Episode Summary:
Cybersecurity failures rarely start with sophisticated hacks. They start with exploiting everyday habits and loopholes that are easy to overlook. In this episode, we unpack cybersecurity for lawyers with one clear message: prevention is better, and much cheaper to implement, than the cure.
Guest:
• Chris Schwinghamer, Chief Information Officer, Victorian Legal Services Board and Commissioner
• Specialist in digital strategy, cybersecurity and data governance in regulatory environments
• https://au.linkedin.com/in/chrisschwinghamer
Host:
• Jayne Gurton, Law Institute of Victoria
• [email protected] | https://www.linkedin.com/company/law-institute-of-victoria
Episode Overview:
Cybersecurity and cyber risk mitigation for lawyers is no longer just about anticipating and preparing for the worst case scenario. It is about managing routine tasks and habit. In this episode, Chris Schwinghamer explains why law practices are attractive targets for cyber crime and how simple behaviours can significantly reduce exposure.
The discussion covers cyber hygiene in legal practice, including password management, multi-factor authentication, software updates, phishing awareness and safer use of social media. We also explore remote work risks, public Wi-Fi, VPN use and protecting devices when travelling or working outside the office. This episode focuses on practical, low-cost actions that support client confidentiality, professional obligations and compliance with minimum cybersecurity expectations.
Topics & Timestamps:
• 02:55 Common cybersecurity vulnerabilities in law firms
• 04:44 Strong passwords, passphrases and password managers
• 06:36 Why software updates matter for ransomware prevention
• 08:28 Phishing red flags and business email compromise
• 10:55 Social media hygiene and over sharing risks
• 12:29 VPNs, public Wi−Fi and remote work security
• 13:50 Securing devices when working outside the office
• 15:12 Where to find trusted cybersecurity resources
Key Takeaways:
• Cybersecurity risk often comes from small, routine decisions rather than major system failures
• Law practices are high-value targets because of the sensitive information they hold
• Long, memorable passphrases and password managers reduce password-related breaches
• Keeping systems updated is a critical defence against ransomware
• Urgency, impersonation and unusual requests are key phishing warning signs
• Simple habits like pausing to verify requests prevent costly cyber incidents
Resources & Links:
• LIV Cybersecurity Hub – Centralised guidance and CPD resources for practitioners | https://www.liv.asn.au/cybersecurityhub
• Law Institute Journal – Cybersecurity and professional obligations – Editorial analysis linking cyber risk to legal duties | https://www.liv.asn.au/web/law_institute_journal_and_news/web/lij/year/2024/09september/practice_management__securing_your_practice_from_cyber_risk.aspx
• VLSB+C Cybersecurity Guidance – Regulator guidance on why cybersecurity is a professional obligation | https://lsbc.vic.gov.au/lawyers/practising-law/cybersecurity
• Minimum Cybersecurity Expectations – VLSB+C standards for Victorian law practices | https://lsbc.vic.gov.au/lawyers/practising-law/cybersecurity/minimum-cybersecurity-expectations
About This Podcast:
Cross-Examined is a new podcast from the Law Institute of Victoria. Tune in to hear experts discuss hot topics in the law and the changes shaping the legal profession. Regular episodes will cover everything from AI and cyber threats to ethical dilemmas, workplace taboos and practice management insights.
This podcast is recorded on the traditional lands of the Wurundjeri people of the Kulin Nation. The Law Institute of Victoria acknowledges the Traditional Custodians of Country across Australia. We pay our respects to Elders past and present.
Disclaimer:
This podcast is for informational purposes only and is not intended to replace professional legal advice. The views expressed in this podcast do not necessarily reflect the views of the Law Institute of Victoria (LIV). The LIV is not responsible for any losses, damages or liabilities that may arise from the use of this podcast. Listeners should seek independent legal advice for their matters.
Production Information:
• Produced by: The Law Institute of Victoria
• Producer and audio editor: Garreth Hanley
• Music: Garreth Hanley
• Copy and show notes: Louise Surette
Connect With Us
Email: [email protected]
Website: https://liv.asn.au
LinkedIn: https://www.linkedin.com/company/law-institute-of-victoria
Apple Podcasts: https://podcasts.apple.com/au/podcast/cross-examined/id1858765728
Spotify: https://open.spotify.com/show/0zvyk5xia4wYv9YWcXphgV
Welcome to Cross-Examined, a podcast by the Law Institute of Victoria.
