Securely transforming your law firm for efficient and compliant practice in a digital world
What are you obliged to do?
The SRA information and cybersecurity rules expect firms to be able to “comply with all the SRA’s regulatory arrangements, as well as with other regulatory and legislative requirements, which apply to you.” They also state that “your managers and interest holders and those you employ or contract with do not cause or substantially contribute to a breach of the SRA’s regulatory arrangements”.
Why is this necessary?
We have approached these as a joint matter as they both have similar ways of achieving them.
It is essential to comply with the SRA regulations or you will be falling short of legislation, which could – in the worst-case scenario – depending on the severity of the offence, result in fines and prison time. It is also important to do this to be certain that you are cyber secure, as not falling short of any SRA regulations means that your defences are prepared and ready for an attack. Being sure that no contribution to a cyber attack is made by anyone in your organisation sounds difficult to achieve – in reality, the solution is relatively simple and, in the process, you are one step closer to complying with all the SRAs regulatory arrangements.
How do I ensure that I comply with SRAs regulatory requirements and be sure that my managers, interest holders, and those I employ or have contracts with don’t cause my organisation to be in breach of regulations?
There are two solutions to this predicament – the first is to install some sort of access control programme and manage it yourself, and the second is to achieve the Cyber Essentials Plus accreditation which has access controls as one of its five key controls. The difference between the two is that with the Cyber Essentials Plus accreditation – as much as it costs considerably more – you have the team at Cyber Essentials monitoring to ensure that everything is running the way it should be.
We will now explore how to achieve a level of access control up to the standards of the Cyber Essentials Plus accreditation, according to the questions they ask you when auditing for it:
- Are user accounts controlled through a creation and approval process?
Prior to a new team member being set up, the account must first go through an approval process. You will need to guarantee that who the access is being given to can be trusted, or at least that they can be held accountable if something goes wrong with the account.
- Are users required to authenticate before being granted access to devices and applications using unique credentials?
Authentication is a sure-fire way to guarantee only users that are authorised gain access to the system. Most commonly, this is done through a combination of both passwords and physical access controls, such as staff passes to get into a secure room containing sensitive files (without a staff pass allowing access to the room they cannot gain physical access to the systems, for example). Sometimes a token is used to gain access to the system in addition to a password. There are many ways of achieving this, and, in each case, the authentication details must be unique to each user. There mustn’t be a generic ‘guest’ or ‘temporary staff’ access facility that can be accessed by several different individuals.
- Are accounts removed or disabled when they are no longer required?
When a team member leaves the organisation, you must lock their account immediately! This prevents access by others on the account. Take your time to go through the account with a fine-tooth comb in the search for critical information (that may need to be kept and recorded) for auditing or other uses. An administrator can delete or disable (preferably disable) the account from the control panel.
- Has two-factor authentication been implemented where available?
Two-factor authentication – for those that are not familiar with the term – involves the use of two different means of identification before being granted access to the system or (if you’re already in) different parts of it. Decide on where this is needed. It can be a drawn-out process to implement across an entire organisation (depending on the size), so it is recommended to pick and choose the accounts that pose the most risk if they were breached.
- Are administrative accounts only used to perform administrative activities?
An administrator should have two accounts – one should be the poster boy for security and should be a near-impenetrable fortress with as limited risk as possible, and the other ‘normal’ one should be for everyday activities such as emailing and web browsing – actions that should not be performed on the other account. The second ‘normal’ account is still secure but it makes sense to perform the ‘risky’ tasks on the account that holds the least number of privileges.
- Do you have Anti-Malware software, application whitelisting, or application sandboxing on each of your devices?
Anti-Malware – or Anti-malicious software – should be installed on all devices and endpoints, including mobile phones where they connect to the internet and to your systems. This software usually allows you to ‘whitelist’ software applications – this is a process whereby any software that’s approved to be used on the network in question is listed, and only that software can be run on the system. There is another option – ‘Sandboxing’ which is when a programme is run in a separate area away from the rest of the system. The aim of whichever one you choose is to stop unauthorised software packages from running on your systems.
- Provide details of the software used
The easiest of all, simply keep note of – and details of – any Anti-virus and other related software that is installed on your system.
A technology partner that can ensure that your team only have access to the point at which they need it, whilst ensuring compliance
Our mission, as a strategically aligned IT partner to the legal sector, is first and foremost to ensure that you, your team, and your systems are safe from cyber-attacks. We also want to ensure that you have the measures in place to ensure that you are compliant with SRA guidelines.
Our partnership with other experts in your sector, combined with keeping ourselves plugged into developments in technology, ensures that, as your IT provider, we keep your firm at the forefront of innovation.
Would you like help with implementing access controls in your organisation? Or perhaps you are interested in achieving the Cyber Essentials Plus accreditation?
If you are actively seeking guidance in the implementation of access controls in your organisation, are interested in achieving the Cyber Essentials Plus accreditation, are getting prepared for an ‘SRA Stress Test’ or are simply in need of help from a strategically aligned IT partner; we are here to help!
Please make contact with our team today to organise a free, no commitment discovery call to learn about the possible threats to your system, our proactive approach to help you get ahead of them, the policies and procedures that you can implement to ensure they never happen again, and how to achieve the Cyber Essentials accreditation and go into the future knowing that your systems are as safe as they can be.
Contact us for more information on 0203 096 2220 or hello@Exi-Go.com
