Managing Cyber Risk in a Chambers Environment: A Conversation with Old Square Chambers

We spoke to Old Square Chambers about why they stopped relying on their IT provider to mark its own homework and moved to independent cyber risk oversight, and why gaining an independent view of a chambers' cyber risk posture is vital in an environment built on BYOD and self-employed barristers.

Share this post

We recently spoke with Sarah Earl, Chambers Director at Old Square Chambers, and a Mitigo client for the past four years, about managing cyber risk across one of the legal sector’s most distinctive working environments – for those not familiar with the business model, they are essentially a cooperative of 17 staff and 82 self-employed barristers, largely operating on their own devices, in court, at home, and in chambers.

The Moment of Realisation  

“The expected dynamic in a chambers is having a BYOD policy in place, allowing barristers to use, within reason, whatever hardware they want to deliver their practice,” Sarah explains. “That comes with real challenges in making sure those devices are secure and managed properly, and that users are taking real ownership and responsibility for them.”

For years, Old Square relied on its outsourced IT provider to keep systems running and, by extension, secure. But that confidence began to erode. “It’s very difficult to rely on the company that provides your services to also self-audit,” Sarah says.

Things came to a head when the chambers’ MSP moved to sell cybersecurity services as a separate, paid-for service. “They were looking to increase our costs to undertake what, in my mind, was something that I thought was already happening,” she recalls. “That left me feeling quite exposed.”

The moment of realisation came when a pen test flagged a long list of action points, Sarah says. “Fairly minor things, but still things that needed to be addressed. When I then saw them pop up again in year two, having been told they’d been completed, with no way of verifying that – that raised, maybe not red flags, but certainly not green flags for me.”

Moving to Independent Assurance

That experience pushed Old Square to look for a partner who could provide impartial, independent assurance, separate from their IT provider – the same independent oversight Mitigo provides across the sector as the recommended cyber risk partner for members of the Bar Council, the Institute of Barristers’ Clerks, and the Law Society of England and Wales. As Sarah puts it: “I’m not a specialist – I can’t look at the back end of our IT systems and say with absolutely no doubt that everything that should be in place is in place.” What she wanted instead was oversight that didn’t rely on the same people marking their own work: “The more eyes you have that are not directly associated with each other, the more reassuring that can be.”

Gaining that independent oversight has also helped in a more practical way – giving Old Square a clear, evidence-based view of where to focus. “Mitigo has helped us recognise our real pinch points and our high risks,” Sarah says, “versus those where, having properly understood the risk, we can make an informed decision not to act immediately – rather than feeling we have to fix everything at once.” It’s replaced guesswork with a clear picture of what actually matters most.

The Culture Shift

“Changing culture in a dynamic like ours is not an easy task,” Sarah highlights. “I’m a big believer in the slow and steady approach.” Part of that has been introducing the sandbox facility, which lets members forward on anything suspicious – a dubious email, an unexpected attachment – straight to Mitigo for a quick check.

“It’s reduced the fear factor amongst our members, particularly junior staff. Now they know they can go to Mitigo, who will say, actually we’ve checked, and everything’s fine. It’s made cybersecurity just part of what we do, rather than something to be frightened of.”

That reassurance comes as much from the relationship as the results. “It’s there to help us, not to criticise us,” she says – a difference that matters when you’re not the expert and every gap can feel like a personal failing. And outsourcing that expertise isn’t a weakness, she’s clear: “it’s actually a strength.”

Sarah’s message to other chambers considering the same step is simple: “You don’t know what you don’t know, and that’s all the more reason to reach out to specialists like Mitigo. Our industry relies entirely on clients reaching out for specialist advice, often after the horse has bolted. Taking this approach allows you to be proactive rather than reactive”

How Mitigo can help

Mitigo provides chambers, law firms, and professional services organisations across the UK with independent and impartial assurance that their cyber risk management is effective, proportionate, and aligned with their regulatory obligations – assessing risk across the full picture of technology, people and governance, not just IT. To discuss an independent cyber review tailored to your chambers or firm get in touch with the Mitigo team.

Would you like to speak to Mitigo?

Please complete your details and we will contact you to discuss your needs.

Share this post