Cybersecurity Checklist for Ontario Law Firms

Ontario law firms answer to several overlapping sets of expectations on cybersecurity. The Law Society of Ontario ties technology competence to confidentiality in the commentary to rule 3.1-2. LAWPRO's professional liability policy limits social engineering coverage unless a firm follows specific written steps. PIPEDA requires private sector organizations to safeguard personal information and to report and record certain breaches. And cyber insurers ask detailed questions about controls before they quote. This checklist brings those threads together into concrete controls, grouped the way an IT team would implement them, with each one tied to the obligation it supports.
How to read this checklist
Each control below names the source it helps you satisfy. LSO refers to the Rules of Professional Conduct commentary on technological competence and confidentiality, and to the LSO's Technology Guideline in its Practice Management Guidelines. LAWPRO refers to the professional liability policy and practicePRO's social engineering toolkit. PIPEDA refers to the federal privacy law's safeguarding, breach reporting and record keeping duties as explained by the Office of the Privacy Commissioner of Canada. Insurance refers to controls cyber insurers commonly ask about on applications and renewals. None of these sources prescribes a single technical standard, so treat the list as a practical way to meet them, not as wording taken from them.
The four obligations in brief
The LSO commentary to rule 3.1-2 says lawyers should understand the benefits and risks of relevant technology, recognizing the duty to protect confidential information. The Technology Guideline adds that lawyers should use firewalls and security software, use encryption, take appropriate measures when using cloud services, make sure staff understand confidentiality, adopt adequate security measures, and keep backup and disaster recovery plans that include routine restore checks.
LAWPRO's policy covers social engineering fraud to a sublimit of $250,000 per claim and in the aggregate. According to LAWPRO, firms that take the mandatory steps set out in its social engineering toolkit can extend that to $1 million per claim and $2 million in the aggregate. The steps are written retainer instructions for moving funds, advising clients not to expect changes, confirming any change by phone at a previously confirmed number or in a meeting, and keeping updated instructions in writing. LAWPRO has also said that cyber losses not connected with providing legal services, such as business interruption or damage to equipment, fall outside its policy.
PIPEDA, as the Office of the Privacy Commissioner explains it, requires organizations to report to the Commissioner any breach of security safeguards that poses a real risk of significant harm, notify affected individuals, and keep records of all breaches whether or not they are reportable.
Cyber insurers vary, but applications consistently ask about multi-factor authentication, backups, endpoint protection, email security, patching and incident response. A gap in any of these can raise the premium, narrow coverage or stop a quote.
Identity and access
1. Multi-factor authentication on every email account, including shared mailboxes and admins. Supports LSO confidentiality duties and is a standard insurance question. 2. Phishing resistant MFA such as an authenticator app with number matching or security keys for partners, bookkeepers and anyone with trust account access. Supports LSO security measures and LAWPRO fraud prevention. 3. Separate admin accounts that are not used for daily email or browsing. Supports LSO security measures and Insurance. 4. A password manager for every user, with unique passwords for banking, practice management and court filing portals. Supports LSO security measures. 5. Same day account removal when anyone leaves, recorded in a checklist. Supports LSO confidentiality duties and PIPEDA safeguarding.
Email and payments
6. SPF, DKIM and DMARC configured on the firm's domain, with DMARC moving toward enforcement. Supports LAWPRO fraud prevention and Insurance. 7. External sender warnings and impersonation protection for partner names. Supports LAWPRO fraud prevention. 8. Alerts on new inbox forwarding rules and sign ins from unusual locations. Supports LSO security measures and PIPEDA breach detection. 9. Written retainer instructions for the receipt, release and transfer of funds, telling clients not to expect changes. Directly meets LAWPRO's mandatory social engineering steps. 10. Every change to payment instructions confirmed by phone at a number already on file or in a meeting, and recorded in writing. Directly meets LAWPRO's mandatory social engineering steps. 11. Encrypted email or a secure client portal for sensitive documents, with the client's agreement to the method recorded. Supports the Technology Guideline's confidentiality section.
Devices
12. Full disk encryption on every laptop, desktop and phone that holds firm data. Supports LSO security measures and PIPEDA safeguarding. 13. Endpoint detection and response on every computer, monitored by someone who will act on an alert. Supports LSO security measures and is a common insurance requirement. 14. Automatic operating system and application patching with a monthly check that it worked. Supports LSO security measures and Insurance. 15. Mobile device management so a lost phone or laptop can be locked and wiped. Supports PIPEDA safeguarding and the Technology Guideline's note on stolen hardware. 16. A written rule on personal devices: either enrolled in management or kept away from client data. Supports LSO confidentiality duties.
Data and backups
17. Client files stored in a document management system or controlled cloud storage, not on local drives or personal accounts. Supports LSO confidentiality duties and the Technology Guideline's document management section. 18. Access limited by matter where conflicts or sensitivity require it. Supports LSO confidentiality duties. 19. Backups of email, documents and accounting data kept separate from the main network and protected from deletion. Supports the Technology Guideline's backup section and Insurance. 20. A restore test at least quarterly, with the result recorded. Directly supports the Technology Guideline's call for routine checks that data can be restored. 21. A retention schedule for closed files so data is not kept longer than needed. Supports PIPEDA safeguarding and the Technology Guideline's section on obsolescence.
Cloud and Microsoft 365
22. Conditional access that blocks legacy authentication and sign ins from unmanaged devices or unexpected countries. Supports LSO security measures and Insurance. 23. Audit logging turned on and retained long enough to investigate an incident. Supports PIPEDA breach assessment and record keeping. 24. External sharing restricted to named people with expiry dates. Supports the Technology Guideline's cloud confidentiality measures. 25. Microsoft Secure Score or equivalent reviewed quarterly with changes recorded. Supports documentation of LSO technology competence.
