How should a law firm protect client confidentiality?
By controlling who can open what, protecting the mailbox properly, managing the devices files are opened on, and being able to demonstrate all three. Confidentiality in practice is an access-control problem long before it is a policy problem, and most firms have a policy and unclear access.
The professional obligation is familiar and the technical implementation usually is not. Firms are careful about what is discussed in a lift and much less careful about the fact that everyone in the office can open every matter on the file server, that a departed paralegal's account is still active, or that client documents are being emailed as attachments to personal addresses because it is easier. None of that is negligence; it is what happens when nobody has looked.
Start with document access, because it is where the exposure is broadest. Every person should be able to reach the matters they work on and not the ones they do not, which sounds obvious and is uncommon. That is achievable when documents are organised by area of work with permissions set per area, and effectively impossible in one large shared drive with folders, which is why the structure of your storage is a confidentiality question rather than a tidiness one. Sensitive matters, conflicts and employment files warrant their own restricted areas.
Then the mailbox, which is the single most attacked point in a legal practice. Multi-factor authentication on every account without exception is the baseline, and it matters most for the people who would object: principals travel, work at odd hours and hold the most sensitive correspondence. Beyond that, conditional access rules that consider the device and location of a sign-in turn a stolen password from an emergency into a blocked attempt. The realistic threat is not someone reading one email; it is someone sitting quietly in a mailbox for weeks, learning how the firm talks about settlements.
Devices are the third layer and the one that becomes obvious the first time a laptop is left somewhere. Every machine that opens client material should be encrypted, managed, patched, and remotely wipeable, which is what device management delivers. That includes phones, because a mobile with the firm's email on it holds as much as a laptop and is far easier to leave in a taxi. Bring-your-own devices are workable provided they are enrolled and subject to the same rules.
Sharing deserves its own attention because it is where good practice most often lapses under time pressure. An attachment leaves your control permanently and cannot be recalled if it went to the wrong address, which for a firm is a notifiable problem rather than an embarrassment. A link to a document you host can be restricted to a named recipient, given an expiry and revoked. Making the secure path the fast path is the only way this survives a busy Friday.
Then the part firms underestimate: being able to prove it. Under the Privacy Act's Notifiable Data Breaches scheme a firm must assess a suspected breach and notify where serious harm is likely, and doing that requires knowing who had access and what was reached. Logging, access records and an incident plan with names on it turn a frightening situation into a process. MKF Lawyers' uplift to Essential Eight Maturity Level 1 was as much about producing that evidence as about the controls themselves.
Departures deserve a specific process rather than an ad hoc one, because they are the moment confidentiality is most often lost. Access should be removed the day someone leaves rather than the week after, their mailbox and files reviewed and retained before any retention clock expires, and any matters they owned reassigned. Firms that handle this casually discover months later that a former employee still had access to a shared area nobody thought about.
The honest caveats. No arrangement removes the human element, and the most common breach in any profession remains an email sent to the wrong person. Security that obstructs the work gets circumvented, so the controls have to be built around how lawyers actually operate, including at eleven at night before a filing. And none of this is legal advice about your professional obligations, which are yours and your regulator's. If you want the access and mailbox side handled properly, call 1800 456 567.
Protect the files and the mailbox
We put proper access control, multi-factor authentication and monitoring around a practice's documents and email, and give you the evidence.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business