Business phones system melbourne
All Posts / 7 IT Mistakes Melbourne Law Firms Make That Lead to Data Breaches
Blog

7 IT Mistakes Melbourne Law Firms Make That Lead to Data Breaches

Abhishek Bhargva

Telco ICT

26/03/2026

7 IT Mistakes Melbourne Law Firms Make That Lead to Data Breaches

If you run a law firm in Melbourne, cybersecurity is something that keeps you up at night. And it should. The legal sector holds some of the most sensitive information in existence, including client identities, financial records, family law details, litigation strategies, and bank account information. That makes law practices a prime target for cyber criminals.

The numbers back this up. Australian businesses and government agencies reported a record 1,113 data breaches to the OAIC in 2024, a 25% increase from 893 notifications in 2023.

And the legal sector is right in the crosshairs.

This article covers the seven most common IT mistakes that lead to a data breach at Australian law firms, and what you can do to protect your firm before it becomes a headline.

Why Law Firms Are a Prime Target for Cyber Attacks in Australia

Law firms hold what cyber criminals want most: confidential client information, financial records, intellectual property, and access to sensitive litigation files. A single breach can expose dozens of clients at once, which is exactly what happened with one of Australia’s most high-profile attacks on law firms.

In April 2023, HWL Ebsworth became aware that ransomware group ALPHV/BlackCat had exfiltrated data from the firm’s systems. By June 2023, at least 1.4TB of data had been published on the dark web. The breach affected federal government agencies, major banks, and thousands of individuals.

Research from the 2024 State of Cyber Security in Law Report found that 56% of Australian legal firms cited cyber security as their biggest business concern, and 21% said they had been targeted by cyber criminals, a 7% rise on the previous year. 

The threat is real, it is growing, and it is targeting firms right here in Melbourne and across Australia.

The 7 IT Mistakes Melbourne Law Firms Make (And How to Fix Them)

1. Using Shared Login Credentials Across the Firm

This is one of the most common and most dangerous security practices still happening inside law firms today. When multiple staff members share a single login, there is no way to track who accessed what, when, or why.

If that password is compromised in a data breach, the hacker has access to everything. The likely cause of the HWL Ebsworth breach was compromised employee credentials, similar to the method used in the Medibank attack. Human error and poor access management remain the leading causes of a data breach occurring in the legal sector.

Fix it:

  • Assign individual logins to every staff member
  • Use role-based access so people can only see what they need
  • Review and revoke access when staff leave the firm

2. No Multi-Factor Authentication on Client Portals

If your client portal, email system, or practice management software only requires a password to log in, you are leaving the door wide open. Passwords get reused, guessed, and stolen. Multi-factor authentication (MFA) adds a second layer of verification that stops unauthorised access even if credentials are compromised.

Phishing attacks impacted 81% of Australian legal firms in 2024, a 14% year-on-year increase. Once a staff member clicks a malicious link, stolen credentials can be used immediately unless MFA is in place.

Fix it:

  • Enable MFA on all client-facing portals
  • Require MFA for remote access and cloud-based systems
  • Use app-based authenticators rather than SMS where possible

3. Practice Management Software Without IT Oversight

Many Melbourne law firms implement LEAP, Actionstep, or MYOB independently without involving an IT provider in the setup or ongoing management. The result is software that may not be properly patched, backed up, or secured against data security breaches.

Practice management systems store matter files, client contact details, trust accounting data, and correspondence. Without proper IT oversight, a vulnerability in the software could go undetected for months.

Fix it:

  • Involve a managed IT provider in the deployment and management of practice management software
  • Ensure regular patching and updates are applied
  • Review user permissions inside the software at least quarterly

4. No Offsite Backup for Client Files

Many firms often rely on a local server or a single cloud storage location. If ransomware hits and encrypts your files, or the server fails, you could lose years of client records with no way to recover them.

The Australian Cyber Security Centre recommends off-site and offline backups as part of the Essential 8 framework, one of the best practice baselines for Australian businesses. A firm that cannot restore its data after a cyber incident is not just dealing with a data breach. It is dealing with potential professional negligence.

Fix it:

  • Implement the 3-2-1 backup rule: three copies, two media types, one offsite
  • Test backups regularly to confirm they can actually be restored
  • Store backups in a separate environment from your main network

5. Unencrypted Email for Sensitive Correspondence

Sending documents containing sensitive data, such as wills, family law materials, or bank account details, via standard email is a data security risk most firms underestimate. Standard email is not encrypted end-to-end. If intercepted, that information can be read, copied, and misused.

The OAIC has confirmed that cybersecurity incidents, including phishing and compromised credentials, represent 38% of all notifiable data breaches in Australia. Office of the Australian Information Commissioner Email is the entry point for many of those incidents.

Fix it:

  • Use encrypted email or secure client portals for sensitive information
  • Train staff to recognise phishing attempts before they click
  • Have a clear policy on what can and cannot be sent by email

6. Ignoring Privacy Act Notifiable Data Breach Obligations

The Privacy Act reforms that took effect in 2024-2025 significantly tightened obligations for organisations holding personal data. For a legal practice in Melbourne, this means stricter timelines, higher penalties, and greater scrutiny from the Australian Information Commissioner.

