Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

    • Lawscot Tech

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Equality and diversity

Journal logo
  • PRACTICE

    PRACTICE

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

    • Practice

    • Corporate law

    • Criminal law

    • Employment law

    • Environment law

    • Family law

    • Industry updates

    • Intellectual property

    • Property law

    • Technology law

    • Technology and innovation

  • PEOPLE

    PEOPLE

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

    • People

    • Equality, diversity & inclusion

    • Ethics & professional responsibility

    • Obituaries

    • Wellbeing & support

    • Noticeboard

    • From the President's desk

  • CAREERS

    CAREERS

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

    • Careers

    • Job board

    • Leadership

    • Management

    • Skills

    • Training & education

  • KNOWLEDGE BANK

    KNOWLEDGE BANK

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next Generation of Scottish Legal Talent

    • The Future of Law on our High Streets

    • Knowledge Bank

    • Book club

    • Interviews

    • Sponsored content

    • Next Generation of Scottish Legal Talent

    • The Future of Law on our High Streets

  • ABOUT THE JOURNAL

    ABOUT THE JOURNAL

    • About the Journal

    • Journal contacts

    • Journal Editorial Advisory Board

    • Newsletter sign-up

    • About the Journal

    • Journal contacts

    • Journal Editorial Advisory Board

    • Newsletter sign-up

SPONSORED: Cyber risk management — a simple truth for law firm leaders

27th November 2025

Law firms are investing heavily in cybersecurity, yet many leaders still carry that nagging fear their defences will fail. Lindsay Hill, solicitor and CEO at Mitigo Cybersecurity, explains why that fear is justified ­– and how to make sure you’re investing in the right areas to protect your firm.

Most law firm leaders I speak to know that cyber risk is the biggest ‘single event’ risk facing their firms. It’s the one thing that could, overnight, demolish firm value, destroy client trust and halt operations.

And yet, despite the awareness, despite the spending, many still have that nagging fear: when the cyber criminals come for our firm, will we be protected?

Here’s the uncomfortable truth: that fear is justified.

Getting the order wrong

Law firms are being persuaded, or persuading themselves, that buying technical ‘solutions’ such as software, monitoring tools or even cyber insurance will make them safe.

But they’re buying solutions before properly identifying the problems they need to solve. In other words, they are getting the order wrong.

It’s the equivalent of prescribing medicine before you’ve diagnosed the illness.

You might think you’re secure – but you don’t actually know if you are.

The starting point is a full, comprehensive risk assessment to identify precisely where your vulnerabilities lie across systems, people, working arrangements, governance and your supply chain. Without this, you’re spending money blind (you are also failing to comply with your legal obligations).

The illusion of security

There’s no question that firms are spending money – and lots of it. At Mitigo, we see evidence of that every day. But the real issue is how it’s being spent.

Ask most firms how their cyber investments were prioritised, and the answer is often vague. Too often, decisions are driven by IT and managed service providers (MSPs), not by risk.

The result? Lots of technology but gaping vulnerabilities. They’ve reinforced one door while leaving others unsecured.

This happens because jumping straight to technical solutions creates blind spots – gaps in visibility across people, governance and supply chain risks that technology alone can’t fix.

That’s why the nagging doubt persists – because deep down, law firm leaders know they’ve done something, but not necessarily the right things, or in the right order.

Ask yourself some questions. Where are your documented cyber risk and vulnerability assessments? Who undertook them and what is their cyber risk management experience and expertise? What visibility have they given you on the actual risks your firm faces? How do your technical and non-technical measures match up to control the risks (technical and non-technical) which have been identified? What proof do you have that they are working as intended? 

Independence matters

You can’t do this yourself, and you shouldn’t ask your IT provider or MSP to do it either.

Your IT team is there to keep your systems running. That’s their job. But cyber risk management is a different discipline entirely – one that demands specialist expertise and independent oversight.

Independent expertise exposes what you may not see. It replaces assumption with assurance.

The simple truth

At Mitigo, we see this pattern every week. Once firms start with an independent, expert-led risk assessment, the uncertainty disappears. They stop guessing and start spending in the right areas.

Get the order right, and that nagging fear finally goes away – replaced by the assurance that your defences will stand when tested.

Of course, assessing cyber risk is not a one-off MOT. Your governance regime must include scheduled audits to identify fresh and emerging risks, as well as evaluating whether the controls you have in place are actually effective and giving you the protection you need.

To find out how independent cyber risk management can strengthen your firm’s resilience, contact Mitigo at www.mitigo.com.

Lindsay Hill is a solicitor, former head of dispute resolution at a City of London law firm, and CEO of Mitigo Cybersecurity, the strategic partner to the Law Society of Scotland for cyber risk management.

Weekly roundup of Scots Law in the headlines including jury trials and ABS group — Monday December 1

1st December 2025
This week's review of all the latest headlines from the world of Scots Law and beyond includes the ongoing row over UK Justice Secretary David Lammy's plans to scrap jury trials in many cases, as well the formation of an ABS campaign group.

SPONSORED: Cyber risk management — a simple truth for law firm leaders

27th November 2025
Law firms are investing heavily in cybersecurity, yet many leaders still carry that nagging fear their defences will fail. Lindsay Hill, solicitor and CEO at Mitigo Cybersecurity, explains why that fear is justified ¬– and how to make sure you’re investing in the right areas to protect your firm.

'Change can appear to be the enemy of stability' — When a historic law firm becomes an LLP

27th November 2025
For any firm that has been around for 175 years, change can appear to be the enemy of stability. But the truth is actually the opposite: the ability to adapt is what allows institutions not only to endure but to thrive.
About the author
Add To Favorites

Additional

https://www.evelyn.com/people/keith-burdon/
https://lawware.co.uk
https://www.lawscotjobs.co.uk/client/frasia-wright-associates-92.htm
https://www.findersinternational.co.uk/our-services/private-client/?utm_campaign=Scotland-Law-society-Journal-online&utm_medium=MPU&utm_source=The-Journal
https://yourcashier.co.uk/

Related Articles

SPONSORED: Planning to Step Back? We’ll Help You Exit Well

24th November 2025
At McKinstry Practice Management, we specialise in helping small, profitable chamber practices transition smoothly while preserving reputation, continuity, and legacy.

Surprise TV twist as record-breaking former SNP MP joins cast of solicitors' drama Counsels

29th October 2025
Upcoming BBC legal drama Counsels, set in Glasgow, has already set solicitors’ tongues wagging and now the production has made...

Weekly roundup of Scots Law in the headlines including Sheku Bayoh latest — Monday October 27

23rd October 2025
A review of all the latest headlines from the world of Scots Law including latest on the Sheku Bayoh inquiry.

Journal issues archive

Find all previous editions of the Journal here.

Issues about Journal issues archive
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited