You don't actually know if you're secure
You have antivirus and a backup "somewhere", but no clear answer to a simple question: are we protected, yes or no?
Managed cyber security, SMB1001 Gold and VLSB+C-aligned compliance for Melbourne law firms — with live proof you can show clients and insurers. We do the work; your fee-earners don't lift a finger. You'll walk away with a prioritised fix-list to keep — even if we never work together.
We take on a limited number of law firms each quarter, so every setup is done properly.
See how it worksYour security, measured against the standard — and ready to show clients and insurers.
Most principals we meet aren't careless — they're busy, and no one has ever shown them where their firm really stands. That uncertainty is the problem.
You have antivirus and a backup "somewhere", but no clear answer to a simple question: are we protected, yes or no?
Trust accounts, settlements and confidential matters make a firm a target. One incident — or one client learning of it — can undo years of reputation.
The VLSB+C has set minimum cybersecurity expectations. Gaps can be relevant to a professional-conduct assessment — and "I didn't know" isn't a comfortable answer.
Renewal forms now ask about MFA, backups and training. Guessing on a proposal form is uncomfortable — and potentially costly at claim time.
Source: ASD Annual Cyber Threat Report 2024–25 (self-reported averages). Downtime figure illustrative only.
Enter your firm's website and we'll show you what criminals and clients can already see — email spoofing risk, website encryption, public exposure. Instant, plain-English result.
Before you take our word for any of this, read the evidence. We ran the same twelve public checks against every Melbourne law firm on the Victorian register, without touching a single system. Three firms in four have not switched on the setting that blocks email pretending to come from their domain.
Passive, external only. No firm is named.
had not enforced protection against email that spoofs their own domain
958 of 1,246 firms · September 2026
In 2024 the Victorian Legal Services Board and Commissioner (VLSB+C) set out minimum cybersecurity expectations for the firms it regulates — covering the basics like multi-factor sign-in, backups, staff awareness and having a plan for an incident.
The VLSB+C has been clear that, depending on the circumstances, failing to manage cyber risks can be relevant to whether conduct amounts to unsatisfactory professional conduct or professional misconduct. This isn't about fear — it's about being able to say, with evidence, that you've done the sensible things.
Source: Victorian Legal Services Board + Commissioner, minimum cybersecurity expectations (2024). We help you meet them; we don't provide legal advice on your obligations.
SMB1001 isn't just our recommendation. The Queensland Law Society supports the standard and urges member firms to reach Gold certification — the level we get you to.
"Law firms have an ethical duty to take reasonable steps to protect the confidentiality of client information. Unfortunately, criminals won't wait for the day you have time to sort it out — and being a small practice is no defence. SMB1001 provides an accessible, cost-effective foundation to strengthen your firm's cybersecurity position and demonstrate your commitment to client care."
From "I'm not sure where we stand" to "here's our security, on a screen" — without tying up your fee-earners.
In a few days we baseline your firm against a recognised standard and show you exactly where you're exposed — no system disruption, almost nothing needed from your team.
We close the gaps: multi-factor sign-in, backups, email protection, training, the written plans. You approve; we do the work and explain it in plain English.
Your security lands in Kevin — a portal that shows how protected you are and lets you prove it at a click. We keep it managed all year, not just on day one.
Log in any time and see exactly how secure your firm is.
Most providers ask you to take their word for it. Kevin shows you — a live scorecard of how aligned your firm is to the standard, what's done, and what's next, ready to share with a client or insurer.
Two levels, both done-for-you and managed all year. Most firms choose Gold, because that's the level the VLSB+C expectations and insurer questions point to.
| What you get | Silver→ SMB1001 Silver | Gold→ SMB1001 Gold + VLSB+CRecommended |
|---|---|---|
| Security X-RayYour baseline and prioritised plan | ||
| Managed IT FoundationHelpdesk, Microsoft 365, devices | ||
| Identity LockdownMulti-factor sign-in, password manager, access control | Core | |
| Data ShieldBackup & recovery you can rely on | ||
| Payment Fraud ShieldStops scammers posing as your firm by email | Core | |
| Human FirewallStaff security-awareness training | – | |
| Incident ReadyA written plan for if something goes wrong | – | |
| Compliance & Insurance EngineCertification, evidence pack, renewal answers | Silver | Gold + VLSB+C |
| Kevin — live security portalYour proof, kept current all year |
"Core" means the everyday essentials are in place; Gold extends them across all your key apps and adds the proactive controls the standard and the regulator expect. Pricing is tailored to your firm's size — you'll have it in writing after your X-Ray.
