Skip to content
Industry

Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For

The Bar Standards Board does not formally require Cyber Essentials. Solicitor firms, CPS counterparts, institutional lay clients, and insurers are increasingly asking for it. This guide covers how CE applies to a criminal barristers’ chambers in London and why the certification has become a practical necessity even without a formal mandate.

a building with a sign on the front of it

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

12 min read

Share

Section 01

Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For

The Bar Standards Board does not require Cyber Essentials. The BSB Handbook requires barristers to take appropriate steps to protect confidential information and to comply with data protection obligations - but it does not specify Cyber Essentials as the mechanism. The Bar Council’s own IT and cybersecurity guidance points to NCSC frameworks (the 10 Steps to Cyber Security, Exercise in a Box) and a jointly-developed cyber security questionnaire produced with the Law Society, but again does not formally mandate Cyber Essentials.

Instructing solicitor firms, corporate or institutional clients, and insurers may ask chambers for cybersecurity assurance. Check the exact request and accepted scope rather than inferring a Cyber Essentials mandate from CQS, Lexcel or an insurer’s name. The SRA’s cybercrime case studies illustrate the legal sector’s exposure to compromised email and client-money fraud; they do not establish a current London chambers breach rate.

This guide covers the specifics of Cyber Essentials for London criminal chambers: why the unusual chambers-as-partnership structure creates scoping questions, how the typical London criminal practice technology stack maps to the CE controls, and why certification has become a practical necessity even though the BSB Handbook does not require it.

Section 02

Why London criminal chambers, specifically

Criminal chambers are a distinct category within the UK legal market. The Bar’s self-employed model - barristers as sole practitioners, chambers as shared services rather than law firms - creates structural complications that commercial or civil chambers do not always face to the same extent. Criminal practice adds specific material: defendant data, sensitive victim testimony, sealed court documents, evidence bundles, DNA and forensic reports, medical records submitted in mitigation.

London criminal chambers are concentrated in the four Inns of Court (Middle Temple, Inner Temple, Lincoln’s Inn, Gray’s Inn) and surrounding locations - Chancery Lane, Fleet Street, the areas around the Royal Courts of Justice and the Old Bailey. The London criminal bar has specific operational patterns: significant use of the Old Bailey and Southwark Crown Court, heavy engagement with the CPS Digital Case System and the HMCTS Common Platform, reliance on CJSM for case communications with the CPS and MOJ, and the continued tradition of some briefs being delivered physically.

The chambers themselves range widely in size: from single-tenant sets to 60- or 80-strong sets with full administrative infrastructure, Heads of Chambers, senior clerks, and dedicated IT teams.

Section 03

The chambers-as-partnership scoping question

The single most important scoping question for a criminal chambers is how to treat the chambers itself versus the individual barristers. Barristers are self-employed. Chambers is, technically, a shared services arrangement - premises, clerks, IT infrastructure, marketing, administration - that barristers pay into via chambers rent or a percentage of fees.

For Cyber Essentials purposes, the practical positions are:

Position 1: Chambers-level certification covering the shared services and the members. The chambers entity is certified within the agreed boundary. Apply v3.3 ownership rules to members’ equipment and retain their organisational accounts in scope. The scope covers the shared infrastructure (email domain, case management system, clerks’ systems, document storage) and the member barristers as users of that infrastructure. Chambers-owned equipment, including equipment loaned to members, is in scope. A third-party member’s own end-user device is excluded under v3.3; management enrolment alone does not change ownership. Their organisational accounts remain in scope.

Position 2: Chambers-level shared services and staff. Define what the applicant entity operates. Third-party barristers using their own devices are treated under the third-party-device rule; their organisational accounts remain included, as do chambers-owned devices loaned to them. Employee BYOD follows the separate inclusion rule.

Choose and describe the agreed organisational boundary accurately. Third-party-owned end-user devices are excluded under v3.3, while their organisational accounts remain in scope; employee BYOD and organisation-owned loan devices require different treatment. Any separately managed subset needs an assessor-accepted technical boundary.

Communicate the agreed certificate scope accurately; a shared-services certificate must not be presented as certification of every member’s independent practice or personal equipment.

The certificate claim must match the agreed scope and evidenced controls. Encryption and MDM can strengthen legal-sector security, but are not universal Cyber Essentials product requirements.

Section 04

The typical London criminal chambers technology stack

The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.

Most London criminal chambers run:

  • A chambers email platform (Microsoft 365, Google Workspace, or occasionally NHSmail-style specialist tenancies)
  • A practice management and case management system (LEX Chambers, Advocate Chambers, Athena, MeridianLaw, Salesforce-based bespoke setups)
  • CJSM accounts for secure messaging with CPS, MOJ, and HMCTS
  • Access to the HMCTS Digital Case System (DCS)
  • Access to the HMCTS Common Platform (increasingly)
  • Document management - often SharePoint, OneDrive, Dropbox Business, or chambers-specific document systems
  • A website and digital marketing platforms
  • Phones - company-issued for senior clerks, personal for most barristers
  • Physical post and physical paper briefs (still significant in criminal practice)

The in-scope device estate depends heavily on how chambers is structured. Chambers-employed staff (clerks, administrators, IT, finance, marketing) almost always use chambers-issued laptops under some form of management. Barristers typically use a mix of personal laptops, personal phones, and - increasingly - chambers-provided laptops or MDM-enrolled personal devices.

