Cyber Security for NZ Law Firms and Accounting Practices: Compliance, AI, and the Controls Clients Expect

Cyber security for NZ law firms and accounting practices is no longer an internal IT question. Corporate clients ask for evidence before they appoint you, insurers ask before they cover you, and regulators expect personal information to be protected and breaches to be reported. And practices hold exactly the data criminals want most: client files, trust account details and financial records, concentrated in one place.

This guide sets out what a practice actually needs: the controls that stop the common attacks, the regulatory overlay, safe use of generative AI, and the certification clients increasingly recognise. OxygenIT has run IT and security for New Zealand businesses since 2005, holds ISO 27001 and ISO 42001 certification, and works with legal and accounting practices nationwide.

What cyber security do NZ law and accounting firms need?

Every NZ law and accounting firm needs multi-factor authentication on every account, endpoint detection and response on every device, tested backups with an offline copy, least privilege access to client files, and email security with an enforced DMARC policy. These controls target the two attacks practices face most often: business email compromise and ransomware.

The reason practices sit high on target lists is concentration. A single compromised mailbox at a law firm can expose settlement instructions, due diligence material and personal information across hundreds of matters. An accounting practice holds financial statements, IRD details and payroll data for every client. Criminals do not need to breach a hundred businesses when one practice holds the records of a hundred businesses.

CERT NZ, now part of the National Cyber Security Centre, consistently reports phishing and business email compromise among the most common incidents affecting New Zealand organisations. For a practice, that usually means intercepted invoices and redirected settlement funds, or matter files encrypted and copied out with a threat of publication.

The baseline controls answer those attacks directly. MFA stops a stolen password from opening email or the practice management system. EDR watches every laptop and server for ransomware behaviour rather than waiting for a signature match. Backups only count once a restore has been tested and one copy sits offline, beyond the reach of an attacker already inside. Least privilege means staff open only the matters they work on, so one compromised account exposes a slice of the practice, not all of it. DMARC enforcement stops criminals sending email that appears to come from your domain. Our work with accounting and finance practices starts with exactly this list, because clients and insurers ask about these controls first.

What regulations and professional rules apply?

The Privacy Act 2020 governs personal information and breach notification for every practice. Law firms and many accounting practices are reporting entities under the AML/CFT Act. Lawyers carry confidentiality duties under the Law Society conduct and client care rules, Chartered Accountants ANZ sets standards for its members, and the FMA has expectations where financial advice is provided.

The Privacy Act 2020 covers personal information held by any practice, from client identity documents to payroll records processed for business clients. When a privacy breach causes serious harm, or is likely to, the practice must notify the Office of the Privacy Commissioner and affected people as soon as practicable. That turns a quiet security incident into a formal, visible event, which is why prevention and a rehearsed response matter equally.

The Anti-Money Laundering and Countering Financing of Terrorism Act (AML/CFT Act) captures law firms and accountants as reporting entities when they provide certain services, such as handling client funds, forming companies or acting on property transactions. Reporting entities must carry out customer due diligence and keep the records, so every practice in scope holds exactly the identity documents criminals value most. A breach that exposes those records is a compliance problem as well as a privacy one, and protecting them sits at the centre of law firm IT compliance.

For lawyers, the Law Society conduct and client care rules make confidentiality a professional obligation, not just a legal one, and a cyber incident that exposes client information engages those duties alongside the Privacy Act. Privilege adds a further layer: privileged material that leaks cannot be made privileged again. Accountants in public practice answer to Chartered Accountants ANZ, whose code of ethics carries confidentiality obligations covering how client information is stored and secured. Where a practice provides regulated financial advice, the FMA expects licensees to keep technology resilient and report material cyber incidents.

This is an overview, not legal advice, and the detail varies by practice. The common thread is the same everywhere: protect confidentiality, and be able to show how. For plain language starting points, the Ministry of Business, Innovation and Employment publishes small business cyber security guidance through business.govt.nz.

Can law firms use generative AI safely?

Yes, with governance. The New Zealand Law Society has published guidance on lawyers using generative AI, and its direction is consistent: protect confidentiality and privilege, keep client identifying information out of unapproved public tools, verify outputs before relying on them, and remember that the lawyer, not the tool, remains responsible for the work.

The New Zealand Law Society guidance treats generative AI as a tool lawyers can use, provided the existing professional obligations travel with it. Client identifying information does not belong in public tools that may retain or train on what is entered. Outputs need verification, because language models produce confident errors, including invented case citations. The NZLS AI guidance also encourages consideration of a privacy impact assessment before adopting AI tools, and responsibility for the final work stays with the lawyer.

