Back
Image Alt

The Singapore Law Gazette

Managing a Cyber Incident: Practical Guidance for Singapore Law Firms

Law firms must treat cyber incident risk as “a practice risk” and not an IT issue

All law firms are attractive targets for cyber criminals because we hold highly sensitive information: sensitive client data, confidential information and transactional documents, litigation strategies, and privileged communications. The Law Society’s Guide to Cybersecurity for Law Practices frames cybersecurity as a risk‑based obligation that applies to all firms (large and small), reflecting that security is now integral to competent legal practice.

Further, ransom demands as a result of cyber incidents have increased the potential for regulatory exposure and significant reputational damage for a firm handling confidential and personal data. The Law Society‑Cyber Security Agency Ransomware Advisory highlights that ransomware often involves both encryption and data exfiltration, making the risks for law firms one of major significance.

Finally, the Personal Data Protection Act (“PDPA”) adds a time-critical compliance action: when a data breach affects personal data under your law firm’s control, you must assess whether it is notifiable and, once that determination is made, notify the PDPC promptly within three days (Seventy-two hours).

Day 0 (Zero) – start with a plan

As a first step, all law firms must have a cyber incident response plan. This does not have to be complicated. This is critical in order to manage the potential harm and risk to the firm. The plan should have three simultaneous objectives: (i) contain the breach (ii) preserve trust, and (iii) meet legal notification duties.

Keep a hard copy of your plan on hand as you will not be able to access this if your systems are down.

Day 1 (One) – “Contain, preserve, and keep the firm steady”

When an incident is suspected—speed matters. PDPC’s breach management guidance emphasises a structured response: contain, assess, and report where required. In ransomware scenarios, SingCERT’s response checklist highlights immediate actions: identify affected systems and accounts, secure remote access pathways, and prevent continued credential‑based access.

Practical steps for your experts (what to do in the first 60 minutes):

  • Consult your cyber incident response plan and follow the steps
  • Activate the incident response team and appoint an incident lead within your firm.
  • Isolate affected systems if you can
  • Preserve logs and images as early as practical.
  • Lock down client matter information repositories and email quickly.
  • Ransom demand – maintain the evidence and do not respond until you speak to your insurer or advisor.
  • Ensure your employees maintain the confidentiality of the incident and circulate information only on a need to know basis.
  • Contact insurers and experts – incident response managers, forensic experts
  • Remain calm.
  • Communications -If your systems and email are affected, consider using other means of communication such as telephone messaging and chat groups.

The next 24–72 (Twenty-Four Hours – Seventy-Two Hours) hours: Assess the situation – determine if the incident has been contained, your response to a ransom demand and determine regulatory and contractual notification requirements

1. Consider getting help – Law firms may wish to consider using an independent law firm to assist with the incident and that can provide objective advice on legal and regulatory obligations.

Ransomware continues to be a prominent threat; Singapore’s legal industry has seen increased reported cases over recent years per the Law Society‑CSA advisory. The advisory is particularly useful because it focuses on the legal sector’s realities: client confidentiality, operational disruption, and extortion tactics involving exfiltrated data.

Practical position on ransom payments:

The Law Society‑CSA advisory addresses “Should I pay the ransom?” and emphasises preparing incident response and business continuity plans to reduce pressure decision making. A useful practical stance is: prioritise containment, forensic scoping, and restoration from clean backups. Ransom payments are not encouraged by the CSA but they are not illegal, and it is not uncommon for payments to be negotiated and paid. If considering a ransom payment, it would be best to use a ransom negotiator who can advise the law firm and who has expertise in negotiating with threat actors and can advise on the credibility of the threat. At the end of the day, the law firm must consider the risk and make the best decision under the circumstances.

2. Determine if notifications are required under laws or contracts

The PDPA notification regime allows you a period of 30 days to assess the breach. This does not mean that you should delay action. Time is critical.

Where personal data is affected by the incident, the PDPA requires you to determine whether a breach is “notifiable” based on significant harm or significant scale and then notify PDPC no later than three (within seventy two hours) calendar days after that assessment conclusion. This makes the quality and speed of your internal assessment important

PDPA’s mandatory notification requirements are met if the breach:

    • is likely to cause significant harm to affected Singapore individuals, or
    • affects more than 500 Singapore resident individuals.

