For Melbourne law firms · Local support you can actually reach
For Melbourne law firms with 3–30 lawyers

Be the law firm that's provably more secure than your competitors.

Managed cyber security, SMB1001 Gold and VLSB+C-aligned compliance for Melbourne law firms — with live proof you can show clients and insurers. We do the work; your fee-earners don't lift a finger. You'll walk away with a prioritised fix-list to keep — even if we never work together.

We take on a limited number of law firms each quarter, so every setup is done properly.

See how it works
  • VLSB+C-aligned
  • SMB1001 Gold-ready
  • Microsoft 365 specialists
Gold-ready
Show it to clients
Where we stand

You're accountable for security you can't actually see.

Most principals we meet aren't careless — they're busy, and no one has ever shown them where their firm really stands. That uncertainty is the problem.

You don't actually know if you're secure

You have antivirus and a backup "somewhere", but no clear answer to a simple question: are we protected, yes or no?

A breach could end client trust

Trust accounts, settlements and confidential matters make a firm a target. One incident — or one client learning of it — can undo years of reputation.

The regulator now expects more

The VLSB+C has set minimum cybersecurity expectations. Gaps can be relevant to a professional-conduct assessment — and "I didn't know" isn't a comfortable answer.

Insurers keep asking questions you can't answer

Renewal forms now ask about MFA, backups and training. Guessing on a proposal form is uncomfortable — and potentially costly at claim time.

$56,600
Average cost of a cybercrime report for a small business (up 14%)
~6min
How often a cybercrime is reported in Australia
~$24,000
Indicative cost of a single day down — 8 fee-earners × ~$400/hr, billing lost

Source: ASD Annual Cyber Threat Report 2024–25 (self-reported averages). Downtime figure illustrative only.

Free · 60 seconds · no login

See your firm's exposure in 60 seconds.

Enter your firm's website and we'll show you what criminals and clients can already see — email spoofing risk, website encryption, public exposure. Instant, plain-English result.

Annual sector research · Edition 1

We checked 1,252 Melbourne law firms. Most can be spoofed today.

Before you take our word for any of this, read the evidence. We ran the same twelve public checks against every Melbourne law firm on the Victorian register, without touching a single system. Three firms in four have not switched on the setting that blocks email pretending to come from their domain.

Read the free report →

Passive, external only. No firm is named.

76.9%

had not enforced protection against email that spoofs their own domain

958 of 1,246 firms · September 2026

The VLSB+C expectations, in plain English

Your regulator has drawn a line. We help you stay on the right side of it.

In 2024 the Victorian Legal Services Board and Commissioner (VLSB+C) set out minimum cybersecurity expectations for the firms it regulates — covering the basics like multi-factor sign-in, backups, staff awareness and having a plan for an incident.

The VLSB+C has been clear that, depending on the circumstances, failing to manage cyber risks can be relevant to whether conduct amounts to unsatisfactory professional conduct or professional misconduct. This isn't about fear — it's about being able to say, with evidence, that you've done the sensible things.

Source: Victorian Legal Services Board + Commissioner, minimum cybersecurity expectations (2024). We help you meet them; we don't provide legal advice on your obligations.

Recommended by the profession

SMB1001 isn't just our recommendation. The Queensland Law Society supports the standard and urges member firms to reach Gold certification — the level we get you to.

Read the Queensland Law Society's position →

What "meeting the expectations" looks like

Multi-factor sign-in on email and key systems Tested backups you could actually restore from Staff who can spot a scam email A written plan for what to do if something goes wrong Evidence you can hand to a regulator, client or insurer
"Law firms have an ethical duty to take reasonable steps to protect the confidentiality of client information. Unfortunately, criminals won't wait for the day you have time to sort it out — and being a small practice is no defence. SMB1001 provides an accessible, cost-effective foundation to strengthen your firm's cybersecurity position and demonstrate your commitment to client care."
How it works

Three steps. We carry the load.