Firms that complete their Security X-Ray and come aboard become a Protected Practice — secure, SMB1001 Gold-certified, and able to prove it to clients, insurers and the regulator.
Become a Protected Practice.
We'll get you Gold-ready (implemented and self-attested to SMB1001 Level 3) by a date we agree in writing. If we miss it, we keep working at no extra cost until you are.
We guarantee everything within our control, and you complete the few steps only the firm can do: timely access and approvals, and the items the standard requires of you directly, such as obtaining cyber insurance and your team finishing the short training. Where a control depends on a third party's decision, such as an insurer issuing a policy, we'll get you fully ready to meet it, but we can't guarantee someone else's yes.
A note we'd rather make than skip: no one can promise you'll never be breached, and SMB1001 Gold is self-attested by a director, not independently audited. What we promise is that the controls are genuinely in place and actively managed, and that you can prove it.
Unity Systems is SMB1001 Gold certified ourselves — so the standard we hold your firm to is the one we hold our own.
Trusted by Melbourne law firms
We're SMB1001 Gold certified, so we've been through exactly what we'll take your firm through — and we keep our own controls current all year. Certification at Silver and above must be done with a provider certified to the same level. We're certified at Gold — so we can take you there.
The documented evidence to answer renewal questions with facts instead of guesses. Better answers make for a better conversation with your insurer — though premiums are always theirs to set.
A security trust page, a "Protected Practice" badge for your website and email signatures (alongside your SMB1001 Gold mark), and a one-page explainer your team can send to clients who ask how you protect their matters.
Your baseline and prioritised fix-list — free, no obligation, and yours to keep whether or not we ever work together.
We onboard a limited number of law firms each quarter, so every setup is done properly. Insurance renewals and the VLSB+C expectations don't wait — the sooner you book your X-Ray, the sooner you have a plan.
Both. Cyber security sits on top of solid day-to-day IT, so your managed IT — helpdesk, Microsoft 365, devices and email — is included. You get one local partner for the lot, not a security vendor on one side and an IT person on the other.
That's fine — we transition you. Moving a small firm onto Microsoft 365 is routine work for us, and we plan it around your matters so your fee-earners aren't disrupted. The X-Ray maps where you are today before anything changes.
We agree a target date up front, based on what the X-Ray finds. For most small firms that's a matter of weeks rather than months. We do the work; you approve and sign the director's attestation once the controls are in place.
It's designed not to. The X-Ray needs almost nothing from your team, and remediation is done-for-you. Where a change touches people — like switching on multi-factor sign-in — we schedule it carefully and explain it in plain English.
Never. Your environment and your security portal are yours alone. Nothing about your firm is shared with, or visible to, any other client.
SMB1001 is an Australian cyber security standard for small and medium businesses, graded across five levels (Bronze to Diamond) and five practical areas. The VLSB+C — the regulator for Victorian lawyers — set out minimum cybersecurity expectations for firms in 2024. Meeting a recognised standard like SMB1001 is a practical way to show you take those expectations seriously.
Silver and Gold are certified on a signed director's attestation that the required controls are in place. Independent third-party audits apply only at the higher Platinum and Diamond levels. What actually protects your firm is genuinely having those controls and keeping them current, which is exactly what we put in place and manage for you all year.
Yes. It's a no-obligation diagnostic. You get a clear baseline of where your firm stands and a prioritised plan to keep — whether or not you ever engage us.
One clear baseline against a recognised standard, a prioritised fix-list to keep, and a preview of the portal you'll use to prove it. No system access, no obligation, no sales pressure.
You'll walk away with a prioritised fix-list to keep — even if we never work together.
Not ready to book? Run the free 60-second Security Pulse first →
Prefer to check yourself first? Take the free 2-minute Readiness Self-Check →
What happens next: we'll reply within one business day to book a short, no-pressure call and start your X-Ray. We take on a limited number of new firms each quarter, so support stays fast.
North Melbourne law firms
Local Melbourne support
Your request is on its way. Need us sooner? Call 1300 313 384.
What happens next:
We're just finishing our online booking setup. The quickest way to reach us right now is to call 1300 313 384 or email contactus@unitysystems.com.au — we'll get straight back to you.