You cross‑examine people for a living.
Your IT provider has never been on the stand.
Since 27 April 2026, a partner at your firm signs a personal legal declaration that your cyber controls stay compliant all year. Not your IT provider. A partner. The five questions below take four minutes and reveal whether that signature stands on evidence, or on faith.
No forms. No email gate. Just five questions your firm should already know the answers to.
The most dangerous sentence spoken in a law firm is “our IT handles it.”
Maybe they do. But look at what that sentence actually is. It is not evidence. It is a belief, held on behalf of the firm, by someone who has never checked. You would not let a client rely on “we assume it’s fine” in a matter worth their life savings. Yet firms holding client money, privileged files and a director’s personal declaration rely on exactly that, every day.
There is a word for IT security that works fine until suddenly it doesn’t. The word is luck.
A generalist IT firm knows technology. That does not make them cyber security specialists, any more than a paralegal is a barrister. Different disciplines. Different examinations. Different accountability.
Ask yourself: would a partner sign a personal legal declaration on a paralegal’s say‑so?
A partner signs. Personally.
A director or partner signs a legal declaration that controls are maintained all year, not just on certificate day. Personal accountability, in writing.
MFA: one gap, auto‑fail
Every cloud service needs multi‑factor login. Miss one system and the firm fails the assessment. No appeals, no grace period.
14 days to patch, or fail
Two new auto‑fail questions test patching speed. “We get to it when we can” is now a certification failure.
Cloud is always in scope
Cloud services can never be excluded from assessment. The “it’s someone else’s problem” defence is dead.
Which brings us to the five questions. Send them to your IT provider by email, so the answers are in writing. Then record what came back.
Five questions. In writing. Watch what comes back.
Ask your IT provider each question, then record the honest result below. There are only three possible outcomes for each: they answered with written evidence, they answered but produced no proof, or they couldn’t answer at all. If you already know you don’t know, that is an answer too.
“Which partner here is signing the personal Danzell compliance declaration this year, and when did you brief them on it?”
“Confirm in writing that multi‑factor authentication is enforced on every cloud service we touch. Email, Microsoft 365, case management, client portals. Zero exceptions.”
“Show us evidence that every critical security update in the last 90 days was applied within 14 days. On every device. Including the laptop in the spare bedroom.”
“If our PI insurer asked tomorrow for evidence of our cyber controls, what document do you hand them? Today. Without writing one first.”
“What cyber security qualifications, specifically, do the people protecting this firm hold? Not IT qualifications. Cyber security qualifications.”
Answer all five questions above and the verdict appears here. Most firms never get this far, which is rather the point.
“I acknowledge the organisation’s responsibility to maintain compliance with all Cyber Essentials controls throughout the certification period.”
The answers above are what stands behind this signature. Nothing else does.
Don’t let them mark their own homework. We’ll mark it.
We are IASME certified Cyber Advisors. IASME is the body that runs the Cyber Essentials scheme for the UK Government, which means the people checking your provider’s answers are accredited by the organisation that writes the exam.
In 20 minutes on the phone we will tell you whether what your provider has set up would pass Danzell today, and you get a written summary of any gaps. We are not here to sell until you ask. If your provider passes all five questions, you get that in writing, you sleep better, and we leave you alone.
20 minutes
One call. We ask the technical questions your provider hopes nobody ever asks, and translate the answers into plain English.
Written gap summary
A one‑page summary of exactly where the firm stands against Danzell v3.3. Yours to keep, whoever you work with next.
Independent verdict
From IASME certified Cyber Advisors who work exclusively with law firms and accountants. Not a sales script with a checklist stapled to it.
Better you hear it from us than from your insurer, your regulator, or page 4 of the Law Gazette.
Sources: SRA enforcement and thematic data (47 interventions citing IT security failures in a single year; 75% of law firms targeted); IASME, Cyber Essentials Danzell v3.3 question set and director declaration, effective 27 April 2026; ICO enforcement: Tuckers Solicitors LLP fined £98,000 (2022, ransomware), DPP Law Ltd fined £60,000 (2025, data breach). Figures correct at time of publication.
