All insights

Does a small law firm need the Essential Eight?

2 min readBy Brendon Whiting, Founder · 31 March 2026

Not as a legal requirement, and increasingly as a commercial expectation. Cyber insurers ask about its controls at renewal, corporate and government clients raise it in supplier due diligence, and panel arrangements assume it. Beyond the paperwork, the eight controls happen to match the risks a legal practice actually faces.

That last point is the more interesting argument. The Essential Eight was not designed for law firms and it fits them unusually well, because the realistic threats to a practice are a compromised mailbox leading to settlement fraud, and ransomware encrypting the file store before a deadline. Multi-factor authentication addresses the first. Tested, protected backups address the second. Restricting administrative privileges limits how far either goes. Those three do most of the work.

The commercial pressure is worth taking seriously rather than resenting. Firms doing government-connected work, acting for larger corporates, or renewing cyber cover are being asked in increasingly specific terms, and the answer that carries weight is a dated maturity level with evidence rather than an assurance that security is taken seriously. There is no Essential Eight certificate; what exists is a report you can produce when asked.

For most small practices Maturity Level 1 is the right target, and it is achievable as a project rather than a transformation. MKF Lawyers went through exactly that alongside an enterprise network rebuild. If you want to know where your firm sits today rather than guess, the Cyber Security Scorecard measures it free and reports control by control, or call 1800 456 567.

Find out where your practice sits

The free Cyber Security Scorecard measures your firm against all eight controls and reports in writing, with the evidence behind each score.

Frequently asked questions

Not as a matter of law for private practices. It arrives through other routes: cyber insurance questionnaires ask about its controls, corporate and government clients embed it in supplier due diligence, and panel appointments increasingly assume it. Voluntary in law, expected in commerce, and the gap is narrowing.

Multi-factor authentication and tested backups, in that order, because the two realistic threats to a practice are a compromised mailbox and ransomware. Restricting administrative privileges follows closely. Those three address the overwhelming majority of what actually happens to firms of this size.

For a typical small firm, a one-to-three-month project rather than a purchase, with the fastest wins landing in the first fortnight. Some evidence is inherently time-shaped, since a patching cadence cannot be demonstrated until it has run a few cycles, which is worth knowing if a client deadline is driving it.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.