Cybersecurity Checklist for Vaughan Law Firms: 20 Controls Your IT Provider Should Be Managing

Most law firms have an IT company.

That doesn’t necessarily mean they have good cybersecurity.

There is a big difference between an IT provider that fixes computers when something breaks and one that actively manages the firm’s cyber risk.

For a Vaughan law firm, that difference matters.

Lawyers have a professional duty to protect confidential client information. The Law Society of Ontario also says lawyers need to understand the benefits and risks of technology relevant to their practice, including risks connected to protecting confidential information.

LAWPRO has also documented what can happen when security fails.

In one Ontario case, attackers gained access to a law firm’s network. The firm eventually had to disconnect from the internet, format computers, rebuild its server and restore its data. Operations were badly affected for about two weeks, and the firm wasn’t fully functional again for roughly four weeks.

So how do you know whether your IT provider is doing enough?

Start with these 20 controls.

The Cybersecurity Checklist for Law Firms:


1. Multi-Factor Authentication

Passwords alone aren’t enough anymore.

Your IT provider should require multi-factor authentication, or MFA, on important business systems.

That normally includes:

  • Microsoft 365
  • Practice management software
  • Remote access
  • VPN connections
  • Administrator accounts
  • Accounting systems
  • Cloud applications

Where possible, stronger phishing-resistant authentication should be used instead of relying only on text messages. The Canadian Centre for Cyber Security now specifically recommends phishing-resistant MFA, especially for accounts with administrative privileges.

Ask your IT provider: What percentage of our accounts are protected by MFA?

They should know.

2. Password Management

A lawyer shouldn’t have the same password for Microsoft 365, Clio, online banking and LinkedIn.

And passwords should not be stored in notebooks, spreadsheets or sticky notes.

Your IT provider should provide or support a proper business password manager.

Each employee should have their own account and unique passwords.

Your provider should be managing:

  • Password policies
  • Business password management
  • Shared credentials
  • Administrator passwords
  • Account recovery procedures

This gets even more important when staff leave the firm.

3. User Account Management

Every person who joins, changes roles or leaves your firm creates an access-control issue.

When a new law clerk starts, what do they get access to?

When someone moves departments, is old access removed?

When an employee leaves, how quickly are their accounts disabled?

Your IT provider should have a documented onboarding and offboarding process.

The Canadian Centre for Cyber Security recommends regularly reviewing user privileges, removing users who have left and changing access when employees no longer require certain systems or data.

Ask: Can you show us a current list of every active user account?

4. Administrator Account Protection

This one gets overlooked.

Normal employees should not have administrator access just because it’s convenient.

Even partners usually don’t need it.

Administrative accounts can make major changes to systems. If one is compromised, the attacker may gain much greater control over the network.

Your IT provider should limit administrator access, separate administrator accounts from normal user accounts and monitor them closely.

After the Ontario law firm attack documented by LAWPRO, the firm reset administrator passwords, reviewed privileged accounts, removed unnecessary accounts and began monitoring administrator activity.

5. Endpoint Detection and Response

Every computer should have modern security software.

But we’re not talking about basic antivirus that checks for known viruses once a day.

Modern endpoint detection and response, usually called EDR, watches computers for suspicious behaviour.

That may include:

  • Ransomware activity
  • Malicious scripts
  • Credential theft
  • Suspicious applications
  • Unusual changes to files
  • Malware attempting to communicate outside the network

The Canadian Centre for Cyber Security includes endpoint detection and response as part of its current cybersecurity hygiene guidance.

Your IT provider should know if every workstation and server is protected.

6. 24/7 Security Monitoring

Installing EDR is only half the job.

Who watches the alerts at 2:17 Saturday morning?

A good cybersecurity program should include monitoring and a process for responding to serious security events.

This may be provided through an MDR service — Managed Detection and Response — or a security operations centre.

LAWPRO’s Ontario breach case specifically identified continuous monitoring of endpoints, servers, cloud services and network components as one of the improvements made after the attack.

Ask: If ransomware starts tonight, who receives the alert?

If the answer is “we’ll see it Monday,” that’s a problem.

7. Security Patch Management

Software has vulnerabilities.

Vendors fix them by releasing updates.

Someone needs to make sure those updates actually get installed.

Your IT provider should manage security patches across:

  • Windows
  • macOS
  • Servers
  • Browsers
  • Microsoft Office
  • Firewalls
  • VPN software
  • Common business applications

The Canadian Centre for Cyber Security recommends automatic updates where appropriate and prompt patching of operating systems, applications, firmware and hardware.

Patching should be managed.

It shouldn’t depend on lawyers clicking “update later” for three months.

8. Unsupported Hardware and Software

Old technology eventually stops receiving security updates.

Windows versions reach end of support.

Firewalls age out.

Servers get old.

Applications stop receiving patches.

Your IT provider should maintain an inventory and identify equipment that is approaching end-of-life.

The Canadian Centre for Cyber Security specifically recommends managing device lifecycles because unsupported devices may remain vulnerable.

A replacement should be planned before the old system becomes a security problem.

9. Firewall Management

Your firewall sits between your office network and the outside world.

