For UK solicitors & law firms
Could a criminal email your client, pretending to be you?
If your domain is not properly protected, someone can send an email that looks exactly like it came from your firm and redirect a client’s completion funds. It has a name: Friday afternoon fraud. We check for it, and for everything else an attacker sees from outside: exposed logins, remote access, out-of-date software, forgotten systems. Plain-English report, free, within 48 hours.
We checked 200 UK law firms. 44% can have their email spoofed.
Check your firm’s domain now. One second, no signup:
Instant. We only read public DNS records. No email captured.
Then take the full free snapshot from the result, back within 48 hours. See how it works · See a sample letter
The threat
Wire-transfer fraud: the “Friday afternoon” scam
A criminal sends email that appears to come from your firm, or intercepts a thread, and tells a client mid-transaction that the account details have changed. The money goes to the criminal. Conveyancing is where it lands hardest: completion funds are large, the timing is public, and the client is expecting an email from you about bank details. A missing or unenforced DMARC record is the gap that lets a spoofed email through, and we check it in a second.
Sources: SRA: Cybercrime · SRA Risk Outlook: information security and cybercrime · SRA scam alerts · Law Society: cybersecurity guidance
The pressure to prove it comes from three directions
Clients, your regulator and your insurer are all now asking the same question: can you show you protect what you hold? Confidentiality is your product, not just your IT.
Your clients
Due diligence & panel reviews
Corporate clients, lenders and insurers increasingly send outside-counsel security questionnaires before instructing or renewing a panel place. A clean, forwardable assessment is the fastest way to answer, and to avoid losing the work over it.
Your regulator
SRA & Lexcel
The SRA expects reasonable steps to keep client information and client money safe, and Lexcel sets an information-security standard. An independent external assessment is the simplest way to evidence that you take it seriously.
Your insurer
PII & cyber renewal
Your compulsory PII renewal, and any cyber add-on, now asks whether you scan externally, enforce MFA and have no exposed remote access. Walk in with a dated assessment instead of guessing at the application.
The deliverable
A letter you can forward
The paid assessment produces a two-page, plain-English attestation with a clear pass or needs-attention on the handful of things client questionnaires and insurers actually ask about: email spoofing, exposed remote access, out-of-date software, breached credentials and lookalike domains.
It is written to be forwarded, to a client, an insurer, or your managing partner. It is an independent assessment of what an attacker can see, not a certification or a guarantee, and it says so plainly.
Independent External Security Assessment
Hartwell & Bramley LLP · hartwellbramley.co.uk
- Email spoofing protection (SPF / DMARC) — needs attention
- Exposed admin & login interfaces — pass
- Remote access exposure (VPN / RDP) — pass
- Known-vulnerable software — pass
- Breached credentials, lookalike domains — full assessment
Hartwell & Bramley LLP is fictional. Your letter is specific to your firm.
For law firms
Law Firm Assurance: prove it to your clients, insurer and the SRA
One fixed price for the assessment, the forwardable letter, and a quarterly re-check with a refreshed letter for a year, so that whenever a questionnaire or renewal lands, the answer is already dated within the last three months.
- ✓The full External Assessment, every finding verified by hand
- ✓A two-page attestation letter: pass / needs attention on the five things clients and insurers ask about
- ✓A briefing for your IT provider on exactly what to change
- ✓A re-check and refreshed letter every quarter for 12 months, so the evidence never goes stale
Nothing is installed and nobody needs access to your systems. We never contact your clients, and we never test anything you have not authorised in writing.
Fixed price
£2,900
1 week, then quarterly for 12 months
Fixed at £2,900 for a firm up to ~25 staff and 3 domains. Covers the assessment, the letter and four quarterly re-checks.
Start with the free snapshot All services & pricing →Preparing for Cyber Essentials? The Assessment + Fix & Re-test package is built for it, from £3,500.
Start with your firm’s domain.
One second, no signup: can someone send email pretending to be your firm? Then take the full free snapshot from the result.
Check my domainPrefer to talk it through first? Book 25 minutes