← All resources
ArticleLaw firms

Law firm cybersecurity in BC: protecting client files and trust accounts

The controls that protect client files and trust money at a small BC firm, and what Law Society Rule 10-4 asks of you when something goes wrong.

Jake, Umbrella IT·September 15, 2026·5 min read

Plenty of small firms in Vancouver and Burnaby run on a practice management system, a Microsoft 365 or Google mailbox, a few laptops, and one person who looks after the computers between files. For law firm cybersecurity in BC, two areas carry a lot of the risk: the email accounts that trust payment instructions travel through, and the client records the Law Society expects you to keep secure. Below are steps a sole practitioner or a 25-person firm can take on both this month.

What the Law Society of BC expects

Law Society Rule 10-4 says a lawyer must protect all records related to their practice “by making reasonable security arrangements against all risks of loss, destruction and unauthorized access, use or disclosure.” It also says you must notify the Executive Director in writing, immediately, if you have reason to believe you’ve lost control of practice records or that someone has improperly accessed or copied them.

The Law Society’s practice resource on compromised records lists lost devices, theft and cyberattacks as examples. It tells firms to report a breach right away to Coalition, the cyber insurer for the Law Society’s Lawyers Indemnity Fund (LIF), and to LIF itself if an imminent transaction or trust funds are involved. So when a mailbox is hacked at a four-lawyer office in New Westminster, the IT cleanup comes with reporting duties and a call to your insurer.

The trust account risk: fake payment instructions

LIF describes the scam on its page about phony changes in payment instructions. A fraudster gets into the email account of someone on the deal (the vendor client, the realtor, the lender, or the lawyer), reads along until the sale proceeds land in trust, then emails new wiring instructions that appear to come from the real party. The address is often the genuine one with one small change, like an extra letter. Sometimes the email invites you to call a number to confirm, and the fraudster answers. Conveyancing is the obvious target because the amounts are large and closing dates are known in advance, but LIF has seen the same trick used on litigation settlement funds.

What stops it is a phone call the fraudster can’t intercept. LIF’s Funds Transfer Instructions Verification Checklist says never to use the phone number in the instructions. Call a number from the file opening sheet or a reliable directory, and ask for a password you collected from the client when you opened the file. If the instructions change again, you stop, bring in a partner, and verify from the start.

Controls that protect client files

MFA on email and practice software

Turn on multi-factor sign-in for every Microsoft 365 or Google Workspace account, including any login several staff share, like reception@. Do the same for your practice management and accounting tools (Clio, PCLaw or a Dye & Durham product, for example) wherever the software offers it, and for the trust account’s online banking. With MFA on, a stolen password alone won’t get someone in.

Stop people sending email as your firm

LIF also describes fraudsters spoofing a senior lawyer’s real email address to tell someone in accounting to send money. A DMARC record set to quarantine or reject tells receiving mail servers what to do with email that pretends to come from your domain. When we checked the public DNS records of 3,392 Lower Mainland businesses in September 2026, about 81% had no DMARC protection being enforced. Our DMARC guide shows how to check and fix yours.

Share files through a portal instead of attachments

Attachments can sit in the client’s inbox, and in anyone’s they forward them to, for years. A client portal in your practice software, or a OneDrive or Google Drive link restricted to the client’s email address with an expiry date, keeps the file under your control. The Law Society’s cloud computing checklist asks whether that data is encrypted in transit and in storage, and where the servers are.

Encrypt every laptop

BitLocker on Windows and FileVault on a Mac are built in and free. If a laptop is stolen from a car in Surrey, encryption keeps the thief from opening the client files synced to it. LIF’s ten steps for protecting your systems include encrypting laptops and backup media and turning on remote wipe.

Back up, then test the restore

The cloud checklist asks whether you can keep a local copy of your data and whether a copy sits with a third party separate from the cloud provider. You don’t know a backup works until you’ve restored from it, so once a quarter, restore a real client folder and a real mailbox somewhere safe and note how long it took.

When someone leaves the firm

LIF’s list includes cancelling network access when an employee’s job ends. On their last day, disable their Microsoft 365 or Google account, remove them from the practice management system, and change any shared passwords they knew, such as the trust banking login. Convert their mailbox to a shared mailbox so client email isn’t lost, and check it for rules forwarding mail outside the firm.

A law firm cybersecurity checklist for BC firms

  • MFA is on for every mailbox, the practice management system and the trust account banking.
  • Payment instruction changes are confirmed by phone, using a number on file and the client’s password.
  • Your domain has a DMARC record set to quarantine or reject.
  • Client files go out through a portal or restricted link.
  • Every laptop is encrypted and can be wiped remotely.
  • Someone restored real files from backup in the last 90 days.
  • There’s a written checklist for staff departures, and the last one followed it.

If you’d like help working through the cloud checklist and Rule 10-4, we can do it as part of a compliance and security audit. Umbrella IT has been based in Burnaby since 2013, and our IT for law firms starts with how your firm handles files and trust payments before we look at the computers.

Common questions

Do I have to report a hacked email account to the Law Society?

If you have reason to believe someone improperly accessed or copied your practice records, Rule 10-4 requires you to notify the Executive Director in writing, immediately. A Law Society practice advisor can answer questions about your obligations.

Can BC lawyers use Clio or other cloud software?

Yes, with due diligence. The Law Society doesn’t publish a list of approved vendors, and its cloud checklist warns against relying on vendor marketing that says a product meets Law Society rules. The checklist covers where the data is stored and whether records can be produced on demand.

How do small law firms in Vancouver prevent wire fraud?

Treat every change in payment instructions as suspect until you’ve confirmed it by phone, using a number from the file and a password agreed at file opening. LIF suggests using its verification checklist on every file.

If you want to know where your firm stands on email, laptops and backups, book a free IT assessment and we’ll walk through it with you.

Want this checked against your own setup?

Book a free IT assessment and a senior tech will review where your business stands, with no obligation.