What IT does a small law firm actually need?
Four things: a practice management system that holds matters, time and trust, document storage that is secure and searchable, email that is protected against interception, and a support arrangement that understands a court deadline is not negotiable. Everything else is built on those.
Legal work has a specific shape that generic IT advice misses. The deadlines are externally imposed and unmovable, so an outage on the wrong afternoon is not an inconvenience but a professional problem. The confidentiality obligations are unusually strong. The money moving through the practice makes it a target. And the record-keeping requirements mean documents matter years after a matter closes. Any IT arrangement for a firm has to be judged against those four realities rather than against a generic checklist.
Practice management is the centre of the system, and it is where most firms have already made their choice: LEAP, Actionstep and Smokeball are the common platforms in Australian small firms, each holding matters, documents, time recording, billing and trust accounting together. The IT question is less which one than whether it is integrated properly with everything else, particularly email and document storage, because a practice management system that staff work around is a filing cabinet with a subscription.
Documents come second and are where firms most often carry avoidable risk. The requirement is straightforward to state and harder to do: everything findable, permissions that reflect who should see what, version history so you know which draft is current, and retention that satisfies your obligations. In a Microsoft 365 firm that means SharePoint structured deliberately rather than a shared drive copied across, with sites and access lists per area of work rather than folders inside one large site.
Email is third and is the most exploited weakness in the profession. Firms discuss settlements, send trust account details and receive instructions by email, which makes a compromised mailbox extraordinarily valuable to an attacker. The realistic scenario is not dramatic: a password is phished, someone watches the mailbox quietly, and at settlement they send amended bank details from a convincing address. Multi-factor authentication on every account and a rule that payment details are verified by phone to a known number are the two controls that prevent most of it.
Fourth is continuity, and here the legal context changes the calculation. A business that loses access to its systems for a day has a bad day; a firm that loses access the day before a filing deadline has a different kind of problem. That means tested backups rather than assumed ones, and a documented answer to how the firm operates while systems are unavailable. It is the reason we treat deadline awareness as part of supporting a legal practice rather than as an add-on, which is how we work with MKF Lawyers.
Underneath all of it sits the security baseline, and for firms the Essential Eight is the practical framework. Multi-factor authentication, restricted administrative rights, patched systems, tested backups and application control cover the attacks that actually happen to practices this size. MKF Lawyers went through exactly that uplift to Maturity Level 1 alongside an enterprise network rebuild, and the reason to do it is not compliance theatre but that the alternative is explaining to a client how their matter was exposed.
One arrangement worth considering for firms with in-house capability is co-managed IT, where a practice manager or an internally capable person handles the day-to-day and an external provider covers security, infrastructure and escalation. It suits firms large enough to have someone technical and not large enough to employ a team, which describes a great many Adelaide practices, and it keeps institutional knowledge inside the firm while removing the single-person dependency.
The honest caveats. Not every firm needs everything at once, and the sensible order is identity and backups first, then documents, then the rest. Practice management migrations are disruptive and should be timed deliberately rather than bundled into an infrastructure project. And technology cannot solve the professional obligations, only support them: the file note, the conflict check and the supervision remain human. If you want an IT arrangement built around how a practice actually runs, call 1800 456 567.
One last piece of advice worth more than any product choice: whoever supports the firm should know the name of your practice management system and how you use it, because a provider who treats it as somebody else's software leaves the practice mediating between two suppliers in the week it matters.
IT that understands court deadlines
We support Adelaide law firms with the practice-management, security and continuity arrangements the work actually requires.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business