What the VLSB+C cyber security expectations mean for your law firm
If you run a Victorian law firm, you may have seen mention of the Victorian Legal Services Board and Commissioner (VLSB+C) and its cyber security expectations — and wondered what, in plain terms, you’re actually expected to do.
Here’s the short version, without the jargon.
What changed
In 2024 the VLSB+C set out minimum cyber security expectations for the firms it regulates. They’re not a long technical standard — they describe the basics any firm holding client money and confidential matters should have in place: things like multi-factor sign-in, reliable backups, staff who can spot a scam email, and a plan for when something goes wrong.
The part that gets principals’ attention: the VLSB+C has been clear that, depending on the circumstances, failing to manage cyber risks can be relevant to whether conduct amounts to unsatisfactory professional conduct or professional misconduct. In other words, this sits alongside your other professional obligations — it isn’t just an “IT problem.”
This article explains the expectations in general terms. It isn’t legal advice on your specific obligations — for that, speak to your professional body or adviser.
What they actually cover
The expectations map closely to a handful of practical controls:
- Multi-factor authentication (MFA) on email and key systems — so a stolen password isn’t enough to get in.
- Backups you could actually restore from — tested, not just assumed.
- Staff awareness — your team can recognise phishing emails and fake invoice or settlement requests.
- A written incident response plan — so if you’re breached or lose data, you know what to do and who to notify.
- Sensible access control — people can only reach what they need, and a departing staff member’s access is removed promptly.
If those sound familiar, it’s because they’re the same fundamentals behind a recognised standard like SMB1001 — which is a practical way to show, with evidence, that you take security seriously.
Why “we think we’re fine” is the real risk
Most firms we meet aren’t careless. They’re busy, and no one has ever shown them where they actually stand. That uncertainty is the problem — because if you can’t answer an insurer’s renewal question or a client’s “how do you protect my matter?” with evidence, you’re exposed whether or not anything has gone wrong yet.
No one can promise you’ll never be breached. What you can do is make sure the sensible controls are genuinely in place, kept up to date, and provable — so you can show a client, an insurer, or the regulator that you’ve done the right things.
A simple way to find out where you stand
You don’t have to guess. The fastest starting point is a baseline:
- See where you are today — a quick, no-system-access review against these controls.
- Close the gaps — done-for-you, scheduled around your matters so your fee-earners aren’t disrupted.
- Keep it provable — a live security status you can show clients and insurers, kept current all year.
That’s exactly what our cyber security service for law firms is built around — and it starts with a free Security X-Ray.
Not sure where your firm stands?
Book a free Security X-Ray. In a few days you'll know exactly how your firm tracks against the expectations — and the simplest way to close the gaps.