If significant harm is likely, you must also notify affected individuals.

Law firms that handle cross-border matters should also consider whether notifications to regulators in other countries may be required. Where the law firm holds data of clients from other countries, the breach of such personal data, for example of EU residents, could trigger notification requirements under other laws such as the General Data Protection Regulation (“GDPR”). Obtain advice from foreign counsel where necessary.

Separately, some clients also require law firms to notify them of any cyber incident under their terms of engagement. Law firms will need to keep a list of such clients so that they can be notified in the event of an incident.

3. Prepare notifications in parallel with ongoing investigations

Notifications to regulators and authorities such as the PDPC and SingCERT, foreign privacy authorities and clients, must be carefully prepared. These notifications should be accurate based on the available information at the time. Also, ensure that the PDPC is always notified before any notification to individuals or the public.

For a law firm, trust is an asset. Your notifications should be developed to maintain credibility with clients, counterparties, the courts where relevant, and regulators.

When dealing with employees, avoid “all staff, all information” communications. Restrict sensitive incident detail to those supporting the incident response. This is consistent with the risk-based governance approach highlighted in Law Society cybersecurity materials and helps prevent rumour driven errors (e.g., staff clicking malicious “helpdesk” links).

When a client matter may be impacted, prepare a client communication message carefully and consider liability issues. Avoid over-informing at the early stage when the facts are unclear.

A note about smaller law firms

Smaller law firms often assume they lack resources for formal incident response. In practice, a “minimum” plan is still possible and could include the following:

  • Pre‑appoint: (i) incident lead, (ii) external IT/forensics, (iii) external counsel point of contact, (iv) communications lead.
  • Prepare draft templates: (i) internal staff notice, (ii) client holding note, (iii) PDPC/affected individual notifications.
  • Bookmark SingCERT playbooks (ransomware, malware) and run one simple tabletop exercise a year.

This approach is consistent with the Law Society’s risk-based framework: start with baseline controls, then deepen based on the sensitivity and scale of matters your firm handles.

Recovery and Post Incident Review

Finally, after the threat has passed, the law firm can take steps towards restoring or rebuilding their systems. The integrity of business systems and controls must be confirmed, and the network should be monitored for any anomalous activity or signs of intrusion.

A post-incident review should be conducted. Identified deficiencies in cyber security practices and processes should be resolved. Further, the company’s incident response plan should be assessed and amended to reflect any gaps in its application. If necessary, additional security measures should be considered.

Liabilities

The law firm may face penalties if it is found that the cyber incident was caused by insufficient security arrangements by the law firm. Pursuant to s 48J, the PDPC is entitled to impose financial penalties of no more than, in the case of an organisation whose annual turnover in Singapore exceeds $10 million – 10% of the annual turnover in Singapore of the organisation; or in any other case, $1 million.

Further, pursuant to s 48O of the PDPA, if the cyber incident causes direct loss or damage to an individual including an employee or client, the individual has a right of action for relief in civil proceedings.

Clients may also have a cause of action in contract depending on the terms of engagement.

A final note

Cyber incidents are stressful for any business, but they are an increasingly common risk. Law firms, large and small, must prepare for the eventuality of a cyber incident and the work put into this preparation can save the law firm a significant amount of time and resources when an incident occurs. The time to take effective action and preparation is now.

Some useful resources (quick links)

Partner
CMS Holborn Asia
Singapore

Sheena Jacob is a Partner at CMS Holborn Asia in Singapore, specialising in cybersecurity and data protection across Asia‑Pacific. She advises multinational clients on data privacy compliance, cyber incident response, cross‑border data transfers and technology risk management, with a particular focus on regulated sectors and complex digital ecosystems. Sheena regularly supports organisations in navigating Singapore’s PDPA, cybersecurity obligations and regional privacy frameworks, and is experienced in handling high‑risk data breaches and regulatory investigations. She holds international IAPP certifications CIPM and CIPP(A).