INDUSTRIES

IT support and security for law firms

For a law firm a breach isn't only a security incident. It's a professional-conduct problem and a privilege problem at the same time, and the notification clock starts before you know what happened. Your Law Society expects you to have done due diligence on the vendor holding your client files. Most providers have never been asked for that file. We keep ours ready.

WHAT APPLIES

Which rules apply to you?

  • Law Society obligations

    Applies now

    Confidentiality and competence duties reach the technology you practise with, and the vendors who touch client information. The firm is expected to have assessed the provider, which means the provider should arrive with the answers.

  • Solicitor-client privilege

    Applies now

    What a third-party administrator can and can't see, and whether you can prove which of them opened what, months later. Access that isn't logged is access you can't account for.

  • PIPEDA breach notification

    Applies now

    A report to the Privacy Commissioner where there's a real risk of significant harm, plus a record of every breach, including the ones you decide aren't reportable.

  • Quebec Law 25

    Applies conditionally

    If you hold files on Quebec clients. Its own thresholds, its own timing, and they don't line up with the federal ones.

TECHNOLOGY

Whose kit does this run on?

The platforms we design, build and support. Named because a buyer with an estate already standardised on one of them needs to know before the first call, not after it.

Microsoft, Cisco, Fortinet, VMware, Azure

QUESTIONS

What buyers in this sector ask.

Only the named people your engagement says can, and every access is logged and reviewable. Ask any provider to show you the log rather than describe the policy. A provider who can describe it but cannot produce it has already told you the answer, and client confidentiality turns on that log.

A named contact, containment, and a written record started immediately, because the record is what your notification decision will later rest on. The first hour decides whether you're reconstructing events or reading them. Law firm ransomware is the common case, and it moves faster than a scheduled call.

Your Law Society expects you to assess the vendors who touch client information, so the obligation is yours and the evidence should be ours. We arrive with the answers written down: where data sits, who can reach it, how access is logged, what happens in an incident. Most providers have never been asked.

Yes, and for a specific reason. The platform secures itself. It doesn't secure the laptop the file gets downloaded to, the mailbox the client emails, or the account whose password was reused. Most firm breaches start outside the practice management system rather than inside it.

If you need advice on whether a specific incident is reportable, or on your conduct obligations, that's counsel's call and not ours. We build and evidence the controls, and we'll work alongside whoever advises you. Knowing which of the two you need is worth asking before you scope anything.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.