Law Society of WA

Editor’s opinion: The LPB’s response to the cyber-attack shows it still needs to lift its game 

June 3, 2026

By Michael DouglasBrief Editor-at-Large

Back in September 2025, I opined for Brief that it was ‘Time for the LPB’s reckoning’

The previous month, the Public Administration Standing Committee of the Legislative Council of the Parliament of WA commenced an inquiry into the Legal Practice Board of Western Australia (LPB). The inquiry followed growing discontent with the LPB among members of the profession, the reasons for which were cogently distilled in a joint submission to the inquiry by your Law Society and four fellow legal associations. 

If you haven’t seen it, you can find that joint submission online on the Parliament of WA’s website

Drawing on the Law Society’s April 2025 survey of the profession and extensive case studies, the submission concludes that the legal profession is not being effectively regulated. It makes for harrowing reading. 

It might be fairly observed that those with an ‘axe to grind’ against the LPB are more likely to speak up against the LPB, and so the underlying data exhibit selection bias. Even so, the scope of discontent within the profession, and reports exhibiting recurring themes, lend credibility to the submission’s position. Broadly stated, those themes relate to: 

  • chronic delays; 
  • ineffective oversight, systems and processes; 
  • inappropriate and highly damaging investigation and prosecution processes, misaligned with the Legal Practice Board’s stated objectives and values; 
  • ineffective governance and financial management; and 
  • failure to engage, communicate and respond to enquiries and applications. 

A serving member of the LPB reading this may ask: why are you writing about this again? Hasn’t the parliamentary inquiry dealt with it? Why are you still whinging? 

To which I reply: I am still whinging for three reasons, my learned senior. 

The first reason I am still whinging: the LPB’s response to the cyber attack 

A cyber-attack can befall any business at any time. But the cyber incident affecting the LPB in 2025 was of deep concern to the profession – not only because of the breach itself, but because of what followed. 

In May 2025, the LPB experienced unauthorised access to part of its IT environment, triggering the shutdown of systems and an incident response process. In the days that followed, a small amount of data was published online before being removed.  

The LPB told practitioners that the incident had been contained, that only limited information had been disclosed, and that the dark web was being monitored for any further activity. 

As the months progressed, the picture became less certain. 

After further review, the LPB revealed that more data had been accessed than initially understood. Notifications to affected individuals were not immediate but occurred progressively, following what was described as a ‘comprehensive investigation’. In the interim, many practitioners were left to navigate a prolonged period of uncertainty, unsure whether their personal or professional information had been compromised. 

Early messaging that emphasised a ‘limited’ disclosure, followed by later confirmation of broader access, created anxiety within the profession. 

More recently, practitioners have been surprised to learn that categories of highly sensitive personal data – including data they didn’t expect the LPB to hold – had been compromised. They were even more surprised to learn that while the LPB informed them their sensitive data had been stolen, the LPB wouldn’t tell them what those data were. 

Since October last year, several members of the profession have contacted the Law Society to share their own experience of being impacted by the breach. In January, Brief online published a letter to the editor from Mr Graeme Young, a barrister who expressed deep concern about the kind of data being held by the LPB, which he was told included religious beliefs or affiliations, philosophical beliefs and sexual preferences or practices. He also asked why it had taken six months for the LPB to inform him that his personal and sensitive data had been stolen. 

Mr Young contacted the LPB seeking answers and received an automated email reply. At the time Mr Young wrote to us, more than six weeks since writing to the LPB, he had still not received a response. Brief then wrote to the LPB following up Mr Young’s concerns, and the LPB responded through its Chair, Mr John Syminton. You can read that response on Brief online.

Following publication of Mr Young’s letter, numerous other practitioners contacted Brief raising similar issues. Some shared a deep concern about the kind of information held by the LPB. Others, who like Mr Young had been informed more than six months after the breach that their personal or sensitive data had been stolen, had their enquiries of the LPB left unanswered for weeks, despite multiple follow-ups. Often, those who did eventually receive a response were left cold at the lack of detail and felt their concerns were not adequately addressed.  

One practitioner told us: 

‘I think it’s outrageous that they failed to keep my information secure; plainly that information is held by people who are by definition not keeping it confidential; and now they say that “to preserve the integrity of the Board’s internal processes and uphold its statutory confidentiality obligations, we unfortunately cannot disclose further specifics relating to this information”!’. 

I query whether the LPB’s position on this issue is consistent with the policy of the notifiable data breaches scheme in the Privacy Act 1988 (Cth). Whatever the scope of that statutory regime, my view is that whenever possible, persons affected by a data breach ought to be provided with sufficient information by a ‘breached organisation’ to protect themselves against the risk of suffering serious harm as a consequence of the breach. 

