Guide

The Small Law Firm IT Security Checklist

Legal I.T. services from DASTech ConsultingRelated serviceLegal I.T.See the service

A small law firm IT security checklist should cover six areas: access and identity, devices, email, backups and recovery, vendors and third parties, and incident response. Work through each item below. If you can honestly tick every box, your firm is in good shape to protect client confidentiality and meet the general expectations of the Law Society of Ontario and PIPEDA. If you cannot, each unchecked box is a place to start.

Before you read on

This guide is general information about technology practice, not legal advice. It reflects what we see doing hands-on IT work with Canadian law firms, and it does not account for your firm’s particular circumstances. Confirm any specific obligation with your own counsel or with the Law Society directly before you act on it.

This is a working checklist. It is built for firms of roughly 5 to 80 people who do not have a full-time IT department. Print it, share it with your team, and revisit it every quarter. For the reasoning behind these controls, see our legal IT services for law firms and the Heeney Lawyers cloud migration case study.

Why this checklist matters

Lawyers hold some of the most sensitive information their clients will ever share. That duty of confidentiality does not stop at the office door: it follows every file into your email, your cloud storage, and your backups. Rule 3.3-1 of the Law Society of Ontario’s Rules of Professional Conduct is the source of that duty: a lawyer shall at all times hold in strict confidence all information concerning the business and affairs of the client acquired in the course of the professional relationship. The rule allows only four exceptions: the client authorizes disclosure, disclosure is required by law or by order of a tribunal, it is required by the Law Society, or it is otherwise permitted by the rules.

Technology is not a side issue to that duty. The commentary to Rule 3.1-2, the competence rule, says a lawyer should develop an understanding of, and the ability to use, technology relevant to the nature and area of their practice, and should understand the benefits and risks of that technology given the duty to protect confidential information. The Law Society adopted the Federation of Law Societies Model Code commentary on technological competence, amended in the fall of 2019.

Privacy law can sit on top of all this. Where PIPEDA applies, the safeguards you put around personal information are expected to match how sensitive that information is, which for a law firm is usually very sensitive indeed. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice. A checklist turns these broad duties into concrete, checkable actions.

Access and identity

Who can get into your systems, and how you prove they are who they say they are.

  • Multi-factor authentication (MFA) is enabled on email, practice management, document storage, and remote access
  • Every person has their own named account (no shared logins)
  • Staff use a password manager, with unique passwords for every service
  • Administrator accounts are separate from everyday user accounts
  • Access is reviewed when someone changes role, and revoked the day they leave
  • Access follows least privilege: people can reach only the matters and folders they need
  • Former staff, contractors, and old vendor accounts are audited at least quarterly

Devices

The laptops, desktops, and phones that touch client files.

  • Full-disk encryption is on for every laptop and desktop (BitLocker or FileVault)
  • Screens lock automatically after a few minutes and require a password or biometric to unlock
  • Operating systems and applications install security updates automatically
  • Reputable endpoint protection (antivirus and anti-malware) runs on every device
  • Personal phones that access firm email require a PIN or biometric and can be wiped remotely
  • A written inventory lists every device that can reach client data
  • Old drives and devices are securely wiped or destroyed before disposal

Email

The most common way client data leaks out and attackers get in.

  • MFA protects every mailbox (repeated here because it matters most)
  • Staff can recognize phishing and know how to report a suspicious message
  • Anti-spam and anti-phishing filtering is active on your mail platform
  • Sensitive documents are shared through a secure link or portal, not open attachments
  • Encrypted email is available for the most sensitive client communications
  • External-sender warning banners are turned on
  • Auto-forwarding rules to outside addresses are blocked or reviewed regularly

Backups and recovery

What you fall back on when hardware fails, ransomware hits, or a file is deleted by mistake.

  • Client data is backed up automatically every day
  • Backups follow the 3-2-1 rule: three copies, two types of media, one off-site
  • At least one backup copy is offline or immutable so ransomware cannot encrypt it
  • A test restore is performed at least quarterly to confirm backups actually work
  • Backup data is encrypted, both while stored and while moving
  • You know your recovery time: how long it takes to be operational again after a failure
  • Retention periods match your professional record-keeping obligations. Under LSO By-Law 9, trust account records are generally kept for ten years plus the current year, and the book of duplicate cash receipts for at least the six years preceding your most recent fiscal year end

Vendors and third parties

Every outside service that stores or processes your client data.

  • You keep a list of every vendor that touches client information
  • Cloud providers keep Canadian client data in a location you are comfortable with, and you know where that is
  • Written agreements cover confidentiality and data protection with each key vendor
  • Vendor access to your systems uses named accounts and MFA, and is removed when no longer needed
  • You review each critical vendor’s security posture before signing and at renewal
  • You understand what happens to your data if you end a vendor relationship

Incident response

What you do in the first hours after something goes wrong.

  • A written incident response plan exists and names who to call first
  • Staff know how to report a suspected breach immediately, without fear of blame
  • Contact details for your IT support, insurer, and counsel are kept somewhere reachable if systems are down
  • You understand your breach-notification obligations to affected clients and regulators
  • You keep a written record of every breach of security safeguards, not only the ones you report
  • Logging is turned on so you can reconstruct what happened
  • The plan is tested with a tabletop walkthrough at least once a year
  • Cyber insurance is in place and you know what it covers

Those last obligations are worth spelling out. Under PIPEDA, the trigger for reporting a breach of security safeguards is a real risk of significant harm to an individual. Significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record, and damage to or loss of property. In weighing the risk, you look at how sensitive the information was and how probable it is that the information has been or will be misused.

If that threshold is met, you report the breach to the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible after you determine that a breach has occurred. Separately, you must keep a record of every breach of security safeguards, whether or not it meets the threshold, and retain those records for 24 months. Confirm with your own counsel whether PIPEDA or a substantially similar provincial law governs your practice, and remember that your reporting duties to clients and to the Law Society sit alongside anything privacy law requires.

Where to start if this feels like a lot

You do not have to fix everything at once. Start with MFA everywhere, daily tested backups, and a written incident plan. Those three cover the failures we see most often. From there, work down the list one category at a time.

If you would like a second set of eyes, DASTech offers a confidential IT security audit for small law firms. We will walk this checklist with you, tell you honestly where you stand, and give you a prioritized plan. Book a confidential audit through our contact page, or learn more about our fractional IT service.

FAQ

Common questions.

What is the single most important item on this checklist?

Multi-factor authentication. Enabling MFA on email and your key systems stops the large majority of account-takeover attacks, which are the most common way client data is exposed. If you do only one thing this week, do that.

Does a small firm really need all of this?

Most of it, yes. The duty to protect client confidentiality does not scale down because your firm is small, and attackers often target smaller firms precisely because their defences are lighter. The controls here are proportionate and achievable for a firm of 5 to 80 people.

How often should we review this checklist?

Review it quarterly and after any major change, such as new staff, a new software vendor, or a move to the cloud. Security is not a one-time project. A short quarterly pass keeps small gaps from becoming real exposure.