For Partners & Practice Managers of UK Law Firms
Exhibit A · The answer every firm gives “Our IT provider handles our cyber security.”

You cross‑examine people for a living.
Your IT provider has never been on the stand.

Since 27 April 2026, a partner at your firm signs a personal legal declaration that your cyber controls stay compliant all year. Not your IT provider. A partner. The five questions below take four minutes and reveal whether that signature stands on evidence, or on faith.

No forms. No email gate. Just five questions your firm should already know the answers to.

47
law firms the SRA intervened in, in a single year, citing IT security failures
75%
of UK law firms have been targeted by cyber attacks
14 days
to apply critical security patches, or the firm auto‑fails certification
1
partner’s personal signature now stands behind all of it

The most dangerous sentence spoken in a law firm is “our IT handles it.”

Maybe they do. But look at what that sentence actually is. It is not evidence. It is a belief, held on behalf of the firm, by someone who has never checked. You would not let a client rely on “we assume it’s fine” in a matter worth their life savings. Yet firms holding client money, privileged files and a director’s personal declaration rely on exactly that, every day.

There is a word for IT security that works fine until suddenly it doesn’t. The word is luck.

A generalist IT firm knows technology. That does not make them cyber security specialists, any more than a paralegal is a barrister. Different disciplines. Different examinations. Different accountability.

Ask yourself: would a partner sign a personal legal declaration on a paralegal’s say‑so?

What changed in April 2026 · Danzell v3.3
01

A partner signs. Personally.

A director or partner signs a legal declaration that controls are maintained all year, not just on certificate day. Personal accountability, in writing.

02

MFA: one gap, auto‑fail

Every cloud service needs multi‑factor login. Miss one system and the firm fails the assessment. No appeals, no grace period.

03

14 days to patch, or fail

Two new auto‑fail questions test patching speed. “We get to it when we can” is now a certification failure.

04

Cloud is always in scope

Cloud services can never be excluded from assessment. The “it’s someone else’s problem” defence is dead.

Which brings us to the five questions. Send them to your IT provider by email, so the answers are in writing. Then record what came back.

The Cross‑Examination

Five questions. In writing. Watch what comes back.

Ask your IT provider each question, then record the honest result below. There are only three possible outcomes for each: they answered with written evidence, they answered but produced no proof, or they couldn’t answer at all. If you already know you don’t know, that is an answer too.

Question 01 · The Signature

“Which partner here is signing the personal Danzell compliance declaration this year, and when did you brief them on it?”

Why it bitesSince 27 April 2026, certification requires a director or partner to sign a legal declaration that controls are maintained all year. Not on certificate day. All year.
The answer that should worry you“The what?” If your provider has not briefed the partner who must personally sign, ask yourself what else they haven’t mentioned.
What actually happened?
Question 02 · The Auto‑Fail

“Confirm in writing that multi‑factor authentication is enforced on every cloud service we touch. Email, Microsoft 365, case management, client portals. Zero exceptions.”

Why it bitesOne unprotected cloud service is now an automatic certification fail. No appeals, no grace period, no partial credit.
The answer that should worry you“Pretty much everywhere.” Pretty much is a fail. The one system without it is the one an attacker logs into.
What actually happened?
Question 03 · The Fourteen Days

“Show us evidence that every critical security update in the last 90 days was applied within 14 days. On every device. Including the laptop in the spare bedroom.”

Why it bitesTwo new auto‑fail questions test patching speed. Slow, manual, “when we get to it” patching now fails the whole firm.
The answer that should worry you“We run updates regularly.” Regularly is not fourteen days. An assessor will not take their word for it. Neither should you.
What actually happened?
Question 04 · The Insurer

“If our PI insurer asked tomorrow for evidence of our cyber controls, what document do you hand them? Today. Without writing one first.”

Why it bitesPI insurers now link Cyber Essentials to cover and premiums. Risk misrepresented at renewal can void a policy entirely, leaving the firm liable for the client’s loss.
The answer that should worry you“We could put something together.” A document written after the question is asked is not evidence. Your insurer knows the difference. So does the ICO.
What actually happened?
Question 05 · The Qualifications

“What cyber security qualifications, specifically, do the people protecting this firm hold? Not IT qualifications. Cyber security qualifications.”

Why it bitesGeneral IT and cyber security are different disciplines with different examinations, the way a paralegal and a barrister are different jobs.
The answer that should worry youA list of helpdesk certificates, or a pause. You would not send a paralegal to the Court of Appeal. Someone sent one to guard your client account.
What actually happened?
The Verdict
Awaiting your answers

Answer all five questions above and the verdict appears here. Most firms never get this far, which is rather the point.

Meanwhile, this is what a partner at your firm is signing
“I acknowledge the organisation’s responsibility to maintain compliance with all Cyber Essentials controls throughout the certification period.”
Director / Partner declaration · Danzell v3.3 · Source: IASME
xA PARTNER AT YOUR FIRM

The answers above are what stands behind this signature. Nothing else does.

The 20‑Minute Compliance Call · Free · No Obligation

Don’t let them mark their own homework. We’ll mark it.

We are IASME certified Cyber Advisors. IASME is the body that runs the Cyber Essentials scheme for the UK Government, which means the people checking your provider’s answers are accredited by the organisation that writes the exam.

In 20 minutes on the phone we will tell you whether what your provider has set up would pass Danzell today, and you get a written summary of any gaps. We are not here to sell until you ask. If your provider passes all five questions, you get that in writing, you sleep better, and we leave you alone.

20 minutes

One call. We ask the technical questions your provider hopes nobody ever asks, and translate the answers into plain English.

Written gap summary

A one‑page summary of exactly where the firm stands against Danzell v3.3. Yours to keep, whoever you work with next.

Independent verdict

From IASME certified Cyber Advisors who work exclusively with law firms and accountants. Not a sales script with a checklist stapled to it.

Better you hear it from us than from your insurer, your regulator, or page 4 of the Law Gazette.

Sources: SRA enforcement and thematic data (47 interventions citing IT security failures in a single year; 75% of law firms targeted); IASME, Cyber Essentials Danzell v3.3 question set and director declaration, effective 27 April 2026; ICO enforcement: Tuckers Solicitors LLP fined £98,000 (2022, ransomware), DPP Law Ltd fined £60,000 (2025, data breach). Figures correct at time of publication.

Cross‑examination in progress · 0 of 5 answered