Jump to section
You do not need a security department. You need one focused afternoon, a short list, and the willingness to say no to a few bad habits. Most breaches at small firms are not clever heists. They are a stolen laptop with no password, a file shared with the wrong person, or a partner who clicked a link at 6 p.m. while tired. The good news: the fixes are cheap, and you can knock out the big ones this week.
What follows is a practical checklist in the order I would actually do it. Start at the top. Each step blocks one of the weaknesses that breaches and honest mistakes most commonly exploit.
Lock Down Devices Before Anything Else
Your first job is the boring one. Every device that touches client data needs a password or PIN, a short auto-lock timer, and full-disk encryption. Encryption is the part firms skip, and it is the part that matters when a laptop goes missing from a car or a courthouse.
Turn it on today. On Windows, it is BitLocker (Pro edition) or Device Encryption on Home. On a Mac, it is FileVault, found in System Settings under Privacy and Security. On phones, modern iPhones and Android devices encrypt automatically once you set a passcode, so set a real six digit passcode, not 1234.
Tip. Set screens to lock after two minutes of inactivity and require the password to wake. It feels annoying for a day, then you stop noticing. A locked screen is what stands between a wandering visitor and an open matter.
While you are in there, turn on automatic updates for the operating system and your browser. Unpatched software is the single most exploited weakness, and updates cost you nothing but a restart.
Encrypt What Leaves the Office
Data at rest is one problem. Data in motion is another. The moment a file leaves your building, by email, USB stick, or a shared link, you lose physical control of it. So make it useless to anyone who is not the intended reader.
Three habits cover most of it:
- Email. Sensitive attachments should be encrypted or, better, not attached at all. Send a secure link instead of the document itself.
- Portable drives. If you must use a USB stick, buy a hardware-encrypted one or encrypt it with the same tools above. Better yet, stop carrying client files on your keychain.
- Cloud and sharing. Use a reputable service with encryption in transit and at rest, and check where the data is stored. For a longer look at that, see our note on cloud storage and client confidentiality.
A client portal is the cleanest fix here. Instead of emailing a will draft back and forth, both sides log in and exchange documents through one encrypted channel. If you already run practice management software, you may have this and not be using it.
Control Who Sees Which Files
Not everyone in your office needs access to everything. The articling student covering a real estate closing does not need the firm's family law files, and your bookkeeper does not need privileged strategy memos. This is called least privilege, and it is mostly free.
Map it out once. Who actually needs each category of file to do their job? Then set permissions to match, and review them when someone joins, changes roles, or leaves.
| Role | Needs access to | Should not have |
|---|---|---|
| Reception | Calendar, contact details | Matter documents, trust records |
| Bookkeeper | Billing, trust ledgers | Privileged case files |
| Associate | Their assigned matters | Unrelated practice areas |
The other half of access control is offboarding. When staff leave, revoke their logins the same day, not the next quarter. A former employee's live account is a wide open door, and it is the kind of gap a law society review will flag.
Spot the Phishing Email Aimed at Lawyers
Lawyers are a favourite target because you move money and you move fast. The classic scam is a fake message about a real estate transaction, redirecting trust funds to a fraudster's account. Others impersonate a partner asking for an urgent wire, or a registry demanding you log in through a lookalike link.
If an email creates urgency and asks you to move money or click a link, slow down and verify on a channel you already trust. A rule worth taping to your monitor
Teach everyone the same short reflex. Hover over links before clicking to see the real address. Confirm any payment change by phone using a number you already have, never the one in the email. Watch for slightly wrong domains, like a missing letter in a familiar company name. And treat pressure itself as a warning sign, because real counterparties rarely demand action in the next five minutes.
Warn. Turn on two factor authentication everywhere it is offered: email, banking, your document system, everything. It is the single highest value step on this whole page, and it stops most stolen passwords cold. Our post on password and two factor habits walks through the setup.
Write a One Page Incident Plan
You will not think clearly during a breach, so decide now. One page, printed, in a folder anyone can find. It answers three questions: who to call, what to do first, and who to notify.
- Contain. Disconnect the affected device from the network and change relevant passwords.
- Assess. Note what was accessed, when, and whose information may be involved.
- Notify. List your law society's practice advisor, your insurer, and, where the breach creates a real risk of harm, the affected clients and the privacy commissioner.
Add the actual phone numbers and account contacts to the page. A plan with blanks in it is not a plan. If you want the regulatory backdrop, your provincial law society and the federal privacy legislation set out your reporting duties, and a short call to your practice advisor is time well spent before anything goes wrong.
None of this requires a consultant. Encrypt your devices, protect what leaves the office, tighten who sees what, train the phishing reflex, and print the one page plan. That is a week's work at most, and it closes the doors real breaches use. When you are choosing tools that make the secure path the easy path, a system with a proper client portal and role based access does a lot of this quietly in the background, which is exactly where good security belongs. Do the boring steps first, and the rest gets much easier.