Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

    • Lawscot Tech

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Equality and diversity

Journal logo
  • PRACTICE

    PRACTICE

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

  • PEOPLE

    PEOPLE

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

  • CAREERS

    CAREERS

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

  • KNOWLEDGE BANK

    KNOWLEDGE BANK

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next Generation of Scottish Legal Talent

    • The Future of Law on our High Streets

    • Behind the Scenes with Scotland’s In-House Legal Professionals

    • Space — Scotland's Next Legal Frontier

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next Generation of Scottish Legal Talent

    • The Future of Law on our High Streets

    • Behind the Scenes with Scotland’s In-House Legal Professionals

    • Space — Scotland's Next Legal Frontier

  • ABOUT THE JOURNAL

    ABOUT THE JOURNAL

    • About the Journal

    • Journal contacts

    • Journal Editorial Advisory Board

    • Newsletter sign-up

    • About the Journal

    • Journal contacts

    • Journal Editorial Advisory Board

    • Newsletter sign-up

SPONSORED: AI Is Turbo-Charging Cyber Attacks. Is Your Law Firm Ready?

2nd April 2026 Written by: Mitigo

Artificial intelligence has changed the rules of cybercrime. Attacks that once required significant skill and resource can now be executed at scale, at speed and with unsettling precision.

Handling large amounts of sensitive client information makes law firms attractive targets for cybercriminals, with attacks on UK law firms surging by 77% in a single year.

And law firms are far from alone. Across UK sectors, the NCSC's Annual Review 2025 recorded a 130% increase in cyber incidents, identifying artificial intelligence as a key driver.

In a separate report, the NCSC warns that AI is already tipping the scales toward attackers by lowering the skill threshold needed to run sophisticated campaigns across any sector, shrinking the window between vulnerabilities being discovered and exploited.

Statistics like these make it clear that AI is accelerating cyber threats - and law firms must strengthen their defences.

How Criminals Are Using AI Against Law Firms

Phishing emails used to be easier to spot - poor grammar, odd phrasing, something slightly off. That is no longer the case. AI can now generate grammatically perfect, convincing messages that replicate the writing style of colleagues, partners or clients, complete with the right logos and tone. For law firms managing client correspondence and financial transactions, this significantly increases the risk of convincing payment diversion or email account takeovers.

Phishing is already the most common form of cyber attack facing firms. The UK Government's Cyber Security Breaches Survey 2025 found that 79% of UK businesses experienced phishing attacks, making it the most widely reported cyber incident. AI is making this method more effective, with AI-generated phishing achieving significantly higher click-through rates than human-crafted attacks.

Then there are deepfakes. In 2024, a finance worker transferred $25 million after a video call in which every participant - including the CFO - was a deepfake. For law firms, this tactic could easily target conveyancing, M&A or litigation teams who routinely authorise significant transfers under time pressure - a convincing deepfake posing as a client, lender or senior partner is all it takes.

The Repercussions Are Severe - And Most Law Firms Are Not Ready

A successful cyber attack doesn't just take down your systems. It can end your business.

The average cost of a data breach in the UK now stands at £3.29 million – before factoring in downtime, recovery costs, and reputational damage. For law firms, the regulatory exposure is compounded. The ICO can issue significant fines under GDPR Article 32, and the SRA expects firms to have robust data security measures in place - making it critical for firms to understand their exposure before an incident occurs.

Yet the gaps are stark. Only 19% of businesses have any cybersecurity training programme in place, and 78% have no incident response plan. Board-level responsibility for cyber risk has fallen to just 27% of organisations.

Too many firms assume their IT provider is managing this. They are not.

Cyber risk management and IT support are not the same thing - and firms that recognise this are the ones best placed to respond.

What You Need to Do

Cyber attacks are inevitable. What you do now is what matters. The right response comes down to three things: Assess your exposure, Act on the gaps, and Assure ongoing resilience.

  • Assess: Start with an independent risk assessment - covering people, processes and governance, not just technology. Your IT provider cannot do this objectively. With AI lowering the bar for attackers, gaps that once seemed minor are now critical for law firms.
  • Act: Build and test an incident response plan. If your firm suffered a cyber attack tomorrow – AI-driven or otherwise - would you survive? Furthermore, if your staff are using AI tools such as Copilot or ChatGPT, ensure clear policies are in place on what client data is being shared.
  • Assure: Board-level accountability is no longer optional - cyber risk is a leadership issue, not an IT one. Treat it as an ongoing discipline, not a one-off exercise. That means regular assessments, continuous oversight, and having a trusted cyber partner with specialist legal sector expertise.

Mitigo is the Law Society of Scotland’s strategic cyber risk management partner, helping firms across Scotland assess risk, close gaps and stay resilient.

Get in touch to strengthen your firm’s cyber resilience

Briefing: Tax, a new landscape, Agricultural Property Relief and Business Property Relief

6th April 2026
Yvonne Evans explores the new rules on Agricultural and Business Property Relief which take effect for deaths on or after 6 April 2026.

Weekly roundup of Scots law in the headlines including SLCC process and Flamingo Land — Monday April 6

6th April 2026
This week's review of all the latest headlines from the world of Scots law and beyond includes comments from the Society and SLCC about the complaints process as well as the latest on Flamingo Land plans.

Warners Solicitors delighted to announce appointment of two new partners

2nd April 2026
Warners Solicitors are delighted to announce that Leigh Gargan and Ellen McWhirter have now been appointed as Partners.
About the author
Add To Favorites

Additional

https://lawware.co.uk
https://yourcashier.co.uk/

Related Articles

Weekly roundup of Scots law in the headlines including SLCC process and Flamingo Land — Monday April 6

6th April 2026
This week's review of all the latest headlines from the world of Scots law and beyond includes comments from the...

Weekly roundup of Scots law in the headlines including Suzanne’s Law changes in force — Monday March 30

30th March 2026
This week's review of all the latest headlines from the world of Scots law and beyond includes a change in...

Weekly roundup of Scots law in the headlines including sheriff's AI warning and assisted dying outcome — Monday March 23

23rd March 2026
This week's review of all the latest headlines from the world of Scots law and beyond includes a fierce rebuke...

Journal issues archive

Find all previous editions of the Journal here.

Issues about Journal issues archive
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: [email protected]
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2026
Made by Gecko Agency Limited