Law Society of Ontario Cybersecurity Requirements: A Practical Checklist for Law Firms

If you run a law firm in Ontario, you may have heard some version of this question:

“Are we compliant with the Law Society of Ontario cybersecurity requirements?”

It sounds like a simple question.

It isn’t.

The Law Society of Ontario does not publish one technical cybersecurity standard that says every law firm must buy a certain firewall, use a certain antivirus product or follow a 50-point security checklist.

Instead, the Rules of Professional Conduct create professional duties. The Law Society then provides technology guidelines, practice-management guidance and cybersecurity resources that help lawyers understand how those duties apply when technology is involved.

For most law firms, two duties sit at the centre of the issue:

Be technologically competent.

And:

Protect confidential client information.

That sounds simple too.

But once almost every client file, email, document and financial transaction is digital, those two duties touch almost every part of the firm’s IT system.

Here is what that means in practical terms.

1. Understand the Technology Your Firm Uses

LSO obligation

Rule 3.1-2 deals with lawyer competence. The commentary specifically says lawyers should develop an understanding of technology relevant to their practice and understand its benefits and risks, including the duty to protect confidential information.

This does not mean every lawyer needs to become an IT expert.

It does mean technology can’t simply be ignored because an outside IT company manages it.

Practical checklist

Your firm should know:

  • What systems contain client information
  • Where that information is stored
  • Who has access to it
  • How email is protected
  • How remote access works
  • How files are backed up
  • How accounts are protected
  • What happens if systems go offline
  • Who is responsible for cybersecurity

If nobody at the firm can answer these questions without calling the IT company, that’s a gap.

☐ The firm understands its key technology systems and the risks attached to them.

2. Protect Confidential Client Information

This is probably the biggest connection between cybersecurity and the Rules of Professional Conduct.

Rule 3.3-1 requires lawyers to hold information concerning the business and affairs of clients in strict confidence. The Law Society explains that this duty applies broadly to information obtained through the professional relationship and continues beyond the end of that relationship.

Thirty years ago, protecting confidentiality might have meant locking a filing cabinet.

Today it also means protecting Microsoft 365, laptops, phones, cloud applications, backups, practice-management software and remote access.

Practical checklist

☐ Client information is only available to people who need access.

☐ Departed employees have their access removed immediately.

☐ Firm laptops and mobile devices are protected.

☐ Sensitive data is encrypted where appropriate.

☐ Client information isn’t being stored in random personal email accounts, USB keys or unmanaged cloud services.

The Law Society’s own technology resources discuss password protection, encryption and network security as ways of maintaining confidentiality and security of electronic files.

3. Use Multi-Factor Authentication

Here is an important distinction.

The Rules of Professional Conduct do not say:

“Every Ontario lawyer must use Microsoft Authenticator.”

That’s not how the rules are written.

But the Law Society’s Technology Resource Centre specifically includes two-factor authentication among its security and data-protection resources.

From an IT security standpoint, MFA is now one of the basic controls we would expect to see protecting systems that contain confidential client information.

Practical checklist

MFA should protect, where supported:

☐ Microsoft 365 or Google Workspace

☐ Practice-management software

☐ Remote access and VPN

☐ Administrator accounts

☐ Accounting applications

☐ Cloud storage

☐ Online banking and financial systems

A law firm that still protects its email with only a username and password is taking an avoidable risk.

4. Have Strong Password Controls

The Law Society’s technology resources specifically include password management, and its Practice Review guidance refers to regular review and updating of passwords and other security features.

But password security should not mean forcing everyone to remember dozens of complicated passwords.

That usually creates a different problem.

People start reusing passwords.

Or writing them down.

Practical checklist

☐ Each person has their own account.

☐ Passwords aren’t shared between staff.

☐ Important accounts use unique passwords.

☐ A business password manager is available.

☐ Administrator passwords are separately controlled.

☐ MFA protects important accounts even if a password gets stolen.

5. Encrypt Sensitive Data

The Law Society’s Technology Guideline discusses using encryption to help maintain confidentiality and privilege. Its Technology Resource Centre also includes encryption within its security guidance.

For a modern law firm, encryption matters in several places.

Practical checklist

☐ Firm laptops use full-disk encryption.

