IT Requirements for Law Firms in Australia: The 2026 Baseline

IT Requirements for Law Firms in Australia: The 2026 Baseline

Ten years ago your IT budget bought productivity: practice management software, document automation, a file server moved into the cloud. In 2026 those same systems carry statutory obligations, reporting deadlines measured in hours, and a professional conduct duty that survives any breach.

Three changes in the past eighteen months apply to lawyers rather than to business at large.

The first is anti-money laundering. Since 1 July 2026, legal practices providing “designated services” have been reporting entities under the amended Anti-Money Laundering and Counter-Terrorism Financing Act 2006. This is the Tranche 2 reform, and it brought roughly 80,000 new businesses — lawyers, conveyancers, accountants, real estate professionals, trust and company service providers — into a regime that previously covered banks and casinos. Enrolment with AUSTRAC opened on 31 March 2026, and firms providing designated services from 1 July had until 29 July to enrol.

The second is the breach picture. The OAIC recorded 1,205 notifications under the Notifiable Data Breaches scheme in the 2025 calendar year, the highest annual total since the scheme began in 2018 and an 8% increase on 2024. Of those, 716 came from malicious or criminal activity. Legal, accounting and management services firms filed 81 notifications between them, which works out at roughly three every fortnight.

The third is artificial intelligence. Courts in each Australian jurisdiction now publish protocols governing how generative AI may be used in proceedings, and several impose technical requirements.

1,205
data breach notifications to the OAIC in 2025, the highest since the scheme began
72 hrs
to report a ransomware payment, with no minimum payment threshold
7 years
minimum retention for AML/CTF records and eConveyancing evidence

The dates that matter

  • 30 May 2025: mandatory ransomware payment reporting commenced
  • 10 June 2025: statutory tort for serious invasions of privacy commenced
  • 1 July 2026: Tranche 2 AML/CTF obligations began applying to law firms
  • 29 July 2026: AUSTRAC enrolment deadline for firms in scope from 1 July
  • 10 December 2026: automated decision-making transparency required in privacy policies

The regulatory stack

Privacy Act 1988 and the Notifiable Data Breaches scheme

The Australian Privacy Principles govern how a firm collects, holds, uses and discloses personal information. APP 11 is the one that bites on IT: reasonable steps to protect information from misuse, interference, loss, and unauthorised access or disclosure.

Historically many small practices sat outside the Act via the small business exemption for entities under $3 million annual turnover. That assumption is now unsafe. The interaction between AML/CTF reporting entity status and the Privacy Act’s exemptions means a firm that was comfortably outside the Act in June 2026 may not be outside it now. Have a specific conversation with your own advisers. Do not plan your IT on the basis that the exemption still protects you.

Under the NDB scheme, an eligible data breach must be notified to the OAIC and to affected individuals where there is unauthorised access, disclosure or loss of personal information likely to result in serious harm, and remedial action has not prevented that risk. The OAIC has been explicit that the clock starts when any employee becomes aware of the incident, not when it reaches the partner group or the IT provider.

Enforcement has teeth it did not have three years ago. The tiered civil penalty regime and the OAIC’s infringement notice powers commenced 11 December 2024. On 10 June 2025 a statutory tort for serious invasions of privacy commenced, giving individuals a direct cause of action against any person, not only APP entities, for intrusion upon seclusion or misuse of information. As of 2026 that tort is over a year old and no longer theoretical.

One date to diarise: from 10 December 2026, automated decision-making transparency requirements must appear in privacy policies. If your firm uses any system that makes or substantially assists decisions about individuals, that is a policy and documentation task with a hard deadline four months out.

AML/CTF and the new record-keeping burden

Tranche 2 obligations are procedural, but they land on IT as a data problem. Reporting entities must enrol with AUSTRAC, maintain an AML/CTF programme, conduct customer due diligence before providing a designated service, screen against sanctions lists and politically exposed persons, submit suspicious matter reports, and retain records for seven years.

The practical implications:

  • Identity documents now sit in your systems in volume. Passports, licences, company structures, beneficial ownership records. This is the data set that makes a firm attractive to an attacker, and Tranche 2 has you collecting it in bulk.
  • Log every screening. Your system should record who ran the check, which list they screened against, the date, and the result. An assurance from a staff member that they checked will not satisfy an AUSTRAC reviewer.
  • Build seven-year retention into the records system. Your backup rotation overwrites itself on a cycle measured in weeks or months, so it cannot hold a record for seven years. Many firms discover this when an examiner asks for a file from 2021.
  • Suspicious matter reporting creates a confidentiality problem inside your own firm. Tipping-off provisions mean access to certain records needs to be restricted, including from staff working on the matter.