In practice, safe adoption of generative AI for lawyers in NZ looks like a short approved tools list rather than a ban. Enterprise tools with commercial terms, such as Microsoft 365 Copilot, keep prompts and responses inside your own tenancy and out of foundation model training, which changes the confidentiality analysis. The prerequisite is tidy access control, because Copilot can surface anything the signed in user can already reach. Our Microsoft Copilot readiness guide covers the permission and data hygiene work that comes first.

The same logic applies to accounting firm cyber security. Client financial data pasted into a free chatbot is a confidentiality breach waiting to be discovered, while a governed deployment with the right protections saves real hours on drafting and analysis. OxygenIT holds ISO 42001 certification, the international standard for AI management systems, so the governance we recommend to practices is the discipline we already apply to ourselves.

What controls do clients and insurers now expect?

Corporate clients send security questionnaires before appointing a practice, and they expect evidence rather than assurances. Cyber insurers now decline cover or load premiums when MFA, EDR, tested backups or an incident response plan are missing. Both groups are converging on the same short list of controls, reviewed annually.

The questionnaire trend flows down from banks, insurers, government agencies and listed companies to every adviser on their panels. A practice bidding for corporate work should expect questions about MFA coverage, endpoint protection, backup testing and incident response, with a request for supporting evidence: policy documents, configuration exports or a current certificate.

SMB1001 Gold packages exactly these controls into an annual, director attested certificate. SMB1001 is a five tier cyber security standard developed by Dynamic Standards International and certified through the CyberCert platform, and Gold is the tier where the controls insurers ask about all appear: EDR, enforced email authentication, offline backups, cyber insurance and an incident response plan. A director attests compliance each year, and the resulting certificate answers most questionnaires in one line. Our SMB1001 Gold certification guide explains the tiers, costs and process in full.

Controls checklist for law and accounting practices

Control What it protects in a practice Evidence to keep
Multi-factor authentication Stops stolen passwords opening email, practice management and remote access MFA policy export and coverage report from your identity platform
Endpoint detection and response Detects and isolates ransomware on laptops and servers before it spreads EDR console device list and alert history
Offline backups Restores matter files and financial records after ransomware or deletion Backup job reports and a dated restore test log
Access control on client matters Limits how much a single compromised account can expose Permission review records and matter access reports
DMARC enforcement Stops criminals sending email that appears to come from your domain DMARC record at enforcement and monitoring reports
Incident response plan Gives the first hour structure instead of panic The written plan and a tabletop exercise record
Staff training Turns staff into a detection layer against phishing Completion records and phishing simulation results
Cyber insurance Transfers response and recovery costs the practice cannot absorb Current policy schedule and renewal confirmation

Keep the evidence current. A questionnaire answered from a live evidence folder takes an hour. One answered from scratch takes a week and reads as improvised.

How should a New Zealand law firm back up and secure client files?

Apply the 3-2-1 rule to every client file: three copies, on two different media, with one held offsite, tested by restoring, not just by confirming a job completed. Two things need to be different for a law firm compared with a general business backup policy: every copy must be encrypted at rest and access-restricted as tightly as the live file, because an unencrypted backup is a second place privileged material can be disclosed from, and retention has to track the practice’s own file and trust account obligations, not the backup platform’s default window.

The table below sets out why each element matters specifically for privileged, client-owned material, not just as generic backup hygiene.

Backup element Why it matters for privileged client files What good practice looks like
Encryption at rest, every copy An unencrypted backup, including the offsite or cloud copy, is a second place privileged material can be disclosed from if the backup vendor or a compromised account is accessed Encrypt the local, secondary and offsite copies, not only the production system
Access control on the backup itself Least-privilege on the live file server means nothing if the backup console or restore function has broader access than the file it protects Apply the same access list to backup and restore functions as to the live matter, and review who at the practice and at the IT provider can trigger a restore
Immutable or versioned copies A matter file’s integrity can be challenged, in a client dispute, a professional conduct complaint, or a claim that a document was altered. A backup that can itself be silently overwritten proves nothing Keep versioned or immutable (write-once) backup copies so a specific point-in-time version of a file can be produced with a clean chain of custody
Restore testing A backup nobody has restored from is not a backup, and an unverified restore claim is weaker evidence than no claim at all if it is ever tested in a dispute Test restores at least quarterly for matter files, and log the date, what was recovered and how long it took
Retention period Deleting backups faster than the practice’s own retention duty destroys evidence a partner may need years later Set retention to match the practice’s file and trust account retention policy, not the backup platform’s default. Trust account records specifically carry a statutory minimum of at least 6 years from the date of the last transaction, under regulation 11(5) of the Lawyers and Conveyancers Act (Trust Account) Regulations 2008.

