Skip to content

Industry

Law firms

A firm's obligation to protect client information is an ethical duty rather than a policy preference, and it does not distinguish between a breach caused by an attacker and one caused by a misconfigured folder. That framing changes how access, retention and client exchange should be set up.

The weakest link in most firms

Email attachments

for client document exchange

A portal removes the problem. Most document management systems already include one, unused.

Six priorities specific to a firm

Law firm IT priorities and why each is different
PriorityNature
ConfidentialityAccess controls must reflect matter level need to know, not firm wide accessEthical duty, not just policy
Document managementVersioning, retention and search matter as much as availabilityThe firm's entire product
Retention and legal holdDeleting the wrong thing is a worse outcome than storing too muchContractual and ethical
Client data exchangeEmail attachments remain the default and remain the weakest linkDaily
Client security questionnairesCorporate clients audit their firms. Answers must be accurateIncreasingly common
Mobile and remote workCourt, client site and home. Data leaves the office continuouslyConstant

What a client questionnaire asks

These six appear on almost every corporate client security addendum. Each needs a truthful answer and evidence behind it.

  • Multi factor authentication on email and remote access
  • Encryption of devices and of data at rest
  • Documented incident response and breach notification process
  • Background checks and confidentiality agreements for staff with data access
  • Vendor management, including what your IT provider can access
  • Evidence of security awareness training with recorded completion

Access should follow the matter

Most small firms run flat access: everyone can open everything, because it is convenient and because the firm trusts its people.

Trust is not the issue. Ethical walls are, conflicts are, and so is the practical reality that a single compromised account with access to everything exposes every client rather than one.

Matter level access takes some setting up and then largely runs itself. It also makes the answer to a client questionnaire considerably more comfortable, and it is the difference between an incident affecting one matter and one requiring notification across the whole client base.

Common questions

Answered before you ask.

Is email good enough for sending client documents?

It is the default and it is the weakest part of most firms' setup. Email is fine for correspondence and poor for anything sensitive: it lands in inboxes nobody controls, forwards silently, and persists indefinitely. A secure client portal removes the problem for document exchange and most document management systems include one. Where email must be used, encryption and expiry controls in Microsoft 365 are usually already licensed and rarely switched on.

Do we need to worry about client security questionnaires?

If you act for corporate clients, institutional lenders or insurers, expect them. They arrive as a condition of panel membership or of a specific engagement, and they ask concrete questions about controls rather than general assurances. The practical issue is not usually whether a firm can meet the requirements but whether it can evidence them. Answering optimistically is the genuine risk, because an inaccurate answer that surfaces after an incident is a contractual problem on top of a security one.

How should retention work?

Deliberately, and this is worth an afternoon with someone who understands both the technology and the firm's obligations. The common failure is a retention policy written in a document and never implemented in the systems, so nothing is ever deleted and legal hold is applied by asking people not to delete things. Retention configured in the document management system, with hold applied at matter level, removes the reliance on individual memory.

Our practice management vendor hosts everything. Is that enough?

It covers their platform. Your workstations, network, identities, email and mobile devices remain yours, and each is a route to client information. Hosted practice management narrows the scope of what needs managing and does not remove the confidentiality obligation, which attaches to the firm regardless of where the data physically sits.

Get an access and exchange review.

Who can reach which matters, how client documents leave the firm, and what a client questionnaire would find. Written findings either way.

CallFree assessment