The Australian Solicitors’ Conduct Rules were amended in 2026 in ways connected to this regime, including changes to Rule 8 on client instructions and a new requirement in Rule 12 that retainer agreements inform clients that the solicitor is subject to statutory reporting obligations that may capture confidential information. Engagement letter templates in your document management system need updating accordingly.

Cyber Security Act 2024 and the 72-hour ransomware clock

Since 30 May 2025, entities carrying on business in Australia with annual turnover of $3 million or more (and responsible entities for certain critical infrastructure assets, regardless of turnover) must report ransomware or cyber extortion payments to government within 72 hours of making the payment, or of learning that someone paid on their behalf, including an insurer or incident response firm. There is no minimum payment threshold. Civil penalties for non-reporting run to $19,800.

The clock starts at payment. Not at discovery, not at containment, and not when your incident response firm finishes its report. If a third party pays on your behalf, the obligation is still yours, and the 72 hours runs from when you become aware of it.

This obligation sits on top of the NDB scheme rather than replacing it. A single ransomware incident involving client personal information triggers both, with different triggers and different clocks. There is also a sanctions screening question that must be resolved before any payment moves, which is a legal question and not an IT one.

Legal Profession Uniform Law and professional conduct

Rule 9 of the Australian Solicitors’ Conduct Rules imposes an ongoing duty of confidentiality. A cyber incident does not discharge it. Where a breach exposes privileged communications, the consequences run beyond regulatory penalty into potential waiver of privilege, damage to the client’s legal position, professional disciplinary exposure and negligence claims.

Trust account record-keeping under the Uniform Law and its associated rules carries its own retention and audit-trail requirements, and trust accounting systems need to produce records in a form an external examiner can actually work with. Watch the interaction between electronic funds transfer authorisation and business email compromise. Trust account fraud through invoice or settlement redirection remains one of the most damaging incident types in the sector.

eConveyancing

For property practices, the Model Participation Rules administered by ARNECC and the operating requirements of the electronic lodgment network impose:

  • Verification of identity to a prescribed standard
  • Digital certificates issued to named individuals, which must not be shared. Using another practitioner’s certificate can invalidate the transaction, breach the platform’s security policy and PI cover, and constitute unsatisfactory professional conduct or professional misconduct
  • Retention of evidence supporting the dealing, including VOI evidence, for at least seven years from lodgment

Digital certificate management is a genuine access-control problem in firms where conveyancing volume is high and staff turnover is normal. Treat certificates as individual privileged credentials: issue them, track them, and revoke them on departure.

Court protocols on generative AI

The Supreme Court of NSW’s Practice Note SC Gen 23 took effect on 3 February 2025 and is the model most other jurisdictions have followed. Its requirements are technical as much as ethical:

  • Practitioners must understand the limitations of the tool they are using, including hallucination and bias
  • Generative AI must not be used to generate the content of affidavits, witness statements, character references or other material intended to reflect a deponent’s evidence
  • AI must not be used to draft expert reports without leave of the court
  • Certain categories of material, including documents subject to the implied (Harman) undertaking and material produced on subpoena, must not be entered into a generative AI system unless the practitioner is satisfied the information stays within the provider’s controlled environment, is used only for that proceeding, and is not used to train the model
  • Any citation or reference generated by AI must be manually verified

That fourth point is an infrastructure requirement. Satisfying it means knowing, contractually and technically, where your AI tooling sends data, whether it is retained, and whether it trains on input. You need an enterprise deployment with zero-retention terms and documented data residency. A consumer chatbot account cannot meet that standard.


What this means for the build

Reading the obligations back into infrastructure, a defensible law firm environment in 2026 needs:

Identity and access

Multi-factor authentication on every account without exception, moving toward phishing-resistant factors for anyone with access to trust accounting, the practice management system or administrative privileges. Conditional access policies. Prompt de-provisioning on departure, including digital certificates, portal logins and any third-party platform.

Email security

SPF, DKIM and enforced DMARC. Business email compromise is the dominant vector for trust account fraud, and the OAIC reports social engineering and impersonation as major contributors. Pair the technical controls with a documented, out-of-band verification process for any change to payment details: a phone call to a known number, never a number supplied in the email.

Endpoint protection and patching

Endpoint detection and response rather than legacy antivirus. Centrally managed OS and application patching with defined timeframes. No end-of-life operating systems on the network.

Backup and recovery, with immutability

Backups that an attacker with domain credentials cannot encrypt or delete. Restoration testing that someone performs and documents. Firms skip this step, then learn how long a restore takes during the outage itself.

Records, retention and disposal

A document management system that can hold matter records for the statutory periods, apply retention rules, and dispose of data when the period expires. Over-retention is now a liability: data you no longer need can still be breached and still be sued over.

Logging and monitoring

You cannot assess whether a breach is notifiable without knowing what was accessed. Firms without meaningful audit logging end up over-notifying, because they cannot rule anything out.

