Still have questions?
Speak to our team
CTS, an IT service provider and software hosting company for the legal sector, experienced a cyber breach. As a result, it is reported that about 80 conveyancing firms lost access to business-critical software, causing delays in house purchase completions. Other firms using CTS’s hosted IT services were also affected, including having access to the Legal Aid Agency (LAA) Digital system blocked. The disruption continued for several weeks, attracting significant attention in the press and social media, with some house purchasers using such platforms to ‘name and shame’ the solicitor acting for them.

This incident serves as a reminder that any cloud or software hosting provider can be vulnerable to cyber attacks. Law firms often use multiple cloud-based systems for critical functions in their businesses, and in many cases, do not have an alternative system to use should their hosted system become unavailable.
The likelihood of such incidents happening again is increasing as cyber criminals see such firms as attractive targets for ransom attacks and seek to cause maximum disruption. CTS has come under criticism for their response, but their communications were likely tightly controlled by the legal team appointed by their cyber insurers.
Law firms can take several steps to improve their resiliency in the face of cyber attacks. These include auditing the cyber security of external suppliers, particularly those hosting or managing IT systems or processing data on behalf of the firm.
Firms should also carry out a risk assessment of all business systems, considering the impact of extended unavailability, and identifying ways to reduce risk and ensure continued operation. A business continuity plan and an up-to-date cyber security incident response plan should be in place, with staff trained and regularly tested on their implementation.
Appropriate cyber insurance coverage should also be in place, including coverage for losses resulting from cyber attacks on third parties. Firms may also consider adopting a recognized information security standard, such as IASME Cyber assurance or ISO 27001, to ensure robust processes and procedures around cyber security.
While it is easy to point the finger at CTS for the disruption caused to house buyers and the financial and reputational damage to law firms, similar incidents are likely to happen again to other providers.
Law firms have a responsibility to consider the impact of outages or breaches of their hosted IT systems, and to have plans in place to reduce disruption and communicate effectively with clients. Failure to do so could result in severe reputational damage and an inability to recover costs through insurance.
To get an assessment of your resiliency to interruption of your hosted services, contact us using the form below or on 0330 124 3599. If you would like to know more about the risks in your business systems, you may be interested in registering for our free security audit.
Speak to our team