TL;DR: Lexcel accreditation requires law firms to have a documented information security policy covering six specific things, from an information asset register to staff training evidence. Missing any of them can hold up your assessment.

What does Lexcel accreditation actually cover?

Lexcel accreditation is the Law Society’s own practice management standard for law firms in England and Wales. One part of the standard deals directly with how your firm handles information security, and it deserves proper attention rather than a quick check before an audit.

Section 3.1 of the standard sets two different levels of obligation. A practice must have an information management and security policy, but it only needs to be accredited against Cyber Essentials, since the standard uses “should” rather than “must”.

You can read the full standard on the Law Society’s Lexcel page.

Why most firms pursue Cyber Essentials anyway

An assessor can pass a firm without Cyber Essentials certification, provided the policy and its six components are in place. Even so, most firms pursue it, since it gives an external way to show the policy works in practice. It is also increasingly what cyber insurers and clients ask to see as part of their own checks.

What does the Lexcel information security policy need to include?

The standard lists six things your policy has to cover. Each one is simple on its own. Proving you’ve done all six, with actual evidence, is where firms lose time at assessment.

An information asset register

This is a list of the information your firm holds, both yours and your clients’. Client files, case management data, financial records, and anything held in the cloud all need a place on this register. Without it, assessors have no way to see what you’re actually protecting.

Protection procedures for those assets

Once you know what you hold, you need documented steps for keeping it safe. This covers access controls and encryption, along with clear rules for who can see what. The policy needs to describe what your team actually does day to day, with regular review as your systems change.

Retention and disposal procedures

Many law firms hold onto client data for years, sometimes decades, for sound professional reasons. Keeping it beyond that point still carries risk with no real benefit. Your policy needs clear rules for how long you keep different types of information, and how you dispose of it securely once that period ends.

A plan for updating and monitoring software

Old software is one of the easiest ways into a firm’s systems. Assessors expect to see a working routine for patching and monitoring, covering when updates happen and who is responsible for them.

Separate policies for email, internet, and social media use

Email, internet, and social media use each need their own separate policy document, rather than one general statement covering everything. These policies set out what staff can and cannot do on firm devices and firm time, giving the firm a clear reference point if something goes wrong.

Evidence that staff have been trained

A policy that nobody has read serves little purpose. Lexcel assessors expect proof that your team has been trained on information security, in the form of training records rather than a single signed acknowledgement.

Where do firms usually fall short at assessment?

Two areas cause most of the trouble. The first is the information asset register. Firms often know roughly what data they hold, but have never written it down in one place, which is exactly what an assessor asks to see first.

The second is training evidence. Plenty of firms have a policy, but far fewer can produce a record of who has actually been trained and when.

Both gaps usually come down to the same cause: a security policy exists, but nobody is checking it against reality day to day. Labyrinth Technology’s managed security services include ongoing compliance and vulnerability management built around frameworks such as Cyber Essentials and GDPR, with regular security audits that identify gaps before an assessor does.

How to prepare for your next Lexcel assessment

Lexcel’s information security requirements are not complicated to read. The asset register, the protection procedures, the retention rules, the software plan, the separate policies, and the training records are each straightforward on their own.

Where the real work happens

Most firms fall down on evidence rather than on the policy itself. It’s straightforward to write the six requirements down. It’s harder to keep proving you’re meeting them month after month, which is why some firms bring in outside verification rather than relying on an annual check.

If you are weighing up Lexcel accreditation, Cyber Essentials, or both, our IT support for law firms is built around this kind of compliance work, so the security side of your accreditation does not fall entirely on your own team.

A policy looks complete right up until an assessor asks to see the records behind it. At that point, it either holds up or it doesn’t.

Newsletter

Stay informed with practical IT insights

Get useful updates, security advice, and technology guidance from the Labyrinth Technology team.