Skip to content
Industry

Cyber Essentials for UK law firms with remote counsel and counsel chambers

The hybrid working model at UK law firms and chambers creates three specific Cyber Essentials scoping questions. This guide walks through how to answer each one.

woman in blue long sleeve shirt using macbook

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

Cyber Essentials for UK law firms with remote counsel and counsel chambers

UK law firms and barristers' chambers have a hybrid working model that does not look like any other sector. Partners work between offices, home, client sites, and court. Counsel chambers are organised around self-employed barristers with shared infrastructure. Remote and flexible working is the norm.

This creates three specific Cyber Essentials scoping questions that neither the NCSC requirements nor most consultancy guidance answers cleanly.

The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements.

Section 02

The three scoping questions

1. Are self-employed barristers' own laptops in scope?

2. Is a home router used by a solicitor working from home in scope?

3. Is the chambers' shared practice management system in scope if it is hosted by a third party?

The answers depend on structure, not just scheme rules. This guide walks through each.

Section 03

Question 1: self-employed barristers' laptops

In most London criminal barristers' chambers, barristers are self-employed individuals sharing space, staff, and some infrastructure. The chambers has its own staff (clerks, administrators, practice managers) with chambers-issued laptops. The barristers themselves often use their own.

The Cyber Essentials scope question is: are the barristers' laptops part of chambers scope?

The answer depends on what they access:

  • Self-employed third-party barristers using their own devices: their own end-user devices are excluded under the v3.3 third-party-device rule, but the accounts they use on organisational services remain in scope. Chambers-owned devices loaned to them are included.
  • Chambers employees using personal devices for work: apply the employee BYOD rule; accessing organisational data or services generally brings those devices into scope.

The practical solution for most chambers is one of:

  • Issue every barrister a chambers-managed laptop. Clean scope, but expensive and typically resisted by senior counsel.
  • Virtual desktop access. This can control data exposure, but does not automatically exclude employee BYOD or remove the virtual desktop service from scope. Apply the ownership and relationship rules with the assessor.
  • Require BYOD enrolment in an MDM. The personal laptop becomes managed for chambers purposes. See the BYOD guide.

A virtual desktop can reduce data exposure and management friction. It is an implementation choice, not an endpoint exclusion; apply the employee BYOD and third-party ownership rules to the actual relationship.

Section 04

Question 2: the home router for a remote solicitor

Under v3.3, worker- or ISP-supplied home routers are excluded; organisation-supplied routers are included. Protect in-scope remote-working devices using the appropriate firewall controls.

For a law firm with a hybrid-working cohort, this means each solicitor's home router does NOT need to be inventoried, password-policed, or attested. What does need to be in place is the device-level posture:

  • The firm-issued (or firm-managed BYOD) laptop has its software firewall enabled, default-deny on inbound, and configured so a standard user cannot disable it.
  • The laptop's MDM posture (Intune, Jamf, Conditional Access) covers the device wherever it is - home, court, client site, hotel.
  • Reliance on the software firewall for home and remote workers is noted in A2.5 of the assessment ("Home and remote workers rely on the device's software firewall as the boundary; no home routers in scope").

Where the home router IS in scope: if the firm supplies a corporate router as managed kit (i.e., issues the router itself, configures it, and manages updates), that router is firm equipment and is in scope. Most firms do not do this; for those that do, the router becomes a managed boundary device and is assessed accordingly.

A corporate VPN may be useful for confidentiality and can move the assessed firewall boundary to the administered corporate endpoint. It is not a universal SRA-mandated product; document the actual architecture and router ownership.

Section 05

Question 3: third-party practice management (LexisNexis, Clio, Leap, Actionstep, BigHand)

Most UK law firms use a cloud-hosted practice management system. The common ones in the UK solicitor market are LexisNexis Enterprise, Clio, Leap, Actionstep, and DPS. For chambers, the common tools are MeridianLaw, LEX Chambers, and Clio for Chambers.

The scope question is: is the practice management system in CE scope?

The practice-management cloud service is in scope, alongside applicable end-user devices and accounts. Record which controls the provider implements and which remain chambers responsibilities. ISO 27001 or SOC 2 assurance does not automatically exclude the service.

What the assessor checks:

  • MFA on the practice management login. Under v3.3 cloud-user MFA is mandatory. Confirm MFA support for your actual product, version, subscription and authentication route, then enforce it for every user of the in-scope cloud service.
  • Role-based access control. Solicitors should not have admin privileges on the practice management system. The firm partner / IT administrator should.
  • User provisioning and de-provisioning. When a fee-earner joins, they get appropriate access; when they leave, access is revoked same-day. Assessors often ask about leaver procedures.

Section 06

SRA and BSB expectations (2026)

Solicitors Regulation Authority. The SRA’s cyber security thematic review discusses protection of client funds and data. Cyber Essentials can contribute evidence of baseline controls; the certificate does not establish that a firm has met every professional, information-security or data-protection obligation.

Bar Standards Board. The BSB does not require Cyber Essentials. But solicitors (who instruct barristers), lay clients, and insurers increasingly do. Chambers in London's commercial and criminal sets are adopting CE and in some cases CE Plus as a response to solicitor-firm supplier requirements.

St James’s Place Partner Practices. SJP has published a Plus accreditation or Device as a Service route for Partner Practices. Confirm the applicable route with SJP; do not apply it as a requirement for unrelated law firms. See the SJP guide.

Section 07

Practical certification plan for a 25-person solicitor firm

1. Scope. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor.

2. MFA. Enforce it for every user of in-scope cloud services, including M365 and cloud practice management. For VPN and other remote interfaces, apply the relevant firewall and administrative-access requirements; do not infer a universal VPN MFA rule from cloud-user MFA.

3. Leaver process. Document it; assessors will ask.

4. Patch management. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

5. Software firewall posture. Note in A2.5 that home and remote workers rely on the device's software firewall as the boundary.

6. Submit. The Basic guarantee is six working hours for a complete, compliant submission before midday on a UK Business Day, subject to the certification terms and successful assessment.

Section 08

Practical certification plan for a 40-member chambers

1. Scope. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor.

2. MFA. Required on chambers email, practice management, diary.

3. Clerk-managed provisioning. When a barrister takes up chambers, access is provisioned; when they leave chambers, access is removed within 24 hours.

4. Virtual desktop. Document the architecture in the scope statement.

5. Shared physical infrastructure. Chambers Wi-Fi, printers, and network gear are in scope.

6. Submit. Fig Group supports chambers submissions; see the chambers guide.

Section 09

Bottom line

Hybrid working and shared chambers infrastructure make the scoping question harder than standard corporate environments. The rules do not change - the scope has to be explicit, the technical controls have to be in place, and the sub-set exclusions have to be technical not policy-based.

Use the actual ownership and access arrangements to choose controls. VDI, VPN and MDM are implementation options, not automatic exemptions or a guaranteed first-time pass. Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

Get certified in 6 hours | Read about chambers | See solicitor-sector guidance

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.