Legal Tech & Innovation

Cybersecurity and Confidentiality for Lawyers

Client confidentiality now lives on laptops, phones, and cloud drives. Here is how to protect privileged information in a digital practice without a technical background.

Sam Okafor· Legal technology writer7 min read
A tidy desk with an open laptop, a notebook, and a coffee mug in soft daylight
On this page

The duty of confidentiality predates the internet by a few centuries, but nobody bothered to update the instincts. A lawyer who would never leave a client file open on a bus seat will happily email a settlement draft over hotel wifi, save it to a personal Dropbox, and reply to a phishing message that spoofs a partner's name. The obligation has not changed. The surface area has exploded.

If you are early in your career, this is the part of the job that no one teaches properly. Law school covers privilege as a doctrine. It does not cover what happens when your phone syncs a client's medical records to a photo backup you forgot you enabled. That gap is where most real-world breaches live, and it is entirely learnable without becoming a security engineer.

Confidentiality and privilege are not the same thing

Worth getting straight early, because people blur them.

Confidentiality is your professional obligation, owed to every client, covering essentially everything you learn in the course of the retainer. It is broad, it starts before the file formally opens, and it survives after the matter closes and after the client dies. Solicitor-client privilege is a narrower legal protection: it shields certain communications from being compelled as evidence.

The practical point: a breach does not require a courtroom. Leaving a document where the wrong person can read it is a confidentiality problem even if privilege never comes up. In a digital practice, the wrong person is rarely a courtroom adversary. It is a hacker, a misdirected autocomplete in the "To" field, or a shared home computer.

Your provincial law society's rules of professional conduct set out the confidentiality duty and, increasingly, expectations around technological competence. Reading your own province's version once, properly, is time well spent. The Federation of Law Societies of Canada publishes the Model Code that most provinces build from, which is a useful reference point.

The threats that actually reach lawyers

Cinematic hacking is not the risk. The risk is mundane and it is aimed at you specifically, because law firms hold money, deadlines, and secrets in the same place.

  • Phishing and spoofed emails. Someone impersonates a partner, a client, or opposing counsel and asks you to click, log in, or move a file. Legal work is deadline-driven and hierarchical, which is exactly what these messages exploit.
  • Business email compromise. A more targeted cousin: an attacker watches a real estate or settlement file and, at the moment funds are due, emails the client "updated" wire instructions that route the money to them. This one has cost firms and clients real money, and it targets the trust that closings run on.
  • Misdirected communication. Autocomplete puts the wrong "Sarah" in the recipient field. You reply-all on a chain that included a client. You attach the wrong version. The most common breach in any practice is a human hitting send too fast.
  • Lost or unencrypted devices. A laptop left in a taxi is a breach if the drive is not encrypted, and a non-event if it is.
  • Weak or reused passwords. One reused password, exposed in some unrelated website breach years ago, becomes the key to your email and every file it touches.

The most expensive security failure I have seen at a firm was not a hacker breaking in. It was a junior lawyer who trusted an email that looked exactly like it came from the managing partner. The whole scheme cost about four seconds of doubt that never happened.

A laptop and phone on a desk showing security and connectivity
Most breaches are ordinary tools used carelessly, not exotic attacks.

Habits that do most of the work

You do not need a security certification. You need a handful of defaults that make the careless mistake harder to commit.

Lock down the basics first

  • Use a password manager. One strong, unique password per service, generated and remembered for you. This single change eliminates the most common cause of account takeover. Stop reusing passwords, and stop keeping them in a document called passwords.
  • Turn on multi-factor authentication everywhere. Especially email, which is the master key to everything else. An app-based code or a hardware key beats a text message, but any second factor is far better than none.
  • Encrypt your devices. Full-disk encryption is built into current Mac and Windows machines and modern phones. Switch it on. A lost encrypted device is a shrug; a lost unencrypted one may be a reportable breach.
  • Keep software updated. Most patches close holes that are already being exploited. "Remind me tomorrow" is a small daily gamble with client data.

Slow down before you send

Speed is the enemy of confidentiality. Build a two-second pause into anything that leaves your control.

  1. Check the recipient field before every send, and check it again when the message contains an attachment or client detail.
  2. Confirm changed payment or wire instructions through a channel you already trust, ideally a phone number you had before the email arrived, never the number in the suspicious message.
  3. Assume any unexpected link or login prompt is hostile until proven otherwise. Type the address yourself rather than clicking.

Mind where the data lives

Know which cloud tools your firm actually sanctions, and use those. Personal file-sharing accounts, consumer messaging apps, and your own laptop's downloads folder are where confidential material quietly leaks out of the firm's protections. If you work from home, keep client work off shared family devices and away from smart speakers that are always listening.

When you are the whole IT department

Solos and small firms carry the same duty as a national firm with a security team, minus the security team. That is not hopeless. It just means choosing tools that are secure by default and not improvising.

Pick reputable, legal-specific practice management and document software where you can, since it tends to bake in encryption, access controls, and audit trails. Use a business-grade email and cloud suite rather than a free personal account, because the paid tiers give you administrative controls that consumer accounts do not. And write down a short, boring plan for what you do if a device goes missing or an account is compromised, because the worst time to invent that plan is at 2 a.m. during an incident.

If you are weighing firms during your job search, this is a fair thing to ask about. A firm that can describe how it protects client data, and how it trains juniors to do the same, is telling you something good about how it is run. Our guide to questions to ask in an articling interview has room for one about their systems.

Two colleagues reviewing something together at a bright table
Ask how a firm protects client data; the answer tells you how the place is run.

If something goes wrong

Breaches happen to careful people. What separates a manageable incident from a career problem is the response, not the perfection.

Report it internally and immediately. The instinct to quietly fix it yourself and hope no one notices is the single worst move, because it turns a technical problem into a candour problem. Firms have protocols and, often, cyber insurance; both work far better when triggered early. Depending on what was exposed and where, there may be obligations to notify the client, the law society, or a privacy regulator, and those clocks start ticking from discovery.

Then learn from it without spiralling. One misdirected email is not a referendum on your fitness to practise. Pretending it did not happen might be.

The mindset that lasts

Treat client data the way you would treat a client's physical file: something you are borrowing, responsible for, and expected to return in the condition you found it. Every convenience that makes your day faster, autofill, cloud sync, one-click login, is also a small door someone else might use. You do not have to be paranoid. You have to be deliberate.

This is genuinely part of practising law now, not a side quest for the technically inclined. If you want to build the broader skill set, our legal tech writing goes deeper on the tools worth knowing, and when you are ready to find a firm that takes this as seriously as you do, start with the current openings on our jobs board.

The lawyers who handle this well are not the ones with the fanciest software. They are the ones who paused for two seconds before hitting send.

S

Written by

Sam Okafor

Legal technology writer

Sam follows how technology is reshaping legal work, with a healthy skepticism for hype. He is most interested in what genuinely helps lawyers do better work, and what quietly does not.

Keep reading

A laptop open on a desk with legal documents beside it
Legal Tech & Innovation7 min read

What AI Actually Changes for New Lawyers in Canada

The honest version: AI is quietly reshaping parts of legal work while leaving the hard parts untouched. Here is what shifts, what does not, and how to build real skill.

Sam Okafor