Third-party and supplier risk

Barristers’ chambers, e-discovery vendors, transcription services, costs consultants, offshore paralegal support. Client data leaves the firm every week, and the obligation stays with you.


Frameworks: which one, and a transition to watch

The ASD Essential Eight remains the de facto Australian baseline and the thing insurers, tenders and assessors measure against. Its eight strategies have not changed since the November 2023 update.

However, in June 2026 the Australian Signals Directorate opened consultation on replacing the Essential Eight with a broader Essentials series, beginning with a chapter on enterprise IT. Consultation closed on 12 July 2026. ASD has signalled a staged transition of roughly two years, with the two frameworks running side by side before deprecation. ASD is moving away from a single fixed maturity ladder toward prioritised, threat-informed controls organised by domain. ASD’s position is that existing Essential Eight investment remains relevant under the new model.

Keep working to the Essential Eight, and build for outcomes, because ASD is going to restructure the checklist.

SMB1001 is worth a look for smaller practices. It is a tiered Australian certification (Bronze, Silver, Gold, Platinum, Diamond) designed for organisations that cannot attempt ISO 27001. Bronze through Gold are self-attested through the certification portal; Platinum and Diamond require independent audit. The 2026 edition expanded the Gold tier from 23 to 27 controls, adding requirements including EDR, enforced email authentication, mandatory cyber insurance, an incident response plan, a digital asset register and a responsible AI use policy. For a firm that needs to answer client and insurer questionnaires with something more substantial than assurances, it is an achievable credential.

ISO 27001 remains the right target for larger firms, particularly those acting for government, financial services or enterprise clients whose procurement processes require it.

Framework Best suited to Assurance Status
ASD Essential Eight Any firm; the default reference for insurers and tenders Self-assessed or independently assessed against four maturity levels Current, but being replaced by the Essentials series over roughly two years
SMB1001 Small and mid-sized practices needing a credential without enterprise cost Bronze to Gold self-attested; Platinum and Diamond independently audited Current; 2026 edition expanded Gold from 23 to 27 controls
ISO 27001 Larger firms acting for government, financial services or enterprise clients Externally certified management system Stable international standard

The incident response plan is now a compliance artefact

The clocks overlap: 72 hours for a ransomware payment report, “as soon as practicable” for NDB notification with a 30-day maximum assessment window, plus AUSTRAC obligations and client notification duties. Your incident response plan needs to be written, tested and accessible when the network is down.

Name the person who decides, the people they call, the facts that trigger each obligation, and who speaks to clients, regulators and insurers. Then print it. Ransomware encrypts the file server holding your only copy of the plan.

A tabletop exercise costs an hour and surfaces the gaps while they are still cheap to close.

We have covered this in more depth, with a free fillable template you can complete for your firm, in Does Your Business Need an Incident Response Plan?


How Mobile Techs IT Consulting closes the gap

Parliament writes these obligations in legal language, and someone has to turn them into configuration. Mobile Techs IT Consulting works in that space, translating what the Privacy Act, the AML/CTF Act, the Cyber Security Act and your court’s AI protocol require into controls that exist on your network, and then keeping them there.

ThreatDown EDR and the modern detection baseline

Legacy antivirus no longer meets the standard. Endpoint detection and response is now an explicit requirement at SMB1001:2026 Gold, an expectation under the Essential Eight’s malware defences, and a practical necessity for demonstrating APP 11 “reasonable steps.”

We deploy and manage ThreatDown EDR across law firm environments, which gives a practice three things it cannot get from a consumer security product:

  • Behavioural detection and containment. Ransomware in a legal environment starts a 72-hour reporting clock, a notifiable data breach assessment, and a confidentiality breach under Rule 9, all at once, on top of the downtime. Detecting and isolating an infected endpoint before it reaches the file server or the practice management database is the difference between an internal incident and a reportable one.
  • Rollback capability. Where encryption does occur on a protected endpoint, reverting those changes shortens recovery and narrows what you have to assess for notification.
  • Evidence you can hand to a third party. Insurers, clients and prospective clients ask what endpoint protection is in place. “We have EDR deployed and centrally managed across all endpoints” is an answer that survives a questionnaire. “We have antivirus” is not.

Remote Monitoring and Management: patching, devices, and the asset register you don’t have

Two of the eight Essential Eight strategies are patching: operating systems and applications. Both are measured on timeframes, and neither can be demonstrated without central management. Most firms fail here through drift: the laptop that has been offline for six weeks, the machine still running an operating system past end of support, the practitioner who has been deferring restarts since March.