It should do more than simply provide internet access.

Your provider should be managing:

  • Security updates
  • Firewall rules
  • VPN access
  • Threat prevention
  • Intrusion detection
  • Logging
  • Remote administration
  • Configuration backups

LAWPRO’s breach case specifically recommended keeping firewalls and VPN applications updated with current security patches.

Installing a firewall five years ago and never touching it again isn’t firewall management.

10. Network Security and Segmentation

Not every device should automatically be able to communicate with everything else.

Guest Wi-Fi shouldn’t have the same access as firm computers.

Printers shouldn’t necessarily have access to servers.

Older devices may need to be isolated.

The Canadian Centre for Cyber Security recommends network segmentation to restrict traffic from reaching sensitive or protected areas.

For larger firms, segmentation becomes even more useful.

If one device gets compromised, the goal is to make it harder for an attacker to move through the rest of the network.

11. DNS and Web Protection

People click bad links.

It happens.

Protective DNS and web filtering can help stop a computer from connecting to known malicious websites, phishing pages or malware infrastructure.

The Canadian Centre for Cyber Security specifically recommends protective DNS as a way to prevent users from accidentally visiting malicious domains.

This gives your firm another layer of protection when an email filter or employee misses something.

12. Email Security

Law firms live in email.

Attackers know that.

A fake DocuSign request, Microsoft login page, invoice, court document or message supposedly from another lawyer can look very convincing.

Your email security should inspect:

  • Links
  • Attachments
  • Impersonation attempts
  • Spoofed senders
  • Malware
  • Phishing messages

Your IT provider should also properly configure the firm’s email domain using controls such as SPF, DKIM and DMARC to make email impersonation harder.

Email security should protect users before the message reaches their inbox.

13. Security Awareness Training

Technology cannot stop every attack.

People still matter.

Employees should receive short, regular cybersecurity training covering things they actually see at a law firm.

That includes:

  • Fake Microsoft login pages
  • Wire fraud
  • Password theft
  • Malicious attachments
  • Fake document-sharing notices
  • QR-code phishing
  • Suspicious phone calls
  • Business email compromise

The Canadian Centre for Cyber Security recommends ongoing, tailored cybersecurity training. LAWPRO’s Ontario breach case also identified employee training and awareness as part of the firm’s improved security program.

14. Phishing Simulations

Training tells people what phishing looks like.

Testing shows whether they recognize it.

Periodic phishing simulations can identify employees who need extra help and show whether the firm’s security awareness is getting better.

The goal should not be to embarrass people.

It should be to make a fake Microsoft login page less likely to work when a real attacker sends one.

Your IT provider should be able to show participation and results over time.

15. Device Encryption

Lawyers work everywhere.

Toronto offices.

Vaughan offices.

Court.

Home.

Client locations.

Airports and hotels.

A laptop can get lost or stolen.

That should not automatically expose everything stored on it.

Firm laptops should use full-disk encryption, and encryption status should be centrally monitored.

Encryption is also part of the defence-in-depth approach recommended in Canadian cybersecurity guidance.

Ask your provider: Can you prove every firm laptop is encrypted?

16. Server and Business Data Backups

Every law firm needs reliable backups.

That includes servers and other systems containing important firm or client information.

Backups should run automatically and failures should generate alerts.

But there is another part that matters:

Ransomware should not be able to easily destroy the backup along with the original data.

The Canadian Centre for Cyber Security recommends regularly backing up critical systems to isolated or offline storage.

LAWPRO’s Ontario breach example shows why this matters. That firm had overnight off-site backups and was able to restore file data to the day before its systems were shut down.

17. Microsoft 365 Backup

This deserves its own item.

For many law firms, Microsoft 365 now contains a large amount of the firm’s information.

That can include:

  • Exchange email
  • OneDrive
  • SharePoint
  • Teams data

Your provider should have a clear answer to this question:

How are we independently backing up our Microsoft 365 data?

Cloud services provide resilience, retention and recovery features, but firms should still decide whether an independent backup is needed based on their recovery and retention requirements.

If Microsoft 365 contains important client information, it needs to be part of the firm’s backup strategy.

18. Backup Restore Testing

This may be one of the most important controls on this list.

Backups can fail quietly.

Files can be corrupted.

Credentials can stop working.

Storage can fill up.

A configuration error can go unnoticed for months.

So don’t just ask:

“Are we backed up?”

Ask:

When was our last successful restore test?

The Canadian Centre for Cyber Security specifically recommends periodically testing backups to confirm systems and data can actually be recovered.

Your provider should be able to show evidence of that test.

19. Incident Response and Disaster Recovery

Eventually something will go wrong.

Maybe it’s ransomware.

Maybe an employee’s Microsoft 365 account gets compromised.

Maybe a server fails.

Maybe someone wires money to the wrong account.

The worst time to figure out what to do is while the incident is happening.

Your firm should have a written cybersecurity incident response plan.

