The four failures we see in this sector.
Not hypotheticals. These are the findings that come up again and again on first documentation.
Access is not just a technical setting; it is something you may have to account for. If you cannot produce a record of who could open a matter file, you have a problem before anything goes wrong.
Redirection attacks against real estate and litigation trust payments are the dominant threat to BC practices. They start in a mailbox, not on a server.
Documents end up in email, in a practice management system, on a desktop, and in a personal cloud folder. Four copies, one of which is current.
A departing associate, their client list, and their mailbox delegations. The technical cleanup has professional consequences if it is done loosely.
What we put in place
Six things, in orderA signed document showing who can reach which matters and mailboxes — ready if a client, an insurer, or the Law Society asks.
MFA, impersonation protection on inbound mail, and a written call-back rule before any banking detail changes. Cheap, and it works.
A structure organised by client and matter, with permissions that follow the file rather than the folder someone happened to create.
A written sequence for offboarding: accounts, delegations, devices, remote access, and the record of what was removed and when.
A defensible way to send documents to clients that is not an unencrypted attachment, and that your clients will actually use.
Credentials, licences, and tenant ownership in the firm's name. If you change providers, nothing about your client data is held hostage.
Legal practices questions
Can you produce an access record for our insurer?
Yes. Quarterly access reviews are part of Managed + Security, and each one is a dated document listing who can reach what.
How do you protect trust-account instructions?
Technically, with MFA and mail impersonation controls. Procedurally, with a written call-back rule. Both are needed; either alone fails.
Do you work with Clio, PCLaw, or Actionstep?
Yes, as supported applications — access, integration, and licensing. Configuration of legal workflow itself stays with your practice-management consultant.
What happens if we are breached?
You have a written runbook naming who to call, in what order, with what authority, including notification wording. We rehearse it once a year so nobody is improvising.