Our RMM platform, backed by our remote support service, addresses this:

  • Automated, enforced patching across operating systems and third-party applications, with defined maintenance windows and reporting on what actually applied rather than what was scheduled.
  • A live device inventory. SMB1001:2026 Gold requires a digital asset register. Most firms do not have one, or have one in a spreadsheet that was accurate eighteen months ago. RMM produces it as a by-product of doing the work: every managed device, its operating system, its patch state, its protection status.
  • End-of-life detection. Machines running unsupported operating systems get flagged and scheduled for replacement before they become the entry point.
  • Proactive alerting on health and configuration drift, including failing drives and backup jobs that stopped completing without anyone noticing. That is how most firms find out their backups were failing.
  • Reporting for audits and insurance renewals. When the underwriter, the external examiner or a corporate client’s procurement team asks for evidence of patch management, we can produce it as a report rather than an assertion.

Custom data storage and internal systems

This is where off-the-shelf products fall short for legal practices, and where most of our law firm work sits.

Seven-year retention under the AML/CTF Act, seven-year retention of VOI and supporting evidence for eConveyancing dealings, trust account record-keeping under the Uniform Law, and matter file retention that in some categories runs far longer — these are not the same requirement and they do not have the same lifecycle. A general-purpose cloud drive does not distinguish between them, and a backup rotation does not satisfy any of them.

Mobile Techs designs and builds custom data storage and internal systems around how a specific firm actually works:

  • Retention built into the storage. Records subject to statutory retention periods are held for those periods, in a location you can identify, and disposed of when the period expires, instead of sitting there by default and growing your breach exposure.
  • Segregated access for sensitive categories. AML/CTF records, suspicious matter documentation and identity document repositories need access controls that differ from general matter files. Tipping-off obligations make this a compliance requirement. We build the segregation into the system rather than relying on staff to remember it.
  • Internal workflow and intake systems that capture CDD evidence, screening results and identity verification at the point they occur, with the metadata (who, when, against what) that turns a completed check into defensible evidence.
  • Audit logging that answers the notification question. When an incident occurs, the assessment is “what was accessed?” Systems built without logging cannot answer, and firms in that position over-notify because they cannot narrow the scope. We build logging in from the start.
  • Integration with what you already run. Practice management, trust accounting, document management and eConveyancing platforms are not going anywhere. We fill the gaps between them instead of replacing them.

What we do not do

Mobile Techs does not provide legal advice on whether your practice provides designated services under the AML/CTF Act, does not act as a certification body, and does not broker cyber insurance. Those are conversations for your own advisers, an accredited assessor and your broker respectively. We make sure that when those conversations happen, the technical answers are already in place, you can evidence them, and you have found the remaining gaps before someone else does.

Compliance readiness review

Find out where your firm actually stands

Most firms are further ahead than they think in some areas and further behind in others. They usually find out which is which from an insurer’s renewal questionnaire, a corporate client’s procurement form, or an incident that has already started the clock.

Mobile Techs assesses your current environment against the obligations set out above: endpoint protection, patching and device management, retention and access controls, email authentication, backup and recovery, and incident response readiness. You get a written, prioritised list of what needs attention now, what can wait, and what each item involves.

No jargon and no obligation. You get a clear picture before someone else asks for one.

Book a review
Talk to us first

Call 1300 644 588  ·  office@mobiletechs.com.au
Supporting Gold Coast businesses on-site since 2008, and firms across Australia remotely.
More on our managed IT services, remote security audit and how we work.


A baseline by firm size

Firm size Baseline controls Target credential
Sole practitioner
to 10 staff
MFA everywhere, EDR, managed patching, immutable backup with tested restores, DMARC enforced, written incident response plan, documented seven-year retention, AI use policy, cyber insurance SMB1001 Bronze or Silver
10–50 staff All of the above, plus centralised device management, conditional access, meaningful audit logging, formal supplier risk review, role-based access controls around AML/CTF records and trust accounting, annual tabletop exercises SMB1001 Gold, or Essential Eight Maturity Level One with a documented path to Level Two
50+ staff All of the above, plus security monitoring with defined response coverage, privileged access management, data loss prevention, a named individual accountable for information security, board or partnership-level risk reporting Essential Eight Maturity Level Two, or ISO 27001

The gaps that show up most often

The recurring failures in legal environments are mundane:

× MFA everywhere except the one legacy system that could not support it
× Backups that have never been restore-tested
× Departed staff whose accounts, certificates or portal access were never revoked
× Retention policy that exists as a document and nowhere else
× Generative AI in daily use with no policy, no approved tool list, and no idea what the provider does with input
× An incident response plan written for the pre-2025 obligations, with no 72-hour ransomware step

Closing these costs less than explaining them to an insurer or an examiner afterwards.


General information only. This article covers the technology and security implications of current Australian regulation. It is not legal advice and does not account for any particular firm’s circumstances. Obligations under the Privacy Act, the AML/CTF Act, the Cyber Security Act, the Legal Profession Uniform Law and jurisdictional court protocols vary by firm and by state, and continue to change. Firms should obtain their own advice on how these regimes apply to them.