SPONSOR - Aon - Cyber risks; protecting your firm and your clients

SPONSOR - Aon - Cyber risks; protecting your firm and your clients

AON logo

Cyber risks; protecting your firm and your clients

 

The media has recognised the newsworthiness of financial crime and, in particular, criminals’ attraction to law firms and their client accounts. As a consequence, TV time and column inches have been dedicated to the plight of solicitors falling victim to scams. Banks are also playing their part through prominent TV advertising campaigns alerting their customers to the risk of financial crime.

Insurers welcome the increased awareness generated by this publicity but, unfortunately, ongoing claims notifications demonstrate that the profession is still firmly in the fraudsters crosshairs. It’s all too easy to assume that fraud is yesterday’s problem and that fraudsters will have moved on to different victims, perhaps even in different countries but this is not the case.

 

To put the enduring nature of this problem into context, one Participating Insurer has recently announced its exit from the Solicitors’ Professional Indemnity market citing client account fraud as one of its key motivators and predicting that this type of fraud is unlikely to abate.

 

One only has to look at the scale of cyber-crime in the UK to empathise with the pessimistic views that are being expressed. BBC’s Moneybox reported there were 7.6 million reports of cybercrime in the last 12 months. In the first 6 months of 2015, financial crime in the UK rose by 6% to £325m, with losses arising from telephone fraud rising by 95% to £14.4m in the same period according to Financial Fraud Action UK. Property-related man-in-the-middle attacks have cost firms and their clients £10m over recent months warns the Telegraph.Law firms hold significant sums of money in their client accounts, particularly if they handle property, estate administration, trusts or high value personal injury and clinical negligence claims. Those sums are very attractive to fraudsters.

 

Any successful fraud is a threat to your practice. The consequences vary from reputational damage to negligence claims, regulatory investigation, intervention and worse. If your business failed as a result and you were made bankrupt, you wouldn’t be the first solicitor to face such a bleak outcome. The consequences for your clients can be as serious if they end up losing a deposit saved up over several years.

 

Partners should be sending strong leadership messages, at least annually, to all personnel about the risks of fraud and the threat it represents to the firm. Underlying this message should be written fraud prevention and awareness training policies and supporting procedures to which all personnel are required to adhere strictly. These policies and procedures, and the adequacy of their performance, should be under ongoing review by a member of senior management, executive committee or similar senior team.

 

The Institute of Risk Management defines cyber risk as any risk of financial loss, disruption or damage to the reputation of an organisation from some sort of failure of its information technology systems. The Solicitors Regulation Authority use cyber risks as a convenient label to describe the current wave of frauds even though many of them do not fit easily within this definition. A more common threat arises from social engineering risk.

 

Social engineering is a low-tech but still highly effective scam where fraudsters raid information from social media and intercepted emails. Using this to make themselves appear convincing and trustworthy, they manipulate their victims into sharing confidential information or transferring funds. LinkedIn is as vulnerable to attack as other types of social networking.

According to the City of London Police (confusingly for law firms known by the initials COLP), the two most common types of social engineering involve email (77%) and phone calls (12%), the remainder being made up of text messages, mobile phone calls and post. 

Vishing attacks are telephone calls which aim to obtain personal or financial information in order to commit fraud or identity theft. Do not underestimate how convincing fraudsters can sound, playing on their victims’ fears and persuading them to transfer significant sums to ‘safe’ accounts to protect them from attack. Five vishing attacks are reported to the SRA every week. One resulted in transfers totalling £1.9m after 3 hours on the phone. ActionFraud (www.actionfraud.police.uk) has produced reconstructions to demonstrate just how convincing vishing can be. 

Prevention is better than cure and we would urge you to consider the following simple but effective controls:
• Vishing relies on creating panic and the need for immediate action. Do not allow yourself to be panicked into doing something you have never done before.


• Understand what banks ask for in terms of security information. Look at the guidance supplied by your bank. A bank will never ask for your full password, PIN or memorable information via email, phone call or text. Nor will it ask you to transfer money to an account that you do not recognise or to share screenshots of login pages or accounts. 
• Do not use the number supplied by the caller to verify their bona fides. Note that fraudsters can spoof the phone number that appears on your caller display so do not trust it. If telephoning your bank after a suspicious call, use a different phone line as the phone line can stay open for up to 2 minutes if the person on the other end does not hang up (although BT are taking steps to reduce this time).


• If you receive a suspicious call, end it immediately (or put them on hold while you ask someone else to contact your bank).

Establishing safeguards against low-tech criminal attacks is relatively simple and, we hope, being widely adopted throughout the profession.

