Professional firms move money on instruction – completion funds, client payments, disbursements. Which is exactly why attackers target them with a scam built on impersonation: an email that appears to come from a partner, a client or the other side’s solicitor, changing where funds should be sent.
The most damaging version hits at the worst moment. Conveyancing completions, deal closings, month-end payment runs – times when pressure is high, timing is tight and a bank-detail change reads as routine rather than suspicious.
What makes professional firms uniquely exposed is that the fraud does not need to breach your systems. Impersonating your client, or you to your client, is often enough – which means defences have to cover both directions.
The defences that actually work:
- Phone verification for every payment instruction and detail change
- Client care letters that warn: we will never change bank details by email
- DMARC configured so your domain cannot be spoofed
- MFA on all mailboxes – partners and finance first
- Email banners flagging external and lookalike senders
- Dual sign-off on outbound payments above a threshold
- Rules for the high-pressure moments, agreed in advance
- Regular briefings using real, current examples
For practices across Guildford and Godalming, insurers and regulators increasingly expect exactly these controls – so putting them in place answers the renewal questionnaire and protects clients in one move.
In a business built on trust, protecting the payment instruction protects everything.
If your firm handles client money on emailed instructions, explore our cybersecurity services for Guildford professional firms.