Refine By
Clear all filter
About 703 results for "cybersecurity"
PRECEDENTS
Quarter 1—Confidential information The tips and reminders for this quarter relate to confidential information. You can find more specific information in the following places: • [insert, eg Clear desk and clear screen policy] • [insert, eg Remote working and removable media policy] • [insert, eg Cybercrime prevention strategy and incident management plan] • [insert, eg Confidentiality and disclosure policy] • [insert, eg Information management and security policy] • [insert, eg Internet, email and communications policy] • [insert, eg Bring your own device (BYOD) policy] • [insert, eg Generative AI policy] Month 1—Think ‘secure’ You work on important and sensitive matters. It’s our duty to make sure those matters stay secure and confidential. Always remember to lock your computer or other device when you’re not using them. This will help to keep these devices secure and those important matters confidential. See our [insert, eg Clear desk and clear screen policy] for more information. Don’t leave sensitive customer or business information lying around on your desk—file it in a locked drawer or shred it. Keeping matters confidential is much easier in a protected workspace like our offices. If you are working from home, you need to be aware
PRACTICE NOTES
This Practice Note provides a summary of the key Practice Compliance developments which have impacted compliance professionals in England and Wales in 2026, including legislation, consultations, and other notable developments. For information on ongoing and expected developments, see Practice Note: Practice Compliance horizon scanner—2026. Complaints What’s happened? When? What’s the impact? Find out more LeO Model Complaints Resolution Procedure The Legal Ombudsman (LeO) published its final Model Complaints Resolution Procedure (MCRP), comprising Early Resolution and Full Investigation stages, with supporting guidance, templates and toolkits. 29 July 2026 The MCRP is voluntary. Firms can adapt it to their business, but must include LeO’s five core features if they state that they use the MCRP. MCRP launched to improve legal sector complaint handlingModel Complaints Resolution Procedure Office for Legal Complaints consultation on LeO 2026–27 business plan and budget On 4 November 2025, the Office for Legal Complaints (OLC) launched a consultation on its draft 2026–27 business plan and budget for the LeO including a proposed 12.1% budget increase and a Scheme Transformation Review which will seek views
NEWS
The European Commission has released an internal Cloud Sovereignty Framework setting out baseline requirements to ensure that data processing and storage in EU institutions and agencies comply with Union data-protection, cybersecurity and sovereignty principles.
PRACTICE NOTES
This Practice Note considers the key EU legal issues arising in relation to the use of unmanned aircraft or drones in a recreational and commercial context. It covers: • Drones—the basics • International aviation regulation • European aviation regulation • Classification of drones under the Implementing Regulation and the Delegated Regulation • Key provisions of the Implementing Regulation • Product liability • Insurance • Cybersecurity • Regulating the design and manufacture of UAS Drones (or other uncrewed aircraft) are generally divided into three broad categories. The largest uncrewed aircraft, including those intended for passenger-carrying operations or long-range military applications are treated in the same way as crewed aircraft. They are, therefore, subject to extensive regulation, including platform certification and registration, pilot licensing and operational procedures akin to conventional aviation operations. This category of drone is not covered in this Practice Note. Unmanned aircraft operations that do not meet traditional certification requirements, but can be demonstrated to be safe, fall into the second category. Most aviation regulators
PRECEDENTS
1 Review Name of person(s) conducting review [Insert name(s)] Date of review [Insert date] Number of files/pages added in the review
PRECEDENTS
Threat What is it? Our defensive measures Advanced persistent threat (APT) Attackers gain unauthorised access to a system and remain undetected for a prolonged period of time. They may carry out unauthorised transfers of sensitive data.Even when they are detected, they may leave several ‘backdoors’ open so they can return. We ensure users are aware of the risk and of basic account security procedures.We use firewalls to inspect and filter traffic.We use antivirus software. Botnet Collection of infected computers remotely controlled by a hacker.The hacker can share or sell access to the computers to other cyber criminals to be used to distribute spam or overload a system. See Malware and Hacking Chain letter An email that encourages the user to forward copies to other people.Not a security threat but can waste time and slow down mail servers. We ensure users know not to forward chain letters or hoaxes.We try to stay informed about chain letters and hoaxes. Commercial identity theft Bogus organisations (eg law firms) present a significant risk to the interests of consumers and our reputation if we become associated with one, eg because it
NEWS
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to laws governing the use and dissemination of information and personal data. Each week these highlights focus on developments in key topics such as data protection, ePrivacy, cybersecurity, breach of confidence, misuse of private information, and defamation. This special edition of the weekly highlights also includes a recap on the yearly highlights of 2024 and key topics to look out for in 2025.