Jayne Gurton:Cyber risks in legal practice are no longer defined by rare catastrophic breaches. Instead, they are defined by routine decisions made every day. Reusing a password, delaying an update or maybe even trusting an email that looks familiar. Or working on the go without stopping to think about who else might be watching.
Reducing these seemingly small risks is achieved not with expensive security measures or sophisticated technology, but with excellent cyber hygiene practices, the topic of today's episode.
So, fasten your seatbelts and don't forget your toothbrush, as we explore the simple, repeatable actions that materially reduce risk for you, your clients and your practice.
I'm Jayne Gurton and this is Cross-Examined.
Today we are joined by Chris Schwinghamer, the Chief Information Officer at the Victorian Legal Services Board and Commissioner.
Chris leads digital strategy, cybersecurity and information governance for Victoria's legal regulator and works closely with the systems and controls that sit behind the VLSB+C's minimum cybersecurity expectations for law practices.
Chris, welcome to Cross-Examined.
Chris Schwinghamer:
Thank you, Jayne.
Jayne Gurton:
Now, let's start with a big-picture question. What are you seeing from your position at the regulation body around cybersecurity?
Chris Schwinghamer:
At the VLSB+C, we've been observing and concerned about cyber crime for quite some time, especially since 2020. I'm sure we've all seen the very public breaches that have happened around cyber with Medibank, Optus and even recently Qantas. And we are seeing more and more attacks on law practices.
that we've published. And, in:And with those expectations, we do encourage lawyers to ensure they are always aware about them, as well as legislation around cybersecurity, such as recent amendments to the Privacy Act, Notifiable Data Breach Scheme and, of course, Australia's first standalone Cyber Security Act, which was issued in 2024.
More broadly, we know cybersecurity is getting more and more, increasingly, important. It's not going anywhere. It is really a topical theme. And we know that cyber criminals are using things like generative artificial intelligence to create things like phishing campaigns and impersonate people with AI-generated voice and video calls and deepfakes.
Jayne Gurton:
Okay, Chris, when we talk about cybersecurity in law practices, where do firms fall short? And what are the most common vulnerabilities you see?
Chris Schwinghamer:
Yeah, that's a great question. So, definitely the first area where people fall short is definitely around good cyber risk awareness. I know it sounds really fundamental and basic, but humans are the last line of defence. Right? You can have a great system, but if you leave the door open and you leave a Post-It Note on your computer with a password, you are opening up yourself to compromise.
So, it's really important to always think about that human layer. And lawyers need to be particularly alive to the risks posed by cyber crime, because law practices are really a honeypot. They contain lots of client information about money and sensitive information they hold. Even law practices that don't handle high-value transactions, even if you are small, it's really important, because you are still a target. You can still be extorted, and you can still have your information potentially stolen. And we are continuing to see this across the sector with Victorian legal practices that really probably could have avoided breaches if cybersecurity controls have been implemented and more strictly adhered to.
Passwords is a really important part. We always encourage people to use multi-factor authentication on top of passwords and being mindful about out-of-date systems, as well as social engineering that might occur.
More than passwords, I think what we are seeing is certainly around emails, so business email compromise is what we call it in the industry. And the Australian centre for cybersecurity released annual information around this. It is by far and away the biggest breach item across all areas, and law is no exception. I think it accounts for around 15 per cent of their total reported items, costs small businesses tens of thousands of dollars a year, and many millions for large organisations once they are breached and compromised.
Jayne Gurton:
Okay, let's start with passwords. What actually makes a strong password? And why do so many professionals still struggle with password management in practice?
Chris Schwinghamer:
Yes, thank you. It is a good question. So, particularly with passwords, a strong password is generally at least eight to 10 characters long, has some symbols and some numbers usually in it. That's the traditional way of thinking about it, and we still encourage that as a minimum.
What I'd like to add too, is that if you do use passwords to not only think about making them complex, but also making them long. So, from a cybersecurity standpoint, the longer your password is, the harder it is to run computational calculations on it and have it breached or hacked. So, having something that's long and memorable is certainly practical.
Personally, I am quite a fan of things like passphrases, which are easy to remember as a human – something like “Mary had a little lamb”, or something that means something meaningful to you, as well as some symbols and some characters. And considering the length of that, that becomes much harder than a smaller password, with the common ones being your family's dog or your date of birth, right? The very common ones.
