Why AML/CTF reform makes a cyber partner a practice necessity
On 1 July 2026, a significant portion of the Australian legal profession became a reporting entity under the anti-money laundering regime for the first time....
· Cybersecurity · MSSP · Professional Services · Legal
On 1 July 2026, a significant portion of the Australian legal profession became a reporting entity under the anti-money laundering regime for the first time. Most firms have by now worked through what that means for their intake processes, their engagement letters and their compliance documentation. Considerably fewer have worked through the second-order consequence, which is that meeting these obligations requires a firm to collect, verify and retain a volume of highly sensitive client information it has never systematically held before, and to keep that information for seven years. The compliance question and the security question turn out to be the same question, and the firms that treat them separately are likely to find that out at an inconvenient moment.
What actually changed, and for whom
Precision matters here, because the regime is narrower and more particular than much of the commentary suggests. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia's AML/CTF regime to legal practitioners for the first time, with obligations commencing on 1 July 2026 for lawyers providing certain services known as designated services. The Law Society of NSW puts the distinction plainly in its own guidance, noting that the regime does not regulate lawyers as a profession, it regulates a subset of what they do, and whether a practice falls inside or outside the net depends on whether it provides one or more designated services. A firm providing one or more of those services with a geographical link to Australia becomes an AUSTRAC reporting entity, with enrolment having opened on 31 March 2026.
The obligations that follow are substantive. Newly regulated firms are required to verify client identity, report suspicious matters, and maintain AML/CTF programs and risk assessments, and clients may be asked to provide additional information and identification documents before a lawyer can act for them. Analysis of the reforms describes the full set as enrolment, an AML/CTF programme, customer due diligence before providing a service, sanctions and politically exposed person screening, suspicious matter and threshold transaction reporting, and seven-year record keeping. The Commonwealth has also confirmed that, in bringing legal practitioners into the regime, the Amendment Act clarifies the treatment of legal professional privilege and preserves the core intention of that doctrine, which resolves one concern the profession raised early but leaves the practical obligations untouched.
The consequence sitting underneath the obligation
Read that list again from a security perspective rather than a compliance one. Customer due diligence means a firm now collects and verifies identity documentation as a matter of course. Source of funds enquiries mean it holds financial information about clients that it may previously have never seen. Beneficial ownership requirements mean it maps the ownership structures behind its corporate clients. Seven-year retention means none of this can simply be discarded when a matter closes.
What that produces, in aggregate, is a concentration of exactly the information criminals value most, held in one place, for years, by an organisation that in many cases has no dedicated IT function at all. A firm that was already an attractive target because it holds commercially sensitive matters and client confidences is now materially more attractive, because it also holds verified identity documents and financial records at scale. The obligation designed to make the profession harder to exploit for money laundering has, as an unavoidable by-product, made each individual practice a more valuable thing to breach.
The profession already has its case study
The legal sector did not need this development to become a target, and Australia has an unusually well-documented illustration of what a serious incident looks like. In April 2023, HWL Ebsworth was compromised by the ALPHV ransomware group. Reporting on the incident, including material filed in the Supreme Court of NSW, indicates that around four terabytes of data was exfiltrated, roughly 2.2 million files, and that after the firm declined to pay the ransom, 1.4 terabytes of firm and client data was published on the dark web. The consequences extended well beyond the firm itself, with the breach affecting 65 government agencies as well as major commercial clients. The direct response costs were substantial, with an affidavit from a firm partner confirming more than $250,000 incurred on the review of leaked data alone, with that cost expected to grow. The regulatory consequences followed, with the Australian Information Commissioner commencing an investigation into the firm's handling and protection of personal information, and into its notification of affected individuals.
Two details of that incident deserve particular attention from any principal reading this. The first is the entry point. Reporting on the breach indicates the attackers accessed data through an employee's personal computer, which is to say that the largest legal partnership in the country was compromised through an endpoint rather than through some exotic failure of enterprise architecture. The second is the commercial consequence. Several major clients, including large banks, reportedly withdrew files from the firm as the incident unfolded. For a practice whose entire proposition rests on client confidence, that is the loss that matters most, and it is the one that no insurance policy restores.
The standard a firm is actually held to
There is a temptation to read the AML/CTF changes as a documentation exercise and to treat security as a separate, discretionary matter. The regulatory position makes that difficult to sustain. Under the Privacy Act, the OAIC has observed that several Australian Privacy Principles require an entity to take reasonable steps to comply, and that this serves as a reminder of the importance of enacting measures that guard against common threats such as compromised credentials, ransomware and phishing, and updating those measures as threats change.
