The SRA expects you to have cybersecurity controls in place. Your clients expect their data to be protected. Fortify makes it straightforward to show both.
Where law firms face compliance risk
SRA cybersecurity expectations
The Solicitors Regulation Authority expects firms to have documented cybersecurity controls in place. Inspections increasingly ask for evidence, not just policy statements.
Client data GDPR obligations
Law firms handle privileged, confidential, and often special category personal data. The ICO enforces GDPR strictly in professional services — and fines are growing.
Cyber insurance requirements
Insurers are tightening requirements for professional indemnity and cyber cover. Documented security controls — not just a firewall — are increasingly a condition of coverage.
AI-guided conversations — no forms, no jargon. A personalised PDF with findings and prioritised actions sent directly to your inbox.
A structured GDPR assessment covering lawful basis for processing client data, data processor agreements with your IT suppliers, retention schedules, and breach response obligations.
Free · No sign up required
Covers access controls, email security, backup maturity, and incident response readiness — the exact areas the SRA and cyber insurers ask about in their assessments.
Free · No sign up required
Cyber Essentials Plus Audit
Portal add-onGet certified — or evidence you meet the standard
AI-guided audit across all 5 Cyber Essentials technical control areas with per-control evidence capture. £99/mo, available in the portal. Supports certification or insurer documentation.
Findings, policies, evidence, and incident logs — in one place, ready for the SRA, an insurer, or a major client asking how you handle their data.
Findings & Action Plan
Every gap from your assessment lands here with a prioritised remediation plan — the documented evidence of your programme that the SRA and insurers want to see.
Policy Library
Draft, maintain, and version your policy library. AI fills templates from your firm profile — data retention, acceptable use, information security, and more.
Evidence Vault
Attach evidence to every control — configuration exports, training records, policy acknowledgements. Everything in one place for an inspection or insurance review.
Incident Management
Log data breaches and security incidents, run structured response procedures, and document your 72-hour ICO reporting decision — all in one place.
Vendor & Supplier Register
Track Data Processing Agreements with every IT supplier and cloud service that touches client data — with contract dates, DPA status, and supplier questionnaires.
Expert-quality compliance — without the waiting list, the day rates, or the big compliance consultancy retainer.
Documented controls, a clear action plan, and an evidence trail — the things the SRA expects to see when they ask how you manage cybersecurity risk.
Structured assessment covering lawful basis, data processor agreements, retention schedules, and breach response — covering the full GDPR obligations for a law firm.
Evidenced security controls support better cyber insurance terms. Show your insurer a programme, not just a statement that you "take security seriously".
Built-in incident management with structured playbooks for data breaches — including the 72-hour ICO reporting decision trail that protects the firm.
Know exactly which suppliers have access to client data and whether a Data Processing Agreement is in place for each. The vendor register tracks DPA status, contract renewals, and supplier security questionnaire responses.
Assessment responses are never used to train AI models, never sold, and never shared with third parties.
Fortify uses the Anthropic Claude API. Anthropic does not train on API data. Your responses generate your report and nothing else.
Your assessment responses and contact details are never sold to third parties or shared with any external organisation.
Assessments ask about your processes — not individuals. Avoid sharing personal data such as client or staff details during the conversation.