Phishing attacks target identity theft via a link in an email which includes malware. The link directs victims to a fake website where they are asked to provide user names and passwords in the belief that they are supplying them to a trusted organisation, such as a bank. Malware and botnets can lie dormant on your computer for months or years. Soft (screen based) keyboards are as vulnerable to malware as physical keyboards. The risks can be minimised if everyone is reminded to think twice before clicking on links in emails. 

A variation on phishing involves ‘man in the middle’ attacks. The fraudster joins a public Wi-Fi network and relies on an established connection to the victim’s device to redirect emails through the attacker’s host network. This allows the hacker to intercept emails. Reports in the Telegraph suggest that there are two successful cases involving property-related fraud every week, netting on average £1m per month for fraudsters.

There is a worrying lack of awareness about how cyber criminals use public Wi-Fi hotspots (270,000 in the UK alone according to ActionFraud) to steal personal and financial details. The top two public Wi-Fi activities, emails and social networking, often reveal plenty of personal information, with online banking close behind. Many firms allow lawyers to use personal devices for business, but little more than a third of firms exercise any control over the configuration and security of such devices.

A recent example occurred as the firm was about to complete a client’s purchase of a second home. The email incorporating the firm’s client account details was intercepted and altered. The client’s email back confirming transmission of funds was intercepted and edited to say there would be a short delay before the funds were sent – giving the fraudsters time to transfer the funds beyond reach, into other accounts or withdrawn in cash.

To minimise your exposure to man in the middle attacks:
• Advise clients face to face and in writing (not by email) of your bank details, that they will not change during the transaction and to ignore contrary instructions by email. Also, only accept bank details from clients that are given face to face, by post or by another trusted method.


• Think of your clients as well as yourselves. Warn them not to post details of their home move on social media as this makes it easier for fraudsters to mount such attacks.


• Ensure that newly set up payee details are verified by more than one person. 


• Instruct your bank to place a restriction on the number of high value payments that can be made within a specified period of time.


More generally, other steps that firms should take to protect themselves, include:
• Training everyone on the risks and providing regular staff updates with intelligence bulletins. The people in your firm may unwittingly be your weakest link. 
• Avoiding passwords that can be guessed easily (such as ‘password’, 123456 or your postcode and avoid pets’ names which can be found easily on social media).
• Keeping passwords secure and change them frequently. Don’t tape them to the underside of your keyboard where a cleaner could find them.
• Keeping software up to date, as updates include the latest patches to combat vulnerabilities.
• Google your firm name regularly to ensure your profile has not been cloned.
• Thinking about behaviour that you want to restrict or modify and then compare it against your email and internet policies. Update your policies and procedures as necessary.

Fraud is so indiscriminate that most Professional Indemnity insurers have developed a comprehensive set of controls they would like their insured firms to adopt. If you are unaware of your insurer’s advice, we would strongly recommend that you contact them and check your policies and procedures against them. Aon’s clients have been sent correspondence on this subject. If you would like additional copies or you have any questions, please contact your Client Manager.

In case the worst happens, set up a crisis management process within your firm so that you know, in advance, who will do what as time may well be of the essence. If you think you have been a victim of fraud, contact your bank immediately, as the more quickly you contact your bank, the greater the chances of recovering funds. Next contact Action Fraud (the police) on 0203 123 2040. If the fraud involves client money, notify your Professional Indemnity insurer as the definition of a claim includes a shortfall on client account. Remember, however, that notifying your insurer does not relieve the Partners of their obligation to make good any shortfall on client account on discovery (your office policy or cyber risks policy may also cover losses on your office account). Finally, you must be conscious of your professional obligations in the SRA Code of Conduct and the Accounts Rules. Apart from the wide ranging obligations in chapter 10 of the Code, your Compliance Officer for Legal Practice (COLP) and/or Compliance Officer for Finance and Administration (COFA) have reporting obligations.

The opportunities that digital technologies, devices and media bring to firms are many and varied, but so are the risks, which are constantly evolving. Cyber risk is never a matter purely for the IT team. Whilst cyber risk insurance policies can provide some comfort, the COLP and COFA need to keep their firm’s processes constantly under review. 

For more information on this, please contact:

Marco D’Ovidio, Associate Director, Aon UK Limited, on 0117 948 5116.

 

AON Newsletter


Like   Back to Top   Seen 486 times   Liked 0 times
Subscribe to Updates And Join Over 1.2K Subscribers Today!

Subscribe to:
x

Subscribe to Updates

If you enjoyed this, why not subscribe to free email updates and join over 1274 subscribers today!

Subscribe to updates



Subscribe to:

Alternatively, you can subscribe via RSS RSS

‹ Return to

All email subscriptions must be confirmed to comply with GDPR.

I've already subscribed / don't show me this again