By Jason Da Silva, Principal Consultant, DASTech Consulting · Last updated: July 2026
Related serviceLegal I.T.See the service →A small law firm IT security checklist should cover six areas: access and identity, devices, email, backups and recovery, vendors and third parties, and incident response. Work through each item below. If you can honestly tick every box, your firm is in good shape to protect client confidentiality and meet the general expectations of the Law Society of Ontario and PIPEDA. If you cannot, each unchecked box is a place to start.
This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.
This is a working checklist. It is built for firms of roughly 5 to 80 people who do not have a full-time IT department. Print it, share it with your team, and revisit it every quarter. For the reasoning behind these controls, see our legal IT services for law firms and the Heeney Lawyers cloud migration case study.
Lawyers hold some of the most sensitive information their clients will ever share. That duty of confidentiality does not stop at the office door: it follows every file into your email, your cloud storage, and your backups. Rule 3.3-1 of the Law Society of Ontario’s Rules of Professional Conduct is the source of that duty: a lawyer shall at all times hold in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship. The rule allows only four exceptions: the client authorizes disclosure, disclosure is required by law or by order of a tribunal, it is required by the Law Society, or it is otherwise permitted by the rules.
Technology is not a side issue to that duty. The commentary to Rule 3.1-2, the competence rule, says a lawyer should develop an understanding of, and the ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted the Federation of Law Societies Model Code commentary on technological competence, amended in the fall of 2019.
Privacy law can sit on top of all this. Where PIPEDA applies, the safeguards you put around personal information are expected to match how sensitive that information is, which for a law firm is usually very sensitive indeed. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice. A checklist turns these broad duties into concrete, checkable actions.
Who can get into your systems, and how you prove they are who they say they are.
The laptops, desktops, and phones that touch client files.
The most common way client data leaks out and attackers get in.
What you fall back on when hardware fails, ransomware hits, or a file is deleted by mistake.
Every outside service that stores or processes your client data.
What you do in the first hours after something goes wrong.
Those last obligations are worth spelling out. Under PIPEDA, the trigger for reporting a breach of security safeguards is a real risk of significant harm to an individual. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. In weighing the risk, you look at how sensitive the information was and how probable it is that the information has been or will be misused.
If that threshold is met, you report the breach to the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible after you determine that a breach has occurred. Separately, you must keep a record of every breach of security safeguards, whether or not it meets the threshold, and retain those records for 24 months. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice, and remember that your reporting duties to clients and to the Law Society sit alongside anything privacy law requires.
You do not have to fix everything at once. Start with MFA everywhere, daily tested backups, and a written incident plan. Those three cover the failures we see most often. From there, work down the list one category at a time.
If you would like a second set of eyes, DASTech offers a confidential IT security audit for small law firms. We will walk this checklist with you, tell you honestly where you stand, and give you a prioritized plan. Book a confidential audit through our contact page, or learn more about our fractional IT service.
Multi-factor authentication. Enabling MFA on email and your key systems stops the large majority of account-takeover attacks, which are the most common way client data is exposed. If you do only one thing this week, do that.
Most of it, yes. The duty to protect client confidentiality does not scale down because your firm is small, and attackers often target smaller firms precisely because their defences are lighter. The controls here are proportionate and achievable for a firm of 5 to 80 people.
Review it quarterly and after any major change, such as new staff, a new software vendor, or a move to the cloud. Security is not a one-time project. A short quarterly pass keeps small gaps from becoming real exposure.