Section 05

Why solicitor firms instructing criminal chambers are asking about CE

The pressure on chambers to certify is coming primarily from the solicitor firms that instruct them. Several overlapping drivers:

Law Society Lexcel. An instructing firm may ask chambers for information-security assurance. Check the firm’s actual requirement and the applicable Lexcel standard rather than inferring a universal Cyber Essentials requirement for its chambers suppliers.

CQS (Conveyancing Quality Scheme). Less directly relevant for criminal chambers than civil, but many criminal barristers are instructed by mixed-practice firms that hold CQS. Those firms have cybersecurity expectations that cascade to their counsel.

Corporate lay clients. Private prosecution work, director liability, and corporate crime cases often bring chambers into direct contact with corporate clients. Those clients, particularly from financial services, pharmaceutical, or regulated sectors, routinely ask about counsel’s cybersecurity posture as part of broader supplier due diligence.

Insurance. Professional indemnity insurance for chambers and for individual barristers is increasingly being priced with reference to cybersecurity posture. CE certification is a signal.

High-profile case exposure. Criminal chambers handling cases with significant public interest, national security context, or sensitive complainant data face reputational and operational exposure from a breach that goes well beyond the BSB’s regulatory reach.

Although the BSB does not prescribe Cyber Essentials, a specific commercial relationship may require it. Confirm the level, entity, scope and deadline in that relationship.

Section 06

How the five CE controls apply to a criminal chambers

Firewalls. Chambers premises in the Inns or surrounding locations typically have a chambers-owned broadband connection with a boundary firewall. The usual requirements apply: default credentials changed, admin interface not exposed to WAN, firmware current. For barristers working from home (which is most of them for paperwork and advice work), the laptop’s software firewall carries the load. Chambers should require managed software firewall configuration on any chambers-issued or MDM-enrolled device.

Secure configuration. This is the area most chambers need to tighten. Typical gaps: shared clerks’ room workstations with local admin rights, legacy software still on unsupported Windows versions, barrister laptops purchased independently with no management baseline, default passwords on chambers network devices. Verify the five required controls using an evidenced management approach; MDM is one option. Separate administrative activity from day-to-day use and review network-device configuration.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

User access control. Under v3.3, MFA on every chambers email account, every case management system user, every CJSM account, every document storage platform user. Shared clerks’ logins (the "chambers_admin" account everyone uses) need to be replaced with individual accounts. Leaver processes - when a clerk, administrator, or barrister leaves chambers - need to reach every in-scope system promptly.

Malware protection. Standard. Windows Defender or EDR on every Windows device, active and updating; Mac built-in protections on Apple devices. The criminal-chambers-specific consideration: CPS digital bundles and other criminal case documents are high-volume file attachments, often from unverified external sources. Real-time scanning on every inbound file matters in practical terms.

Section 07

CJSM’s limitations - an important caveat

One specific insight worth understanding: CJSM (Criminal Justice Secure Mail) is a transport-level security mechanism, not a message-level encryption service. CJSM provides a secure network path between participating organisations (CPS, MOJ, HMCTS, police forces, authorised defence practitioners) but the messages themselves are not end-to-end encrypted or signed in the way that, say, S/MIME or PGP messages are.

The practical implication: an attacker who compromises a barrister’s chambers email account can, in most cases, read CJSM messages that landed in the inbox. CJSM does not defend against post-delivery compromise of the recipient account. That is exactly why MFA on CJSM-linked email accounts, and proper endpoint security on the devices that access those accounts, is more important in a criminal chambers than the CJSM branding alone might suggest. See the dedicated article on CJSM, Common Platform, and criminal chambers cybersecurity for a deeper look.

Section 08

What chambers should do now

If you run a London criminal chambers and have not yet certified:

1. Scope decision. Agree the assessment boundary with the Certification Body using actual ownership and working relationships. Include organisational cloud services and accounts; apply the v3.3 third-party endpoint exclusion without treating employee BYOD or organisation-loaned devices as excluded.

2. MFA sweep. Every chambers cloud platform - email, case management, CJSM, document storage, any secondary tool. MFA on every account.

3. Device baseline. Chambers-managed MDM for staff and ideally for barristers. Intune for M365-based sets, Jamf for Mac-heavy.

4. Leaver process. Integrate with chambers HR. Disable accounts within one working day of departure across every in-scope system.

5. Document the scope carefully. For chambers, the scope statement is especially important because the structure is unusual. Be clear about who is covered and who is not.

6. Certify to Cyber Essentials first (from £299.99 + VAT for micro chambers). Add Plus once chambers is ready for the technical audit (from £1,499.99 + VAT).

Section 09

Bottom line

The BSB does not formally require Cyber Essentials for criminal barristers’ chambers. Check each instructing firm, client, CPS-related arrangement and insurer’s actual conditions. A certificate can support assurance, but does not establish a universal buyer mandate.

London criminal chambers that have already certified find the ongoing compliance posture manageable. Chambers that have not certified face the growing question of why from the people they work with and for. CE is now a credibility artefact in a sector that runs on credibility.

Check your readiness | View pricing | Cyber Essentials in London | Talk to an assessor

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.