest budgets. They’re the ones that turned on multi-factor authentication, trained their people, tightened access, and kept those things running. Dull work, and it’s exactly what keeps your firm’s name out of next year’s report.
Want to know where your firm really stands?
Book a free Security X-Ray. In a few days you'll see how your firm tracks against the basics that keep practices out of the breach reports, and the simplest gaps to close.