Terrells Solicitors LLP: Cyber Security

Terrells Solicitors LLP is a well-respected and established legal practice.  The firm operates from offices in Peterborough. As part of Terrells commitment to quality it holds the Law Society Accredited, Lexcel Legal Practice Quality Mark (Excellence in legal practice management and client care).  Terrells recertification process for this quality mark meant it was necessary to demonstrate good practice when it comes to Cyber Security processes.

Challenge

The steps outlined in the Lexcel requirement reflect the key controls set out in the assurance framework for the government backed and industry endorsed Cyber Essentials Scheme.

Additionally, with the new General Data Protection Regulation (GDPR) requiring that Cyber Security be addressed and tested by “applying appropriate technical and organisational measures to ensure a level of security appropriate to the risk” it was necessary to address the risks and tackle any Cyber Security issues which may exist prior to the GDPR entering UK law on May 25th 2018.

Terrells sought the reassurance that their sensitive customer data could be considerably more secure and to achieve a second opinion by way of a government and industry endorsed certification (Cyber Essentials) that they had secured their network effectively.

Solution

Upon instructions from Terrells, we examined their IT systems and identified the areas where improvement was required.  This involved audits on:

  • Firewall Configuration
  • Systems Access
  • Patch Management
  • Password complexity
  • A software audit report
  • A report of users/admin accounts
  • The configuration status of various other systems.

Following this initial audit, we provided Terrells with a report/risk assessment detailing where potential vulnerabilities existed and identify areas for improvement. We discussed an action plan to make necessary improvements.  This included firewall configuration work, the removal of non-required software programs, ensuring that system patching was bought up to date and many other tasks all designed to make Terrell’s systems more “Cyber Safe”.

Result

Once these remedial works had been carried out, we were then able to prepare the relevant documentation to submit a request for Cyber Essentials certification for Terrells.  This certification was granted on 1st February 2018. 

Upon receipt of the certification Cherry Terrell – Practice Manager at Terrells commented “Thank you and your team for all your help, we are so happy to get the certificate”

Featured service:

Service Family