The verification rule has been in the Legal Practice Council Rules for years. Whether it gets followed on a busy Friday afternoon is a separate matter.
If you have been anywhere near a law firm’s accounts function in the last few years, you have probably heard some version of this story, or lived through a colleague’s version of it.
Someone gets into a mailbox. Not on the day of the theft, usually, but weeks earlier, and then they sit there quietly and read. Over time they work out who owes what to whom, and roughly when it tends to move. When a transfer comes due, an email arrives with new banking details and a plausible reason for the change: a problem at the bank, a new account, an old one being closed. It is fluent, it sits in the right thread, and it comes from an address that has been in the correspondence for a month. Someone acts on it. By the time anybody realises, the money has been withdrawn and moved on.
Law firms make particularly good targets for this, for two fairly obvious reasons. Conveyancing and litigation both run to a rhythm, so a patient observer can learn when money is likely to move. And when it does move, there tends to be a lot of it.
The version that lands on the practice
It matters a great deal which way round the fraud runs.
If a client is tricked into paying a criminal instead of the firm, that is a bad day for everyone and there will usually be an argument about who carries the loss, but the money never touched the practice’s accounts.
The other version is worse. That is where the firm itself is induced to pay out to the wrong account, and it is the pattern the Legal Practitioners’ Indemnity Insurance Fund (LPIIF) has reported seeing in claims notified to it.
Those claims are not covered. Clause 16(o) of the LPIIF Master Policy has excluded cybercrime claims since 1 July 2016, and that exclusion expressly covers business email compromise where a payment went out without the new bank details being verified. Speaking at a Law Society of South Africa webinar in 2022, the fund’s claims executive Joseph Kunene put the position about as plainly as it can be put: where money is diverted to an alternative account because an email was taken at face value, there has been a failure in basic security protocol. By that point the fund had turned down in the region of 210 claims under the exclusion, worth roughly R150 million between them. The largest single one was R8.8 million.
Kunene made a second point that smaller practices should probably sit with for a moment. Smaller firms tend to have fewer risk measures in place, and the people running these attacks know it, which is exactly why they go looking for them.
There is another gap sitting behind that one. LPIIF analysis of Fidelity Fund Certificate application data has suggested that fewer than a third of practitioners carry cyber insurance. For the other two thirds, a business email compromise loss falls outside professional indemnity cover and outside any cyber policy, which means it falls on the firm.
The control already exists
This is where the legal sector parts company with most of the businesses I talk to about phishing. Everywhere else, the conversation starts with whether a verification step is worth the friction it adds. Here, that was settled years ago and written into the rules.
Writing in De Rebus, the General Manager of the LPIIF set the position out. Rule 54.14.7 of the Legal Practice Council Rules requires internal controls to be developed, implemented and monitored. Rule 54.13 prescribes that those controls include a system for verifying a recipient’s banking details, and any claimed change to them, before payment is made. He also pointed out what follows if trust funds go in a cyber scam, which is a shortfall in the trust balances and a reporting obligation to the Council.
So the rule is not what is missing. What is missing is the part that only happens if a person actually does it: picking up the phone at twenty past four on a Friday, on the twelfth payment of the day, about an email that reads perfectly well and appears to come from someone you have been dealing with for weeks.
I have never met a practitioner who disagrees with the policy. Whether the policy survives contact with a busy Friday is a different question, and the answer to it is training.
POPIA and confidentiality sit on top of this
Attorneys hold more sensitive personal information than almost any small business I can think of, and they hold it under a duty of confidentiality that goes back a great deal further than any statute. Section 19 of POPIA adds a statutory layer on top: appropriate, reasonable technical and organisational measures to protect that information. Organisational measures are generally taken to include training your staff. If it ever comes to explaining yourself to a regulator, a policy nobody has been trained on is an uncomfortable thing to be holding.
What actually changes behaviour
Ongoing training paired with simulated phishing does shift the numbers, and the shift is measurable. KnowBe4’s 2025 benchmarking report, built from 67.7 million simulations across more than 62 000 organisations, puts the baseline at roughly one in three employees clicking a simulated phishing link, dropping to under one in twenty after a year of continuous training. It is a training vendor reporting on its own product, so read the figure as a direction of travel rather than a promise. The sample is large, though, and I have not come across anyone seriously arguing the opposite.
In my experience the reason most practices do not run a programme like this is rarely doubt about whether it works. It is that booking the modules, running the simulations, chasing the people who have not completed them and pulling the reports together adds up to three to five hours a month, and nobody in the firm has three to five hours a month going spare.
That is the part we take on. IronTree’s Security Awareness Training runs as a fully managed service. We schedule it, run the simulations, do the chasing, and produce the documentation that your risk file and your insurer are each likely to ask for. If you would rather see where you stand before committing to anything, our free Phishing Risk Check takes about five minutes.
Get your free Phishing Risk Score. Five minutes, no obligation.
Byron Robertson is Managing Director of IronTree. This article is general commentary on cyber risk and does not constitute legal advice.









