Law firms · SRA-regulated

IT and cyber security for law firms in the City and across London.

Managed IT, Microsoft 365 governance and cyber security for SRA-regulated law firms, built around client confidentiality, secure matter data and the SRA’s expectations.
Built for law firms

Client money, confidential matters and a regulator that expects you to report

Law firms are a prime target for cybercrime, from payment diversion fraud and email compromise to ransomware. The SRA expects effective systems and controls and prompt reports when an attack affects clients, and you stay responsible for client confidentiality when you use IT providers.
Cre8 IT runs the technical controls you own, supplies the information you need to assess us as a provider, and keeps the evidence organised so a request from the SRA, your insurer or a client takes minutes to answer.

What law firms ask us for

What the regulator expects

How we support the SRA’s expectations

The SRA Standards and Regulations are outcomes-focused and apply in proportion to the size and work of the firm. Here is what we do for each area.

Governance and risk

The SRA expects effective governance structures, arrangements, systems and controls (Code of Conduct for Firms, paragraph 2.1). We supply the technical risk inputs and evidence that the controls work.

IT supplier oversight

Due diligence before you appoint, clear contract terms and ongoing supervision. We expect to be assessed and provide our certificate, scope and control information.

Contract terms

Security obligations, review and audit rights, incident notification, subcontractor controls and data return. We will work through these terms with you.

Protective controls

Multi-factor authentication, Conditional Access, device management, patching, encryption, backup and training, reported monthly.

Incident readiness

Cyber incidents that affect clients should be reported to the SRA promptly, and personal data breaches to the ICO within 72 hours where feasible. We help you agree who decides, rehearse the process and keep the logs you will need.

Evidence

A standing evidence pack for the SRA, insurers and client audits, so a request takes minutes rather than days.
Summary for orientation, reviewed 25 September 2026. Confirm the current wording in the FCA Handbook, PRA Rulebook and SRA Standards and Regulations. This is not legal advice.

Where we help on data protection

Data protection

UK GDPR and client confidentiality

UK GDPR requires a controller to notify a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. If notification is later than 72 hours, it must explain the delay. Solicitors also owe clients a duty of confidentiality under the SRA Codes of Conduct.
We build the technical measures that make that possible: access control, encryption, logging and a fast way to establish what happened. Decisions about lawful basis, notices and whether a breach must be notified belong with your data protection lead or legal adviser.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against Cyber Essentials and the SRA’s expectations, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance officer can use.

4. Operate

Helpdesk, monitoring and regular reviews, with reports written for your governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

We have supported businesses since 2012, including regulated firms that hold confidential client data. Our own information security management system is certified to ISO 27001:2022, and we are a certified Microsoft Partner.
Our UK office is in South Wales, and we support London firms remotely and on site by arrangement.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for law firms

Sourced to the regulator’s own text, dated and written by a named specialist.
Vendor management

IT vendor and outsourcing management for FCA, PRA and SRA regulated firms

How to manage IT providers when you are regulated in the UK: a register, tiering, due diligence, contract terms, ongoing oversight and the new third-party reporting rules.
4 min read · Reviewed 25 September 2026
Cyber Essentials

Cyber Essentials for UK regulated firms: what changed in 2026 and why it matters

What Cyber Essentials covers, what changed in April 2026, why it matters to FCA- and SRA-regulated firms, and how it compares with ISO 27001 and the regulators’ own rules.
4 min read · Reviewed 25 September 2026
ISO 27001

ISO 27001 for regulated firms: how it supports FCA, PRA and SRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to FCA, PRA and SRA expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 25 September 2026
FAQ

Law firm and SRA questions

Does the SRA require Cyber Essentials?

No. The SRA does not mandate a particular certification, but it expects effective systems and controls and prompt reporting. Cyber Essentials is a low-cost way to evidence the basics, and insurers and clients increasingly ask for it.

When should a law firm report a cyber incident to the SRA?

Promptly, where there has been a serious breach of the SRA’s Standards and Regulations, and in any case where an attack has had, or could have had, an impact on clients, such as lost client money or data or a delayed completion. Personal data breaches may also need to be notified to the ICO within 72 hours where feasible.

What should a law firm’s contract with an IT provider include?

Clear security obligations, the right to verify the provider’s compliance (by your own audit, a review of its controls or independent reports), prompt notification of incidents, controls on subcontractors and return or deletion of data at the end. See our vendor management guide.

Do you have an office in London?

Our UK office is in Blackwood, South Wales. We support London law firms remotely and with on-site visits by arrangement.

Talk to a specialist about your SRA obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.