Skip to main content

Ransomware: Lessons for Conveyancers

The recent cyber attack on the NHS is a stark warning to a conveyancing industry targeted and vulnerable to cyber crime.

Imagine the scenario..It’s 7 p.m. on a Friday. You are about to finish a report on title due the next day when a message pops up on your laptop. It informs you that a third party has gained control of your system and encrypted all your files. To unencrypt your files, you must pay a ransom.

All your files on your computer system are now unreadable. Thanks to this ransomware attack, your firm has basically been shut down while your system is held hostage. Have you completions been compromised? Did clients expecting their balances receive them? How is everyone in the firm going to to work on Monday? Did you open a file that you should not have. A hundred questions and scenarios are going through your mind.

The most common ways for the software to be installed on a law firm’s systems is through phishing emails, malicious adverts on websites, and questionable apps and programs. After the ransomware is downloaded, generally only a unique “key” can decrypt the firm’s files.

Ransom amounts differ, but the price — depending on the hacker behind the scheme — is usually about £500. Larger firms may face significantly higher ransoms. The hackers normally demand payment in bitcoins, a digital form of currency that is difficult to track.

Lawyers should always exercise caution when opening unsolicited emails or visiting websites they are unfamiliar with. Never download an app that hasn't been verified by an official store, and read reviews before installing programs. Most ransomware programs are extremely difficult to combat. Nevertheless, there are certain steps one can take to work around a virus, rather than simply acceding to the hackers demands.

One way is to recover files. Lexsure was offering conveyancing firms backup solutions as one of its suite of risk management tools back in 2010. The easiest way to fix a virus is to clean it off the infected properties and restore the information from backup systems. That is why you should frequently back up your files and use a service that provides redundant backup facilities. There are of course regulatory compliance requirements in relation to protecting and backing up client data.

When a firm has the option of paying hackers a lot of money or losing a couple of minutes of work and restoring from files that have been backed up, the choice becomes obvious. If you are not completely satisfied with your backup system and provider, now is a good time to conduct a review and make any necessary changes.

This is also a good time for conveyancing firms to considering the use file-accessing auditing to open their files. This functionality, which is built into Microsoft Windows and available through most secure, cloud-based solutions, tracks each time a user opens a file or folder. By monitoring the logging activity, the firm’s IT professionals can identify patterns or instances of unauthorized access. Through file-accessing auditing, you can launch a course of action such as stopping the server or removing file share creating the opportunity to halt the attack.

Conveyancing firms law firms have been hearing for years that they could be the victims of a cyberattack, the danger has never been clearer.

Firms with a CQS (CPMS) Information Management And Security Policy will have set out the latest procedures on the firms can do to keep cyber-secure.

Comments

Popular posts from this blog

Argie Bargie over Home Information Packs

In response to a question from Conservative MP David Amess on what methodology would be used to use to evaluate the effectiveness of the Home Information Pack programme, Communities and Local Government Minister Ian Austin was involved in heated argument. The wording of the debate ( reported in Hansard ) makes interesting reading, so I thought I would share it with you : Mr. David Amess (Southend, West) (Con): What methodology his Department plans to use to evaluate the effectiveness of the home information pack programme; and if he will make a statement. Mr. Andrew Mackay (Bracknell) (Con): What methodology his Department plans to use to evaluate the effectiveness of the home information pack programme; and if he will make a statement. Mr. David Jones (Clwyd, West) (Con): What methodology his Department plans to use to evaluate the effectiveness of the home information pack programme; and if he will make a statement. The Parliamentary Under-Secretary of State for Communities and Local...

Paperwork is not a shield: Why your SRA aml audit demands more than just a dusty manual

The Solicitors Regulation Authority continues its aggressive crackdown on financial crime with a recent fine issued against Whiteheads Solicitors (Staffordshire) Ltd . This decision serves as a stark reminder that the regulator is looking far beyond simple paperwork during an SRA aml audit . The firm was fined 2,584 GBP plus 600 GBP in costs following an investigation into its compliance with the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017. While the firm had a firm-wide risk assessment and general policies in place, the SRA identified critical failures at the matter level. Key compliance failures included: Failure to conduct adequate client and matter risk assessments . The SRA found a consistent pattern where the firm failed to sufficiently assess client matter risk levels as required by Regulation 28. Inadequate scrutiny of source of funds . In one specific property transaction, the firm failed to properly investigate the origin of funds provided by ...

The High Street Practitioner’s Guide to Surviving the FCA

For a sole practitioner or the MLRO in a small high-street firm, "AML compliance" often feels like just another mountain of paperwork standing between you and your actual work. When you are juggling a heavy conveyancing caseload, a sensitive probate matter, and the day-to-day survival of your practice, the last thing you need is a new regulator with a reputation for being data-heavy and "zero-tolerance." But the ground is shifting. As the Financial Conduct Authority (FCA) takes over AML supervision from the SRA, the "high-street way" of doing things—relying on long-standing local reputations and gut instinct—is being replaced by a requirement for hard, documented proof. The end of "I’ve known them for years" In a small town, you often act for the same families for generations. You know their business, their parents, and their reputation. Under the old mindset, that felt like enough. Under the FCA, it isn’t. T...