You have 0 free articles left this month.

The checklist trap: Why top firms build a security culture, not just a compliance file

Ask most law firm principals whether cyber security matters, and you'll get a fast "yes." Ask them whether their firm would know what to do in the first ten minutes of a payment redirection scam, and the answer gets a lot less certain.

September 29, 2026 • By InfoTrack
Share this article on:
expand image

That gap between knowing cyber security matters and being ready when something goes wrong was the focus of a recent InfoTrack webinar, "The Checklist Trap: Why Top Firms Build a Security Culture Instead." Host Jerome Boutelet, InfoTrack's Head of Government Relations and Industry Affairs, sat down with Chirag Joshi, founder and CEO of Seven Rules Cyber and a globally recognised CISO and board advisor, to unpack what the checklist approach to cyber security gets wrong, and what firms of every size can do instead.

The threat landscape hasn't changed as much as its speed has

Joshi was clear that the fundamentals of cyber risk, ransomware, data exposure, insider error, third-party compromise, haven't gone anywhere. What's changed is the pace and sophistication behind them, largely driven by AI: attacks move faster, minor system weaknesses get chained together into serious breaches, AI tools now carry real authority to act on a firm's behalf, and firms are more dependent than ever on suppliers and models outside their direct control.

Compliance isn't the same as security

One of the most pointed observations from the session: plenty of well-resourced, highly compliant organisations still get breached. Ticking every box on a standard doesn't guarantee resilience.

Joshi's recommended starting point isn't a framework, it's a plain-English risk conversation. He shared a simple model firms of any size can use: think business, then risk, then controls, then action. Formal standards like ISO 27001 or SMB1001 still have their place, but they work best after this risk-first thinking, not instead of it.

Payment redirection fraud: Still the sharpest risk in property law

Given how central property transactions are to many legal practices, the conversation spent real time on payment redirection scams, where a legitimate payment is diverted to a fraudulent account. This type of fraud now costs Australians well over $160 million a year and is growing at roughly 10 per cent annually.

Joshi's core message: don't rely on being able to spot every scam. Build controls that protect you even if someone does fall for one, including independent verification of any changed payment details and a culture where junior staff feel empowered to question instructions that feel off.

If a client reports a suspicious transfer, the priority is speed: contact the bank immediately, loop in your cyber support and insurer, and don't try to cover it up. An incident isn't the reputational risk; a mishandled response is.

Build "muscle memory" before you need it

A recurring theme was the value of rehearsing incidents before they happen. Joshi described "executive decision stress tests", structured walkthroughs where firms map out plausible scenarios and work through who makes decisions and who has authority to act.

This doesn't need to be a technical exercise. A simple conversation, "if our email went down for three days, what would we do?", is often enough to expose gaps early. Backups get a specific warning too: having them isn't the same as having tested recovery, and firms are often shocked to find that out the hard way.

Practical priorities for smaller firms

For sole practitioners and smaller firms without dedicated security resources, Joshi's advice starts with one thing above all else: turn on multi-factor authentication everywhere, across email, practice management software and accounting platforms. If a firm does only one thing this month, that's it.

Beyond MFA, he pointed to understanding where sensitive data actually lives, engaging external advisers on a defined cadence rather than as a one-off, and starting with a proportionate cyber health check rather than an expensive technical audit.

Cyber insurance and regulation: Useful, not a silver bullet

On cyber insurance, Joshi's view was measured: a genuinely useful risk management tool, but not a substitute for good controls, and insurers are increasingly specific about the practices they expect firms to have in place.

On regulation, he expects existing instruments, the Privacy Act reforms, the AML/CTF regime, the Cyber Security Act, to keep being strengthened rather than replaced by a wave of new rules.

The closing message

Asked for one thought to leave the audience with, Joshi's answer was simple: understand the risks to your business first, know where your sensitive data really lives, and accept that prevention will fail sometimes, which is exactly why response and recovery planning matters just as much.

For law firms handling client funds, sensitive records and time-critical transactions, that's not a compliance exercise. It's simply good practice.

Want the full conversation? This article only scratches the surface of what Jerome Boutelet and Chirag Joshi covered, including deeper discussion on AI-driven fraud, identity impersonation, and how defenders are using AI to fight back. Watch the full webinar here, part of the InFocus series exploring the issues shaping the future of the legal profession.

LW discover
Latest articles