October is Cyber Security Awareness Month, making it a timely opportunity for legal practitioners to check their cyber risk and look for high return on investment improvement opportunities. While this is always a good idea, there is particular urgency this year due to cyber criminals using AI tools to automate and improve the effectiveness of their attacks.
The Australian Government’s Cyber Security Centre (ACSC) issued an urgent warning on 24 September that AI agents were starting to initiate automated attacks on government and business websites.
The legal profession has always been an attractive target for cyber criminals. Law firms hold highly sensitive (and valuable) client information and often manage significant financial transactions. Cyber criminals understand this. What AI has done is lower the barriers to launching effective attacks while increasing their sophistication.
One of the most significant developments is the rise of AI-assisted phishing and social engineering attacks. Historically, phishing emails were often easy to identify through poor grammar, unusual language or obvious formatting issues.
Today’s generative AI tools can produce convincing and professional communications in seconds. Criminals can analyse publicly available information from websites, court records and social media profiles to create highly targeted messages that appear to come from colleagues, clients or trusted institutions. These attacks are becoming increasingly difficult to distinguish from genuine communications.
AI is also amplifying the risk of impersonation. Deepfake technologies can now generate realistic audio and video recordings that mimic real people with alarming accuracy. Attackers can use cheap software to clone your client’s voice and issue funds transfer instructions. It is extremely important that all your staff are aware of this and to ensure that transfer verification is only done during a live, outbound call that you initiated to a known contact number. Leaving a message then accepting instructions from a return call or message left on your phone is no longer safe.
The pace of cyber attacks is also accelerating. AI enables threat actors to automate many tasks that previously required time, expertise and significant resources. Vulnerabilities can be identified faster, malicious code can be refined more quickly and attacks can be launched at greater scale. For law firms, this means cyber security can no longer be viewed as a periodic compliance exercise. The bad guys are moving faster and working smarter so we must too.
At the same time, legal practices face risks from their own use of AI. The rapid adoption of generative AI tools has created new questions around confidentiality, governance and risk management.
This has three dimensions:
First: Ensuring that your firm has an AI policy that prevents staff adopting AI tools without approval or uploading confidential information. For policies to work, they must be communicated to and understood by staff.
Second: Selecting AI tools that preserve confidentiality (See the QLS AI Selection checklist) and have a cybersecurity certification that converts promises to credible defence.
Third: Do as much as you can to ensure clients are aware of the risks and do not act on unexpected inbound calls or email when transferring funds. The client is often an easier target than the firm and the criminal’s know it.
Basic cybersecurity is a professional responsibility.
Law firms have an ethical duty to take reasonable steps to protect confidential client information and maintain secure systems. The SMB1001 Cybersecurity Standard provides a practical and achievable framework specifically designed to help small and medium-sized practices strengthen their cyber security posture and demonstrate due diligence to clients, insurers and regulators.[*]
Ultimately, AI is not making cyber security impossible to manage, but it is making it harder. For legal practices, success will depend on combining people, processes and technology, supported by strong governance and a commitment to continuous learning. Those firms that proactively adapt will be best positioned to realise the benefits of AI while protecting their clients, reputation and business from evolving cyber threats.
[*] Note: SMB certification does not necessarily supply safe harbour from regulatory attention. It does, however, represent an excellent starting point and a pathway to ensure time and resources are well targeted.




Share this article