At minimum, it should identify:

  • Who contacts the IT provider
  • Who makes decisions
  • Who contacts cyber insurance
  • How systems can be isolated
  • How backups are restored
  • Where emergency contact information is kept
  • How the firm continues operating
  • Who handles outside communications

The Canadian Centre for Cyber Security recommends having an incident response plan and testing it annually. LAWPRO’s breach case also identified development of an incident response plan as one of the firm’s post-attack improvements.

20. Trust Account and Financial Fraud Protection

Law firms have a risk that many other businesses don’t have.

They may move very large amounts of client money.

That makes trust accounts attractive targets.

In June 2026, LAWPRO warned Ontario lawyers about a growing number of unauthorized transfers from trust and general accounts. In one reported case, $1.6 million was removed through eight unauthorized transactions over three days. LAWPRO said the bank’s MFA login and transaction verification processes appeared to have been bypassed.

Your IT provider can’t control every part of the firm’s financial process.

But it should help secure:

  • Computers used for banking
  • User accounts
  • Email
  • MFA
  • Malware protection
  • Web filtering
  • Administrative access

The firm should separately have a strong process for verifying payment instructions.

LAWPRO currently recommends checking trust and general accounts daily for unauthorized transactions, with extra attention around Fridays, long weekends and holidays.

Never treat an email saying “our banking information has changed” as enough proof to move client money.


The 20-Point Law Firm Cybersecurity Checklist

A managing partner doesn’t need to know every technical detail.

But they should be able to ask their IT provider these questions and get clear answers.

  • ☐ MFA is active on important accounts
  • ☐ Passwords are securely managed
  • ☐ User accounts are properly created and removed
  • ☐ Administrator access is limited
  • ☐ Every computer and server has managed EDR
  • ☐ Security threats are monitored
  • ☐ Security updates are managed
  • ☐ Unsupported technology is identified
  • ☐ Firewalls are actively managed
  • ☐ Networks are properly secured
  • ☐ DNS and web filtering are active
  • ☐ Email has advanced phishing protection
  • ☐ Employees receive security training
  • ☐ Phishing testing is performed
  • ☐ Firm laptops are encrypted
  • ☐ Servers and business data are backed up
  • ☐ Microsoft 365 has a backup strategy
  • ☐ Backup restores are tested
  • ☐ An incident response plan exists
  • ☐ Trust and financial systems have additional protection

If you can confidently check all 20, you’re in a much better position.

If the answer to five or six is:

“I’m not sure.”

That’s useful information too.

Your IT Provider Should Be Able to Prove It

There is one more thing we’d add to this checklist.

Don’t just ask whether these controls exist.

Ask for evidence.

A good managed IT provider should be able to show the firm things such as:

  • MFA coverage
  • Endpoint protection coverage
  • Devices missing patches
  • Backup results
  • Restore-test results
  • Security incidents
  • Training completion
  • Phishing-test results
  • Device encryption
  • Outstanding risks

That can be reviewed quarterly with the firm’s partners or management team.

It changes the conversation.

Instead of:

“Is our IT secure?”

You can ask:

“Show us what is protected, what was tested and what still needs attention.”

That’s a much better question.

Cybersecurity for Vaughan Law Firms Is a Managed Process

There is no single product that makes a law firm secure.

Not Microsoft 365.

Not a firewall.

Not antivirus.

Not a backup system.

Cybersecurity works when several layers are managed together.

The Law Society of Ontario’s Rules connect technological competence with the lawyer’s duty to protect confidential information. The Canadian Centre for Cyber Security recommends many of the same technical safeguards discussed above, including MFA, endpoint protection, patch management, least privilege, isolated backups, restore testing, security training and incident response.

LAWPRO’s own reporting shows that the risk isn’t theoretical. Ontario law firms are dealing with network attacks, compromised email and increasingly sophisticated financial fraud.

For law firms in Toronto, Vaughan and across Ontario, your IT provider should be doing more than keeping the computers working.

They should be helping protect the confidentiality of your clients, the continuity of your practice and the money moving through your firm.

How Atomic Guardian Helps Law Firms

Atomic Guardian provides managed IT services and cybersecurity for law firms in Vaughan, Toronto and across the GTA.

Our law firm cybersecurity approach is built around the controls in this checklist.

That includes identity protection, Microsoft 365 security, endpoint protection, security monitoring, email protection, network security, patching, backup, restore testing, employee training and ongoing cybersecurity reporting.

The goal isn’t to sell a collection of security products.

It’s to build a managed security program where the firm can answer three questions:

Are the controls in place?

Are they working?

Can we prove it?

If your current IT provider can’t answer those questions clearly, run through the 20-point checklist with them.

You’ll learn a lot.

This article provides general technology and cybersecurity information and is not legal advice. Law firms should refer to current Law Society of Ontario rules and guidance, LAWPRO resources and applicable privacy laws when determining their professional and legal obligations.

Related industry guidance

Put this guidance into practice

Connect these recommendations to a complete technology and risk-management program. Explore Atomic Guardian’s cybersecurity services for Ontario law firms, including Microsoft 365, legal applications, cybersecurity, vendor coordination, backups, and strategic planning.

These controls are most effective when supported by a consistent program of cybersecurity services, monitoring and remediation.