Practice Management Integration

Streamline administrative tasks and optimise workflows

Integration Support Guides

Access our support guides for comprehensive self-help assistance

Partner Network

Discover an ecosystem of trusted partners designed to support your matters

InfoTrack Connect

Allows suppliers to connect their products and services with the InfoTrack Ecosystem

News and Insights

Find out the latest industry updates

AML/CTF Training

Take on compliance with confidence

Events and Webinars

Take your professional development to the next level

Cyber Security Awareness Training

Build your cyber resilience

Property Market Update

Discover leading edge property insights

InfoTrack on Claude Cowork

Access InfoTrack directly inside Claude Cowork

playbook playbook white logo
Monthly digest covering the latest news for legal and conveyancing industries.

About Us

Learn more about who we are and what we do

Our Team

Find out who drives InfoTrack's innovation and strategy

Join Us

Be a part of our award-winning culture

Media

Featured media releases and mentions

Contact

Get in touch with a member of our team

Awards

Showcasing our people, solutions and service

Discover our award-winning technical innovations.

Cyber training has moved from a technical safeguard to a financial and legal necessity

Vishal Duggal

For years, cyber security training was largely treated as an IT responsibility.

 

Employees were shown how to spot a phishing email, reminded to use strong passwords and perhaps asked to complete an annual online training module. It was important, but often viewed as another technical safeguard sitting alongside firewalls, endpoint protection and access controls.

 

That approach no longer reflects the reality of cyber risk.

 

For legal and conveyancing practices in particular, cyber security has become inseparable from financial risk, client trust and professional responsibility. The question is no longer simply whether your people know how to recognise a threat. It is whether your organisation has built the knowledge, behaviours and processes needed to prevent a cyber incident from becoming a financial or legal crisis.

The human factor has become a business risk

Technology can block an enormous number of threats, but it cannot eliminate the human element. A convincing payment-redirection email can arrive in an inbox that has passed every technical security control. A compromised credential can give an attacker a legitimate way into systems. A deepfake or impersonation attempt can exploit trust rather than technology.


In a legal or property transaction, the consequences of getting that interaction wrong can be significant. Money can be redirected. Sensitive information can be exposed. Transactions can be delayed. Clients can suffer financial loss. A firm’s reputation can take years to rebuild.

 

This is why I increasingly see cyber training as a business risk control, rather than simply an IT control. The objective should not be to turn every employee into a cyber security expert. It is to give people the confidence and practical knowledge to recognise unusual behaviour, challenge something that does not look right and know what to do when something goes wrong.

 

One of the biggest misconceptions about cyber training is that completion equals preparedness. It doesn’t. A person can complete a 30-minute training module, pass the quiz and still be susceptible to a sophisticated social engineering attempt six months later. Security behaviours need reinforcement. They need to be relevant to the situations people actually encounter in their roles and, importantly, they need to be part of the culture of the organisation.

 

For a conveyancing team, that might mean understanding the warning signs of payment redirection and knowing how to independently verify changes to bank account details.For a legal practice, it might mean knowing how to handle sensitive client information when using new technology or AI tools. For managers and partners, it might mean understanding their role when a potential incident is identified and making sure staff know they can escalate concerns without hesitation.

Cyber risk increasingly has financial consequences

The financial case for effective training is straightforward. The cost of prevention is almost always easier to absorb than the cost of an incident.

 

But financial exposure extends beyond the immediate loss associated with a breach or fraudulent payment. Organisations may face investigation and remediation costs, business interruption, technology recovery, legal expenses, insurance implications and reputational damage.

 

For professional services firms, there is another layer: the potential impact on client relationships. Clients don’t necessarily distinguish between an IT failure and a business failure. If their information is compromised or funds are sent to the wrong account, the experience is ultimately associated with the firm they trusted. That makes cyber resilience part of the client experience.

The legal and regulatory conversation is changing

The regulatory environment is also placing greater emphasis on how organisations manage cyber risk. For legal and conveyancing practices, this means cyber security cannot be considered in isolation from professional obligations, privacy requirements, contractual responsibilities and the broader expectations placed on businesses handling sensitive information and financial transactions. Importantly, compliance should not become the objective of training.

 

A checkbox approach can create a false sense of security: we completed the training; therefore, we are protected. The better question is whether your people can demonstrate the behaviours that reduce risk in the real world. Building a security culture means making security everyone’s business.

From training to readiness

The next evolution of cyber training is therefore about creating readiness.

 

That means combining training with practical exercises, regular reinforcement, clear escalation pathways and leadership that consistently demonstrates the behaviours expected of everyone else. It means testing whether people know what to do, rather than simply testing whether they know the theory. And it means recognising that cyber security is not a project with a completion date. It is an ongoing business discipline.

 

For firms operating in environments where a single email, credential or transaction can have significant consequences, that shift is particularly important. Cyber training has moved beyond being a technical safeguard.

 

It is now part of how an organisation protects its finances, its clients, its people and its ability to operate and, increasingly, part of how it demonstrates that it is meeting its legal and professional responsibilities.

About Vishal Duggal

Vishal Duggal is a technology leader with 20+ years of experience, overseeing IT & Security operations across four geographies. He partners with leadership teams to turn technology strategy into outcomes, covering cloud, infrastructure, cybersecurity, and IT service management, while leading teams through change and maximising ROI.