Great article thanks Joanna. It does seem like more and more law firms are embarking on ISO 27001, or at least adopting a well documented ISMS as a means of establishing controls and policies. Indeed, can they afford not to? It's a small cost in comparison to the cost of information security breaches.