Vendors
26. A list of every vendor that stores or processes client information, including practice management, e-signature and transcription tools. Supports LSO confidentiality duties and PIPEDA accountability. 27. A security review before signing a new vendor, covering data location, encryption, MFA and breach notice terms. Supports the Technology Guideline's cloud measures. 28. Written confirmation of who the firm's IT provider is, what they manage and how quickly they respond. Supports the Technology Guideline's point about access to someone who understands the technology.
Incident response
29. A written incident response plan naming who calls LAWPRO, the cyber insurer, the bank, affected clients and the IT provider. Supports PIPEDA reporting and Insurance. 30. A breach log kept for every incident, including ones that are not reportable. Directly supports PIPEDA's record keeping duty. 31. A process for assessing real risk of significant harm and reporting to the Privacy Commissioner when required. Directly supports PIPEDA's breach reporting duty. 32. A tabletop exercise at least yearly covering wire fraud and ransomware. Supports LSO technology competence and Insurance.
Training
33. Security awareness training at onboarding and at least yearly for lawyers, clerks and assistants. Supports the Technology Guideline's point that staff must understand confidentiality. 34. Simulated phishing with follow up coaching. Supports LAWPRO fraud prevention and Insurance. 35. A short annual briefing for partners on the firm's risks, controls and insurance limits. Supports LSO technology competence at the decision making level.
The plain checklist
Print this section or copy it into your compliance file and tick each item as it is confirmed.
- MFA on every account, including shared and admin accounts
- Phishing resistant MFA for anyone with trust account access
- Separate admin accounts
- Password manager for every user
- Same day account removal on departure
- SPF, DKIM and DMARC configured and monitored
- External sender and impersonation warnings
- Alerts on forwarding rules and unusual sign ins
- Retainer letters include LAWPRO payment instruction wording
- Payment changes confirmed by phone at a known number and recorded
- Secure portal or encrypted email for sensitive documents
- Full disk encryption on all devices
- Monitored endpoint detection and response
- Automatic patching, checked monthly
- Mobile device management with remote wipe
- Written personal device rule
- Client files in managed storage only
- Matter level access where needed
- Offsite, deletion protected backups
- Quarterly restore test recorded
- Closed file retention schedule
- Conditional access and legacy authentication blocked
- Audit logs on and retained
- External sharing restricted and time limited
- Secure Score reviewed quarterly
- Vendor inventory
- Vendor security review before signing
- Written IT provider scope and response times
- Written incident response plan
- Breach log for every incident
- Real risk of significant harm assessment process
- Yearly tabletop exercise
- Onboarding and annual security training
- Simulated phishing
- Annual partner briefing
Where to start
If the list feels long, start with the controls that stop the losses Ontario firms see most: MFA everywhere, email authentication on the domain, the LAWPRO payment verification steps, and tested backups. Those four close most of the doors that wire fraud and ransomware come through. Our guide to LSO technology competence explains how to document all of this so the firm can show its work, and our cyber insurance readiness checklist goes deeper on the application questions.
How IT Rapid Support helps
IT Rapid Support focuses on legal technology, with a 24/7 helpdesk and an office in Vaughan serving law firms across the GTA. We implement and monitor the controls above and keep the evidence ready for insurers and reviewers. See our legal industry page, our guide to IT for law firms in Mississauga, our virtual CISO service for firms that need security governance, and our guides to stopping phishing attacks and SPF, DKIM and DMARC.
Frequently asked questions
Does PIPEDA apply to Ontario law firms?
PIPEDA applies to private sector organizations that collect, use or disclose personal information in the course of commercial activity, which generally includes a law firm's handling of client information. Firms should confirm how it applies to their practice, but most treat its safeguarding, breach reporting and record keeping duties as applying to them.
What does LAWPRO cover if a firm is tricked into wiring trust funds?
LAWPRO covers social engineering fraud to a sublimit of $250,000 per claim and in the aggregate. Firms that follow LAWPRO's mandatory steps on written retainer instructions and verifying changes by phone or meeting can extend that to $1 million per claim and $2 million in the aggregate.
Is LAWPRO coverage enough on its own for cyber incidents?
LAWPRO has said that cyber losses not connected with providing legal services, such as business interruption and damage to equipment or software, are not covered by its policy. Many firms carry separate cyber insurance for those risks.
Which controls do cyber insurers ask about most?
Multi-factor authentication, backups kept separate from the network, endpoint detection and response, email security, patching and a written incident response plan come up on almost every application.
How often should a law firm review this checklist?
At least yearly and before every cyber insurance renewal, plus after any incident, a change of IT provider or the adoption of a major new system.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorRelated Resources

IT for Law Firms in Mississauga: What the LSO Expects
IT for Mississauga law firms: LSO technology expectations, document management, wire fraud on closings, MFA and secure remote work, with a checklist.
Read more: IT for Law Firms in Mississauga: What the LSO Expects
Mississauga Small Business IT: Streetsville and Port Credit
Small business IT for Streetsville and Port Credit: POS, Microsoft 365, backups, Wi-Fi and when to move from informal help to managed IT in Mississauga.
Read more: Mississauga Small Business IT: Streetsville and Port Credit
Cottage Cyber Security in Muskoka: Wealth Makes a Target
Cyber security for Muskoka cottage owners and the executives who work from the lake: Starlink and Wi-Fi hygiene, cameras and smart locks, wire fraud on purchases and renovations, impersonation scams, and a 10-point checklist.
Read more: Cottage Cyber Security in Muskoka: Wealth Makes a TargetNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch