For Lexcel-accredited and Lexcel-seeking firms

IT and security support built around what Lexcel actually asks of you

Your policies say one thing. Your systems do another. An assessor will ask you to show that they agree — and on the IT side, that means evidence you have been generating all year, not a fortnight of screenshots.

I help small practices meet the IT and information security requirements of Lexcel v6.1: a gap assessment to find out where you stand, a readiness project to close what it finds, and an indexed evidence pack you can hand to your assessor.

Legal sector background Cyber Essentials support Lancashire-based
The IT evidence

What an assessor asks for, in plain English

Lexcel v6.1, Section 3 covers information management. The wording is for your assessor to interpret, not me — but in practice, on the IT side, these are the things firms get asked to produce. Most practices have some of them. Very few have the records that show the control was operating rather than merely written down.

An information management and security policy

Approved, dated, version-controlled, with a named owner and a review date that has not already passed. Most firms have the document. Fewer have the approval and the review record that make it count.

An email policy that covers storage and destruction

Not just acceptable use. Where email is stored, how long it is kept, and how it is destroyed — the three parts most template policies leave out.

An information asset register

What you hold, where it lives, who owns it, how long it is kept. Written once and never updated is the single most common finding, because an assessor can check it against reality in about a minute.

A software update and monitoring plan

A stated patching timescale, and evidence it was actually met — not an intention. Monthly compliance reporting turns this from an assertion into a record.

Backups that have been restore-tested

A green backup report is not a tested restore. Expect to be asked when you last actually recovered something, and by whom.

Access removed when people leave

Can you show that the last person who left lost access on their last working day? This is the control assessors most often ask to see operating, rather than merely documented.

Training records, not training intentions

A policy promising annual awareness training, with one completion two years ago, is worse than no promise at all.

Due diligence on your IT supplier

Your IT provider handles your client information. You are expected to have assessed them, and to hold the record.

Who it's for

Built for firms without an IT department

Small practices and sole practitioners

Firms without an IT department, where the COLP or practice manager has absorbed the technology questions alongside everything else. That is the firm this service is built for.

Legal aid contract holders

Lexcel or the SQM remains a condition of LAA contract work, and information management is one of the assessed areas. Separately, holding a criminal legal aid contract has required a valid Cyber Essentials certificate since 1 October 2025 — that one is not optional.

Firms with a date in the diary

Whether it is a first assessment or an annual maintenance visit, the IT evidence needs to have been running beforehand. The earlier we start, the less of it has to be explained rather than shown.

How I help

Three stages, and you can stop after any of them

Most firms start with the gap assessment. It is deliberately a small commitment, because until somebody has looked at your systems, neither of us can honestly say what the rest would cost.

Lexcel IT Gap Assessment

Find out where you actually stand.

A structured review of your IT and information security against the IT-relevant parts of Lexcel v6.1. I read what your policies claim, then check it against your systems rather than taking it at face value.

  • Review of your existing policies, registers and records
  • Verification against your live systems, not a questionnaire alone
  • RAG-rated gap report with evidence for every finding
  • Prioritised remediation plan, split by who has to do it
  • An honest view on whether your timescale is realistic
Fixed fee · quoted after a short call
Book a gap assessment

Lexcel IT Readiness

Most firms

Close the gaps and build the evidence.

The project that gets you there. Tailored policies issued with real owners and review dates, the technical baseline put in place, and — the part firms most often miss — the evidence run-in so the controls have been operating before anyone asks.

  • Eight tailored policies, issued for your approval
  • Information asset register and policy register, populated
  • Microsoft 365 hardening, device compliance, patching, backup
  • Staff security awareness training, with records kept
  • Cyber Essentials support, if you want it
  • An indexed Assessor Evidence Pack at the end
Project fee · scales with the size of your practice
Talk about readiness

Lexcel IT Assure

Stop it decaying between visits.

At your first assessment an assessor looks back three months. At every visit after that, twelve — which is not something anyone crams. Assure keeps the controls running and the evidence generating itself.

  • Ongoing management of the technical baseline
  • Scheduled policy reviews, with the review records kept
  • Monthly patch and monitoring reports
  • Quarterly asset register refresh
  • Annual Cyber Essentials renewal and refresher training
  • A pre-visit evidence refresh before each maintenance visit
Monthly, per person · minimum applies
Ask about Assure

Everything is quoted in writing before any work starts, and no VAT is chargeable — the figure quoted is the figure you pay. Cyber Essentials certification fees are set by the certification body and passed through at cost.

How it works

From where you are to evidence you can hand over

1

Gap assessment

A fixed-fee review of where you stand, with a RAG-rated report and a costed plan. Ideally six months or more before your assessment date.

2

Readiness

Policies tailored and issued, registers populated, the technical baseline applied, staff trained.

3

Evidence run-in

The controls run and produce records. This is the part that cannot be compressed, and the reason to start early.