From "I'm not sure where we stand" to "here's our security, on a screen" — without tying up your fee-earners.

1

The free Security X-Ray

In a few days we baseline your firm against a recognised standard and show you exactly where you're exposed — no system disruption, almost nothing needed from your team.

2

We remediate — done-for-you

We close the gaps: multi-factor sign-in, backups, email protection, training, the written plans. You approve; we do the work and explain it in plain English.

3

Live proof, kept current

Your security lands in Kevin — a portal that shows how protected you are and lets you prove it at a click. We keep it managed all year, not just on day one.

Yours alone — never shared
Meet Kevin — your proof

See your security — and prove it to anyone.

Most providers ask you to take their word for it. Kevin shows you — a live scorecard of how aligned your firm is to the standard, what's done, and what's next, ready to share with a client or insurer.

  • See your alignment score and gaps at a glance
  • Prove it to clients and insurers at the click of a button
  • Watch the items we're handling tick over to "verified"
  • Your data stays yours — never visible to any other firm
The Protected Practice

The Protected Practice — everything a small firm needs to be secure, and prove it.

Two levels, both done-for-you and managed all year. Most firms choose Gold, because that's the level the VLSB+C expectations and insurer questions point to.

What you get Silver→ SMB1001 Silver Gold→ SMB1001 Gold + VLSB+CRecommended
Security X-RayYour baseline and prioritised plan
Managed IT FoundationHelpdesk, Microsoft 365, devices
Identity LockdownMulti-factor sign-in, password manager, access control Core
Data ShieldBackup & recovery you can rely on
Payment Fraud ShieldStops scammers posing as your firm by email Core
Human FirewallStaff security-awareness training
Incident ReadyA written plan for if something goes wrong
Compliance & Insurance EngineCertification, evidence pack, renewal answers Silver Gold + VLSB+C
Kevin — live security portalYour proof, kept current all year

"Core" means the everyday essentials are in place; Gold extends them across all your key apps and adds the proactive controls the standard and the regulator expect. Pricing is tailored to your firm's size — you'll have it in writing after your X-Ray.

Firms that complete their Security X-Ray and come aboard become a Protected Practice — secure, SMB1001 Gold-certified, and able to prove it to clients, insurers and the regulator.

Become a Protected Practice.

Our guarantee

We put our guarantee in writing.

Gold-ready by the date we agree, or we keep going

We'll get you Gold-ready (implemented and self-attested to SMB1001 Level 3) by a date we agree in writing. If we miss it, we keep working at no extra cost until you are.

It's a two-way street

We guarantee everything within our control, and you complete the few steps only the firm can do: timely access and approvals, and the items the standard requires of you directly, such as obtaining cyber insurance and your team finishing the short training. Where a control depends on a third party's decision, such as an insurer issuing a policy, we'll get you fully ready to meet it, but we can't guarantee someone else's yes.

A note we'd rather make than skip: no one can promise you'll never be breached, and SMB1001 Gold is self-attested by a director, not independently audited. What we promise is that the controls are genuinely in place and actively managed, and that you can prove it.

Why firms trust us

We don't just recommend Gold. We live it.

Unity Systems is SMB1001 Gold certified ourselves — so the standard we hold your firm to is the one we hold our own.

Trusted by Melbourne law firms

IronGroup Lawyers By George Legal
We're SMB1001 Gold certified, so we've been through exactly what we'll take your firm through — and we keep our own controls current all year. Certification at Silver and above must be done with a provider certified to the same level. We're certified at Gold — so we can take you there.
Unity Systems Unity SystemsSMB1001 Gold certified
Microsoft 365 specialists SMB1001 Gold certified Melbourne-based · local support
Included with your engagement

Three things that make the proof easy to use.

Cyber-Insurance Readiness Pack

The documented evidence to answer renewal questions with facts instead of guesses. Better answers make for a better conversation with your insurer — though premiums are always theirs to set.