Under the updated NDB scheme, the maximum penalty for a serious or repeated privacy breach has increased to the greater of AU$50 million, three times the value of any benefit obtained through the misuse of information, or 30% of a company’s adjusted turnover. 

Many firms still do not have a documented incident response plan. In the case of a data breach, the clock starts immediately.

Fix it:

  • Document your data breach response plan and review it annually
  • Know your notification obligations under the Australian Privacy Principles
  • Appoint a privacy officer or engage an IT provider who understands compliance

7. Relying on a Break-Fix IT Provider Instead of Managed IT

A break-fix IT provider only shows up when something goes wrong. For a law firm, that model creates a dangerous gap between when a cyber incident begins and when it is detected. Most breaches are not discovered immediately. In the HWL Ebsworth case, it is believed that the data exfiltration had been occurring for some time before the firm became aware of it in April 2023. 

Managed IT for law firms means continuous monitoring, proactive patching, threat detection, and a team that understands the compliance obligations specific to the legal profession. It is the difference between knowing there is a problem before it becomes a breach-occurred situation, and finding out after the damage is done.

Fix it:

  • Move to a managed IT model with 24/7 monitoring
  • Ensure your IT provider has experience with legal practices and compliance
  • Ask about Essential 8 alignment and cyber insurance requirements

Ready to protect your firm? Telco ICT Group works with Melbourne law firms to build secure, compliant IT environments. Get in touch today to find out what your firm might be missing.

What a Properly Managed IT Environment for a Law Firm Looks Like

A secure law firm IT environment is not just antivirus software and a firewall. For a Melbourne legal practice, it should include:

  • Identity and access management: Individual logins, role-based permissions, MFA across all systems
  • Endpoint protection: All devices, including laptops used for remote work, are secured and monitored
  • Encrypted communications: Secure email and client portal solutions
  • Backup and disaster recovery: Offsite, tested, and aligned with the Essential 8 framework
  • Patch management: Regular updates across all software, including LEAP or Actionstep
  • Compliance monitoring: Alignment with Privacy Act obligations and the Australian Privacy Principles
  • Incident response planning: A documented plan so your firm knows exactly what to do if a breach occurs

The goal is not just to prevent data breaches. It is to make sure that if something does happen, your firm can respond quickly, limit the damage, and meet its legal obligations.

Law Firm IT Compliance Checklist 2026

Area Requirement Status
Access Control Individual logins, no shared credentials ✓ Review
MFA Enabled on all portals and remote access ✓ Review
Backups Offsite, tested, 3-2-1 rule ✓ Review
Email Security Encrypted for sensitive correspondence ✓ Review
Privacy Act NDB response plan documented ✓ Review
Essential 8 Assessed and aligned ✓ Review
Cyber Insurance Coverage reviewed and current ✓ Review
Patch Management Software updates are applied regularly ✓ Review

Practice Management Software: IT Support Requirements

Software Key IT Considerations
LEAP Cloud access controls, MFA, and user permission reviews
Actionstep API security, data residency, and regular patching
MYOB Financial data encryption, access logs, backup integration

How Much Does IT Support Cost for a Melbourne Law Firm?

The cost of managed IT support for a Melbourne law firm depends on several factors, including the number of staff, the software your firm uses, and the level of security and compliance monitoring required.

What we can say with confidence is that the cost of a data breach is far higher than the cost of preventing one. According to IBM, the average cost of a data breach in Australia in 2024 was A$4.26 million. 

Managed IT for law firms is typically structured as a monthly per-user or per-seat fee, covering monitoring, support, security, and compliance services. The right package depends on your firm’s size and risk profile. Speak to a provider who understands the legal sector to get an accurate scope.

Telco ICT Group helps Melbourne law firms build IT environments that are secure, compliant, and built for the demands of modern legal practice. Contact our team to book a no-obligation IT review.

Frequently Asked Questions

What IT systems do law firms use in Australia?
Most Australian law firms use practice management software such as LEAP, Actionstep, or MYOB for Accountants, combined with Microsoft 365 for email and document management. A managed IT provider ensures these systems are properly secured, backed up, and maintained.

Is LEAP software covered by managed IT support?
Yes. A managed IT provider experienced with legal practices can support LEAP, including user access management, patching, integration with backups, and ensuring the platform meets your firm’s security requirements.

What are a law firm’s obligations under the Privacy Act?
Under the Privacy Act 1988 and the Notifiable Data Breaches scheme, law firms must notify the OAIC and affected individuals if a data breach is likely to cause serious harm. The Privacy and Other Legislation Amendment Act 2024 introduced tighter enforcement powers and higher penalties for non-compliance.

What does cyber insurance require of law firms?
Most cyber insurance policies now require a baseline level of security controls, including MFA, documented backups, and an incident response plan. Firms that cannot demonstrate these controls may face higher premiums or reduced coverage.

How can a Melbourne law firm reduce its risk of a data breach?
Start with the basics: individual logins, MFA, encrypted email, regular backups, and a documented response plan. Then engage a managed IT provider familiar with the legal sector to close the gaps and maintain ongoing compliance.