And what I will add just on top of that is password managers have come a long way. They are quite secure these days. And we do encourage people to always not reuse passwords, but to instead use a password manager where possible. And that way you can use a unique password for each one of your systems that you might be using on a day-to-day basis.
The last important part that I want to add is around security, particularly with biometrics. It might not be applicable for everyone, but if you can afford it, it is best practice to use things like fingerprint scanners on laptops or USB security keys. And that way, even beyond a password, you are really strongly protected against compromise.
Jayne Gurton:
Device updates often feel like an inconvenience. Can you explain why keeping systems and software current is so critical for legal professionals?
Chris Schwinghamer:
Yeah, that's right. Another good analogy for this, I like to think, Jayne, is around leaving systems not updated is like leaving your car or house unlocked, right? It's a first level of defence against intrusion. So, certainly, updating your software and patching reduces that likelihood pretty dramatically, particularly for ransomware. So, ransomware really targets systems or software that is out of date and uses it as a way of going through and entering in a network to access sensitive information. So, if you are concerned about ransomware, which we all should be, then be very mindful about making sure that your systems are up to date, patched and especially the ones facing outward, towards internet and providing services to your clients.
So, the way to do that is to always keep an eye on the latest releases that are published by your software. Now it depends on what software you use. I always encourage you to liaise strongly with your IT teams as well as checking notifications from your suppliers around latest releases. In particular, one little tip I have is around subscribing to security releases. So, not all releases are the same. There might be some releases about functionality, which is quite difficult for your practice or area to implement. However, if there's a security one, apply it straight away.
Make sure that your automatic updates are on for your systems that you critically use all the time, especially the ones that are facing towards the internet or that you might have publicly accessible for clients. And make sure you proactively check with your software provider, subscribe to their newsletters and updates, particularly around security updates and get them to inform you straight away. If you can receive those emails, then it allows you to take proactive action towards making sure that your systems are up to date.
Jayne Gurton:
Phishing emails are becoming increasingly sophisticated. What are the red flags that lawyers should train themselves and their teams to recognise?
Chris Schwinghamer:
Yes, so there are a couple of things with phishing emails. Urgency is absolutely the predominant one. Phishing emails often try to short circuit your usual checks with false urgency and try to create pressure for you to click.
Secondly, impersonation. They are getting more and more sophisticated when it comes to this. Quite often, phishing emails use trusted names or brands to leverage your trust. I'm sure many of our listeners have received emails from the likes of impersonating Google or Microsoft or other large companies.
And then, certainly, out of ordinary requests, right? So, if you get things around approval or funds transfer, updated bank accounts that are not routine, that is always a big flag. One you see all the time is urgent language around funds transfer or critical items with senior staff being away overseas. You see that quite constantly. And there's always usually a trigger in which to either process a payment or to provide more information.
The last part there I want to outline is sometimes we have seen more broadly that cyber criminals are getting smarter and they are leveraging not only urgency, but gathering more and more information to build that trust, to build more and more rapport with who they are corresponding with before actually initiating their attack.
I like to use an example from other industries as ways to protect yourself. So, if we look at the aviation industry, safety is very paramount. They always cross-check between cabins and flight staff, and ground staff manually point and confirm visuals when they are using radio. So, do the same with cybersecurity, if in doubt, right? Especially with payments to third parties. We always encourage you to stop, pause and verify and check.
With the advent of AI, there's been more phishing attempts around voice impersonation. The other one is, QR codes are very prominent these days. It's a lot easier to scan a QR code than it is to necessarily sometimes click on a link if you are in a protected environment.
So, quite often cyber criminals are forcing staff and employees to scan that on their personal devices when they are not connected into their protected network. And then lastly, social media posts, you know, publicly accessible information is more and more evident than it has ever been before.
Jayne Gurton:
Okay, Chris, you mentioned that social media presents particular risks for legal professionals. What hygiene practices should lawyers adopt to reduce their exposure?
Chris Schwinghamer:
Sure. Social media is a feeding ground for lots of social engineering. Sometimes, we give up personal information on social media, and that can be used to craft an attack. So, if you think about some of your social media profiles or some of your family and colleagues, it's quite common to have your name, your date of birth and potentially family members. All of that information can be used to either impersonate you or to potentially authorise you with another provider or another service.
So, it really means that it instantly labels you as a potential source. Also, identifying yourself as a lawyer online is often necessary, but it does identify you as a high-value target for a financially motivated hacker.