☐ Mobile devices accessing client information are secured.

☐ Sensitive information is encrypted when appropriate.

☐ The firm has considered security when exchanging confidential documents electronically.

This is especially important for lawyers working from home, court, client sites or while travelling.

The Law Society’s remote-work guidance specifically raises encryption of electronic files as a consideration where computers may be accessible to others.

6. Secure Every Computer and Server

Having a laptop password isn’t enough.

The Law Society’s Practice Review guidance references maintaining and regularly reviewing passwords, firewalls, antivirus software and other security features.

For a law firm today, we would translate that into a managed endpoint security program.

Practical checklist

☐ Every supported computer has managed endpoint protection.

☐ Servers are protected.

☐ Security alerts are monitored.

☐ Computers aren’t running unsupported operating systems.

☐ Security software can’t simply be disabled by normal users.

☐ Someone is responsible for responding when a threat is detected.

Buying security software is the easy part.

Knowing whether it is installed, running and being monitored is more important.

7. Keep Systems Patched and Current

Old software creates risk.

That includes Windows, macOS, browsers, firewalls, VPN software, servers and applications.

The Law Society’s Technology Guideline specifically tells lawyers to address concerns relating to security and technological obsolescence.

Practical checklist

☐ Operating-system updates are centrally managed.

☐ Critical security updates are installed promptly.

☐ Firewalls and network devices receive firmware updates.

☐ Unsupported computers and servers have a replacement plan.

☐ Old accounts and unused systems are removed.

Nobody should be depending on each employee to remember to run Windows Update.

8. Back Up the Firm — and Test the Backups

The Law Society’s practice resources discuss backup systems as part of reliable and secure access to data, while its practice-management materials also address contingency planning and maintaining backup copies of plans where appropriate.

For a law firm, backups aren’t only about recovering a file someone deleted.

They’re part of ransomware recovery and business continuity.

Practical checklist

☐ Servers are backed up automatically.

☐ Critical workstations are backed up where needed.

☐ Microsoft 365 or other cloud data has been reviewed for backup requirements.

☐ Backup copies are separated from normal production systems.

☐ Backup failures create alerts.

☐ Restore tests are performed regularly.

That last one matters.

A backup report saying “successful” is not the same thing as proving the firm can restore its data.

Ask your IT provider:

When did you last test an actual restore?

9. Protect Remote and Hybrid Work

Many Toronto and GTA law firms now have lawyers and staff working between the office, home, court and client locations.

The Law Society has specific resources addressing home offices, remote work, virtual meetings, cloud computing and security risks associated with those technologies.

Practical checklist

☐ Remote access uses secure authentication.

☐ MFA is required.

☐ Firm computers are used instead of shared family computers where possible.

☐ Devices are encrypted.

☐ Public Wi-Fi use is controlled.

☐ Lost devices can be locked or wiped where appropriate.

☐ Client conversations can’t easily be overheard by other people.

Remote work doesn’t remove the lawyer’s confidentiality obligation.

It just changes where the risk exists.

10. Protect Email Against Phishing and Fraud

Email is one of the main ways attackers target law firms.

The Law Society maintains cybersecurity and fraud resources dealing with the common cyber threats facing lawyers and strategies for managing those risks.

A lawyer can have excellent legal judgment and still click a convincing fake Microsoft login page.

That’s why the firm needs both technology and training.

Practical checklist

☐ Email filtering checks malicious links and attachments.

☐ Impersonation and phishing protection is enabled.

☐ Staff receive cybersecurity awareness training.

☐ Phishing testing is performed periodically.

☐ Employees know how to report suspicious messages.

☐ There is a process for verifying unusual financial requests.

Training shouldn’t be about trying to trick employees.

It should teach them what a real attack looks like before they see one.

11. Put Extra Protection Around Trust Transactions

For firms handling trust funds, technology security and financial controls meet in the same place.

Law Society By-Law 9 includes specific record-keeping requirements for electronic trust transfers. The Law Society requires the use and retention of records such as Form 9A for electronic trust transfers, with procedures governing how those transfers are authorized and documented.

Cybersecurity does not replace those accounting controls.

It supports them.

Practical checklist

☐ Banking accounts use MFA.

☐ Wire instructions are independently verified.