Another practitioner was told by the LPB in early December 2025 that her sensitive data had been compromised. The following day she asked the LPB why it held sensitive data of that kind about her and asked for specific details. She received no response for over two months, despite her chasing.

Eventually, the LPB told her that it couldn’t provide details of the sensitive information it had lost, because the LPB owes duties of confidentiality which are designed to protect the privacy of complainants, legal practitioners, applicants and other individuals. In her communication to Brief, she said that she “would have thought a responsibility in relation to protecting data would be extended to me” as well. 

Reflecting on these stories prompts the following questions: 

Why is it taking weeks or months for the LPB to get back to practitioners after the LPB sends out alarming notifications about stolen sensitive data? 

For what purpose is the LPB retaining data about religious beliefs or sexual preferences in the first place? 

And even if stolen information sits in a confidential document – for example, from a complainant – why can’t the LPB tell us the nature of the data without handing over the document?  

None of this is to diminish the complexity of responding to a cyber incident of this nature. Containment, investigation and remediation are demanding processes, often undertaken under significant pressure and with incomplete information. 

But there are lessons to be learned here. Cyber resilience is no longer simply a technical issue. It depends upon governance, preparedness and accountability. As regards those substantive matters, addressing the concerns raised by members of the profession could – and in my view, likely would – serve the public interest. 

The second reason I am still whinging: the LPB’s submission to the parliamentary inquiry 

The LPB made its own submission to the parliamentary inquiry, which you can also find publicly available on the Parliament of WA’s website. The submission exceeds 500 pages, including 6 schedules. The 100-or-so pages of the ‘primary’ aspect of the submission are summarised in an Executive Summary, which begins with the following: 

The Board is responsible for administering a complex legislative framework and regulating a uniquely challenging profession. It has a statutory mandate to protect the public and uphold the integrity of the legal profession, not to advance the interests of practitioners. The Board’s performance should be assessed against that mandate; isolated events or anecdotes of practitioner dissatisfaction are not grounds for structural reform. The legal profession requires a regulator that is independent, firm, proportionate and mindful of impacts on all parties, but with the overarching public interest at the heart of its purpose and execution. 

The LPB’s report, and this passage within it, were authored before the joint submission of the Law Society and other representative organisations was made publicly available. In that context, the authors of the LPB report may be forgiven for not telegraphing the kinds of case studies that were detailed in the joint submission, which were provided to substantiate the premise that the legal profession is not being effectively regulated by the LPB. 

That is a charitable interpretation. A charitable interpretation is not the kind of interpretation that the LPB would seem to afford practitioners who make mistakes; see eg Legal Practice Board v Barry [2026] WASCA 12. 

A less charitable interpretation of the quoted paragraph of the Executive Summary is this: despite months of conscientious lobbying from the Law Society and other sectors of the legal profession, the LPB remains wilfully blind to its causal responsibility for the widespread dissatisfaction with the LPB within the legal profession; to its ineptitude, callousness, and occasional cruelty. 

How many ‘anecdotal’ accounts would the LPB report’s authors like for the LPB-critical data to become statistically significant? Name your ‘n’ value: I reckon we could get your number pretty easily. 

My opinion (and I know not everyone involved with the profession or the Law Society agrees with me), is this: 

The time for ‘tinkering’ with policy settings is over. We need a new regulatory model. It is time to start again, tabula rasa

The third reason I am still whinging: at the time of writing, we are waiting on an outcome to the parliamentary inquiry 

It has been well over six months since the parliamentary inquiry received written submissions from lawyers, stakeholders and members of the public and we are still waiting on a substantive response from the committee responsible, being the Standing Committee on Public Administration. 

The delay was foreseeable. The State Government has a fair bit going on; lawyers’ problems are likely way down on their list of priorities. And probably fair enough, too. 

But when parliament turns its ‘mind’ back to these issues, I hope they consider the ongoing issues described above that post-date the inquiry. I hope they pay these issues the attention they deserve and take bold action. 

The issue of the ‘regulation of the legal profession in Western Australia’ deserves attention not only because of the impact on the humans who are members of the profession – even though that, of course, matters to us and our families. 

The regulation of the legal profession in Western Australia matters because of the public good that legal practitioners serve through observance of their paramount duty to the administration of justice. 

A well-regulated profession serves a higher good worth pursuing. Whatever your view on the politics surrounding the LPB – and on who is in charge of what in whatever circumstances – I hope we can all agree on that. 

Previous Story

Shaping the in-house profession: A conversation with Irene Kuo

Next Story

LPP and regulatory investigations: The ethics of compliance

Discover more from brief.

Subscribe now to keep reading and get access to the full archive.

Continue reading