Client Trust Pack

A security trust page, a "Protected Practice" badge for your website and email signatures (alongside your SMB1001 Gold mark), and a one-page explainer your team can send to clients who ask how you protect their matters.

The Security X-Ray itself

Your baseline and prioritised fix-list — free, no obligation, and yours to keep whether or not we ever work together.

We onboard a limited number of law firms each quarter, so every setup is done properly. Insurance renewals and the VLSB+C expectations don't wait — the sooner you book your X-Ray, the sooner you have a plan.

Questions principals ask

Straight answers, no jargon.

Do you handle our whole IT, or just security?

Both. Cyber security sits on top of solid day-to-day IT, so your managed IT — helpdesk, Microsoft 365, devices and email — is included. You get one local partner for the lot, not a security vendor on one side and an IT person on the other.

What if we're not on Microsoft 365 yet?

That's fine — we transition you. Moving a small firm onto Microsoft 365 is routine work for us, and we plan it around your matters so your fee-earners aren't disrupted. The X-Ray maps where you are today before anything changes.

How long does it take to get to SMB1001 Gold?

We agree a target date up front, based on what the X-Ray finds. For most small firms that's a matter of weeks rather than months. We do the work; you approve and sign the director's attestation once the controls are in place.

Will this disrupt our fee-earners?

It's designed not to. The X-Ray needs almost nothing from your team, and remediation is done-for-you. Where a change touches people — like switching on multi-factor sign-in — we schedule it carefully and explain it in plain English.

Is our data ever visible to other firms?

Never. Your environment and your security portal are yours alone. Nothing about your firm is shared with, or visible to, any other client.

What are SMB1001 and the VLSB+C expectations?

SMB1001 is an Australian cyber security standard for small and medium businesses, graded across five levels (Bronze to Diamond) and five practical areas. The VLSB+C — the regulator for Victorian lawyers — set out minimum cybersecurity expectations for firms in 2024. Meeting a recognised standard like SMB1001 is a practical way to show you take those expectations seriously.

Is SMB1001 Gold independently audited?

Silver and Gold are certified on a signed director's attestation that the required controls are in place. Independent third-party audits apply only at the higher Platinum and Diamond levels. What actually protects your firm is genuinely having those controls and keeping them current, which is exactly what we put in place and manage for you all year.

Is the Security X-Ray really free?

Yes. It's a no-obligation diagnostic. You get a clear baseline of where your firm stands and a prioritised plan to keep — whether or not you ever engage us.

Book your free Security X-Ray

See exactly where your firm stands — in days, not weeks.

One clear baseline against a recognised standard, a prioritised fix-list to keep, and a preview of the portal you'll use to prove it. No system access, no obligation, no sales pressure.

You'll walk away with a prioritised fix-list to keep — even if we never work together.

Not ready to book? Run the free 60-second Security Pulse first →

Prefer to check yourself first? Take the free 2-minute Readiness Self-Check →

FreeA few daysNo obligationKeep your plan

What happens next: we'll reply within one business day to book a short, no-pressure call and start your X-Ray. We take on a limited number of new firms each quarter, so support stays fast.

Serving

North Melbourne law firms
Local Melbourne support

Book your free Security X-Ray

Free · no system access · no obligation.

Please enter your name.
Please enter a valid email address.
Please add a short message.

We'll reply within one business day. Your details stay private.

Thanks — we've got it!

Your request is on its way. Need us sooner? Call 1300 313 384.

What happens next:

  • We'll reply within one business day to book your readout.
  • No system access needed — about 15 minutes of your time.
  • You'll get a written scorecard and a prioritised fix-list to keep — even if we never work together.

Let's talk directly

We're just finishing our online booking setup. The quickest way to reach us right now is to call 1300 313 384 or email contactus@unitysystems.com.au — we'll get straight back to you.