Start typing to search across courses, articles, and pages.

SRA

Cyber and Information Security Training (Law Firms)

Course Overview

This eLearning course provides comprehensive cyber and information security awareness training tailored for staff working in law firms. Legal practices hold large volumes of highly sensitive client and commercial information, making them an attractive target for cyber criminals, so every member of staff has a role to play in protecting the firm's information assets.

The course begins with an introduction to the threat landscape, explaining the types of threat actors that target law firms and the methods they use. It then examines social engineering in depth, including phishing, spear phishing and pretexting, and the steps employees can take to identify and resist these attacks. The training also addresses the emerging risks and safeguards associated with the use of artificial intelligence.

Learners are guided through the dangers of ransomware and other malware, how infections occur, and how to avoid them. The course covers safe email and internet use, the importance of strong passwords and good authentication practices, and the protection of physical data — including the secure handling of confidential client information both in and out of the office.

Finally, the training explains what to do when things go wrong, including how to recognise a potential breach, the importance of prompt reporting, and the firm's incident response process. Upon completion, learners will have a practical understanding of cyber and information security and be equipped to protect the firm and its clients from harm.

Learning Outcomes

  • Understand the current cyber threat landscape facing law firms
  • Recognise social engineering techniques such as phishing and pretexting
  • Understand the risks and safeguards relating to artificial intelligence
  • Identify ransomware and other malware threats and how to avoid them
  • Apply safe practices for email and internet use
  • Maintain strong password security and authentication practices
  • Protect physical data and handle confidential client information securely
  • Know how to respond when a security incident occurs