CRYPTON practical guides

Cyber health guide

Ten practical questions about client information, payments, access and recovery.

Use these checks with your current IT provider. This guide is a starting point, not an audit or confirmation that your systems are secure.

Do not enter passwords, client names or confidential information.

Make my checklist

1. Client-Data Access

client and financial records need access that follows each person’s role

Check: Review shared folders and practice-system access against current roles.

Ask your IT provider: A current access list and one recent role-change or leaver record.

2. Payment Instruction Changes

payment redirection can look like normal business correspondence until money has already moved.

Check: Confirm that no one can approve changed bank details from an email thread alone.

Ask your IT provider: Ask for the written release-of-funds process showing the known-number call-back and second approval.

3. Suspicious Mailbox Activity

an overseas sign-in or forwarding rule can expose client instructions before anyone sees obvious symptoms.

Check: Confirm who monitors alerts for finance, shared mailboxes and administrators.

Ask your IT provider: Ask who receives overseas sign-in, forwarding-rule, and risky-mailbox alerts, and what the response target is.

4. MFA And Admin Access

trusted admin access still needs limits, logging, and review because admin misuse or compromise has broad impact.

Check: Review admin accounts with the provider and remove access that is no longer needed.

Ask your IT provider: Ask for the current administrator list, MFA status, separate administrator accounts and security log retention.

5. Departed Staff Access

disabling the main account does not confirm that synced files, sessions or personal devices have been cleaned up.

Check: Add personal-device and synced-data checks to the offboarding checklist.

Ask your IT provider: Ask for a recent leaver record showing account disablement, session revocation, device review, and app access removal.

6. Backup Restore Confidence

a backup is only useful if the practice knows it can restore the right data quickly enough.

Check: Run a controlled restore test for one mailbox and one matter-data location.

Ask your IT provider: Ask for the last restore-test date, what was restored, and how long it took.

7. Deadline-Critical Systems

deadline pressure is when people are most likely to use unmanaged copies, personal devices, or risky workarounds.

Check: Document the fallback path for urgent filing, settlement, or client-deadline work.

Ask your IT provider: Ask IT to demonstrate access to current email and matter documents from a second managed device.

8. Device Protection

lost, stolen, and personal devices can keep client documents outside the systems everyone thinks are protected.

Check: Close any gap between firm-managed devices and personal-device access.

Ask your IT provider: Ask for device encryption, remote-wipe coverage, and whether personal devices can sync client documents.

9. AI And Client Data

AI can improve drafting, summaries, research, and admin work, but staff need clear boundaries for client and matter information.

Check: Define two or three useful AI uses and the information that must not be entered.

Ask your IT provider: Ask for the approved AI tools, allowed use cases, and data rules given to staff.

10. Incident Ownership

urgent matter work needs a defined support path if the normal response is too slow.

Check: Agree what counts as urgent and who takes over when matter work is blocked.

Ask your IT provider: Ask what counts as urgent, who to contact and the target response time for practice-blocking issues.

Talk to CRYPTON

Tell us where IT gets in the way of your work. We can discuss the findings and a sensible next step.

Request this guide by email