Lastly, on social media, besides oversharing of information, threat actors can really compromise accounts of trusted friends or colleagues and use these to spread threats or to send you your links. So, be very careful, and we always encourage lawyers to never discuss anything sensitive on social media. Never click on any links and exercise caution when you are dealing with requests from unknown profiles at a minimum.
Make sure that you limit any of the information that you have there, so it's not used for oversharing. Be conscious about your birth dates, your family members, as well as your other connections – those all can be used against you.
Jayne Gurton:
Okay. VPNs are often misunderstood. Why should lawyers working remotely or travelling consider using one? And what should they look for when choosing a VPN solution?
Chris Schwinghamer:
Sure, yeah. I think just to context set, to recap, VPN is a virtual private network, so it allows you to communicate securely with your work environments. And to help answer the question, we all know confidentiality is a cornerstone of the profession. So, if you are not using a VPN, it just means it's more easily intercepted and it increases your exposure.
I always encourage, if you are using a cafe or a hotel Wi-Fi that might come up from time to time, those are high-risk areas and you should always use a VPN to make sure that your communications are secure. And it can also make sure that anything that's on your network, either in a home or at the office, or while you are transiting, isn't compromised and you can allow secure communications.
So, what you want to look for is ensuring that it transits with data in Australia, so you limit how much overseas exposure you have. And certainly be mindful of, you get what you pay for, and some free ones, while they might appear valuable on the surface, are actually exposing yourself to more malware and harvesting your data.
Jayne Gurton:
Thank you so much for talking us through what VPNs are, which brings me to my next question. When lawyers are working outside the office, say at home, in a cafe, at an airport or at a client site, what else is important to secure their devices and the data they contain?
Chris Schwinghamer:
Yeah, so I think it starts with thinking about what you are working on first and be mindful of shoulder surfing and privacy, and the risk of someone overhearing or seeing you conduct legal matters.
Definitely use a VPN if you can. The other one is free Wi-Fi points around airports and cafes – notorious – and you should always use a hotspot if you can from your phone just to add that layer of protection.
Also make sure that you keep your devices up to date beforehand. It sounds simple, but proactive measures help a lot. It reduces your risk when you connect into a network.
One of the other ones that I know is more broadly being seen is things that we call “juice jacking”. So, if you are at a cafe or if you are at an airport, quite often you see the little plugs to charge your phone or your laptops. We are seeing more and more of these little different connections as good sources where people have put in fake points and are actually looking for connections into your devices.
You always want to make sure that you lock your computer, or it shuts down after a certain period of time. The other part you should be mindful of is making sure that you keep your device always within arm's reach, as well as look at low-cost, cheap devices like privacy screen filters, which will help that information stay secure.
Jayne Gurton:
So, Chris, if I wanted to check whether my practice is in the right shape today, where would you point me to start?
Chris Schwinghamer:
Yeah, thank you. So, I encourage listeners to connect with us. So, we've got a number of resources and guidance on our website that help protect you around targeted and opportunistic cyberattacks. Also, the Law Institute of Victoria has some great resources, as well as the Legal Practitioners’ Liability Committee. And, combined, these are really valuable, valuable resources that will help know whether or not you've got the right things in shape.
For the top three takeaways, certainly, I've got around investing in training. I mentioned before, humans are the last layer of defence. And, as an organisation, you know, training and awareness of cybersecurity is so vital and so important.
So, really encourage you to invest in training for your staff, particularly around business emails and phishing. That will hold you in good stead. And then other parts is, setting up and maintaining systems, making sure they are auto updated. That will protect you against external threats and vulnerabilities. Seek professional help if you are a small practitioner to get the systems and the processes in place.
And then, lastly, I would encourage everyone, of course, to be vigilant. If you are getting information, always double check, always verify information, and please don't give out your authentication codes.
Jayne Gurton:
Chris, thank you so much for your time today. What comes through very clearly from today's conversation is that the most effective cyber habits can also be the simplest ones, and most of them cost nothing to implement, which is great news.
Chris Schwinghamer:
My pleasure, Jayne. Thank you.
Jayne Gurton:
And to everyone listening to Cross-Examined today, this has been the final episode in our five-part cybersecurity series. We hope it has given you not just the context for why cyber risk matters, but also some practical and low-cost steps that you can implement to reduce your risk starting from today.
Don't forget to check the show notes of this episode for links to the LIV Cybersecurity Hub, the VLSB+C minimum cybersecurity expectations, and any other resources mentioned in today's show.
And until next time, thank you for listening to Cross-Examined.