☐ Changes to payment information aren’t accepted based only on email.

☐ Banking access is limited to authorized people.

☐ Electronic trust transfer procedures are documented.

☐ Trust transaction records required by the LSO are retained.

A compromised email account should never be enough by itself to redirect client money.

12. Have a Plan for a Cyber Incident

What happens if the firm gets ransomware at 9:00 tomorrow morning?

Who calls IT?

Who contacts management?

Who contacts the insurer?

How does the firm work if Microsoft 365 isn’t available?

How will lawyers access court deadlines and client information?

The Law Society’s technology guidance tells lawyers to address disaster management, while its broader practice resources also address contingency planning and protection of sensitive information contained within those plans.

Practical checklist

☐ The firm has a written incident response plan.

☐ Emergency contacts are documented.

☐ Cyber-insurance contact information is available.

☐ The plan can be accessed if the firm’s network is offline.

☐ Responsibilities are assigned before an incident happens.

☐ The plan is reviewed periodically.

You do not want to invent this process while ransomware is spreading.

13. Ask for Proof

This is where managing partners should push their IT provider a little harder.

“Everything is protected” isn’t enough.

A firm should be able to see what is actually happening.

Ask your IT provider for evidence of:

☐ MFA coverage

☐ Endpoint security coverage

☐ Patch status

☐ Backup status

☐ Recent restore testing

☐ Security awareness training

☐ Administrator accounts

☐ Encryption status

☐ Firewall and network security

☐ Security incidents and alerts

☐ Outstanding security risks

The Law Society’s Practice Review guidance itself points lawyers toward reviewing passwords, firewalls, antivirus software and other security safeguards.

The firm should be doing the same thing internally.

So, Is Your Law Firm “LSO Cybersecurity Compliant”?

We would be careful using that phrase.

There is no single Law Society of Ontario cybersecurity certification that an IT company can install and then declare complete. The LSO’s framework is better understood as professional obligations supported by technology and practice-management guidance.

The better question is:

Can the firm show that it is taking reasonable steps to understand its technology, protect confidential client information and manage the risks created by the systems it uses?

That is much more useful.

And it’s something a firm can actually test.

A Simple Law Firm Cybersecurity Scorecard

If you want a fast check, start here.

Your firm should be able to say yes to these questions:

  • ☐ MFA protects important accounts
  • ☐ Every computer has managed security
  • ☐ Security alerts are monitored
  • ☐ Computers and servers are patched
  • ☐ Firm laptops are encrypted
  • ☐ Passwords are properly managed
  • ☐ Email has phishing protection
  • ☐ Staff receive security training
  • ☐ Backups run automatically
  • ☐ Backup restores are tested
  • ☐ Microsoft 365 data has a backup strategy
  • ☐ Administrator access is limited
  • ☐ Remote access is secured
  • ☐ Financial transfers have verification controls
  • ☐ A cyber incident response plan exists
  • ☐ Management receives proof that these controls are working

If several answers are “no” or “I don’t know,” that tells you where to start.

Cybersecurity for Ontario Law Firms Should Be Measurable

Law firms in Toronto, Vaughan and across Ontario hold information that clients expect them to protect.

The Law Society’s rules place duties on the lawyer.

Your IT provider’s job is to help turn those duties into working technical controls.

At Atomic Guardian, we work with law firms to build and manage the security controls behind those obligations. That includes identity protection, endpoint security, email security, backups, encryption, cybersecurity training, monitoring and documented reporting.

More importantly, the firm should be able to see the evidence.

Not just hear:

“Your IT is fine.”

If you’re unsure where your firm stands, start with the checklist above.

For every box you can’t confidently check, ask one more question:

Who is responsible for this, and can they prove it’s being done?

That question alone can uncover a lot.

This article provides general technology and risk-management information. It is not legal advice. Ontario lawyers should consult the Law Society of Ontario’s current Rules, By-Laws and practice resources when determining their professional obligations.

Related industry guidance

Put this guidance into practice

Connect these recommendations to a complete technology and risk-management program. Explore Atomic Guardian’s law firm IT support and cybersecurity services, including Microsoft 365, legal applications, cybersecurity, vendor coordination, backups, and strategic planning.

For support putting these requirements into practice, explore our cybersecurity services for professional firms.