16% Of Top 50 UK Law Firms Don’t Have Secure Website

2 November 2018by Abdallah Alhajeid

A recent survey by Trustify has indicated that 16% of the top 50 law firms in the UK do not have a secure website. Commenting on the survey report, Rachel Moloney from The Lawyer, added that over 10 per cent of the top 200 law firms in the UK may have insecure websites, including four of the top 25 law companies.

Steve Boland, CMO at Trustify, confirmed: “Law firms’ online presence plays a vital role in client validation and purchasing decisions nowadays, so eroding any trust in the firm is a business-critical issue. Our survey findings show that too many law firms are soon to see their traffic drop dramatically as a result of not having appropriately secured their websites from hackers, copycats and phishers.”

Trustify highlights that many law firms are still using outdated or free SSL security certificates. They indicate that three of the top 50 UK law firms’ websites may not be secure because of the recent new releases of the Google Chrome browser. Chrome 66 and 70 releases will not support SSL/TLS certificates from Symantec issued before June 1, 2016.

 

What is an SSL Certificate?

SSL Certificates are small data files that digitally bind a cryptographic key to an organisation’s details. When installed on a web server, this file activates the https secure protocol and allows secure connections from a web server to a browser. Typically, SSL (now TLS) is used to secure credit card transactions, data transfer and logins, and more recently is becoming the norm when securing browsing of social media sites.

When a certificate is successfully installed on a server, the application protocol (known as HTTP) will change to HTTPs, where the ‘S’ stands for ‘secure’. Depending on the type of certificate and the browser employed, users will see a padlock or green bar displayed at the bottom of a browser screen.

 

Google Chrome and Symantec Certificates

In January 2018, Google announced that If a company website was using an SSL/TLS certificate from Symantec issued before June 1, 2016, it will stop functioning in its Google Chrome 66 (April) and 70 (October) software releases. This applies to the Symantec Certificate Authority and affects Symantec-owned brands like Thawte, VeriSign, Equifax, GeoTrust, and RapidSSL.

Google is advising all web site managers to check the version of their Symantec certificates as soon as possible by accessing the Chrome Canary development resource. If the website of the organisation is not secured, Chrome users will start to see ‘Your connection is not private’ message in their browser.

 

Don’t use self-signed SSL certificates

Many organisations are tempted to use free or low-cost self-signed SSL Certificates instead of those issued and verified by a trusted Certificate Authority. While they do encrypt the user login and account credentials, they also prompt most web browsers to display the message ‘There is a problem with this website’s security certificate’. This is usually enough to drive away a potential customer from ordering a product or service on an e-commerce web site!

Self-signed web sites are also used by hackers to create spoof websites that collect data redirected from a legitimate web site. RiskIQ has published details of its research on the possible cyber attack strategy used in the recent theft of the data of 380,000 British Airways customers. They believe that hackers used cross-site scripting to inject code into a poorly configured web application. As British Airways customers ordered their services online, confidential information was being sent to a hacker-controlled server which encrypted the stolen data using a self-signed SSL certificate.

 

——————–

The Wizard Cyber Network and Web Application Penetration Testing services are designed to discover cyber security vulnerabilities in websites and their applications. This includes identifying insecure SSL security certificates and the presence of cross-site scripting (XSS) in the server or client-side web applications.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation