Back to all resources
guide

LSO Technology Competence: What Ontario Law Firms Need

September 23, 2026
9 min read
IT Rapid Support Team
LSO Technology Competence: What Ontario Law Firms Need

Every Ontario lawyer has had a duty of technological competence written into the Rules of Professional Conduct since the Law Society of Ontario amended the commentary to rule 3.1-2 in June 2022. Most firms know the duty exists. Far fewer can say what it requires of their own office, or show a reviewer, an insurer or a client that they meet it. This guide sets out what the rule and the LSO's guidance actually say, what reasonable technology competence looks like in a working firm, a checklist sized to solo, small and mid-sized practices, the gaps we see most often, and how to document the whole thing so it stands up later.

What the rule and commentary actually say

Rule 3.1-2 of the Rules of Professional Conduct requires a lawyer to perform legal services to the standard of a competent lawyer. The technology duty lives in the commentary to that rule. Commentary 4A says that to maintain the required level of competence, a lawyer should develop an understanding of, and ability to use, technology relevant to the nature and area of the lawyer's practice and responsibilities. It adds that a lawyer should understand the benefits and risks associated with relevant technology, recognizing the duty to protect confidential information set out in section 3.3, the confidentiality section of the Rules.

Commentary 4B explains how far the duty reaches. The required level of technological competence depends on whether using or understanding technology is necessary to the nature and area of the practice, and whether the technology is reasonably available to the lawyer. In deciding what is reasonably available, the commentary lists three factors: the practice areas of the lawyer or firm, the geographic locations of the practice, and the requirements of clients.

Two things follow from that wording. First, the standard is not fixed. A real estate practice that moves closing funds by wire and registers electronically has a higher bar than a solicitor who drafts wills on paper, and a firm whose institutional clients demand encrypted file sharing has to be able to provide it. Second, the duty is tied directly to confidentiality. The LSO did not frame technology competence as a productivity matter; it framed it as part of protecting what clients tell you.

Where the Technology Guideline fits

The LSO's Practice Management Guidelines include a Technology Guideline that fills in the practical detail. It opens by noting that some technology is mandatory, such as electronic registration of real property and the Law Society's own electronic filings. It then invites lawyers to consider document management, calendaring, conflict checking databases and legal accounting systems, and it cites rules 3.1-1 and 3.1-2 as the reason: these systems help lawyers serve clients on time and at reasonable cost.

Several parts of the Guideline speak directly to security. Its competent use section says lawyers should have a reasonable understanding of the technologies used in their practice, or access to someone who has that understanding. Its confidentiality section says lawyers using electronic communication should understand how to minimize the risk of disclosure or interception, use firewalls and security software, use and advise clients to use encryption, take appropriate measures when using cloud services, and make sure non-lawyer staff understand how to protect client confidentiality. Its security section lists threats such as unauthorized copying, viruses, hackers and stolen hardware, and says lawyers should adopt adequate measures to protect against them. Its backup section says lawyers should have backup and disaster recovery plans, including regular backups, secure offsite storage and routine checks that data can actually be restored.

The Guideline carries its own disclaimer: departing from it does not by itself mean a lawyer failed to provide quality service, and following it does not guarantee quality service. It is a framework, not a certification. In practice it is also the most specific statement the LSO has published of what it expects a firm's technology to do, which makes it the natural benchmark for any review.

What reasonable competence means in practice

The phrase that matters most in the Guideline is the one about having access to someone who understands the technology. The LSO does not expect every lawyer to configure a firewall. It does expect the lawyer to know what the firm relies on, what could go wrong, and who is accountable for each piece. Put simply, reasonable technology competence for an Ontario firm usually comes down to five things.

You know your systems. There is a current list of every system that holds client information: email, document storage, practice management, accounting, backups, phones, and any personal devices that touch firm data.

You understand the main risks. Lawyers and staff can recognize a phishing email, know that trust account instructions sent by email can be forged, and know what to do when something looks wrong.

You have controls that match the practice. The more the firm moves money, stores sensitive files or works remotely, the stronger the controls need to be. A firm doing real estate closings needs payment verification procedures that a criminal appeals practice may never use.

You can recover. Backups exist, are kept away from the main network, and have actually been restored in a test.

You can show it. There is a written record of what is in place, who looks after it, and when it was last reviewed.

Checklist by firm size

The commentary ties the standard to the nature of the practice, so the checklist below scales with the firm. Each tier includes everything in the tier before it.

Solo practitioners

  • Multi-factor authentication on email, practice management, online banking and cloud storage.
  • A password manager in place of reused or written passwords.
  • Full disk encryption and automatic updates on every laptop and phone that holds client information.
  • Automatic backups of client files to a separate location, restored in a test at least twice a year.
  • A trust account verification habit: any change to payment instructions is confirmed by phone at a number already on file.
  • A one page note listing your systems, who supports them, and what you would do if your email were compromised.

Firms of 2 to 10 lawyers

  • Everything in the solo tier, enforced centrally rather than left to each person.
  • Business grade Microsoft 365 or Google Workspace with admin controls, not personal accounts.
  • A document management system or structured matter folders with access limited by matter where needed.
  • SPF, DKIM and DMARC configured on the firm's email domain so it is harder to impersonate.
  • Firm managed devices that can be locked or wiped remotely, and a same day process for removing departing staff.
  • Security awareness training at onboarding and at least yearly, with simulated phishing.
  • A written incident response plan naming who calls LAWPRO, the cyber insurer, affected clients and your IT provider.

Firms of 10 or more lawyers

  • Everything in the smaller tiers, plus centralized monitoring of sign ins, mailbox rules and endpoint alerts.
  • Endpoint detection and response on every device rather than basic antivirus alone.
  • Conditional access rules that block sign ins from unmanaged devices or unexpected countries.
  • A formal vendor review for any provider that stores or processes client information.
  • An annual risk assessment and a tabletop exercise that walks partners through a ransomware or wire fraud scenario.
  • A named person or committee accountable for technology risk, with a governance role such as a virtual CISO where the firm has no in-house security lead.

The gaps we see most often

The same weaknesses come up in firm after firm, regardless of size.

Multi-factor authentication is on for some accounts but not all. The admin account, the old shared reception mailbox or the remote access tool is often the one left out, and it is usually the one an attacker finds.

Backups exist but have never been restored. A backup that has never been tested is a hope, not a plan, and the Technology Guideline specifically calls for routine checks that data can be restored.

Payment verification is informal. LAWPRO's social engineering coverage turns partly on whether the firm follows specific written steps, and many firms have never updated their retainer letters to meet them.

Nobody owns the technology. A part time contractor or a technically minded partner looks after things as time allows, with no written record of what is in place.

Personal devices and personal email creep in. Client documents end up in personal Gmail, on home computers or in consumer file sharing apps outside the firm's control.

How to document compliance

Neither the Rules nor the Technology Guideline prescribe a compliance form, which means the firm has to create its own record. A short, current document is far more useful than a long one that nobody updates. We suggest a technology compliance file with five parts.

An inventory of systems that hold client information, with the vendor, who has admin access and where the data is stored.

A controls summary that lists what is in place against each area in the checklist above, with the date it was last checked.

Policies that staff have actually acknowledged: acceptable use, remote work, password and MFA, and payment verification.

Evidence: backup restore test results, training completion records, and screenshots or reports showing MFA and encryption are enforced.

A review log showing that a partner looked at the file at least once a year and what was changed as a result.

That file also answers most of the questions a cyber insurance application or a sophisticated client security questionnaire will ask. Our cyber insurance readiness checklist covers the controls insurers look for most often, and our companion cybersecurity checklist for Ontario law firms maps each control to the LSO, LAWPRO and PIPEDA obligation it supports.

How IT Rapid Support helps

IT Rapid Support focuses on legal technology, with a 24/7 helpdesk and an office in Vaughan serving firms across the GTA. We build and maintain the controls in this guide, keep the evidence current, and give firms a written record they can hand to an insurer or a reviewer. Our legal industry page explains how that engagement works, our guide to IT for law firms in Mississauga covers local considerations, and our virtual CISO service provides governance for firms that need a named security lead without a full time hire. Email security is where most law firm incidents start, and our guides to stopping phishing attacks and SPF, DKIM and DMARC explain the fixes.

Frequently asked questions

Does the LSO require law firms to meet a specific cybersecurity standard?

No specific standard is named. Commentary 4A and 4B to rule 3.1-2 require technology competence relevant to the practice, and the LSO's Technology Guideline describes security measures, encryption, backups and confidentiality steps lawyers should consider. Firms are expected to judge what is reasonable for their own practice areas, locations and clients.

When did the technology competence duty come into force in Ontario?

The commentary on technological competence in rule 3.1-2 is marked as amended in June 2022 in the Law Society of Ontario's published Rules of Professional Conduct.

Can a lawyer rely on an IT provider to meet the duty?

Partly. The Technology Guideline says lawyers should have a reasonable understanding of the technology they use or access to someone who has that understanding. The lawyer remains responsible for the practice, so the firm should know what the provider does and keep a written record of it.

Is a solo practitioner held to the same standard as a large firm?

The duty applies to every lawyer, but the commentary ties the required level to the practice area, location and client requirements. A solo practice still needs the basics such as MFA, encryption, backups and payment verification, while a larger firm will usually need central monitoring and formal governance as well.

How often should a firm review its technology compliance?

At least once a year, and whenever the firm adds a major system, changes IT providers, starts moving client funds electronically or has an incident. Recording each review in a simple log is the easiest way to show the duty is being taken seriously.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
Cybersecurity Checklist for Ontario Law Firms
guide
September 23, 2026

Cybersecurity Checklist for Ontario Law Firms

35 cybersecurity controls for Ontario law firms, each tied to LSO, LAWPRO, PIPEDA or cyber insurance requirements, plus a printable checklist.

Read more: Cybersecurity Checklist for Ontario Law Firms
IT for Law Firms in Mississauga: What the LSO Expects
guide
September 5, 2026

IT for Law Firms in Mississauga: What the LSO Expects

IT for Mississauga law firms: LSO technology expectations, document management, wire fraud on closings, MFA and secure remote work, with a checklist.

Read more: IT for Law Firms in Mississauga: What the LSO Expects
Mississauga Small Business IT: Streetsville and Port Credit
guide
September 5, 2026

Mississauga Small Business IT: Streetsville and Port Credit

Small business IT for Streetsville and Port Credit: POS, Microsoft 365, backups, Wi-Fi and when to move from informal help to managed IT in Mississauga.

Read more: Mississauga Small Business IT: Streetsville and Port Credit

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch

We use cookies for analytics and ads. Cookie Policy · Privacy