The significance of a reasonable steps standard is that it moves. What was defensible five years ago is not necessarily defensible now, and a firm that has newly taken on the obligation to hold verified identity and financial data has, by that very fact, raised the bar for what reasonable protection of that data looks like. This sits alongside the profession's existing and more fundamental duty of confidentiality to clients, which does not soften merely because the failure was technical rather than professional. The broader threat environment gives the point its weight, with the Australian Signals Directorate recording a cybercrime report lodged in Australia on average every six minutes and the average self-reported cost to a small business rising 14 percent to around $56,600.
Why this calls for a partner rather than a purchase
The instinct of a well-run practice facing a new obligation is to buy the thing that solves it, and in most compliance contexts that instinct serves a firm well. Security resists that treatment, for reasons worth being clear about.
A security posture is a continuing state rather than a completed project. The controls that protect a firm today require monitoring, updating and testing as both the practice and the threat environment change, which is a fundamentally different commitment to purchasing a policy template or a piece of software. It also spans domains that rarely sit with one person in a small firm, covering the network the practice runs on, the devices its people carry, the cloud services holding its documents, the identity systems governing who can reach what, and the human judgement of the staff opening the attachments. A gap in any one of those undermines the others, which is precisely what the HWL Ebsworth entry point demonstrates.
Most significantly, the obligation to demonstrate that a firm has taken reasonable steps is an evidentiary one. A practice that can show a documented risk assessment, a defined set of controls, continuous monitoring and a tested response plan is in a materially different position, both before a regulator and before a client, than one relying on the assurance that nothing has gone wrong so far. Producing that evidence on an ongoing basis is the work of a partner who knows the practice, rather than a vendor who sold it something.
For a firm of ten to a hundred people, the practical reality is that this expertise cannot sensibly be hired. The right arrangement gives a practice access to senior security and risk capability when it genuinely needs it, sitting on top of infrastructure that is already monitored and maintained as a matter of course, so that the principal's attention returns to practising law rather than to administering a security programme.
The connected view
The reason this belongs in a conversation about a firm's whole technology foundation, rather than in a separate conversation about compliance, is that the risk is distributed across every layer of how a practice operates. The network carrying its data, the devices its lawyers use, the identity controls governing access to matters, and the people exercising judgement daily are all part of the same exposure, and they are only genuinely defensible when they are designed, monitored and governed together. A firm that addresses these in isolation, through separate vendors with separate scopes and no single point of accountability, has the appearance of coverage without its substance.
The AML/CTF reforms have given the profession a clear and dated reason to examine that foundation properly. The obligations themselves are now in force, the data they require a firm to hold is materially more sensitive than what it held before, and the standard of protection expected of it has risen accordingly. Firms that treat this as the moment to put a genuine security capability behind their practice will find they have satisfied the obligation and protected the client relationships that the practice actually runs on. Both outcomes follow from the same decision.
References
- The Law Society of Tasmania, Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) Reform. https://lst.org.au/anti-money-laundering-counter-terrorism-financing/
- Law Society Journal (Law Society of NSW), Understanding designated services: when legal services trigger Tranche 2 AML/CTF obligations. https://lsj.com.au/articles/understanding-designated-services-when-legal-services-trigger-tranche-2-aml-ctf-obligations/
- Zyphe, Tranche 2 reforms: Australia's AML cliff, July 2026. https://www.zyphe.com/resources/news/austrac-tranche-2-aml-reforms-july-2026
- Australian Government Department of Home Affairs, Overview of the AML/CTF Amendment Act. https://www.homeaffairs.gov.au/criminal-justice/Pages/overview-of-the-amlctf-amendment-act.aspx
- Law Management Hub, The HWL Ebsworth cyber incident: lessons for the legal profession. https://www.lmhub.com.au/article/the-hwl-ebsworth-cyber-incident---lessons-for-the-legal-profession
- Lawyers Weekly, 16 AFP personnel deemed at risk following HWL Ebsworth data breach. https://www.lawyersweekly.com.au/biglaw/38388-16-afp-personnel-deemed-at-risk-following-hwl-ebsworth-data-breach
- Lawyers Weekly, Data breaches will cost firms more than money. https://www.lawyersweekly.com.au/newlaw/37896-data-breaches-will-cost-firms-more-than-money
- Office of the Australian Information Commissioner, OAIC opens investigation into HWL Ebsworth over data breach. https://www.oaic.gov.au/news/media-centre/oaic-opens-investigation-into-hwl-ebsworth-over-data-breach
- Eftsure, A full timeline of the HWL Ebsworth data breach. https://www.eftsure.com/blog/industry-news/hwl-ebsworth-data-breach-timeline/
- Office of the Australian Information Commissioner, Notifiable Data Breaches Report: January to June 2024. https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2024
- Australian Signals Directorate, Annual Cyber Threat Report 2024 to 2025. https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
This article references publicly available government, regulatory, professional body and industry reporting current as of mid-2026. It is general information about security and technology practice and should not be treated as legal or compliance advice.