4

Your assessment

You go into it with an indexed evidence pack rather than a fortnight of hunting. Your assessor decides the outcome — that is not mine to promise.

5

Assure

The evidence keeps generating itself, ready for the next maintenance visit and for reaccreditation.

Start earlier than feels necessary

The single most common problem is timing. Controls need to have been operating before your assessment, so a gap found three weeks out is a very different conversation from the same gap found six months out. If your date is close, I will tell you honestly what is achievable rather than sell you a timeline that cannot be met.

Why me

Legal sector security, at small firm scale

Before founding Lewis McKee Consulting I worked in information security across the legal sector, including securing systems at five top-100 law firms, and rewriting firm policy sets to meet Lexcel requirements aligned with ISO 27001.

That work is normally only available to firms large enough to employ it. This service exists because the requirements do not scale down — a four-person practice is asked for the same information management evidence as a four-hundred-person one, with nobody in-house to produce it.

To be explicit: I am not accredited, approved or endorsed by the Law Society, I do not carry out Lexcel assessments, and I cannot guarantee any assessment outcome. I prepare the IT evidence; your assessor decides.

What makes the evidence hold up

  • Policies checked against your systems, not accepted at face value
  • Every finding recorded with where I looked, so the report is defensible
  • Gaps separated into "not in place" and "in place but not evidenced" — different problems, very different costs
  • Your documents in your Microsoft 365 tenant, owned by you
  • Nothing claimed that your licensing cannot actually deliver
Works alongside

The services that generate the evidence

Several Lexcel IT requirements are satisfied by things that should be running anyway. Where they are, the evidence produces itself.

FAQ

Common questions

Do you guarantee we will pass our assessment?+

No, and you should be wary of anyone who says otherwise. Accreditation decisions rest entirely with your assessor. What I do is put the IT controls in place and produce the evidence, so that the IT and information security side of the assessment is prepared, documented and demonstrable. I am not accredited, approved or endorsed by the Law Society, and I do not carry out Lexcel assessments.

Is Cyber Essentials mandatory for Lexcel?+

Not for accreditation — Lexcel recommends it rather than requiring it, though assessors do look for it and it answers several questions at once. Separately, it is mandatory if you hold a criminal legal aid contract: a valid certificate has been required since 1 October 2025. Those are two different things and it is worth keeping them apart, because firms sometimes conclude they need it when they do not, or that they do not when they do.

How long does it take?+

The gap assessment is a day, with the report following shortly after. The readiness project depends on what the assessment finds, but the part that cannot be rushed is the evidence run-in: the controls need to have been operating before your assessment, not configured the week before. That is why the honest advice is to start the gap assessment six months or more ahead of your date rather than a month before.

Do you work with firms that already have IT support?+

Yes. The gap assessment works perfectly well alongside an existing provider — it is a review, not a takeover, and several of the findings usually turn out to be things your current provider can fix once somebody has identified them. If you would rather I carried out the remediation, that is a conversation; if you would rather your existing provider did, the report tells them exactly what to do.

What if the assessment finds our policies are wrong?+

That is the normal outcome, and it usually runs the opposite way to what people expect: the policy is stricter than the systems. A manual promising 90-day password expiry while your tenant correctly sets passwords never to expire is a very common example. Where the policy is right, I change the configuration. Where the systems are right and the policy is out of date or copied from a template, the fix is a wording change — faster and cheaper.

Who owns the policies at the end?+

You do, and that matters. I draft them; your management approves and owns them. A policy approved by your IT supplier on your behalf carries no weight with an assessor. The same applies to two things I will not decide for you: who owns each information asset, and how long you keep things. Retention is a legal and professional judgement involving limitation periods and your insurer — I will tell you what your systems can technically enforce, and implement whatever you decide.

What do we actually get at the end?+

An Assessor Evidence Pack: an indexed folder mapping each IT-relevant requirement to the artefact that evidences it, alongside the approved policies, populated registers and the technical reports. The index is the deliverable rather than the folder — anyone can hand over a pile of screenshots, and the value is in the line that says this artefact answers that question.

Where do the policies live afterwards?+

In your own Microsoft 365, in a SharePoint library you control, with version history switched on and the review dates held as columns. That library view becomes your policy register, which means it cannot drift out of step with the documents it describes. They are your documents in your tenant, not something held on my systems.

Find the gaps while they are still private

A fixed-fee gap assessment tells you exactly where you stand on the IT side, what it would take to close it, and whether your timescale is realistic. Cheap, quick, and very much better than finding out at the assessment.

Book a Lexcel IT gap assessment
Enquire

Book a Lexcel IT gap assessment.

Tell me a little about your practice — how many of you there are, whether you are accredited already or going for it, and when your next assessment or maintenance visit is. I will come back within one working day with a straight answer on what is involved and what it costs.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.