Q&As
Pandemics cause difficult business conditions and uncertainty for many law firms and solicitors. Often they involve doing all you can to close your office and work from home, and that results in an unprecedented number of solicitors and staff working from home and providing their services digitally, some having rarely or never done so before. The SRA acknowledges that this will present many with new cyber security challenges. Legal requirements The SRA expects you to identify, monitor and manage all material risks to your business. See Practice Note: How to identify and evaluate risk across the business. Information and cyber-security are important risks to consider for most law firms. Confidentiality You must keep the affairs of clients confidential unless disclosure is required or permitted by law or the client consents—see subtopic: Confidentiality and disclosure. All firms must have measures in place to keep client’s information confidential. Most firms will already have in place arrangements to protect client information for
PRECEDENTS
1 Introduction 1.1 We have performed an organisation-wide assessment of the risk of our systems and/or services falling victim to cybercrime. 1.2 The review included consideration of: 1.2.1 our critical IT assets; 1.2.2 the most likely targets; 1.2.3 potential types of attack; and 1.2.4 our defences. 2 Critical IT/data assets 2.1 We have considered our critical IT and data assets. These include: 2.1.1 client data; 2.1.2 [personnel data;] 2.1.3 [website;] 2.1.4 [IT server;] 2.1.5 [e-mail server;] 2.1.6 [transactional data;] 2.1.7 [sensitive information about our business.] 3 Likely targets 3.1 We know that our organisation is particularly attractive to cybercriminals because of the confidential information we hold—about our clients, third parties, [transactions,] staff and the business itself. 3.2 We also know that some cybercrime is committed simply to disrupt genuine commercial operations. 3.3 It follows that the potential targets of cybercriminals are those routes into that confidential information, including weak spots such as: 3.3.1 smart/mobile devices—these devices are highly vulnerable to attack, lack notification methods when vulnerabilities are discovered, and do not always have user-friendly methods to patch new vulnerabilities; 3.3.2 social networks—attacks by cybercriminals are becoming more targeted, and social networks are a useful source of data for crafting these types of attacks. Highly targeted attacks like these are more likely to compromise our network; 3.3.3 out of date hardware/software—letting any hardware or software
PRECEDENTS
1 Introduction 1.1 While remote working (whether at home or on the go) and removable media offer our business and customers great benefits, they can also expose us to risks that are not easy to manage. 1.2 This policy explains details of those risks, as well as the procedures we have in place to mitigate them. 2 Responsibility and application 2.1 [State name or role, eg The Data Protection Officer (DPO)] is responsible for this policy. 2.2 This policy applies to all staff. 3 The risks Remote working and removable media involve the transit and storage of confidential and sensitive data outside the secure environment of the office, usually across the internet and sometimes in public places. This exposes us to significant risks. 3.1 Loss or theft of data Mobile devices are highly susceptible to being lost or stolen and they may not have the same level of physical security as devices we keep at the office. 3.2 Public place vulnerability Working remotely sometimes means working in a public place (such as a café or on a train). This presents the risk that you are observed by someone else, and the security
NEWS
This week's edition of EU Law weekly highlights includes the finalisation of the EU’s budget for 2025 and the final approval of Ursula von der Leyen’s second Commission. In addition, this week, revisions to the EU CLP Regulation and a recast of the Ambient Air Quality Directive were published in the Official Journal, the European Chemicals Agency published a progress report on the proposal for a sweeping PFAS restriction, the European Union Agency for Cybersecurity released a report on cybersecurity investments under the NIS 2 Directive, and the Commission initiated a review of the Technology Transfer Block Exemption Regulation and mandated risk reports from the 19 major online platforms designated under the EU Digital Services Act. These highlights also include analyses on importer requirements under the EU Methane Regulation, the Court of Justice decision on harmonising EU copyright protection for non-EU designs, the Unified Patent Court’s (UPC) first main action decision on a standard essential patent, and the relationship between the EU AI Act and Medical Devices Regulations.
NEWS
On 25 September 2024 the G7 Cyber Expert Group (CEG) published a public statement highlighting the potential cybersecurity risks associated with developments in quantum computing and recommending steps for financial authorities and institutions to take to address those risks.