None of this replaces a practice’s own file and trust account retention policy. It sets the backup floor that policy needs to sit above, not below.

The same backup discipline applies whether the client-owned material is a legal matter file, an accounting client’s financial records, covered in our guide to IT support for accounting firms, or an insurer’s policy and claims data, covered in our guide to IT support for insurance companies.

How do you protect trust accounts and privileged data?

Treat trust account payments as the highest risk workflow in the practice: dual authorisation on every disbursement, callback verification for any new or changed bank account details, segregated access to matters, and monitoring with audit trails. Privileged material stays on approved systems only, and everyone knows exactly what to do in the first hour after suspected compromise.

Invoice fraud against trust accounts is the highest value attack a practice faces. The pattern is consistent: a compromised or spoofed mailbox, an email changing bank account details shortly before settlement, and pressure to move quickly. The counter is procedural as much as technical. Every change to payee details is verified by phone to a number already on file, never one supplied in the email. Every trust payment carries dual authorisation, with no urgency exception, because urgency is precisely what the attacker manufactures.

Access to matters should be segregated so staff open only the files they work on, with information barriers where conflicts require them and same day removal of access when someone leaves. Sign in logs and audit trails across email, document management and the practice management system make unusual access visible and leave a factual record when something goes wrong. Privileged material belongs on approved systems only: not personal email, not consumer file sharing accounts, and not unapproved AI tools.

The first hour after suspected compromise decides most of the damage. Isolate the affected device, revoke sessions and reset credentials, preserve evidence rather than deleting it, call your IT provider and insurer, and start the assessment against the Privacy Act notification threshold. Practices that have rehearsed this sequence move in minutes. It is the operating rhythm we run with our legal clients, including the law firm Argyle Welsh Finnigan, and it fits any practice that moves client money.

Cyber security for NZ law firms: frequently asked questions

Are small practices really targets for cyber criminals?

Yes. Attackers target the data, not the headcount. A three partner firm holds the same kind of confidential client information as a national one, and criminals know smaller practices often have weaker controls. Business email compromise campaigns run at scale and largely on autopilot, so a small practice is found and probed just as quickly as a large one.

What does a data breach cost a law or accounting practice?

The direct costs include incident response, system rebuilds, legal advice and regulatory notification work. The larger cost is usually reputational: clients trust a practice with their most sensitive affairs, and that trust is hard to rebuild once files are exposed. Add downtime across every fee earner and the total impact grows quickly, even without a ransom payment.

Do we have to report data breaches in New Zealand?

Under the Privacy Act 2020, a privacy breach that has caused serious harm, or is likely to, must be notified to the Office of the Privacy Commissioner and to affected people as soon as practicable. Reporting entities under the AML/CFT Act and FMA licensees can face further notification duties, so build the reporting steps into the incident response plan.

Can staff use ChatGPT for client work?

Only within a clear policy. Public AI tools may store and learn from whatever staff type into them, so client names, matter details and financial data must stay out. Approve specific tools that carry commercial data protections, train staff on what is permitted, and require outputs to be verified. The Law Society guidance for lawyers takes the same position.

What cyber security certification should a practice aim for?

SMB1001 Gold is the practical first target for most NZ practices. It is a director attested certification covering MFA, EDR, backups, incident response and staff training, renewed annually. Larger practices serving enterprise or government clients may step up to ISO 27001 later. Start with the tier that answers the questionnaires you actually receive.

How quickly can a practice lift its cyber security controls?

Most practices can lift the core controls in about 90 days. MFA and email authentication move fastest, while backup testing, training rollout and incident response planning each take a few weeks. A gap assessment sets the order of work. Contact OxygenIT to arrange one for your practice.

Secure your practice with OxygenIT’s SMB1001 Gold in 90 days

OxygenIT has run IT and security for New Zealand organisations since 2005. We are ISO 27001 and ISO 42001 certified, Christchurch based with Wellington coverage, and we work with legal and accounting practices daily. Our 90 day programme takes a practice from gap assessment to a director attested SMB1001 Gold certificate, and layers on the practice specific controls covered above: trust account payment verification, matter level access control and AI governance.

Book a discovery call and we will map your practice against the Gold controls, then give you a fixed price and a start date. Or call us on 0800 101 095.

Let’s transform your business with our reliable IT solutions!